Checker for Gmail™
Primary navigation Security Local mail component Chrome Web Store

Privacy Policy

Last updated: August 14, 2026

1. Introduction

SafeX Inc. ("we", "our", "us") provides the Checker for Gmail™ browser extension, its local mail component, and this website (gmail.safex.cloud). Whether you use Gmail or an IMAP/SMTP account you add, sending and receiving mail data and attachments happens only between your device and the email provider you chose; gmail.safex.cloud does not receive, proxy, store, or log messages, attachments, or IMAP/SMTP credentials. Only when you enable optional KeyLockr mode is the encrypted portable IMAP/SMTP account bundle synchronized to your KeyLockr AppData; templates, signatures, scheduled messages and bodies, Gmail data, and OAuth values remain in the current browser profile. Supported non-Chrome Chromium browsers use SafeX only as a stateless Google OAuth exchange and refresh proxy: OAuth authentication values are encrypted to a pinned server public key, decrypted only in proxy process memory, and never stored or logged by SafeX.

2. How Access Works: Gmail and Other Email Accounts

After you accept the first-run disclosure, the extension uses your current Gmail website sign-in to read the Gmail Atom feed directly. Atom provides only basic unread information—account email, unread count, sender, subject, snippet, and time—and does not provide full messages, search, changes, or sending permission. Those advanced features require Google OAuth; Google may ask again if access expires or is revoked.

In Google Chrome, the extension uses Chrome Identity: Chrome manages the access token and the extension does not persist it. In supported non-Chrome Chromium browsers, the extension uses Google's web OAuth with authorization code, PKCE, and state. The extension package pins SafeX's X25519 server public key and creates a fresh ephemeral X25519 key and nonce for every exchange or refresh, using a libsodium authenticated box to encrypt the authorization code, PKCE verifier, or refresh token. The proxy authenticates and decrypts only in process memory, injects the server-side client secret, and forwards to Google; Google's returned access/refresh tokens and errors are encrypted back to that ephemeral client key. The extension rejects plaintext or unauthenticated responses. This prevents TLS/CDN intermediaries from reading or forging OAuth content, although they can still observe connection source, destination, timing, and size. It is not end-to-end encryption from the extension to Google because the proxy must obtain plaintext in memory before forwarding it to Google. SafeX does not store or log these values. Source IP is used only in memory for security rate limiting and is not written to application or /oauth reverse-proxy access logs. Gmail mail data is never sent to this proxy.

Only after you explicitly choose "Add another email account" and continue does the extension request the optional Native Messaging permission. That permission is used only to connect to the SafeX mail component installed on the same device; the component connects directly from your device to the IMAP and SMTP servers you enter and does not connect to gmail.safex.cloud. Account settings and passwords or app passwords are encrypted in the application vault, which stays on this device by default and is additionally synchronized to your KeyLockr AppData if you enable the optional KeyLockr mode. They are decrypted only in extension session memory when a connection is needed and passed through Native Messaging to one local component port's memory. The local component creates no account file, does not use the system Keychain, and clears port-held account data on lock, disconnect, or idle. Gmail features do not depend on this optional permission.

If you then explicitly choose "Import from Thunderbird," the local component checks only the standard Thunderbird profile registry and its registered account settings, logins.json, and key4.db. It does not read message bodies, recursively scan the disk, or accept an arbitrary file path from the extension. A one-shot helper dynamically loads the password service from your installed Thunderbird and asks for the Thunderbird Primary Password only if needed. That Primary Password passes through Native Messaging and the main local component to the helper only in device memory; it is not stored, logged, or uploaded. The helper seals each decrypted account password directly to an ephemeral key for this extension and exits; the main local component can only forward that ciphertext, while the UI and gmail.safex.cloud do not receive the decrypted account passwords. Thunderbird OAuth tokens are not imported; OAuth accounts require manual setup and fresh authorization.

3. What We Collect and Process

Your mail data is processed only in the extension, browser, and same-device local mail component for display, notifications, message rendering, search, and mail actions you initiate. Messages and attachments travel directly to or from the applicable email provider and are never uploaded to or stored by SafeX or KeyLockr; optional KeyLockr persistence is restricted to the encrypted IMAP/SMTP account bundle.

