Privacy Policy

Last updated: August 8, 2026

As of version 2.0, Email Elysium requests no Gmail permission at all. There is no Google sign-in, no OAuth consent screen, and no Gmail API call. The extension reads the message list Gmail has already rendered in your own browser tab, the same way any extension can read a page you're looking at, and does every bit of sorting, rule matching, and analytics locally from there. Nothing about your inbox is cached anywhere but your device, and nothing is sent to us or anyone else.

Exactly two optional Premium features use an Email Elysium server, because they cannot work without one: open tracking and meeting scheduling. Both are off by default, require your explicit opt-in, and are described precisely below. If you never enable them, this extension makes no network connections other than to Google.

What runs 100% locally (free and premium alike)

Payments (Premium)

Payments are processed by ExtensionPay (extensionpay.com) and Stripe. We never see your card details. The extension contacts extensionpay.com only after you click "Upgrade" or "Restore purchase"; a free install that never clicks those buttons makes zero requests to it. What ExtensionPay stores about you is governed by their privacy policy.

Optional server features (Premium + explicit opt-in, off by default)

If, and only if, you enable them, these features talk to our server (a Cloudflare Worker):

Open tracking. When you switch "Track opens" on for a specific email, an invisible tracking pixel is added to that email. When a recipient's mail client loads the pixel, our server records: the pixel's random token, the time, the user-agent string, and a keyed cryptographic hash of the IP address (never the raw IP). We never receive the email's content, subject, or recipient list: only a random token and, where available, a Gmail thread identifier. Tracking is per-email: nothing is tracked unless you switch it on for that message.

Meeting scheduling. If you set up a booking page, our server stores your display name, chosen page handle, weekly availability window, and timezone. When someone books a slot, it stores the time, their name, the email address they enter, and an optional note, the minimum needed to hold the booking.

Both features are keyed by a random installation identifier that contains no personal information. Disabling a feature stops all associated network activity immediately.

What we never do

What we read from the page, and what we do with it

What we read. Email Elysium has no Google API access, so there is no scope or token defining what it can see. Instead it reads exactly what's visible in Gmail's own rendered message list in your browser tab: sender name/address, subject, a short preview snippet, the date, read/unread state, and whether Gmail is already showing its own "Unsubscribe" link on that row. It never reads message bodies or attachments: Gmail doesn't render those in the list view, and the extension only parses what's on screen.

How it is used. Solely to provide the user-facing features you can see: sorting messages into your folder tree, running your rules, generating rule suggestions, computing the Urgent / Needs-reply / Awaiting-reply smart folders, snooze, unsubscribe surfacing, the local analytics dashboard and the network graph. All of this computation happens inside your browser.

Aggregated and derived data. The folder assignments, counts, charts and graph layouts the extension derives from your mail are also stored only on your device and are never transmitted anywhere.

Transfer. Nothing read from your inbox, raw or derived, is ever transmitted to Email Elysium's servers, sold, or shared with any third party, including advertisers, data brokers, or AI/ML providers. It does not leave your browser.

How your data is protected

Data retention & deletion

No Google API use

As of version 2.0, Email Elysium makes no calls to any Google API and requests no Google OAuth scope, so the Google API Services User Data Policy (opens in new tab) and its Limited Use requirements do not apply to this extension: there is no Google user data received from an API to be subject to them. Earlier versions (before 2.0) used the read-only gmail.readonly Gmail API scope under that policy; this section is kept for historical transparency.

AI/ML. Email Elysium contains no AI or machine-learning models and makes no calls to any AI service. Rule suggestions and smart-folder flags are produced by local pattern matching in your browser. Nothing read from your inbox is ever used to develop, improve or train any AI/ML model, and is never transferred to any third-party AI/ML service.

Contact

Questions or deletion requests: [email protected].