Last updated: 10 August 2026
Gmail AI Polisher is a bring-your-own-key browser extension. It helps users rewrite text they explicitly select inside a Gmail compose box.
DATA THE EXTENSION ACCESSES
The extension accesses only:
• text the user explicitly selects inside a Gmail compose box;
• the selected AI provider, model name, API key, and right-click actions entered by the user in the extension settings; and
• the minimum temporary state needed to replace the selected text after the AI provider responds.
The extension does not intentionally read the user's inbox, recipients, contacts, subject line, attachments, browsing history, or unselected Gmail content. It does not send email.
HOW DATA IS USED AND SHARED
Selected text is sent directly from the extension to the AI API provider chosen by the user: Google Gemini, OpenAI, DeepSeek, or Moonshot/Kimi. It is sent only after the user invokes a configured right-click action. The provider's response is used to replace the selected draft text.
The extension developer does not operate an intermediary server and does not receive the selected text, API key, or provider response. Data is shared only with the AI provider selected and authorized by the user for the purpose of providing the rewrite feature.
STORAGE
Provider settings, API keys, and custom actions are stored in the browser's local extension storage (chrome.storage.local). They are not stored in the extension source files and are not placed in Chrome synchronized storage by this extension.
The extension does not include analytics, advertising, or content logging. Temporary selection state remains in the Gmail tab and is cleared after replacement or page closure.
THIRD-PARTY PROCESSING
Data sent to Google Gemini, OpenAI, DeepSeek, or Moonshot/Kimi is governed by the selected provider's terms, privacy policy, data-retention practices, and account configuration. Users are responsible for verifying that their use complies with applicable institutional rules and confidentiality obligations.
SECURITY
The extension transmits provider requests over HTTPS, uses a Manifest V3 service worker, uses a restrictive extension Content Security Policy, and loads no remote JavaScript.
Local browser storage is not a hardware-backed secret store. Anyone or any software controlling the user's device or browser profile may be able to access locally stored credentials. Users should apply provider quotas or restrictions where available and revoke any credential suspected of exposure.
DATA DELETION
Users can replace a stored API key from the extension settings page. Removing the extension through Chrome's extension manager deletes its local extension storage. Users must separately revoke API keys through the relevant provider dashboard if desired.
CHANGES
Material changes to this policy will be documented on this page together with an updated effective date.