Privacy Policy
Effective Date: March 26, 2026
MailToDock (hereinafter "the Service") values your privacy and strictly adheres to the Google Chrome Web Store User Data Policy, specifically the Limited Use requirements.
This Privacy Policy explains how the Service collects or processes, uses, and protects your data.
1. Limited Use Disclosure
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
The Service uses Google user data with the following strict limitations:
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
- No Sale: We do not sell your data to third parties.
- No Transfer: We do not transfer your data to third parties unless for approved purposes such as user consent, legal compliance, or security.
- No Prohibited Use: We do not use your data for purposes unrelated to the Service’s core functionality, such as creditworthiness, lending, or advertising.
2. Data Collection and Processing
The Service processes only the minimum data necessary to provide its features.
A. User-Selected Email Data (Core Functionality)
We access only the currently open email when the user explicitly runs task extraction. We do not scan or collect emails in the background without user action.
- Processed items when task extraction is run: The current email subject, body, and sender information.
- Purpose: To summarize content and recommend tasks using AI models.
- Stored metadata: Task title, notes, due date, priority, email, thread, and task identifiers, plus limited email metadata such as subject, sender, and received time for UI display and multi-device sync.
- Retention: Active data stays during service use and is destroyed on account deletion. Dismissed or deleted data is soft-deleted immediately, with only minimal sync tombstones kept for up to 30 days.
B. Created Task Data
This is data related to tasks confirmed by the user from AI suggestions.
- Collected items: Task title, notes, due date, priority, and status metadata needed for synchronization.
- Purpose: To synchronize Google Tasks status and provide convenience features inside the Service.
- Storage: The Service stores only the minimum synchronized copy needed for UI display and multi-device sync. Google Tasks remains the original source of truth.
C. Account and Authentication Information
- Items: Email address used as the account ID.
- Purpose: User identification, settings synchronization, and usage statistics for tier management.
- Google OAuth tokens are not stored on the server. Authentication is performed client-side through the Chrome Identity API.
3. Third-Party Services
The Service uses trusted third-party services to provide its features.
A. AI Models (Email Analysis)
- Recipients: Google Cloud (Vertex AI / Gemini) or OpenAI (GPT series).
- Purpose: Natural-language task extraction.
- Provided items: The current email subject, body text, and sender information to the extent needed for task extraction.
- Protection: Provided data is used only within the scope needed for task extraction and is not sold or used for advertising.
B. Usage Analytics (PostHog)
The Service uses PostHog to understand feature usage patterns and improve the product.
- Recipient: PostHog, Inc. (posthog.com).
- Purpose: Product analytics and service improvement.
- Provided items: Anonymized user identifier (one-way SHA-256 hash of email address, not reversible), browser type, and anonymized interaction events (e.g., panel opened, task saved).
- Your email address is never transmitted to PostHog. Only a non-reversible cryptographic hash is used as an identifier.
- PostHog Privacy Policy: https://posthog.com/privacy
4. Data Storage and Security
A. Data Retention
- Email body: Processed only when the user runs task extraction and not permanently stored as a general service record on the server.
- Task and sync metadata: Stored in a secured database only as needed for UI display, service stability, and synchronization.
B. Security Measures
- All data transmission uses HTTPS (TLS) encryption.
- Database access rights are granted only to the minimum necessary administrators and are strictly controlled.
5. User Rights
You may stop using the Service and remove the extension at any time.
You can revoke the Service’s access permissions in your Google Account settings at myaccount.google.com/permissions.
For data deletion requests or inquiries, please contact us using the email below.
6. Contact Information
If you have any questions about this Privacy Policy, please contact us at the email below.