  • Basic reading: account email, unread count, sender, subject, snippet, and time via Gmail Atom using the current Gmail website sign-in; this path does not require OAuth.
  • OAuth reading: after authorization, search results, full HTML/plain-text message bodies, recipients, and necessary reply headers via Gmail API.
  • Actions: archive, delete by moving to trash, mark read/unread, star, mark important, report spam, reply, compose, and similar flows you actively trigger are completed by the extension directly through the Gmail API.
  • IMAP/SMTP reading and actions: after you add another email account, the local component obtains message lists, search results, bodies, and attachments directly from that provider and performs supported marking, moving, deleting, and SMTP sending that you initiate. This data does not pass through the SafeX website backend.
  • IMAP/SMTP authentication: account settings and credentials persist only as encrypted vault ciphertext and never enter Chrome Sync, settings exports, URLs, logs, the system Keychain, or gmail.safex.cloud. If you enable the optional KeyLockr mode, that same ciphertext is also synchronized to your KeyLockr AppData, which sees only authenticated ciphertext and required non-secret envelope metadata (schema version, key ID, app tag); without it the ciphertext stays on this device. During a connection, credentials exist only in extension and local-component memory and are provided only to the email provider you chose for authentication.
  • Thunderbird import: only supported accounts you explicitly select are imported. A saved password is decrypted inside the one-shot helper, immediately sealed to the extension, tested through the existing account flow, and stored in the encrypted application vault — the same vault as manually added accounts, so with KeyLockr mode enabled it is likewise synchronized to your KeyLockr AppData. Settings and credentials are not uploaded to SafeX.
  • Authentication handling: on the supported non-Chrome web OAuth path, authorization codes, PKCE verifiers, and OAuth tokens transit SafeX's stateless proxy only after encryption with a pinned server public key and a fresh per-request key, as described in Section 2. This is an authentication-data path through proxy memory, not a Gmail mail-data path.
  • Feedback: the external Feedback link in the footer opens the feedback service at safex.cloud. The content and email you deliberately submit are sent to the SafeX ticket service only to handle your feedback. Do not paste Gmail message content, cookies, passwords, or other sensitive data.

4. Limited Use Commitment

We comply with the Limited Use requirements of the Chrome Web Store User Data Policy and the Google API Services User Data Policy: we do not sell your data; we do not use it for advertising; we do not allow humans to read it; we do not use it for any purpose unrelated to the extension's core functionality; and we do not use Gmail data to train AI or models. The Gmail OAuth permissions requested by the extension are used only to read, modify, and send Gmail messages you manage in the extension.

The same commitment applies to IMAP/SMTP accounts you add: messages, attachments, and credentials are used only for the local mail functions you request; they are not sold, used for advertising or model training, or made available for SafeX personnel to read.

5. Third-Party Sharing: Only Services You Choose

We do not share your mail data or credentials with any third party except in two cases: (1) direct exchanges with the email provider you chose, to perform mail functions you request; and (2) when you enable optional KeyLockr mode, only the encrypted portable IMAP/SMTP account bundle is synchronized to your KeyLockr AppData. KeyLockr is a third-party remote persistence service; even though it sees authenticated ciphertext and required non-secret envelope metadata (schema version, key ID, app tag), that remains a third-party storage boundary. Templates, signatures, and scheduled messages and bodies never enter KeyLockr. After you deliberately trigger and first confirm the "AI draft" feature (see Section 7), it only copies a drafting prompt to your clipboard and opens the AI website you selected; the extension does not automatically transmit the content. That AI service receives it only if you paste or submit it yourself.

6. Storage, Retention and Deletion

On your device (with optional encrypted IMAP account sync)

The mail-list cache (IndexedDB, including recent Gmail or IMAP inbox senders, subjects, snippets, unread counts, opaque message IDs, thread IDs when available, and necessary headers), the offline action-intent queue, and any custom notification sound are stored only on your device and are never synced anywhere. Search results are shown only in the current UI memory and are not written to the 30-day mail cache. Full message bodies and attachments are processed only when you open or request them for rendering or download; they are not included in settings exports and are not sent to SafeX servers.

The extension also stores detected Gmail account email addresses, the last selected account, the ignored-account email list, and local seen, unread, and polling state in chrome.storage.local. This account state stays on the device, is not Chrome-synced or included in settings exports, and is never sent to SafeX. An ignored email remains ignored across account reprobes and extension updates; choosing "Watch this account" removes that preference.

For IMAP/SMTP accounts, the email address, server settings, folder mappings, and password or app password persist only inside authenticated ciphertext in the application vault; with KeyLockr mode enabled, that same ciphertext is also synchronized to your KeyLockr AppData. The decrypted data key is kept only in browser session storage. Ordinary chrome.storage.local keeps only a random account ID without the address and its unread, polling, cache, and offline-intent partition state. The local component does not write accounts or credentials to files or the system Keychain.

