Privacy Policy
Last updated: August 8, 2026
Exactly two optional Premium features use an Email Elysium server, because they cannot work without one: open tracking and meeting scheduling. Both are off by default, require your explicit opt-in, and are described precisely below. If you never enable them, this extension makes no network connections other than to Google.
What runs 100% locally (free and premium alike)
- Reading your inbox: the extension parses the message list Gmail has already drawn in the page (sender, subject, snippet, date, read/unread, and whether Gmail shows its own "Unsubscribe" link). It cannot see anything Gmail hasn't rendered, and it has no way to send, modify, delete, or label your mail. There is no API access of any kind, so there's nothing at the account level for a bug or a compromised extension to abuse.
- Folder classification, rules, rule suggestions, smart folders (Urgent / Needs reply / Awaiting reply), snooze, unsubscribe surfacing, analytics dashboard, network graph
- All of the above store data only in
chrome.storage.localon your device. Uninstalling the extension deletes it.
Payments (Premium)
Payments are processed by ExtensionPay (extensionpay.com) and Stripe. We never see your card details. The extension contacts extensionpay.com only after you click "Upgrade" or "Restore purchase"; a free install that never clicks those buttons makes zero requests to it. What ExtensionPay stores about you is governed by their privacy policy.
Optional server features (Premium + explicit opt-in, off by default)
If, and only if, you enable them, these features talk to our server (a Cloudflare Worker):
Open tracking. When you switch "Track opens" on for a specific email, an invisible tracking pixel is added to that email. When a recipient's mail client loads the pixel, our server records: the pixel's random token, the time, the user-agent string, and a keyed cryptographic hash of the IP address (never the raw IP). We never receive the email's content, subject, or recipient list: only a random token and, where available, a Gmail thread identifier. Tracking is per-email: nothing is tracked unless you switch it on for that message.
Meeting scheduling. If you set up a booking page, our server stores your display name, chosen page handle, weekly availability window, and timezone. When someone books a slot, it stores the time, their name, the email address they enter, and an optional note, the minimum needed to hold the booking.
Both features are keyed by a random installation identifier that contains no personal information. Disabling a feature stops all associated network activity immediately.
What we never do
- No analytics, telemetry, fingerprinting, or usage tracking of you
- No AI/model calls; no email content ever leaves your browser
- No selling, sharing, or transferring of data to third parties
- No Gmail permission, Google sign-in, or OAuth token of any kind, ever
What we read from the page, and what we do with it
What we read. Email Elysium has no Google API access, so there is no scope or token defining what it can see. Instead it reads exactly what's visible in Gmail's own rendered message list in your browser tab: sender name/address, subject, a short preview snippet, the date, read/unread state, and whether Gmail is already showing its own "Unsubscribe" link on that row. It never reads message bodies or attachments: Gmail doesn't render those in the list view, and the extension only parses what's on screen.
How it is used. Solely to provide the user-facing features you can see: sorting messages into your folder tree, running your rules, generating rule suggestions, computing the Urgent / Needs-reply / Awaiting-reply smart folders, snooze, unsubscribe surfacing, the local analytics dashboard and the network graph. All of this computation happens inside your browser.
Aggregated and derived data. The folder assignments, counts, charts and graph layouts the extension derives from your mail are also stored only on your device and are never transmitted anywhere.
Transfer. Nothing read from your inbox, raw or derived, is ever transmitted to Email Elysium's servers, sold, or shared with any third party, including advertisers, data brokers, or AI/ML providers. It does not leave your browser.
How your data is protected
- There is no Google credential to protect: no OAuth token exists anywhere in the extension, because it never asks Google for one.
- Everything read from your inbox is stored in
chrome.storage.local, inside Chrome's extension sandbox on your own device, not on our servers. - The extension has a strict, exhaustive network allowlist enforced in its manifest:
mail.google.com(to inject the sidebar into the page you're already viewing, no API calls), and, only for the two opt-in Premium features, extensionpay.com and our own Cloudflare Worker. It cannot contact anything else. - The optional Premium server (Cloudflare Worker + D1) never receives Gmail content, subjects, or recipient lists. Requests are authenticated with a random 128-bit install key, served over TLS, and visitor IPs are stored only as a keyed cryptographic hash, never in raw form.
- There is nothing to revoke: uninstalling the extension, or using the in-app Full wipe control, immediately deletes everything it ever read.
Data retention & deletion
- The local email index is capped at your most recent 1,000 messages; older entries are dropped automatically as new mail arrives.
- All local data is erased when you uninstall the extension, and can be erased at any time from the in-app Full wipe control.
- Server-side data exists only if you opted into a Premium server feature. Email us at [email protected] with your booking-page handle or the email used at purchase and we will delete it within 30 days.
No Google API use
As of version 2.0, Email Elysium makes no calls to any Google API and requests no
Google OAuth scope, so the
Google API Services User Data Policy (opens in new tab)
and its Limited Use requirements do not apply to this extension: there is no Google
user data received from an API to be subject to them. Earlier versions (before 2.0)
used the read-only gmail.readonly Gmail API scope under that policy; this
section is kept for historical transparency.
AI/ML. Email Elysium contains no AI or machine-learning models and makes no calls to any AI service. Rule suggestions and smart-folder flags are produced by local pattern matching in your browser. Nothing read from your inbox is ever used to develop, improve or train any AI/ML model, and is never transferred to any third-party AI/ML service.
Contact
Questions or deletion requests: [email protected].