Privacy Policy
In short: the extension runs entirely in your Chrome browser. It has no server of its own, collects no analytics and sells or shares nothing. Your mail and sign-ins stay on your computer and are exchanged only with the email and file-hosting services you choose to connect.
What the extension accesses
- Gmail (Google API, scope
gmail.modify): to list, read, mark read or unread, delete, draft and send your email. - Outlook.com / Hotmail (Microsoft Graph,
Mail.ReadWrite,Mail.Send): the same, for Microsoft accounts. - iCloud, Yahoo and AOL: through a small helper program on your Mac that connects to their mail servers (IMAP and SMTP) with app passwords you create. The app passwords are kept in your Mac's Keychain.
- Proton Mail: through your signed-in Proton session in Chrome; messages are decrypted inside the extension on your computer.
- Catbox, x02 and ImgLink: only when you upload a file to one of them, using the user hash or API keys you enter in Settings.
What is stored, and where
- Sign-in tokens, settings, upload keys, the list of recent uploads and an offline cache of your emails and attachments are stored in your Chrome profile on your computer.
- You can clear the offline cache in Settings, and removing an account removes its stored data. Uninstalling the extension removes everything it stored in Chrome.
- Nothing is sent to the developer or to any server operated by the developer.
Who data is shared with
Only the services you connect: Google, Microsoft, Apple (iCloud), Yahoo, AOL and Proton for your mail, and Catbox, x02 or ImgLink for files you upload. Files you upload are available to anyone who has their link. The extension also checks this project's GitHub repository for new versions, which sends no personal data.
Google user data
Unread Mail & File Hosting's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only to show and manage your own mail in the extension; it is not used for advertising, not transferred to others, and not read by people.
Revoking access
- Remove an account in the extension (⋯ → Remove account).
- Revoke access for Google at myaccount.google.com/permissions and for Microsoft at account.live.com/consent/Manage.
- Delete app passwords in your Apple, Yahoo or AOL account settings.
Changes and contact
Changes to this policy are published on this page. Questions can be raised as an issue on GitHub.