When you explicitly schedule a Gmail or IMAP/SMTP message, its recipient, subject, body, send time, and job status persist only inside authenticated ciphertext in the current browser profile. They never enter KeyLockr, Chrome Sync, settings exports, ordinary plaintext storage, logs, or SafeX servers. Confirmed successful delivery or cancellation removes the encrypted job; a job proven not submitted (blocked) or with an uncertain delivery result remains until you retry or remove it. A job interrupted while sending is marked uncertain and is never automatically resent.

When you select an outbound attachment in compose or quick reply, the extension reads it only in sequential 256 KiB chunks. Each attachment has an independent random data key; its file name, MIME type, account identity, and content are temporarily stored only as authenticated AES-256-GCM ciphertext in local IndexedDB, while the data key remains only in browser session storage. The attachment travels directly to Gmail or your chosen SMTP provider, never through SafeX. Temporary ciphertext and its key are removed after a send result, when you remove the attachment or account, or at the 30-minute expiry; an uncertain delivery result is never retried automatically. Because of that 30-minute limit, scheduled sends do not accept attachments.

Only when you explicitly choose "Save message locally" in message details does the extension copy the complete conversation into a separate local-archive IndexedDB. It is independent of the replaceable 30-day inbox cache and its LRU eviction. Each item is limited to 4 MiB and each account to 500 items or 256 MiB. Gmail archives follow the existing local model and remain unencrypted on this device. IMAP archives use authenticated AES-256-GCM encryption with the vault mail subkey; account and message identities appear outside ciphertext only as irreversible HMAC tokens, and a locked vault cannot read them or fall back to plaintext.

Local-archive search checks headers and bodies only after decrypting one item at a time in memory and creates no plaintext search index. Remote images are always blocked in the archive viewer. Archive content never enters Chrome Sync, settings exports, logs, or SafeX servers. You can search, read, and remove individual items from the Accounts page.

The IMAP mail-list index does not use Gmail's plaintext cache rows. It is stored in a separate local encrypted IndexedDB: message IDs, senders, subjects, and snippets remain inside authenticated ciphertext. Only irreversible HMAC tokens, timestamps, and byte counts remain outside for partitioning, paging, and capacity control, and are bound as authenticated data; account, folder, and message identity are checked again after decryption. Gmail cache behavior remains unchanged and does not enter the IMAP vault.

An IMAP body you open may be retained in the same separate database as chunked AES-GCM ciphertext for offline fallback when the Native component is temporarily unavailable; attachments use the same bounded chunked ciphertext format. Account, message, body or attachment identity, content, and attachment metadata remain inside ciphertext. Only AAD-authenticated HMAC tokens, timestamps, chunk positions, and byte counts remain outside. Clearing local mail cache or removing an account deletes its indexes and blobs together by irreversible message token; while the vault is locked, the cache is neither read nor written and never falls back to plaintext.

Body and attachment last-access time lives in a separate small authenticated sidecar, so a cache hit re-encrypts only the sidecar rather than the large content ciphertext. Local-retention windows, the 256 MiB per-account and 512 MiB global budgets, browser-storage recovery from an 80% high watermark toward 70%, and quota-error recovery evict only local blobs by LRU; they do not delete list indexes or mail held by the provider. Turning local storage off only stops new blob reads and writes; it neither converts existing ciphertext to plaintext nor deletes it automatically.

Explicit remote images in an opened message are shown by default and loaded directly by your browser from the sender or its image host; this may reveal your IP address and open time to that party. You can turn off Show remote images in extension settings. Hidden remote-loading paths such as CSS, SVG, audio, and video are blocked in either setting; notifications never load remote images.

OAuth access

Chrome-path tokens are managed and cached by Chrome Identity and are not persisted by the extension. For the non-Chrome web path, each browser profile generates a random vaultId; k_oauth is derived from the unlocked vault DEK with an independent HKDF domain, and each account's persistent refresh grant is encrypted with AES-256-GCM and AAD binding the schema, vaultId, keyId, and account key before it enters chrome.storage.local. Short-lived access tokens exist only in chrome.storage.session and disappear when the browser closes. Grants never enter chrome.storage.sync, IndexedDB, settings exports, URLs, logs, or the system Keychain. If an account's access token becomes invalid, only that account's session access fields are cleared before refresh; confirmed invalidation or insufficient permission clears only that account's encrypted grant.

KeyLockr AppData stores only the encrypted portable IMAP/SMTP account bundle. Templates, signatures, scheduled messages and bodies, Gmail data, OAuth tokens/grants/ciphertext, user vault passwords, and k_oauth are never stored in or sent to KeyLockr. The KeyLockr data_filekey is not a password; after phone authorization it is used briefly only as a high-entropy KEK to unwrap the vault DEK, then overwritten. Different browser profiles may share the same encrypted IMAP settings while retaining independent local content, vaultIds, and OAuth ciphertext.

