Privacy Policy
Our commitment to you

We don't read,
store, or sell
your emails.

ThinkMail exists to help you communicate better — not to collect your data. This policy explains exactly what we touch, what we don't, and why.

Effective: April 2026 Last updated: April 2026 Version 1.1
🔒
The short version: Your email content is processed in real time to generate a response and is never logged, stored, or retained on our servers. We only store your name, email address, and usage count. That's it.
01

Who we are

ThinkMail is a Chrome extension and backend service that helps you write better email replies by reading the context of your email thread and suggesting situationally-aware responses.

This Privacy Policy applies to the ThinkMail Chrome extension, the ThinkMail backend API hosted at thinkmail-backend.vercel.app, and any related services.

02

What we collect

We collect the minimum possible. Here is everything we store:

That is the complete list. We store nothing else.

03

What we never collect

We want to be explicit about what we do not store:

Email content is sent to our backend API solely to generate a response. It passes through our server transiently and is never written to disk or any database.

04

How your data flows

When you click "Think about this email", here is exactly what happens:

05

Third-party services

ThinkMail uses the following third-party services to operate:

06

Google API scopes

ThinkMail uses Google Sign-In with the following OAuth scopes only:

We do not request the https://www.googleapis.com/auth/gmail scope or any scope that would allow us to read, send, delete, or modify your Gmail messages. ThinkMail reads your email thread directly from the Gmail web page in your browser using the Chrome extension — no Gmail API access is required or requested.

07

Data retention and deletion

Your account data (name, email, usage count) is retained for as long as you have an active account.

To delete your account and all associated data, email us at the address below. We will permanently delete your record within 7 days and confirm when done.

Because we do not store email content, there is no email data to delete.

08

Security

All data in transit is encrypted via HTTPS/TLS. Authentication uses short-lived JWT tokens (30-day expiry) stored in Chrome's local extension storage, not accessible to websites. We do not store passwords — authentication is handled entirely by Google OAuth.

Our database credentials and API keys are stored as environment variables and never exposed in client-side code or public repositories.

09

Children's privacy

ThinkMail is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

10

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify users via the extension.

Continued use of ThinkMail after changes constitutes acceptance of the updated policy.

11

Contact

Questions, concerns, or data deletion requests — reach us here: