Privacy Policy
The short version. EmailSort reads your email so it can sort it. Your mail is not stored on our servers. To sort messages or answer your questions, email content is sent to Anthropic’s Claude API and used only to produce your result. We store your email address and a credit balance — nothing else about you.
1. Who we are
EmailSort (“EmailSort”, “we”, “us”) is a Chrome extension that connects to your email accounts and sorts your inbox using AI. It is operated by Alexander Wassef, Palos Verdes, CA, United States of America. You can reach us at alexwassef1212@gmail.com.
2. What we collect
Email content and metadata
When you connect an account, EmailSort reads messages from your mailbox: senders, recipients, subjects, dates, message bodies, attachment names, and read/starred status. This is what makes sorting, searching, and replying possible.
Credentials
- Gmail and Outlook: OAuth access and refresh tokens issued by Google or Microsoft. We never see or ask for your password.
- IMAP accounts (Yahoo, iCloud, AOL, and others): the app password you generate in your email provider’s security settings. This is not your main account password.
Account and billing data
Your email address, your AI credit balance, and a log of credits consumed (timestamp, model used, amount). We do not receive or store your payment card details — payments are handled entirely by our payment processor.
What we do not collect
No advertising identifiers, no browsing history, no tracking across websites, and no analytics on how you use the extension.
3. How it is used
Your data is used only to run the features you asked for:
- Sorting your inbox into categories
- Answering questions about your mail, and performing actions you request in chat
- Sending, replying to, forwarding, and drafting messages on your instruction
- Archiving, starring, and deleting messages in your provider on your instruction
- Metering AI usage against your credit balance
We do not sell your data. We do not use it for advertising. We do not use your email content to train any AI model, and our AI provider is not permitted to use it to train their models either.
4. Where it is stored
| Data | Where it lives |
|---|---|
| Email content and metadata | Your device only, in the browser’s extension storage. It is never written to our servers or database. |
| OAuth tokens / IMAP app passwords | Your device only. App passwords are transmitted to our server for each request so it can log in to your mail provider on your behalf, but are never stored there. |
| Email address and credit balance | Our database, hosted by Supabase. |
| Usage log (credits spent) | Our database. Contains no email content. |
Because credentials and mail live on your device, they are removed when you remove an account in the extension, sign out, or uninstall it.
5. Who else sees it
Anthropic (AI processing)
To sort your inbox, answer questions, or write drafts, EmailSort sends the relevant email content — senders, subjects, and message text — to Anthropic’s Claude API. Anthropic processes it to return a result and does not use it to train their models. This is the core of how the product works: if you use the AI features, your email content is processed by Anthropic.
Infrastructure providers
- Render — hosts our server, which relays requests and connects to IMAP mail servers.
- Supabase — hosts the database holding email addresses and credit balances.
- Google / Microsoft / your mail provider — your mailbox itself; we act on it only as you instruct.
- Our payment processor — handles credit purchases and holds your payment details. We never see your card number.
We may disclose information if required by law, or to protect the rights and safety of our users. We do not otherwise share your data with anyone.
6. Google user data
EmailSort’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We request these Google permissions, and use them only as described:
| Permission | Why |
|---|---|
gmail.modify | Read your messages so they can be sorted and searched, and archive, star, or trash them when you ask. |
gmail.send | Send the replies, forwards, and new messages you write. |
userinfo.email | Identify which account is connected, and tie your credit balance to it. |
We do not permanently delete your Gmail messages — deleting in EmailSort moves a message to Trash, where you can recover it.
7. Your choices
- Remove an account — deletes its credentials and cached mail from your device immediately.
- Revoke access — at any time, in your Google account permissions or your Microsoft account settings. For IMAP accounts, delete the app password in your provider’s security settings.
- Turn off AI features — you can disable AI-generated categories and use only your own, or turn off automatic refresh, in Settings.
- Request deletion — email us and we will delete your database record (email address, balance, usage log). Note this forfeits any remaining credits.
- Get a copy — email us and we will send you the data we hold about you, which is your email address, balance, and usage log.
If you are in the EU, UK, or California, you have rights of access, correction, deletion, and portability. Contact us and we will honour them.
8. How long we keep things
- Email content: not retained by us at all. It exists on your device until you remove the account, and is held only momentarily in memory on our server while a request is processed.
- Email address and balance: until you ask us to delete them.
- Usage log: kept for billing and support, then deleted on request.
9. Security
All traffic uses HTTPS. Mail server connections use TLS. Our database connection is encrypted and certificate-verified. Access to the AI service requires a signed session proving you control a real mailbox, so the service cannot be used by anyone else.
Be aware that credentials stored in your browser’s extension storage are protected by your device and your browser profile. Anyone with access to your unlocked computer could reach them, so use a password or passcode on your device. We recommend generating a dedicated app password for EmailSort so you can revoke it without affecting anything else.
No system is perfectly secure. If we ever discover a breach affecting your data, we will tell you promptly.
10. Children
EmailSort is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child under 13 has used EmailSort, contact us and we will delete the associated record.
11. Changes
If we change this policy in a way that materially affects how your data is handled, we will update the date above and notify you in the extension before the change takes effect.
12. Contact
Questions, deletion requests, or privacy concerns: alexwassef1212@gmail.com. We aim to respond within 30 days.