Home · Changelog · Privacy · Terms · Donate

TriageBox — Privacy Policy

Effective date: 10 September 2026 · Contact: paulfaisant@gmail.com

TriageBox AI Gmail Checker (short name: TriageBox; marketing name: Gmail cleanup, unsubscribe & scam checks) is a Chrome extension that helps you triage your own Gmail inbox: unread badge, fast actions (archive / snooze / mark read / label), an optional Google Calendar agenda, and optional AI summaries of your email threads.

Mail processing has no developer server, telemetry, analytics or advertising. Working data is stored in your browser; your Todo list can also use Chrome Sync so it appears in your other signed-in Chrome browsers. The extension communicates directly with Google and an AI provider you configure. Feedback is an email you choose to send. The Support heart reads a public count from the project website and sends a random token when recording your vote. It sends no Gmail content, account address, settings or AI key. The separate public website uses consent-controlled Google Analytics as described below.

What the extension accesses, and why

DataWhyWhere it goes
Gmail messages and labels (Gmail API, gmail.modify scope) Show your inbox in the popup; perform the actions you click (archive, mark read/unread, label, snooze, trash, report spam) Directly between your browser and Google. A local cache is kept in chrome.storage.local on your device
Google Calendar (calendar.calendarlist.readonly + calendar.events) List calendars for the agenda picker; show events; create/edit/delete events you ask for Directly between your browser and Google
Email text and (optionally) a PDF attachment processed by an AI feature you use or enable Generate the AI summary, relevance score, digest, or answer you requested Sent directly from your browser to the AI provider you configured with your own API key — Google Gemini, xAI (Grok), or OpenRouter and its serving provider. Background rating/summarising runs only when those features are enabled
Settings, API keys, summaries cache and usage counters Make the extension work and remember your preferences Stored only in chrome.storage.local on your device. Optional export produces a file on your machine
Todo text, completion state and an optional Gmail thread identifier Keep your Todo list available across Chrome browsers without a TriageBox account or server Written first to chrome.storage.local, then to chrome.storage.sync. Chrome associates it with your signed-in Chrome profile when Chrome Sync is enabled. Todos are partitioned by an opaque hash of the connected Gmail address; the address itself is not put in the sync key
Remote images embedded in email Display an email as its sender designed it Blocked by default. If you press “Load remote images”, or switch on Load remote images automatically in Settings → Gmail, your browser contacts the image host when a preview is displayed; that host can observe your IP address and the unique image URL. Nothing is fetched in the background either way — only for a preview you have open
Feedback report text and diagnostics you choose to include Let you report a problem or request help Shown in a redacted preview, then sent through Gmail to the displayed support address when you send. The recipient sees your sending address. Retry history retains the original redacted report and diagnostics; exports include them

What we do NOT do

Authentication

Sign-in uses Google OAuth via Chrome's identity API. The access token is held by your browser and used only for the Google API calls listed above. Revoke access at any time at myaccount.google.com/permissions; uninstalling the extension deletes all locally stored data.

Third parties

When you use or enable an AI feature, the relevant content is handled by the provider under its own terms: Google Gemini API terms or xAI terms, or OpenRouter’s terms and the terms of the provider serving that request. Your OpenRouter account/provider settings affect routing. TriageBox sends nothing to these providers unless you added a key and used or enabled the feature.

This website

The public website at triagebox.pfa87.cc is separate from the extension. It uses Google Analytics 4 (measurement ID G-P5G7YVWE93) to measure page views and understand how visitors find and use the site. Consent Mode defaults analytics storage to denied before Google's script loads. Until you accept, Google receives cookieless measurement pings; if you accept, Google Analytics may set identifiers such as _ga. Advertising storage, ad personalisation and ad user data remain disabled. Your choice is stored in this browser's local storage and can be changed using the Cookie settings button on any page.

Analytics may process the page URL and title, referrer, approximate location, device/browser information and interaction timing. It does not receive Gmail messages, extension settings, API keys or other extension data. Google processes analytics data under its Privacy Policy. Analytics-cookie processing is based on your consent; declining does not affect the website or extension.

Public support likes

The support page and the extension’s Support heart share one public count, starting with the 10 September 2026 counter. A donation click does not count as a like.

The old support-page event logger, IP-based deduplication and donation-click emails were removed. This does not erase historical events already received. The support-page code emits no analytics events; any consent-controlled tag injected by the site’s shared edge infrastructure is separate. Website analytics do not run in the extension. The support counter never handles your mail or settings.

Limited Use disclosure

triageBox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: data obtained from Google APIs is used only to provide the features you use or enable in the extension. It is never sold or used by the developer for advertising or profiling. AI content goes directly to the configured provider for requested or enabled processing. Mail you send, forward or include in feedback goes to the recipient you choose; the developer does not otherwise receive or inspect your mailbox. The support counter is separate from Google API data.

Who is responsible, and on what basis

For website analytics, the lawful basis for storing or reading analytics identifiers is your consent (Article 6(1)(a) UK GDPR / GDPR). You can withdraw it at any time through Cookie settings; doing so disables analytics storage and removes accessible GA cookies from this site.

For the other small amount of processing the developer performs — the public like counter described above, plus any feedback email you choose to send — the data controller is the publisher, Paul Faisant (paulfaisant@gmail.com). The lawful basis is legitimate interests (Article 6(1)(f) UK GDPR / GDPR): counting supporters without repeating the same browser vote, and responding to requested feedback. You can object to it at any time using the contact address, and nothing about the extension depends on it.

For everything the extension does with your mailbox, you are the one who decides: it acts on your Google account with your OAuth consent, it keeps its working data on your own device, and the developer is not a recipient of it.

How long anything is kept

Your rights

Where UK/EU data protection law applies, you have the right to ask for access to, correction of, or erasure of personal data the developer holds about you, to object to or ask for a restriction of the processing described above, and to receive a copy of it. Write to paulfaisant@gmail.com — there is no form and no account to close. If you are not satisfied with the answer, you can complain to the UK Information Commissioner's Office (ico.org.uk) or to your own national data protection authority.

Data the extension keeps on your device is not something the developer can retrieve, delete or produce on request — it is yours, on your machine. Uninstalling the extension removes it, and revoking access at myaccount.google.com/permissions ends the extension's access to your Google account immediately.

Where data goes geographically

The extension talks to Google and to the AI provider you configured; where those companies process data is governed by their own terms, linked above. Google Analytics, Cloudflare and payment providers may process outside the UK and EEA under their own safeguards. The public counter runs on the publisher’s existing site host; requests pass through Cloudflare. No mailbox content or AI credentials accompany likes. Payment providers receive the information you give them during checkout.

Children

TriageBox is a productivity tool for the holder of a Google account and is not directed at children. If you are under the age at which you can consent to online services where you live, please do not use it.

Changes

Changes to this policy will be published at this URL with an updated effective date.