Home · Privacy · Terms · Donate
TriageBox AI Gmail Checker — Privacy Policy
TriageBox AI Gmail Checker (short name: TriageBox) is a Chrome extension that helps you triage your own Gmail inbox: unread badge, fast actions (archive / snooze / mark read / label), an optional Google Calendar agenda, and optional AI summaries of your email threads.
What the extension accesses, and why
| Data | Why | Where it goes |
|---|---|---|
Gmail messages and labels (Gmail API, gmail.modify scope) |
Show your inbox in the popup; perform the actions you click (archive, mark read/unread, label, snooze, trash, report spam) | Directly between your browser and Google. A local cache is kept in chrome.storage.local on your device |
Google Calendar (calendar.calendarlist.readonly + calendar.events) |
List calendars for the agenda picker; show events; create/edit/delete events you ask for | Directly between your browser and Google |
| Email text and (optionally) a PDF attachment processed by an AI feature you use or enable | Generate the AI summary, relevance score, digest, or answer you requested | Sent directly from your browser to the AI provider you configured with your own API key — Google Gemini API and/or xAI (Grok). Background rating/summarising runs only when you enable those features |
| Settings, API keys, summaries cache and usage counters | Make the extension work and remember your preferences | Stored only in chrome.storage.local on your device. Optional export produces a file on your machine |
| Todo text, completion state and an optional Gmail thread identifier | Keep your Todo list available across Chrome browsers without a TriageBox account or server | Written first to chrome.storage.local, then to chrome.storage.sync. Chrome associates it with your signed-in Chrome profile when Chrome Sync is enabled. Todos are partitioned by an opaque hash of the connected Gmail address; the address itself is not put in the sync key |
| Remote images embedded in email | Display an email as its sender designed it | Blocked by default. If you press “Load remote images”, or switch on Load remote images automatically in Settings → Gmail, your browser contacts the image host when a preview is displayed; that host can observe your IP address and the unique image URL. Nothing is fetched in the background either way — only for a preview you have open |
| FeedAI feed URLs, feed/article content and generated briefing | Build the optional news briefing after you enable FeedAI and add feeds | Your browser contacts the selected publishers directly. Content selected for analysis is sent to your configured AI provider. FeedAI is off by default |
| Feedback report text and diagnostics you choose to include | Let you report a problem or request help | Shown to you before sending, then sent through Gmail to the developer’s support address only after you confirm |
What we do NOT do
- The extension has no developer server, telemetry, analytics, or crash reporting.
- No selling, sharing, or transferring of user data to anyone.
- No use of data for advertising, profiling, or creditworthiness.
- No background loading of remote email images or tracking pixels. They load only in a preview you have open, and only after you press “Load remote images” or switch automatic loading on yourself (off by default).
Authentication
Sign-in uses Google OAuth via Chrome's identity API. The access token is held by your browser and used only for the Google API calls listed above. Revoke access at any time at myaccount.google.com/permissions; uninstalling the extension deletes all locally stored data.
Third parties
When you use or enable an AI feature, the relevant content is handled by the provider under its own terms: Google Gemini API terms or xAI terms. TriageBox sends nothing to these providers unless you added a key and used or enabled the feature. FeedAI also contacts the feed and article publishers you selected. Those sites receive an ordinary request from your browser and may apply their own privacy policies.
This website
The public website at
triagebox.pfa87.cc
is separate from the extension. It uses Google Analytics 4 (measurement ID
G-KVV7QW9D5E) to measure page views and understand how visitors find and use the
site. Consent Mode defaults analytics storage to denied before Google's script loads. Until
you accept, Google receives cookieless measurement pings; if you accept, Google Analytics may
set identifiers such as _ga. Advertising storage, ad personalisation and ad user
data remain disabled. Your choice is stored in this browser's local storage and can be changed
using the Cookie settings button on any page.
Analytics may process the page URL and title, referrer, approximate location, device/browser information and interaction timing. It does not receive Gmail messages, extension settings, API keys or other extension data. Google processes analytics data under its Privacy Policy. Analytics-cookie processing is based on your consent; declining does not affect the website or extension.
Separately, on the donate page only, a minimal event log may be recorded so the developer can build aggregate statistics (for example unique supporters and rough geography):
- What: IP address, coarse location (country / city from a public geo-IP
lookup), timestamp, event type (
view,like,unlike,donate— a click on a payment link), page path, referrer, and browser user-agent. - Why: Count likes without double-counting the same network, and build simple traffic / support statistics. Not used for advertising or profiling.
- Where: Processed via a form/inbox service and/or a private spreadsheet controlled by the developer. The public like total is a simple counter service (no message content).
This website analytics and logging do not apply to the Chrome extension, Gmail data, or AI features. The extension still has no developer server and does not send your mail or settings to the developer.
Limited Use disclosure
triageBox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: data obtained from Google APIs is used only to provide the features you invoke in the extension, is never transferred to anyone except the AI provider whose key you configured (and only for the request you triggered), is never sold, is never used for advertising or profiling, and is never read by a human other than you.
Who is responsible, and on what basis
For website analytics, the lawful basis for storing or reading analytics identifiers is your consent (Article 6(1)(a) UK GDPR / GDPR). You can withdraw it at any time through Cookie settings; doing so disables analytics storage and removes accessible GA cookies from this site.
For the other small amount of processing the developer performs — the donate-page event log and public like counter described above, plus any feedback email you choose to send — the data controller is the publisher, Paul Faisant (paulfaisant@gmail.com). The lawful basis is legitimate interests (Article 6(1)(f) UK GDPR / GDPR): counting supporters without double-counting a network, and understanding basic traffic to the project's own site. You can object to it at any time using the contact address, and nothing about the extension depends on it.
For everything the extension does with your mailbox, you are the one who decides: it acts on your Google account with your OAuth consent, it keeps its working data on your own device, and the developer is not a recipient of it.
How long anything is kept
- On your device: settings, caches, summaries and todos stay in
chrome.storage.localuntil you clear them or uninstall the extension, which deletes them. Todos you chose to sync also live in your own Chrome Sync account. - Donate-page events: kept only as long as they are useful for those statistics — in practice no longer than 24 months — and deleted sooner if you ask.
- Website analytics: retention is controlled in the Google Analytics property. Your consent choice remains on your device until you change it or clear site data.
- Feedback you send: kept in the developer's mailbox while the issue is open and for a reasonable period afterwards, so a follow-up reply still makes sense.
Your rights
Where UK/EU data protection law applies, you have the right to ask for access to, correction of, or erasure of personal data the developer holds about you, to object to or ask for a restriction of the processing described above, and to receive a copy of it. Write to paulfaisant@gmail.com — there is no form and no account to close. If you are not satisfied with the answer, you can complain to the UK Information Commissioner's Office (ico.org.uk) or to your own national data protection authority.
Data the extension keeps on your device is not something the developer can retrieve, delete or produce on request — it is yours, on your machine. Uninstalling the extension removes it, and revoking access at myaccount.google.com/permissions ends the extension's access to your Google account immediately.
Where data goes geographically
The extension talks to Google and to the AI provider you configured; where those companies process data is governed by their own terms, linked above. Google Analytics and the two small website services used by the donate page (a form/inbox service and a public counter) may process outside the UK and EEA under their own safeguards. No mail content, and nothing from the extension, is sent to any of them.
Children
TriageBox is a productivity tool for the holder of a Google account and is not directed at children. If you are under the age at which you can consent to online services where you live, please do not use it.
Changes
Changes to this policy will be published at this URL with an updated effective date.