← Back to site

Privacy Policy

Last updated: 2026-08-25

Soft Send processes only the data needed to delay and send messages you choose to queue. No server operated by Soft Send receives Google user data. Queued message data is processed in the extension and transmitted to Google's Gmail API at your request.

Google user data we access and how we use it

Data accessedWhere it is processed or storedPurpose
Recipients, subject, and HTML body of an API-delivered message you choose to queueProcessed by the extension and stored temporarily in chrome.storage.local; transmitted over HTTPS only to the Google Gmail API when the message is sentTo hold the message for your selected delay, restore it to Gmail when you choose Edit, and send it when the timer expires or when you choose Send now
Recipients, subject, timing data, risk warnings, Gmail tab identifier, and a one-way content fingerprint for a native Gmail draftProcessed by the extension and stored temporarily in chrome.storage.local; the message body and attachments remain in GmailTo delay replies, forwards, and messages with attachments while preserving Gmail threading and content, and to locate the same open composer for native delivery
Gmail message identifier returned after sendingProcessed briefly in extension memory and not retainedTo confirm that Gmail accepted the send request
OAuth access tokenObtained through Chrome's identity API and cached temporarily in extension memoryTo authorize the send request made to the Gmail API
Addresses used in messages sent through Soft Sendchrome.storage.local on your deviceTo determine whether a recipient is new
Daily counters (sent / saved)chrome.storage.local on your deviceShown in the popup
Trial start date, Founding Pro eligibility, and paid statuschrome.storage.local on your device; paid status is also checked with ExtensionPayTo determine which Free, trial, Founding Pro, or paid Pro features are available
Your settings, including any high-risk addresses or domains you enterchrome.storage.sync, which Google may sync through your Chrome profile when Chrome Sync is enabledTo apply your preferences across Chrome browsers where you are signed in

Soft Send does not list or read inbox messages or Gmail drafts through the Gmail API. When a user chooses Edit for an API-delivered queue item, the content script uses that locally stored queue data to populate a new Gmail composer. For replies, forwards, and messages with attachments, the content script processes only the Gmail composer the user is actively using. The original composer remains in Gmail and Gmail's own Send button performs delivery. Gmail and that draft must remain open. If they are unavailable when the timer expires, Soft Send pauses the queue item and does not send it.

Sharing, transfer, and disclosure of Google user data

Soft Send does not sell, rent, share, transfer, or disclose your Google user data to any third party. Google user data is disclosed only to Google itself, and only to provide the feature you requested:

ExtensionPay and Stripe process the optional Pro purchase. They may receive the account and payment details needed to complete that purchase, and Soft Send receives only the resulting paid or unpaid status. They never receive Gmail message content, recipients, Gmail identifiers, contact history, settings, or OAuth tokens. For their handling of payment data, see https://extensionpay.com/privacy.

Data protection and security mechanisms for sensitive data

Soft Send protects your Google user data, including any sensitive data such as passwords or payment card numbers that may appear in a message you write, using the following data protection mechanisms:

Limited Use compliance

Soft Send's use of information received from Google Workspace APIs adheres to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.

Google user data is used only to provide the visible delayed-send, editing, cancellation, pause, risk-warning, and send features requested by the user. It is never sold, used for advertising, used to determine creditworthiness, provided to data brokers or information resellers, or used to train general-purpose artificial intelligence or machine-learning models.

Permissions and why they're needed

Gmail API scope

Soft Send requests a single scope: https://www.googleapis.com/auth/gmail.send. This permits Soft Send to send messages only. It does not permit Soft Send to read, create, modify, list, or delete inbox messages or Gmail drafts. Soft Send uses this permission only for API-delivered messages you explicitly queue through the extension. Native Gmail replies, forwards, and messages with attachments do not use this OAuth permission.

Data retention and deletion

Contact

For privacy questions or help deleting locally stored Soft Send data, contact softsend.review@gmail.com.