Mass Email Sender.Add to Chrome

Last updated 30 August 2026

Privacy policy

This policy explains what Mass Email Sender does with personal data. It covers the Chrome extension, this website, and the sending service at api.mass-sender.com (together, the “service”). It is written to be read, not to be survived. If something here does not match what the software does, the software is the thing we will fix.

The short version

Who we are

Mass Email Sender is operated by Alex Gromov, an individual trader based in Yerevan, Armenia. For anything in this policy, including requests to access or delete data, write to support@mass-sender.com.

Two kinds of data, and two different roles

This distinction runs through the whole policy, so it comes first.

Your data. Your Google account address, your API key, your settings, your campaign history. For this we are the data controller. This policy describes how we handle it.

Your recipients’ data. The addresses and spreadsheet columns you upload, and the delivery results that come back. For this you are the controller and we are your processor: we hold and use that data only to carry out the sending you asked for. Deciding who belongs on your list, and having a lawful basis to email them, is your responsibility, not ours. Our terms of service set out what you commit to when you upload a list.

What we ask for from your Google account

Connecting an account opens Google’s own consent screen. We request exactly three scopes.

Two consequences worth stating plainly. First, because we hold no read scope over your mailbox, we cannot see replies or bounce notifications that arrive in your inbox; delivery failures are only visible to us when the sending server reports them at the moment of sending. Second, we delete the source draft from your Gmail once the campaign starts. The campaign sends from a copy held in our queue, and leaving the original in place produces a duplicate you did not ask for. If you want to keep the text, keep a copy before you send.

Limited use of Google user data

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

What we collect

Your account

Your Gmail address, an API key we generate for you, the encrypted Google refresh token, your sending settings, your daily limit, your timezone offset, and the date you connected. If you configure your own SMTP server instead of the Gmail API, we store its host, port, username and security setting, and the password encrypted. If you supply your own OpenRouter key for the AI features, we store it encrypted.

Your recipient list

When you upload a list, the whole parsed table reaches our server: each recipient’s email address and every other column of your spreadsheet, stored as arbitrary name and value pairs so they can be used as merge fields. We do not inspect, restrict, or interpret those columns. Whatever you put in the spreadsheet is what we store, so do not put anything in there you would not want on our server. Lists are capped at 2,000 recipients per campaign.

Files are parsed in your browser and never uploaded as files. A Google Sheets link is fetched only if the sheet is published publicly; we use no Google Drive or Sheets scope and cannot open a private sheet.

Your campaign and your message

We store the Gmail draft identifier, the subject line, your campaign settings, and counts of what was sent, failed, or bounced.

The message body is never written to our database. It exists in two places: the Gmail draft, which we delete when the campaign starts, and an encrypted cache in our job queue holding the raw message while the campaign runs. That cache expires 14 days after the last activity on the campaign, and is deleted outright when the campaign finishes.

Delivery and engagement

For each message we record the recipient’s address, the merge values used, the destination URLs of any links in the message, the recipient’s domain, the provider’s message id, the send timestamp, and any error the receiving server returned. Provider error text sometimes quotes the rejected address, so it can contain a recipient’s address.

If you enable tracking, we also record the timestamp of the first open and the first click for each message. We do not count repeat opens, and we do not store the recipient’s IP address, user agent, device, or location against those events. An open is a time and nothing more.

When a recipient unsubscribes we record their address and the reason on a suppression list tied to your account, so that later campaigns skip them. Addresses that hard-bounce are suppressed the same way.

Product analytics

The extension reports how the product is used to our own server, which forwards it to Amplitude. There is no third-party script in the extension and no analytics vendor is contacted directly by your browser.

What is sent: a random device identifier generated once per browser profile, your internal account id, an event name, a timestamp, and a few properties. What is deliberately not sent: no email address of any kind, no subject, no body, no merge values, and no merge field names. Recipient counts go out as ranges such as “51-200” rather than exact figures, because an exact count and a timestamp identify one specific campaign.

Server logs

Our server writes an application log for operational and security purposes. Those log lines include the IP address of the requesting client. This applies to requests from the extension and also to requests made by your recipients’ mail clients when they load a tracking pixel, follow a tracked link, or use an unsubscribe link. IP addresses are not written to our database and are not linked to engagement records; they exist only in the log stream.

Stored in your browser

The extension keeps the following in Chrome’s local extension storage, on your machine only. None of it syncs across devices.

Your uploaded list is never written to browser storage. It is held in memory and disappears when the tab closes.

Checks that run entirely on your machine

The content check that flags spam markers in your draft, and the list hygiene that reports invalid rows, duplicates and role addresses, both run locally in your browser. Neither sends your text or your list anywhere to do its work.

