Checker for Gmail™

Checker for Gmail™ is a browser extension that checks your signed-in Gmail accounts for new mail, shows unread badges and desktop alerts, and lets you read, search, organize, reply to, and send messages after Google OAuth authorization. Gmail mail data never goes through SafeX; supported non-Chrome browsers send only encrypted OAuth authentication values to SafeX's stateless token exchange and refresh proxy.

Add to Chrome

Chrome: v1.2.2 · Install via Chrome Web Store

Why Checker for Gmail™

Instant notifications

Unread badges, desktop alerts, sound, and TTS let you notice new mail without switching back to Gmail.

Multiple accounts

Shows Atom-visible accounts and basic unread information from your current Gmail website sign-in; OAuth is not required for this step.

Fast in-extension actions

After Google OAuth authorization, native Gmail conversations stay grouped while you read the full thread, search, mark read, archive, delete, reply, or compose in the popup or side panel.

Privacy-first

Gmail mail data, templates, signatures, and scheduled bodies remain in the current browser profile; optional KeyLockr sync is restricted to the encrypted IMAP/SMTP account bundle. There is no SafeX mail server or telemetry. Non-Chrome web OAuth values transit encrypted to a pinned server key, are decrypted only in proxy memory, and are not stored or logged by SafeX.

Your email never goes through SafeX servers

Where your data goes with Checker for Gmail™ Your device exchanges mail directly with your mail provider. The optional KeyLockr sync carries only the encrypted portable IMAP account bundle and never message bodies. The SafeX OAuth proxy is used only by the non-Chrome sign-in path, and it never receives mail. Your device Checker for Gmail™ extension Mail is fetched and cached here. Search, compose, send: all local. Atom feed: unread list and badge. Gmail API: bodies, search, send. IMAP/SMTP via the local component. Your mail provider Gmail, or the IMAP/SMTP provider you choose. Sending and receiving happen only on this line. SafeX OAuth proxy Used only by the non-Chrome sign-in path. OAuth values are encrypted in both directions. The proxy decrypts them in process memory, adds the client secret, forwards them to Google, and returns Google's reply. It is discarded right after; never stored, never logged. KeyLockr sync (optional) Off by default; you turn it on yourself. It syncs only the encrypted portable IMAP account bundle. Templates, scheduled messages, and bodies stay profile-local. OAuth tokens are never written to KeyLockr.
Homepage overview: mail moves only between your device and your mail provider.
  • Mail is sent and received only between your device and the mail provider you choose.
  • The KeyLockr remote persistence you enable yourself syncs only the encrypted IMAP/SMTP account bundle and no message bodies.
  • OAuth values are encrypted in transit; the SafeX proxy decrypts them only briefly in process memory, forwards them to Google, returns Google's reply, and never stores or logs them.
  • Without OAuth, the extension processes only basic Gmail Atom information such as account email, sender, subject, snippet, time, and unread count; Atom does not provide full messages or mail-action permission.
  • Full messages, search, changes, replies, and sending require Google OAuth. On Google Chrome, Chrome Identity manages the access token and the extension does not persist it. The supported non-Chrome path creates an independent local vault for each browser profile, stores each account's refresh grant as AES-256-GCM ciphertext, and keeps short-lived access tokens only for the browser session.
  • For non-Chrome web OAuth, the authorization code, PKCE verifier, access token, and refresh token are encrypted in both directions using a SafeX public key pinned in the extension and a fresh per-request key. TLS/CDN intermediaries see ciphertext; the SafeX proxy decrypts only in process memory to forward to Google and never stores or logs the values. Source IP is used only in memory for security rate limiting.
  • Gmail data is processed inside the extension and cached locally, never uploaded to SafeX; the KeyLockr remote persistence you enable yourself syncs only the encrypted IMAP/SMTP account bundle.
  • SafeX servers never touch Gmail mail data or message content; this backend only serves pages, distributes the local component, and provides the stateless OAuth token proxy described above.
  • Signing out of the Gmail website does not automatically revoke extension OAuth; use Disconnect account in the extension or revoke it in Google Account permissions.