Privacy Policy
Last updated: March 7, 2026
GmAssist ("the Extension") respects your privacy and is committed to protecting your personal information. This policy describes what information the Extension collects and how it is used.
1. Information We Collect
The Extension handles the following information:
- Google Account Information — We retrieve your email address and display name for login authentication.
- Email Content (via Gmail API) — We access your inbox threads through the Gmail API to provide AI analysis, summarization, and reply generation. Email content is temporarily sent to our server for processing.
- Email Sending (via Gmail API) — When you explicitly choose to send, AI-generated replies are sent through the Gmail API on your behalf.
- Usage Data — We record daily request counts and token usage.
- Feedback — We collect optional survey responses submitted upon uninstallation.
- Scheduled Send Data — We store scheduling information (send date/time, recipients, email content) in Firestore and send the email via Gmail API at the specified time. Email content is discarded after successful delivery.
- Open Tracking Data — For emails with tracking enabled, we record the recipient's open date/time and open count. We do not collect recipient IP addresses.
- Reply Queue Data — We retrieve email metadata (sender, subject, date) from your inbox via Gmail API for priority scoring. Email body content is not stored on our server.
2. How We Use Information
- Providing AI analysis of email threads (summarization, reply generation, action item extraction)
- Reading your inbox via Gmail API for priority analysis and bulk summarization
- Sending email replies via Gmail API (only upon your explicit action)
- User authentication and plan management
- Usage limit management
- Sending emails at scheduled times via the scheduled send feature
- Visualizing email open status via open tracking
- Analyzing priority of unreplied emails via the smart reply queue
- Service improvement
3. Email Data Handling
The Extension accesses your email data through the Gmail API. Regarding the email data retrieved:
- It is used solely for AI analysis and reply generation.
- It is not permanently stored on our servers.
- It is not sold or shared with third parties.
- It is not used for advertising or ad targeting.
- AI analysis uses the OpenAI API. Per OpenAI's API data usage policy, data sent via the API is not used for model training.
- Scheduled send email content is stored encrypted in Firestore until delivery and discarded after sending.
- Open tracking embeds a 1x1 transparent pixel image in emails, and our server detects when the image is loaded. Recipient IP addresses are not collected or stored.
4. Google API Services User Data Policy
GmAssist's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Data obtained from Gmail API is used only to the extent necessary to provide the Extension's features.
- Data is not transferred to or disclosed to third parties without the user's explicit consent.
- Data is not used for serving advertisements.
- A human may read data only for security purposes, to comply with applicable law, or with the user's explicit affirmative agreement.
5. Data Storage
- Account information & usage data — Stored in Firebase Firestore (Google Cloud).
- Payment information — Managed by Stripe. The Extension does not directly handle credit card information.
- Email content — Discarded from our server after analysis. No permanent storage.
- Scheduled send data — Stored in Firestore until delivery. Email content is deleted after sending. Schedule information (date/time, status) is retained for administrative purposes.
- Tracking data — Stored in Firestore. Deleted when a user requests account deletion.
6. Third-Party Services
The Extension uses the following third-party services. Please review their respective privacy policies:
- Firebase (Google) — Authentication, database, hosting
- OpenAI — AI analysis processing
- Stripe — Payment processing
7. Data Deletion
Users may request account deletion at any time. When an account is deleted, all associated data (account information, usage history) will be promptly removed.
8. International Data Transfer
For email analysis, email content is sent to the OpenAI API (United States). Data is processed according to OpenAI's API data usage policy and is not used for model training. Account information is stored in Firebase (Google Cloud).
9. Age Restrictions
This service is intended for users aged 18 and older. Users under 18 should obtain parental consent before use. We do not intentionally collect personal information from minors.
10. Cookies
The Extension's web pages use cookies and local storage to maintain authentication state. We do not use tracking cookies.
11. Changes to This Policy
This policy may be updated as needed. Significant changes will be announced on this page.