What may sync via Chrome

Non-sensitive preferences (e.g. notification toggles, theme) live in chrome.storage.sync; if you enable Chrome Sync, they sync to your other Chrome browsers via Google's infrastructure — never through, and never stored on, any SafeX server. The mail cache, action-intent queue, custom notification sound, IMAP/SMTP vault ciphertext, and decrypted key never enter Chrome Sync.

Retention

The mail cache keeps at most 500 recent mail entries and evicts entries after 30 days or when the cap is exceeded using least-recently-used (LRU) eviction; it is kept only for fast display of recent mail, not as a long-term archive. User-saved local archives are not affected by that LRU. They remain until removed individually, the corresponding IMAP account is removed, or the extension is uninstalled, subject to the per-item and per-account hard limits above.

Deletion

  • Use "Clear cache" in the extension settings to wipe the local mail cache at any time.
  • Use "Local archive" on the Accounts page to remove explicitly saved messages one by one. Clearing the ordinary mail cache or disconnecting Gmail OAuth does not automatically delete Gmail local archives.
  • Choose "Watch this account" in the account menu to remove that email from the local ignored-account list.
  • Use "Disconnect account" in the extension settings or account menu. The Chrome path clears the global Chrome Identity state; the web path immediately clears only the selected account's local grant before making a best-effort direct Google revocation request and does not proactively clear other web OAuth accounts' local grants. Google revocation may also invalidate other tokens for the same project; an affected account will require authorization again. Both paths remove the selected account's local mail cache, queued actions, seen-message state, and unread state. If Gmail remains signed in on the web, the basic Atom inbox still works.
  • If you upgraded in place from a retired review build, the local web OAuth container may be tied to a key that is no longer in use and cannot be opened. The extension never deletes it automatically: the authorization page lists the container's public account indexes, and only after you explicitly confirm does it clear the whole local container and session access tokens, after which each account must be authorized again. Because the refresh tokens inside cannot be decrypted, this path cannot revoke access at Google on your behalf; you can remove this extension yourself in Google Account permissions. The clearing affects only Gmail authorization state and leaves IMAP/SMTP accounts, mail snapshots, and unread counts untouched.
  • For an IMAP/SMTP account, "Remove local account" deletes the account and credential from the vault plus that account ID's cache, explicitly saved local archive, queued actions, seen, unread, and polling state; it does not delete mail held by the email provider. With KeyLockr mode enabled, that removal also updates your KeyLockr AppData through a compare-and-swap, so the remote encrypted vault no longer contains the account; if KeyLockr cannot be reached at that moment the operation fails visibly instead of silently deleting only the local copy. Separately choosing to forget this browser's KeyLockr pairing clears only local pairing and identity and does not delete remote AppData. Locking the vault removes the decrypted key from the session and clears local-component port memory while retaining local ciphertext for the next unlock.
  • Uninstalling the extension removes all of its local data.
  • Signing out of the Gmail website does not automatically revoke extension OAuth; use Disconnect account or remove this extension in Google Account permissions.

The key boundary

This website backend never touches Gmail or IMAP/SMTP mail data, message content, attachments, or mail-account credentials. It only serves disclosure pages and local-component releases, and provides /oauth/exchange and /oauth/refresh, where non-Chrome Google OAuth authentication data arrives and leaves as ciphertext, is decrypted only in process memory, and is never persisted.

7. AI Assistance

"AI draft" is a user-controlled clipboard handoff. After you deliberately trigger it and complete the first-use confirmation, the extension copies a drafting prompt containing the selected email content to your clipboard and opens the third-party AI website you chose; the body is not placed in the URL, and the extension does not automatically paste or submit it. That third party receives the content only if you paste or submit it yourself, under its privacy policy; SafeX never handles, stores, or sees it.

8. This Website

Every asset is self-hosted on this origin—there are no third-party CDNs, analytics, or trackers. The Home, Privacy, Security, Terms, and local-component pages load only this site's hand-written styles and local brand assets. The /oauth endpoints serve no page or tracker and only perform the encrypted stateless Google OAuth forwarding described in Section 2. None of this touches Gmail or IMAP/SMTP mail data, attachments, or mail-account credentials.

9. Changes to This Policy

Any changes will be posted on this page with an updated "Last updated" date.

10. Contact

For privacy-related questions, please contact us: info@safex.cloud

© 2026 SafeX Inc. All rights reserved.

Gmail™ is a trademark of Google LLC. Checker for Gmail™ is an independent product, not affiliated with or endorsed by Google.

Footer navigation Privacy Terms Feedback