Privacy Policy
Last updated: 2026-08-25
Soft Send processes only the data needed to delay and send messages you choose to queue. No server operated by Soft Send receives Google user data. Queued message data is processed in the extension and transmitted to Google's Gmail API at your request.
Google user data we access and how we use it
| Data accessed | Where it is processed or stored | Purpose |
|---|---|---|
| Recipients, subject, and HTML body of an API-delivered message you choose to queue | Processed by the extension and stored temporarily in chrome.storage.local; transmitted over HTTPS only to the Google Gmail API when the message is sent | To hold the message for your selected delay, restore it to Gmail when you choose Edit, and send it when the timer expires or when you choose Send now |
| Recipients, subject, timing data, risk warnings, Gmail tab identifier, and a one-way content fingerprint for a native Gmail draft | Processed by the extension and stored temporarily in chrome.storage.local; the message body and attachments remain in Gmail | To delay replies, forwards, and messages with attachments while preserving Gmail threading and content, and to locate the same open composer for native delivery |
| Gmail message identifier returned after sending | Processed briefly in extension memory and not retained | To confirm that Gmail accepted the send request |
| OAuth access token | Obtained through Chrome's identity API and cached temporarily in extension memory | To authorize the send request made to the Gmail API |
| Addresses used in messages sent through Soft Send | chrome.storage.local on your device | To determine whether a recipient is new |
| Daily counters (sent / saved) | chrome.storage.local on your device | Shown in the popup |
| Trial start date, Founding Pro eligibility, and paid status | chrome.storage.local on your device; paid status is also checked with ExtensionPay | To determine which Free, trial, Founding Pro, or paid Pro features are available |
| Your settings, including any high-risk addresses or domains you enter | chrome.storage.sync, which Google may sync through your Chrome profile when Chrome Sync is enabled | To apply your preferences across Chrome browsers where you are signed in |
Soft Send does not list or read inbox messages or Gmail drafts through the Gmail API. When a user chooses Edit for an API-delivered queue item, the content script uses that locally stored queue data to populate a new Gmail composer. For replies, forwards, and messages with attachments, the content script processes only the Gmail composer the user is actively using. The original composer remains in Gmail and Gmail's own Send button performs delivery. Gmail and that draft must remain open. If they are unavailable when the timer expires, Soft Send pauses the queue item and does not send it.
Sharing, transfer, and disclosure of Google user data
Soft Send does not sell, rent, share, transfer, or disclose your Google user data to any third party. Google user data is disclosed only to Google itself, and only to provide the feature you requested:
- Google (Gmail API): the recipients, subject, and body of an API-delivered queued message are transmitted only to Google's Gmail API when Soft Send sends that message from your own Gmail account. Native Gmail drafts are sent by Gmail's own interface and are not transmitted through the Gmail API by Soft Send.
- Google (Chrome Sync), optional: if you enable Chrome Sync, Google may sync your Soft Send settings, including any high-risk addresses or domains you enter, through your own Chrome profile.
- No third parties: Soft Send does not share, transfer, or disclose Google user data to ExtensionPay, Stripe, advertisers, analytics providers, data brokers, information resellers, or any other third party. There is no Soft Send server, so no Soft Send employee or contractor can access your Google user data.
ExtensionPay and Stripe process the optional Pro purchase. They may receive the account and payment details needed to complete that purchase, and Soft Send receives only the resulting paid or unpaid status. They never receive Gmail message content, recipients, Gmail identifiers, contact history, settings, or OAuth tokens. For their handling of payment data, see https://extensionpay.com/privacy.
Data protection and security mechanisms for sensitive data
Soft Send protects your Google user data, including any sensitive data such as passwords or payment card numbers that may appear in a message you write, using the following data protection mechanisms:
- Encryption in transit: all data exchanged with the Gmail API is transmitted over encrypted HTTPS / TLS connections.
- Data minimization: sensitive data is processed only on your own device. It is never copied to a Soft Send server (there is none) and is never transmitted to any third party.
- Access control and token handling: OAuth access tokens are obtained and held by Chrome's identity system, are never written to logs or extension storage, and are sent only to Google's Gmail API. Locally stored data is isolated to your Chrome browser profile and your operating system user account.
- Retention and deletion: queued data, including any sensitive content, is deleted from local storage as soon as the message is sent, returned to Gmail for editing, or permanently discarded.
- Least privilege: Soft Send requests only the
gmail.sendscope and calls only the Gmail message send endpoint. It cannot read your inbox or drafts. - No remote code: all code ships inside the extension package, and a Manifest V3 Content Security Policy blocks remote code execution.
Limited Use compliance
Soft Send's use of information received from Google Workspace APIs adheres to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
Google user data is used only to provide the visible delayed-send, editing, cancellation, pause, risk-warning, and send features requested by the user. It is never sold, used for advertising, used to determine creditworthiness, provided to data brokers or information resellers, or used to train general-purpose artificial intelligence or machine-learning models.
Permissions and why they're needed
storage: persists the queue, contact history, stats, and settings locally.identity: obtains an OAuth token so the Gmail API can act on your mailbox.alarms: wakes the service worker every 30s to process the queue.notifications: tells you if an email failed to send.host_permissions: https://www.googleapis.com/*: calls the Gmail API.host_permissions: https://extensionpay.com/*: processes the optional Pro upgrade and checks paid status (no email content is ever sent there).- Content script on
https://mail.google.com/*: intercepts the Send button, renders the queue banner inside Gmail, and restores a queued message to the Gmail editor when requested.
Gmail API scope
Soft Send requests a single scope: https://www.googleapis.com/auth/gmail.send. This permits Soft Send to send messages only. It does not permit Soft Send to read, create, modify, list, or delete inbox messages or Gmail drafts. Soft Send uses this permission only for API-delivered messages you explicitly queue through the extension. Native Gmail replies, forwards, and messages with attachments do not use this OAuth permission.
Data retention and deletion
- A queue entry, including recipients, subject, body, timing data, and risk warnings, remains in local Chrome storage until the message is sent, returned to editing, or permanently discarded. A paused message remains until you resume, edit, or discard it.
- Choosing Return to editing restores an API-delivered item in a new Gmail composer or focuses the original Gmail composer for a native item. Soft Send removes the queue entry only after Gmail confirms that the editor is available. Sending the edited message again creates a new queue entry with a fresh delay.
- Choosing Discard permanently deletes the local API-delivered message or asks Gmail to discard the original native draft. If Gmail cannot complete the requested action, Soft Send keeps the queue entry.
- If sending fails after the built-in retry, Soft Send pauses the local queue entry so you can retry or cancel it.
- If a native Gmail draft or tab is unavailable, Soft Send pauses the item. The user must reopen the draft and resume it or choose Send now.
- Recipient history, counters, and settings remain in Chrome extension storage until you clear the extension's storage or remove the extension. Synced settings are also subject to your Google Chrome Sync settings.
- The local trial start date, Founding Pro eligibility, and cached plan status remain until you clear extension storage or remove Soft Send. ExtensionPay retains payment records according to its and Stripe's policies.
- Removing Soft Send or clearing its extension storage deletes data stored locally by Soft Send. Soft Send has no server-side copy to delete.
- To revoke Gmail API access, remove Soft Send from your Google Account connections.
Contact
For privacy questions or help deleting locally stored Soft Send data, contact softsend.review@gmail.com.