Last updated 30 August 2026
Privacy policy
This policy explains what Mass Email Sender does with personal data. It covers the Chrome extension, this website, and the sending service at api.mass-sender.com (together, the “service”). It is written to be read, not to be survived. If something here does not match what the software does, the software is the thing we will fix.
The short version
- We ask Google for one restricted scope,
gmail.compose. It lets us read the draft you are sending and send copies of it. It cannot read your inbox, and we never do. - Your recipient list is uploaded to our server. It has to be, because the server is what sends the messages and personalises them.
- The body of your email does not travel through the extension and is never written to our database. It lives in the Gmail draft, and in an encrypted queue cache for up to 14 days while the campaign runs.
- If you use the AI writing features, your subject line and message text are sent to our server and relayed to OpenRouter, an external model provider. This is the one place your message text leaves our infrastructure. It only happens when you press an AI button.
- We do not sell personal data, we do not share it for advertising, and we never email your recipients on our own behalf.
- We do not delete your data on a timer. Ask us and we will remove it.
Who we are
Mass Email Sender is operated by Alex Gromov, an individual trader based in Yerevan, Armenia. For anything in this policy, including requests to access or delete data, write to support@mass-sender.com.
Two kinds of data, and two different roles
This distinction runs through the whole policy, so it comes first.
Your data. Your Google account address, your API key, your settings, your campaign history. For this we are the data controller. This policy describes how we handle it.
Your recipients’ data. The addresses and spreadsheet columns you upload, and the delivery results that come back. For this you are the controller and we are your processor: we hold and use that data only to carry out the sending you asked for. Deciding who belongs on your list, and having a lawful basis to email them, is your responsibility, not ours. Our terms of service set out what you commit to when you upload a list.
What we ask for from your Google account
Connecting an account opens Google’s own consent screen. We request exactly three scopes.
| Scope | Why we need it |
|---|---|
gmail.compose | Read the one draft you are sending, and send one personalised copy per recipient from your mailbox. This is a restricted scope. It does not grant access to your inbox, your threads, or any message other than the draft in question. |
openid | Complete the sign-in. |
userinfo.email | Learn which account you just connected, so your campaigns and API key attach to the right mailbox. We read the address and nothing else from your Google profile. |
Two consequences worth stating plainly. First, because we hold no read scope over your mailbox, we cannot see replies or bounce notifications that arrive in your inbox; delivery failures are only visible to us when the sending server reports them at the moment of sending. Second, we delete the source draft from your Gmail once the campaign starts. The campaign sends from a copy held in our queue, and leaving the original in place produces a duplicate you did not ask for. If you want to keep the text, keep a copy before you send.
Limited use of Google user data
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the features you are using it for.
- We do not transfer Google user data to third parties except as needed to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition.
- We do not use Google user data for advertising, and we do not sell it.
- We do not use Google user data to develop, improve, or train generalised artificial intelligence or machine learning models.
- Humans do not read your Google user data, except where you have given specific consent for a support request, where it is necessary for security purposes or to investigate abuse, or where the law requires it.
What we collect
Your account
Your Gmail address, an API key we generate for you, the encrypted Google refresh token, your sending settings, your daily limit, your timezone offset, and the date you connected. If you configure your own SMTP server instead of the Gmail API, we store its host, port, username and security setting, and the password encrypted. If you supply your own OpenRouter key for the AI features, we store it encrypted.
Your recipient list
When you upload a list, the whole parsed table reaches our server: each recipient’s email address and every other column of your spreadsheet, stored as arbitrary name and value pairs so they can be used as merge fields. We do not inspect, restrict, or interpret those columns. Whatever you put in the spreadsheet is what we store, so do not put anything in there you would not want on our server. Lists are capped at 2,000 recipients per campaign.
Files are parsed in your browser and never uploaded as files. A Google Sheets link is fetched only if the sheet is published publicly; we use no Google Drive or Sheets scope and cannot open a private sheet.
Your campaign and your message
We store the Gmail draft identifier, the subject line, your campaign settings, and counts of what was sent, failed, or bounced.
