LEGAL
Privacy Policy
Last updated: 2026-07-02
Tolomail is a Chrome extension that helps you navigate Gmail by visualizing thread structure, tracking awaiting replies, browsing attachments, and organizing conversations into projects. This privacy policy explains what data Tolomail accesses, what it does with that data, and what choices you have.
Summary
- Tolomail reads your Gmail in your browser to render visualizations and to find emails that match the keywords you set up.
- All thread data, attachments, notes, and project data are stored locally on your device in your browser's IndexedDB and Chrome storage.
- The Projects feature and keyword auto-file run Gmail searches to pull matching emails into your projects. Those searches go to Google's own Gmail API (the same first-party API Gmail itself uses) — not to Tolomail or any third party. Your keywords, project names, and to-do lists stay on your device.
- A Drive backup feature (ON by default) mirrors your notes, awaiting list, favorites, project data, and team roster to your own Google Drive (
appdatafolder — invisible to you outside Tolomail). It runs automatically so your data survives a reinstall or a move to a new computer; you can turn it off, or delete the Drive copy, at any time in Tolomail's Settings. - No data is sent to Tolomail's servers. We do not operate any server that receives your data.
- No third-party analytics, advertising, or tracking SDKs. No AI/ML processing of your mail.
Limited Use disclosure (Google API Services User Data Policy)
Tolomail's use of information received from Google APIs — including data obtained via the gmail.readonly restricted OAuth scope — adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Use only to provide or improve user-facing features. Tolomail uses Gmail data exclusively to render the in-product features the user opens Tolomail to use (thread map, awaiting-reply tracker, searchable attachments view, per-thread notes, and the Projects workspace with keyword auto-file). The data is never used for any purpose unrelated to these user-facing features.
- No transfer to others. Tolomail does not transfer Gmail data to any third party except (a) as necessary to provide or improve user-facing features (none, since all processing is local), (b) for security purposes (e.g. to investigate abuse), (c) to comply with applicable law, or (d) as part of a merger, acquisition, or sale of assets with the user's explicit consent.
- No advertising use. Tolomail does not use Gmail data for advertising of any kind, anywhere.
- No AI/ML model training. Tolomail does not use Gmail data to develop, improve, or train generalized AI and/or ML models. Tolomail does not run any AI/ML model on user data. The keyword auto-file feature uses plain Gmail search queries (the same kind you would type into Gmail's search box) — there is no AI classification of your mail.
- No human reads of user data except (a) with the user's explicit consent for specific messages, (b) where necessary for security purposes such as investigating abuse, or (c) to comply with applicable law. The developer does not have access to any user's Gmail data — all data is processed and stored in the user's own browser; there is no server-side copy.
Why gmail.readonly and not a narrower scope?
Tolomail renders the structure of conversations (sender, subject, body excerpts, in-reply-to relationships) and indexes attachments by filename, type, and metadata. The narrower gmail.metadata scope returns only headers and labels — no message bodies, no attachment payloads, no body snippets — which is insufficient for Tolomail's core thread-map and attachment-browsing features. gmail.readonly is the minimum scope that supports the features described in the Tolomail Chrome Web Store listing.
