ES EmailSort

Privacy Policy

Last updated: 8/23/2026 · Effective: 8/23/2026

The short version. EmailSort reads your email so it can sort it. Your mail is not stored on our servers. To sort messages or answer your questions, email content is sent to Anthropic’s Claude API and used only to produce your result. We store your email address and a credit balance — nothing else about you.

Contents
  1. Who we are
  2. What we collect
  3. How it is used
  4. Where it is stored
  5. Who else sees it
  6. Google user data
  7. Your choices
  8. How long we keep things
  9. Security
  10. Children
  11. Changes
  12. Contact

1. Who we are

EmailSort (“EmailSort”, “we”, “us”) is a Chrome extension that connects to your email accounts and sorts your inbox using AI. It is operated by Alexander Wassef, Palos Verdes, CA, United States of America. You can reach us at alexwassef1212@gmail.com.

2. What we collect

Email content and metadata

When you connect an account, EmailSort reads messages from your mailbox: senders, recipients, subjects, dates, message bodies, attachment names, and read/starred status. This is what makes sorting, searching, and replying possible.

Credentials

Account and billing data

Your email address, your AI credit balance, and a log of credits consumed (timestamp, model used, amount). We do not receive or store your payment card details — payments are handled entirely by our payment processor.

What we do not collect

No advertising identifiers, no browsing history, no tracking across websites, and no analytics on how you use the extension.

3. How it is used

Your data is used only to run the features you asked for:

We do not sell your data. We do not use it for advertising. We do not use your email content to train any AI model, and our AI provider is not permitted to use it to train their models either.

4. Where it is stored

DataWhere it lives
Email content and metadata Your device only, in the browser’s extension storage. It is never written to our servers or database.
OAuth tokens / IMAP app passwords Your device only. App passwords are transmitted to our server for each request so it can log in to your mail provider on your behalf, but are never stored there.
Email address and credit balance Our database, hosted by Supabase.
Usage log (credits spent) Our database. Contains no email content.

Because credentials and mail live on your device, they are removed when you remove an account in the extension, sign out, or uninstall it.

5. Who else sees it

Anthropic (AI processing)

To sort your inbox, answer questions, or write drafts, EmailSort sends the relevant email content — senders, subjects, and message text — to Anthropic’s Claude API. Anthropic processes it to return a result and does not use it to train their models. This is the core of how the product works: if you use the AI features, your email content is processed by Anthropic.

Infrastructure providers

We may disclose information if required by law, or to protect the rights and safety of our users. We do not otherwise share your data with anyone.

6. Google user data

EmailSort’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We request these Google permissions, and use them only as described:

PermissionWhy
gmail.modifyRead your messages so they can be sorted and searched, and archive, star, or trash them when you ask.
gmail.sendSend the replies, forwards, and new messages you write.
userinfo.emailIdentify which account is connected, and tie your credit balance to it.

We do not permanently delete your Gmail messages — deleting in EmailSort moves a message to Trash, where you can recover it.

7. Your choices

If you are in the EU, UK, or California, you have rights of access, correction, deletion, and portability. Contact us and we will honour them.

8. How long we keep things

9. Security

All traffic uses HTTPS. Mail server connections use TLS. Our database connection is encrypted and certificate-verified. Access to the AI service requires a signed session proving you control a real mailbox, so the service cannot be used by anyone else.

Be aware that credentials stored in your browser’s extension storage are protected by your device and your browser profile. Anyone with access to your unlocked computer could reach them, so use a password or passcode on your device. We recommend generating a dedicated app password for EmailSort so you can revoke it without affecting anything else.

No system is perfectly secure. If we ever discover a breach affecting your data, we will tell you promptly.

10. Children

EmailSort is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child under 13 has used EmailSort, contact us and we will delete the associated record.

11. Changes

If we change this policy in a way that materially affects how your data is handled, we will update the date above and notify you in the extension before the change takes effect.

12. Contact

Questions, deletion requests, or privacy concerns: alexwassef1212@gmail.com. We aim to respond within 30 days.