The message body is never written to our database. It exists in two places: the Gmail draft, which we delete when the campaign starts, and an encrypted cache in our job queue holding the raw message while the campaign runs. That cache expires 14 days after the last activity on the campaign, and is deleted outright when the campaign finishes.
Delivery and engagement
For each message we record the recipient’s address, the merge values used, the destination URLs of any links in the message, the recipient’s domain, the provider’s message id, the send timestamp, and any error the receiving server returned. Provider error text sometimes quotes the rejected address, so it can contain a recipient’s address.
If you enable tracking, we also record the timestamp of the first open and the first click for each message. We do not count repeat opens, and we do not store the recipient’s IP address, user agent, device, or location against those events. An open is a time and nothing more.
When a recipient unsubscribes we record their address and the reason on a suppression list tied to your account, so that later campaigns skip them. Addresses that hard-bounce are suppressed the same way.
Product analytics
The extension reports how the product is used to our own server, which forwards it to Amplitude. There is no third-party script in the extension and no analytics vendor is contacted directly by your browser.
What is sent: a random device identifier generated once per browser profile, your internal account id, an event name, a timestamp, and a few properties. What is deliberately not sent: no email address of any kind, no subject, no body, no merge values, and no merge field names. Recipient counts go out as ranges such as “51-200” rather than exact figures, because an exact count and a timestamp identify one specific campaign.
Server logs
Our server writes an application log for operational and security purposes. Those log lines include the IP address of the requesting client. This applies to requests from the extension and also to requests made by your recipients’ mail clients when they load a tracking pixel, follow a tracked link, or use an unsubscribe link. IP addresses are not written to our database and are not linked to engagement records; they exist only in the log stream.
Stored in your browser
The extension keeps the following in Chrome’s local extension storage, on your machine only. None of it syncs across devices.
- Your API key, held per Gmail address so several accounts can be used in one browser. It is stored unencrypted, as browser extension storage has no key vault; anyone with access to your computer profile can read it.
- Campaigns currently running, so a progress card survives a tab reload.
- A cache of your recent campaign list for seven days. It includes subject lines. It does not include any recipient address.
- Your last used campaign settings, a random analytics device id, and a flag noting you have seen the onboarding tour.
Your uploaded list is never written to browser storage. It is held in memory and disappears when the tab closes.
Checks that run entirely on your machine
The content check that flags spam markers in your draft, and the list hygiene that reports invalid rows, duplicates and role addresses, both run locally in your browser. Neither sends your text or your list anywhere to do its work.
When your message text leaves our infrastructure
This section exists on its own because it is the exception to everything above.
The AI features - improve, rewrite, suggest subject lines, and write from a brief - send your text to our server, which relays it to OpenRouter, a routing service that passes the request to a language model provider. What is sent is your subject line, your message body as sanitised HTML, and, for personalisation, the names of your spreadsheet columns. Recipient addresses and merge values are never sent to the AI features. Neither is the content of your list.
This only happens when you press an AI button. If you never use those features, your message text never reaches OpenRouter. If you supply your own OpenRouter key, the request is billed to your key and is governed by your own agreement with them. OpenRouter’s handling of the data, and that of the model provider it routes to, is subject to their terms, which you should read if the content of your emails is sensitive.
Who we share data with
We do not sell personal data and we do not share it for cross-context behavioural advertising. We disclose it only to the following, and only for the purposes named.
| Recipient | What they receive |
|---|---|
| The OAuth exchange, the draft read, and every message we send on your behalf, including recipient address, subject, body and attachments. We also attach a feedback identifier to outgoing mail containing your campaign and account ids, which Google’s Postmaster Tools uses to report spam rates back to a sender. | |
| OpenRouter | Subject and message text, but only when you use an AI feature. See above. |
| Amplitude | Product analytics events as described above. No addresses, no content. |
| Cloudflare | Network traffic to our API passes through Cloudflare, which sees connection metadata in transit. |
| Your SMTP provider | If you choose SMTP transport instead of Gmail, your messages go through the provider you configured, under your own agreement with them. |
| Public DNS | We look up mail records for your sending domain and your recipients’ domains to run the deliverability checks. These are ordinary public DNS queries for domain names, not for individuals. |
We may also disclose data where the law requires it, to enforce our terms, to investigate abuse or fraud, or to protect the rights and safety of our users and the public. If the business is ever sold or merged, account data would transfer with it, and we would say so here first.