What permissions Tolomail uses, and why
| Permission | Why |
|---|---|
gmail.readonly (OAuth) | Read message bodies and headers to render thread maps, extract attachment metadata, scan sent mail for awaiting replies, and run keyword searches that pull matching emails into your Projects. Tolomail never writes, sends, deletes, or modifies your Gmail. |
drive.appdata (OAuth) | Used for the "Drive backup" feature. Backup is ON by default — Tolomail writes one JSON file per account (notes, awaiting list, favorites, project data, and your team roster) to a private folder in your own Google Drive that only Tolomail can see, so your data survives a reinstall. You can turn backup off, or delete the Drive file, from Settings ("Delete my Drive backup" button); existing Drive data is left untouched when you turn it off. |
drive.file (OAuth) | Used only for the optional Team Workspace feature. When you create or join a shared team workspace, Tolomail reads/writes a single Drive file you explicitly pick or create via Google's file picker. drive.file grants access only to files you specifically open or create with Tolomail — never the rest of your Drive, other files, or folders. The file holds your team's shared project list so teammates' installs stay in sync. |
openid (OAuth) | Used solely to obtain your Google Account ID for correctly namespacing multi-account data. No additional profile information is requested. |
storage | Save your Tolomail settings, notes, awaiting-reply state, account list, project data (project/sub-project names, keywords, to-dos, and any email addresses you add to a project's scope), and — if you use the Team & stations feature — this install's station name/alias and your team roster (teammate names + addresses), in your browser's local storage. |
sidePanel | Render the Tolomail attachments, thread-map, and Projects views in Chrome's side panel. |
downloads | Save attachments you choose to download via the Attachments panel's Download button. Tolomail never writes to Downloads without an explicit click. |
alarms | Schedule periodic Drive backup runs and fire your Projects to-do reminders at the date/time you set. |
notifications | Show a desktop notification when a Projects to-do you scheduled becomes due. No notification content leaves your device. |
identity, identity.email | Identify which Google account you're using so per-account data stays isolated. |
Host permissions: mail.google.com, gmail.googleapis.com, www.googleapis.com/drive/v3, www.googleapis.com/upload/drive/v3, www.googleapis.com/oauth2/v3, oauth2.googleapis.com | Required to make authorized requests to Google's Gmail, Drive (appdata only), and OAuth userinfo endpoints on your behalf. Narrowed in v0.9.68 to the specific endpoints actually used. |
Where your data lives
| Data | Location |
|---|---|
| Thread maps, message metadata | Your browser's IndexedDB (gtv database) |
| Attachment metadata + cached blobs | Your browser's IndexedDB (gmail-attachments database) |
| Projects, sub-projects, to-dos, and which emails belong to each | Your browser's IndexedDB (tolomail-projects database) |
| Project keywords, project email scope (addresses you add), contact-name labels | Your browser's chrome.storage.local / the tolomail-projects database |
| Station identity (this install's name + alias) | Your browser's chrome.storage.local — local to this install, never synced |
| Team roster (teammate names + addresses you add) | Your browser's chrome.storage.local, per account — included in the Drive backup if you enable it |
| Notes (per thread) | Your browser's chrome.storage.local |
| Awaiting-reply state | Your browser's chrome.storage.local |
| Account registry | Your browser's chrome.storage.local |
| Drive backup (ON by default) | Your own Google Drive (appdata folder — only Tolomail can access). Runs automatically; turn it off or delete the copy in Settings. |
| OAuth tokens | Chrome's built-in chrome.identity token cache (encrypted at rest by Chrome) |
Tolomail does not transmit any of this data to any third party. Tolomail operates no server.
Projects and keyword auto-file — what is sent where
The Projects workspace lets you group Gmail threads into projects and sub-projects, add to-dos, and automatically pull in matching emails. Here is exactly how that works:
- Keyword auto-file runs a Gmail search. When you click "Find emails" (or set up keyword auto-file), Tolomail builds a Gmail search query from the keywords and project names you entered and sends it to Google's first-party Gmail API — the same API Gmail's own search box uses. This is not a third party, and it is not an AI service. It is the only way to find your matching emails. Tolomail receives the matching threads back and shows them to you for review.
- Per-project email scope (optional). You can add email addresses to a project so auto-file only pulls threads to/from those addresses. Those addresses are added as
from:/to:/cc:/bcc:/deliveredto:terms in the same Gmail search. The addresses are stored locally on the project record; adding them does not request any new Gmail permission. - Contact names (optional). You can label an address or domain with a friendly name (e.g. "Acme Legal"). This map is stored locally in your browser and is used only to make sender/recipient names readable in your Gmail list. It never touches the network.
