Private Gmail Mail Merge Privacy Policy
Last updated: July 10, 2026
Overview
Private Gmail Mail Merge is a Chrome extension that performs a user-initiated mail merge inside Gmail. It imports a CSV file selected by the user, reads the subject and body of the active Gmail compose window, optionally reads attachments selected by the user, previews personalized messages, and sends one separately addressed Gmail message to each valid recipient only after the user explicitly confirms the task.
Information Processed
The extension may temporarily process the following information when the user runs a mail merge:
1. Personally identifiable information, such as recipient email addresses, names, company names, and other fields contained in a CSV file selected by the user.
2. Personal communications, including the subject, body, recipient address, and attachments of an email that the user chooses to send.
3. Website content from the active Gmail compose window, including the user-authored subject and HTML message body.
4. A temporary Google OAuth access token provided through the Chrome Identity API. The token is used only to authorize user-confirmed Gmail API sending requests. The extension does not ask users to enter their Google password and does not store the OAuth token in chrome.storage.
How Information Is Used
The extension uses this information only to provide the mail merge functionality requested by the user. CSV values are substituted into template variables, personalized messages are displayed for preview, and each confirmed message is submitted separately to the Gmail API.
Each generated email contains only one To recipient. The extension does not place multiple recipients together in To, Cc, or Bcc.
Data Transmission and Sharing
The extension does not transmit contact lists, message content, attachments, sending logs, or OAuth tokens to a developer-operated server.
When the user confirms a sending task, the recipient address, personalized message content, attachments, and OAuth authorization token are transmitted directly to Google's Gmail API solely to perform the requested send action.
The extension does not sell, rent, trade, or share user data with advertisers, data brokers, analytics providers, or unrelated third parties. User data is not used for advertising, creditworthiness, profiling, or personalized marketing.
Local Storage and Retention
CSV contact rows, message subjects, message bodies, attachments, and task logs are held in the current Gmail page's memory only for the active task. They are not restored after Gmail is closed or reloaded, the browser tab is closed, or the extension is reloaded.
The extension stores only the following minimal local preferences in chrome.storage.local:
- The selected sending interval.
- The last selected recipient email column.
- Whether the user has acknowledged the sending safety notice.
The extension does not store contact lists, recipient email addresses, email subjects, message bodies, attachments, OAuth tokens, or sending logs in chrome.storage.
Permissions
The extension requests the following permissions:
identity: Used to request Google OAuth authorization before submitting messages to the Gmail API.
storage: Used only to store the minimal local preferences described above.
https://mail.google.com/*: Used to add the mail merge interface to Gmail compose windows and read the user-authored compose subject and body when the user requests a mail merge.
https://gmail.googleapis.com/*: Used to submit user-confirmed messages through the Gmail API.
The extension requests only the Gmail OAuth scope https://www.googleapis.com/auth/gmail.send. It does not request permission to read, modify, or delete the user's existing Gmail messages.
Remote Code
The extension does not use remote code. All executable JavaScript and other extension code is included in the installed Chrome extension package. The extension does not download or execute external JavaScript, use external script tags, or evaluate remotely supplied code.
User Control and Deletion
Users can review personalized samples before sending, stop future sending requests during a task, download the task log, close Gmail to discard in-memory task data, revoke the extension's Google Account access, clear the extension's local storage, or uninstall the extension at any time.
Messages already accepted by Gmail cannot be withdrawn by the extension.
Security
The extension limits its permissions and data processing to the functionality described in this policy. Data is transmitted to the Gmail API over HTTPS. No contact database or developer-operated mail server is used.
Google API Limited Use
The extension's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the user-facing Gmail mail merge functionality described in this policy.
Changes to This Policy
This privacy policy may be updated if the extension's functionality or legal requirements change. The updated policy will be published at this same URL with a revised “Last updated” date.
Contact
For privacy questions or requests concerning Private Gmail Mail Merge, contact:
kangyutian@gmail.com