Mail Toolbox
登录

Privacy Policy

Last updated: 11 September 2026

This page is available in English only; the English version prevails.

The short version

  • Exporting and notes happen entirely in your browser. Your email content is not sent anywhere.
  • Only when you click an AI button does that one conversation's text go to our server, and on to our AI provider.
  • We do not store email content and we do not use it to train any model.

Who is responsible

Mail Toolbox is a product of Xeviora, a brand operated by LIU HU, a sole proprietor, who is the controller of the personal data described in this policy. Contact: support@xeviora.com

What the extension reads

The extension runs only on mail.google.com. When you ask it to export, summarize or annotate a conversation, it reads that conversation through Gmail’s own print view, using the browser session you are already signed in with. For unread alerts it reads the unread feed that Gmail publishes to your signed-in session.

It does not use the Gmail API, does not request Google OAuth permissions, and cannot access your mailbox when your browser is closed. It never sends email on your behalf.

AI processing

To provide summaries, drafted replies, translation, data extraction and inbox triage, the content you submit is sent to our AI service providers (OpenRouter and the model providers it routes to) for processing. AI features are off unless you sign in and click one. When you do, the text of that single conversation (or, for triage, the sender, subject, date and preview snippet of each conversation on screen) is sent over HTTPS to our server, which forwards it to our AI provider to generate the result.

We do not write the conversation text to our database. We keep only metadata about the run: which task, which model, how many credits, how long it took, and how many characters were sent — never the content itself.

We do not use your content to train models, and our providers process it only to return results to you.

Notes

Notes are stored in your browser’s local storage and never leave your device on the Free plan.

On Pro and Max, notes are synced: the note text is stored on our servers so your other signed-in devices can see it. You can delete a note at any time; deletions sync too.

Account data

If you create an account we store your email address, a hashed password (or your Google or GitHub account identifier if you sign in with one of those), your plan and subscription status, and your credit ledger.

Payment processing

Payments are processed by our reseller and Merchant of Record, Paddle.com (“Paddle”). Paddle collects and processes your payment and billing information (such as name, email, billing address, country and payment details) as an independent data controller in order to process your order, calculate taxes, prevent fraud and meet its legal obligations. We never receive or store your full card details. We receive limited order information from Paddle (such as your email, country, plan and transaction status) to provide the service. See Paddle’s Privacy Notice: https://www.paddle.com/legal/privacy.

Checkout for all Xeviora products opens on xeviora.com. When you start a checkout, we pass your account ID, email address and the plan you chose to xeviora.com so the order can be opened with Paddle and linked back to your Mail Toolbox account.

Newsletter

If you subscribe to our newsletter, your email address is passed to MailerLite, our email service provider, together with a tag identifying which page you subscribed from. It is not stored in our own database, and subscribing is entirely separate from having an account.

Subscription uses double opt-in — nothing is sent until you click the confirmation link — and every email includes a one-click unsubscribe. We do not link your subscription to your purchases or product usage.

Cookies

We set one cookie: your login session, scoped to this site only. We do not use advertising or cross-site tracking cookies, and we do not run third-party analytics that profile you.

How long we keep things

Account data is kept while your account exists. AI run metadata is kept for 90 days for troubleshooting and billing accuracy, then deleted. Deleting your account removes your account record, synced notes and credit ledger. Paddle keeps its own order records as required by law.

Service providers

Vercel (hosting), Neon (database), OpenRouter and the model providers it routes to (AI processing), Paddle (payments, as an independent controller), MailerLite (newsletter delivery, when you subscribe), and Google or GitHub (sign-in, when you choose to sign in with them). Each receives only what it needs to do its job, and none of them receives your email content except the AI provider handling a run you started.

Your rights

You can ask to access, correct, export or delete your personal data, or object to how we process it, by emailing support@xeviora.com. We will respond within 30 days. If you are in the EEA or UK, you have the rights granted by the GDPR, including the right to complain to your local supervisory authority.

Changes

If this policy changes materially, we will update the date above and, where appropriate, notify you by email or in the product.

Contact

Questions about this policy: support@xeviora.com