What we put inside the emails you send
You are the sender of every message, and these additions are made on your instruction, with the settings you choose.
- Open tracking, if enabled, adds a 1x1 transparent image whose URL identifies the message. Loading it records a first-open timestamp.
- Click tracking, if enabled, rewrites links so they pass through our server before redirecting to the original destination, recording a first-click timestamp.
- An unsubscribe link and the matching one-click headers, so mail clients can offer an unsubscribe button. This is forced on for lists of 100 recipients or more, whatever your settings say, because sending bulk mail without a working opt-out is both bad practice and unlawful in most of the jurisdictions our users send into.
Tracking and unsubscribe links are served from a domain shared by all senders on the service. Recipients are not profiled across senders, and we do not build audience data from engagement.
Legal bases for processing
Where the GDPR or similar law applies, we rely on: performance of a contract, for everything needed to run the service you signed up for; legitimate interests, for product analytics, security, abuse prevention and support, balanced against your rights; consent, where you give it, such as connecting your Google account or choosing to use an AI feature; and legal obligation, where we must retain or disclose something. For recipient data, the lawful basis for contacting those people is yours to establish, not ours.
How long we keep data
We are candid about this: the service has no automatic deletion. Account records, recipient lists and their merge fields, campaign records, per-message delivery results, and suppression entries are kept for as long as your account exists, so that your reports stay available to you.
The exceptions, which do expire on their own, are the message body cache in our queue, which clears 14 days after a campaign’s last activity or immediately on completion, and the browser-side campaign cache, which clears after seven days.
To have your data deleted, email support@mass-sender.com from the address you connected. We will delete your account and everything attached to it - lists, recipients, campaigns, messages and suppressions - within 30 days, other than anything we are legally required to keep. If you want a copy of your data before it goes, ask in the same message and we will send it.
Security
Google refresh tokens, SMTP passwords and OpenRouter keys are encrypted at rest with AES-256-GCM under a key held only on the server. Refresh tokens never leave the server and the extension never sees one. All traffic runs over HTTPS. API access is authenticated per account, and the list tokens and per-message tracking tokens are long random values that cannot be guessed or enumerated.
No system is perfectly secure, and we do not claim otherwise. If you believe your API key has been exposed, write to us and we will issue a new one and invalidate the old.
Your choices and your rights
Disconnecting Google
You can revoke our access at any time from your Google account’s third-party access page. Revoking stops us reading drafts or sending on your behalf, and any running campaign will fail at the next message. It does not by itself delete data already stored; email us for that.
Turning things off
Open and click tracking are switches you control per campaign. The unsubscribe link is forced on from 100 recipients up. The AI features are inert until you use them. Uninstalling the extension removes everything held in browser storage.
Data subject rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. Where we act as your processor for recipient data, requests from your recipients should go to you; if one reaches us, we will refer them to you and assist you in answering.
To exercise any right, email support@mass-sender.com. We answer within 30 days and do not charge for it, and we will not treat you differently for asking. If you are in the EEA or the UK and are unhappy with our answer, you may complain to your local supervisory authority, though we would rather you came to us first.
We do not sell or share personal information as those terms are used in California law, and we have not done so in the preceding twelve months.
Where your data is processed
The service is operated from Armenia, and our database is hosted there. Our subprocessors - Google, OpenRouter, Amplitude and Cloudflare - operate internationally, which means data may be processed outside your country and outside the EEA. Where we transfer personal data out of the EEA or the UK, we rely on the safeguards those providers offer for international transfers. If you would like detail on a particular provider, ask us.
Children
The service is for people aged 18 and over, and is not directed at children. We do not knowingly collect data from anyone under 18. If we learn that we have, we will delete it.
Changes to this policy
The service is in beta and changes often. When we change what we do with data, we will update this page and change the date above. For material changes we will say what changed, and, where we hold your address, tell you before it takes effect. Continuing to use the service after that means you accept the updated policy.
Contact
Questions, requests, complaints, or a security report: support@mass-sender.com.