When your message text leaves our infrastructure

This section exists on its own because it is the exception to everything above.

The AI features - improve, rewrite, suggest subject lines, and write from a brief - send your text to our server, which relays it to OpenRouter, a routing service that passes the request to a language model provider. What is sent is your subject line, your message body as sanitised HTML, and, for personalisation, the names of your spreadsheet columns. Recipient addresses and merge values are never sent to the AI features. Neither is the content of your list.

This only happens when you press an AI button. If you never use those features, your message text never reaches OpenRouter. If you supply your own OpenRouter key, the request is billed to your key and is governed by your own agreement with them. OpenRouter’s handling of the data, and that of the model provider it routes to, is subject to their terms, which you should read if the content of your emails is sensitive.

Who we share data with

We do not sell personal data and we do not share it for cross-context behavioural advertising. We disclose it only to the following, and only for the purposes named.

We may also disclose data where the law requires it, to enforce our terms, to investigate abuse or fraud, or to protect the rights and safety of our users and the public. If the business is ever sold or merged, account data would transfer with it, and we would say so here first.

What we put inside the emails you send

You are the sender of every message, and these additions are made on your instruction, with the settings you choose.

Tracking and unsubscribe links are served from a domain shared by all senders on the service. Recipients are not profiled across senders, and we do not build audience data from engagement.

Legal bases for processing

Where the GDPR or similar law applies, we rely on: performance of a contract, for everything needed to run the service you signed up for; legitimate interests, for product analytics, security, abuse prevention and support, balanced against your rights; consent, where you give it, such as connecting your Google account or choosing to use an AI feature; and legal obligation, where we must retain or disclose something. For recipient data, the lawful basis for contacting those people is yours to establish, not ours.

How long we keep data

We are candid about this: the service has no automatic deletion. Account records, recipient lists and their merge fields, campaign records, per-message delivery results, and suppression entries are kept for as long as your account exists, so that your reports stay available to you.

The exceptions, which do expire on their own, are the message body cache in our queue, which clears 14 days after a campaign’s last activity or immediately on completion, and the browser-side campaign cache, which clears after seven days.

To have your data deleted, email support@mass-sender.com from the address you connected. We will delete your account and everything attached to it - lists, recipients, campaigns, messages and suppressions - within 30 days, other than anything we are legally required to keep. If you want a copy of your data before it goes, ask in the same message and we will send it.

Security

Google refresh tokens, SMTP passwords and OpenRouter keys are encrypted at rest with AES-256-GCM under a key held only on the server. Refresh tokens never leave the server and the extension never sees one. All traffic runs over HTTPS. API access is authenticated per account, and the list tokens and per-message tracking tokens are long random values that cannot be guessed or enumerated.

No system is perfectly secure, and we do not claim otherwise. If you believe your API key has been exposed, write to us and we will issue a new one and invalidate the old.

Your choices and your rights

Disconnecting Google

You can revoke our access at any time from your Google account’s third-party access page. Revoking stops us reading drafts or sending on your behalf, and any running campaign will fail at the next message. It does not by itself delete data already stored; email us for that.

Turning things off

Open and click tracking are switches you control per campaign. The unsubscribe link is forced on from 100 recipients up. The AI features are inert until you use them. Uninstalling the extension removes everything held in browser storage.

Data subject rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. Where we act as your processor for recipient data, requests from your recipients should go to you; if one reaches us, we will refer them to you and assist you in answering.

To exercise any right, email support@mass-sender.com. We answer within 30 days and do not charge for it, and we will not treat you differently for asking. If you are in the EEA or the UK and are unhappy with our answer, you may complain to your local supervisory authority, though we would rather you came to us first.

We do not sell or share personal information as those terms are used in California law, and we have not done so in the preceding twelve months.

Where your data is processed

The service is operated from Armenia, and our database is hosted there. Our subprocessors - Google, OpenRouter, Amplitude and Cloudflare - operate internationally, which means data may be processed outside your country and outside the EEA. Where we transfer personal data out of the EEA or the UK, we rely on the safeguards those providers offer for international transfers. If you would like detail on a particular provider, ask us.

Children

The service is for people aged 18 and over, and is not directed at children. We do not knowingly collect data from anyone under 18. If we learn that we have, we will delete it.

Changes to this policy

The service is in beta and changes often. When we change what we do with data, we will update this page and change the date above. For material changes we will say what changed, and, where we hold your address, tell you before it takes effect. Continuing to use the service after that means you accept the updated policy.

Contact

Questions, requests, complaints, or a security report: support@mass-sender.com.