- Everything else stays local. Your project names, sub-project names, keywords, to-dos, due dates, and the record of which threads belong to which project all live in your browser (the
tolomail-projectsIndexedDB and Chrome storage), per Google account. None of it is sent to Tolomail (there is no Tolomail server) or to any third party.
To be precise: the only thing that "leaves your device" for Projects is the Gmail search query, and it goes only to Google's own Gmail API using your existing read-only access. Tolomail never writes, labels, sends, or deletes anything in your Gmail.
To-do reminders
Projects to-dos can have a due date and time. When that time arrives, Tolomail fires a local desktop notification (using Chrome's alarms and notifications permissions). The reminder is scheduled and shown entirely on your device — no reminder content is transmitted anywhere.
Team & stations (targeted notes and to-dos)
If your team shares one Google account, Tolomail lets you address a note or to-do "For:" a specific teammate so it only surfaces on their copy of Tolomail. This is entirely local — it does not involve Gmail or any server:
- You optionally give this install a station name + alias, and build a team roster of teammate names + addresses, in Settings. The station identity stays on this device; the roster is stored per account and is included in your Drive backup (if you enabled it) so your own installs can share it.
- A note or to-do can carry a target address ("For:") and the address of whoever created it. These are stored alongside the note/to-do (locally, and in your Drive backup if enabled).
- The "For:" targeting is a visibility filter in Tolomail's interface — it decides which items each station shows. Because everything is stored locally / in your own Drive, this reduces noise; it is not a security boundary, and no addresses or content are sent to Tolomail (there is no Tolomail server) or any third party.
Inbox grouping (week dividers and day labels)
Tolomail can add week dividers ("This week", "Last week"…) and a small colored weekday label to your Gmail list. These read the date Gmail has already displayed on each row and add visual markers in the page — no Gmail API call, no network request, and nothing leaves your device. Both can be turned off in Settings.
Multi-account support
If you register more than one Google account in Tolomail, each account's data — including all project data and your team roster — is stored under a separate namespace keyed by your Google account ID. Tolomail does not share data between your registered accounts.
Data deletion
| To delete | Action |
|---|---|
| One registered account + its local data | In Tolomail's popup, click "Remove" next to the account. This clears IndexedDB + storage entries for that account. |
| All Tolomail data | Uninstall the extension. Chrome automatically clears all chrome.storage.local and IndexedDB entries owned by the extension. |
| The Drive backup file | In Tolomail's Settings, click "Delete my Drive backup." Or go to drive.google.com → Settings → Manage apps → find Tolomail → Disconnect. Either deletes the appdata folder. |
| Revoke OAuth grant | Go to myaccount.google.com/permissions → find Tolomail → Remove. |
Support diagnostics
Tolomail includes built-in diagnostics panels (press Alt+Shift+L in Gmail for the main panel, or Alt+Shift+D in the Projects side panel) that show the extension's internal logs and state. They exist so you can troubleshoot issues and, if you choose, share diagnostics with support.
- Local only. The panels read data already on your device. Nothing is transmitted anywhere — diagnostics leave your machine only if you manually copy them and send them to us.
- Privacy-masked by design. Email addresses are masked (
t•••[email protected]), Gmail search queries and label names are redacted, attachment filenames are truncated, and message subjects and bodies are never logged at all. Project, sub-project, and keyword names are likewise never logged — the Projects diagnostics show only counts and redacted operation codes. - You see exactly what you send. The "Copy all" button copies the same text the panel displays — review it before sharing. Diagnostics you email us are used only to debug your issue and then deleted.
Children's privacy
Tolomail is not directed at children under 13. We do not knowingly collect data from children under 13.
Changes to this policy
We may update this policy when Tolomail adds new features. Material changes will be reflected in the "Last updated" date at the top. Continued use of Tolomail after a change constitutes acceptance.
Contact
Questions or concerns: [email protected]
Compliance
See the "Limited Use disclosure" section above for the full Google API Services User Data Policy statement.