MailMerge Pro ("the Extension") is a Chrome browser extension that lets you send personalised bulk emails via your Gmail account using data from Google Sheets or CSV files. This policy explains what data is collected, how it is used, and your rights.
Limited Use Compliance Statement: The use of information received from Google APIs, including raw and derived user data received from Gmail and Google Sheets, will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1. Google User Data Accessed
The Extension accesses the following Google user data solely to provide its core functionality:
- Gmail — send access (gmail.send): Used only when you click "Send Now." The Extension transmits each personalised email directly to the Gmail API on your behalf. The Extension never reads, lists, searches, or stores any existing emails in your mailbox.
- Gmail — draft access (gmail.compose): Used only when you choose "Save as Drafts" or "Schedule." The Extension creates draft messages in your Gmail account via the Drafts API. The Extension never reads, updates, or deletes your existing drafts.
- Google Sheets — read-only access (spreadsheets.readonly): Used to read the recipient list and merge-tag column data from a Google Sheet URL you provide. The Extension reads only the specific sheet you nominate. It never writes to, modifies, or lists your other spreadsheets.
- Google account email address (userinfo.email): Used to display your signed-in Gmail address inside the Extension popup so you know which account is active. No profile data beyond the email address is read.
All Google user data listed above is processed locally in your browser. It is never stored on servers owned or operated by the Extension developer.
2. How Google User Data Is Used
- Gmail send data is used exclusively to deliver the personalised emails you compose and explicitly initiate. It is not used for any other purpose.
- Gmail draft data is used exclusively to create draft messages in your account when you choose Save as Drafts or Schedule mode. It is not used for any other purpose.
- Google Sheets data (email addresses and merge-tag fields) is used exclusively to populate the recipient list and personalise each email. It is processed in-memory during the send operation and is not retained after the send completes.
- Account email address is used exclusively to display your identity in the Extension UI. It is not transmitted to any server other than Google's own OAuth endpoints.
Google user data is never used for advertising, analytics profiling, resale, or any purpose unrelated to providing the email merge service to you.
3. Data Transfer and Sharing
Google user data is shared only in the following limited ways:
- To Gmail recipients — the body and subject of each personalised email is transmitted to the Gmail API, which delivers it to the recipient's inbox. This is the core function you explicitly request.
- To no other parties — Google user data (email addresses, email content, spreadsheet data, account email) is never sold, rented, shared, or disclosed to any third party, advertiser, data broker, or analytics service.
The Extension sends anonymous usage events (e.g. "send button clicked") to a developer-owned Google Apps Script analytics endpoint. These events contain no personal data, no email addresses, no email content, and no recipient or spreadsheet information. Each event is identified only by a randomly generated session ID that is discarded when the popup closes.
4. Data Protection and Security
- OAuth tokens — access tokens are obtained via Chrome's built-in chrome.identity API and are held only in memory during the active session. They are never written to chrome.storage.local or any external storage.
- In-transit encryption — all communication with Google APIs (Gmail, Sheets, OAuth endpoints) is performed over HTTPS/TLS. No data is transmitted over unencrypted connections.
- Local processing — recipient data and email content are processed entirely within your browser. They are never sent to servers owned by the developer.
- No server-side storage — the developer operates no database or server that receives or stores your Google user data.
- Minimal local storage — only usage counters, scheduled job payloads (subject/body/recipient list for pending scheduled sends), and a send audit log are stored locally in chrome.storage.local on your device. This data never leaves your device.
5. Data Retention and Deletion
- Google user data (email content, recipient lists) — not retained. Recipient data is held in-memory during a send operation and discarded immediately after. No copy is kept by the developer.
- Scheduled job payloads — if you use the Schedule mode, the email subject, body, recipient list, and send time are stored in chrome.storage.local on your device until the scheduled send fires. Completed or failed jobs are automatically deleted after 7 days.
- Send audit log — a per-session record of sent/failed recipients is stored in chrome.storage.local on your device.
- Usage counters — monthly email send counts are stored locally and reset each calendar month.
- Deletion — all local Extension data is permanently deleted when you uninstall the Extension. You can also clear it manually at any time via chrome.storage.local.clear() in the Extension's DevTools console.
- Anonymous analytics — anonymous event logs (containing no personal data) are retained on the developer's private analytics sheet for up to 12 months, then deleted.
6. Data Handling — Limited Use Restrictions
The Extension's use of Google user data is strictly limited to providing and improving the email merge service. Specifically:
- Google user data is never used for serving advertisements or building advertising profiles.
- Google user data is never sold or transferred to data brokers, advertisers, or any third party for commercial purposes.
- Google user data is never used for credit scoring, lending, insurance, or employment screening.
- Google user data is never used to train, develop, or improve AI or machine learning models of any kind.
- Google user data is never transferred to third-party AI or ML services.
7. AI and Machine Learning
MailMerge Pro does not use, integrate, or connect to any AI or machine learning service. No Google user data — raw or derived — is used to train, develop, fine-tune, or improve any AI or ML model. No Google user data is transferred to any third-party service that trains AI or ML models.
8. Sender Responsibilities and Prohibited Uses
MailMerge Pro is designed exclusively for communicating with recipients who have explicitly consented to receive emails from you. By using the Extension you agree to the following:
- Consent required. You must only send emails to recipients who have explicitly opted in to receive commercial or marketing communications from you. Importing a contact list does not itself constitute consent.
- Prohibited uses. Using MailMerge Pro for cold outreach, spam, email warming, or any unsolicited commercial email is strictly prohibited and violates Google's API usage policies.
- Consequences. Violations may result in removal from the Chrome Web Store and revocation of OAuth verification status.
The Extension enforces an in-product consent acknowledgment gate before every send, draft-save, or schedule action. This gate resets on every popup open.
9. Third-Party Services
The Extension integrates with the following Google services under your account credentials:
- Gmail API — to send emails and save drafts on your behalf.
- Google Sheets API — to read your recipient data from Google Sheets (read-only).
- Google OAuth 2.0 — to authenticate you and obtain the permissions above. No passwords are stored by the Extension.
- Google Apps Script — anonymous usage events are sent to a developer-owned Apps Script endpoint (not under your credentials). No personal data is transmitted.
Use of these services is subject to Google's Privacy Policy.
10. Permissions Used
- gmail.send — send emails on your behalf (Send Now mode only).
- gmail.compose — create Gmail drafts on your behalf (Save as Drafts and Schedule modes only).
- spreadsheets.readonly — read your recipient data from Google Sheets (read-only; no data is written to your sheets).
- userinfo.email — display your Google account email in the Extension UI.
- identity — Chrome's built-in OAuth API, used to obtain the above tokens.
- storage — store local state (usage counters, scheduled job payloads, audit log) on your device.
- alarms — fire scheduled email sends at the time you specify.
11. Your Rights
Local extension data (usage counters, scheduled jobs, audit log) can be cleared at any time by uninstalling the Extension or by running chrome.storage.local.clear() in the Extension's DevTools console. For any other privacy-related questions or data deletion requests, contact the developer at the address below.
12. Children's Privacy
The Extension is not directed at children under 13. We do not knowingly collect personal data from children.
13. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the Extension after changes constitutes acceptance of the updated policy.
14. Contact
For privacy-related questions or data deletion requests, contact: