Leadomator tools

Gmail Sender Guard privacy policy

Effective October 10, 2026

Gmail Sender Guard is a Chrome extension. Before an email is sent, it warns when the From address does not match the reply, or the address usually used for that recipient. This policy describes what the extension does with information.

What it accesses

The extension signs in through Google using chrome.identity.launchWebAuthFlow. The permission requested is the read-only Gmail scope https://www.googleapis.com/auth/gmail.metadata.

With that permission it reads only the headers of the user's sent emails: From, To, Cc, Bcc, and the date. It never reads message bodies or attachments. It also reads the Gmail account's email address, so it knows which account the index belongs to.

On Gmail's page, when the user presses Send, the extension reads the From, To, Cc, and Bcc addresses of the message being written. On a reply it reads which of the user's addresses the original message was sent to. It reads the subject only to tell a reply from a new email, and it does not keep the subject. It does not read the body of the open message.

If Chrome is signed in to a Google account, the extension can read that account's email address. It uses the address only to connect that account.

What it stores

Everything the extension keeps is stored in chrome.storage on the user's own browser, in local storage and in sync storage.

Local storage holds a sent-mail index, by default the 3,000 most recent sent messages per account. The user can change that number in settings. Each entry is the message date, the From address, and the recipient addresses taken from To, Cc, and Bcc. Local storage also holds the email addresses of connected accounts, the addresses those accounts send from, and a 30-day pause for a recipient when the user chooses not to save a default.

Sync storage holds whether the extension is on, the history size, aliases the user adds, and the default sending address saved for a recipient.

The Google sign-in token is kept in memory so the extension can refresh the index. It is not written to storage.

Nothing is sent to any server run by the developer or any other third party. Nothing is sold or used for ads. The only servers the extension contacts are Google's: to sign in, and to read the sent-mail headers above. If Chrome Sync is on, Chrome may sync the settings in sync storage through the user's Google account. The sent-mail index stays in local storage and is not part of that sync.

Why

The extension uses this information only to warn the user when the From address does not match the reply or their history with the recipient, and to switch the sender or remember a default when the user asks it to.

Control

In the extension's settings, Disconnect removes that account and deletes its sent-mail index from the browser. Saved default addresses can be removed there as well. Uninstalling the extension removes all of the data it stored.

Disconnecting an account inside the extension does not cancel Google's permission. Access can be revoked at https://myaccount.google.com/permissions.

Google API data

Gmail Sender Guard's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements, and the Google API Services User Data Policy, including the Limited Use requirements.

Contact

Questions about this policy: use the contact form on leadomator.com.