QuillReply for Gmail 的隐私政策
QuillReply for Gmail 作者: Quill Marketing
QuillReply for Gmail — Privacy Policy
Full policy, always current: https://quillreply.com/privacy
WHAT THE EXTENSION READS
QuillReply requests no Gmail API permission and holds no Gmail OAuth scope. When you click a QuillReply button on an open email, the extension reads that one message from the page you are already looking at. It does not browse, search, or read your mailbox in the background, and it reads nothing unless you click.
WHAT HAPPENS TO EMAIL CONTENT
The subject and body of that one message are sent over TLS to our backend, which passes them to Anthropic to generate the draft or the task suggestion. We discard the content immediately and never store it. Anthropic retains it under their own published API terms for at most 30 days. Email content is never used to train any model of ours.
YOUR WRITING VOICE
Stored locally in your browser as a short set of style patterns (roughly how formal you are, typical length, whether you use contractions, how you sign off) rather than as your messages. It is sent with each request and is not retained on our servers. Per-recipient adjustments are stored in your browser under a hashed address, never the address itself.
WHAT WE STORE ON OUR SERVERS
- Opaque account identifier, to know which subscription a request belongs to. Until you delete your account.
- Subscription and Stripe billing data, for billing. Until deletion, then as tax law requires.
- Action counts, to enforce the free allowance. Until you delete your account.
- Session token, hashed, for authentication. Deleted automatically when it expires.
- Queued Apple Reminders, for delivery to your Mac app or Shortcut. 30 days, or as soon as your device confirms receipt.
- Reminder list names, so the list picker is accurate. Until you disconnect that destination.
- Install identifier, for anonymous install and uninstall counting. Kept permanently, and anonymised if you delete your account.
- Product events, meaning which QuillReply buttons were used and when. Until you delete your account.
We do not store your email address, your message content, your subjects, or your drafts.
THIRD PARTIES
Anthropic (draft and task generation), our hosting provider, Todoist and Microsoft To Do (their tokens stay in your browser and never reach our servers), Basecamp (its token passes through our server with each request and is never stored, because Basecamp requires an identifying header a browser extension cannot set), Stripe (payments, we never see a card number), and Google Analytics on the marketing website only, not in the extension.
APPLE REMINDERS
Handled by a companion Mac app or an iOS Shortcut that you install yourself. Reminders are written locally by Apple's own Reminders engine. We never request or hold an Apple credential of any kind.
DELETING YOUR DATA
"Delete my data" in the extension's settings revokes your tokens, removes any queued reminders, and marks the account for purging within 30 days.
Two anonymous records outlive the account by design: the install identifier and whether that install was later removed. This is so historical install counts do not change as people leave. Neither can be traced to a person, and neither is linked to an account once the account is gone.
Contact: hello@quillreply.com