Privacy Policy
Last updated: 2026-08-18
EmailKnow is privacy-first by construction. This policy states plainly what we access, what we store, and what we never touch. The wording matches our Google OAuth verification exactly.
What we access
To detect replies and send follow-ups on your behalf, EmailKnow requests only two sensitive Gmail scopes: gmail.send (send email) and gmail.metadata (read message headers — sender, subject, thread ID, timestamps). Sign-in uses openid, email, and profile only.
What we never access
We never read your email body, attachments, or message contents. gmail.metadata cannot access them by design, and we never request a broader scope.
What we store
We store only header-level metadata (subject, thread ID) and tracking events (opens, clicks, replies). Email bodies and attachments are never stored. Follow-up templates you configure are stored only as the content you chose to send.
How we handle IP addresses
Open and click events record an IP only as a salted SHA-256 hash — never plaintext. The sender's own IP hash is recorded at send time so opens from your own device are classified as “self” and excluded from recipient signals.
Honest signals
Open detection is inherently imperfect (Apple Mail Privacy Protection preloads images). We label every signal by confidence — human / apple / unknown / self — and never claim 100% accuracy.
Your control
Your tracking data lives under your account. You can export or delete it at any time. We never sell your data. Disconnecting Gmail clears your stored refresh token immediately.
Token security
Refresh tokens are encrypted at rest (AES-256-GCM) and never stored in plaintext. The Google client secret lives only on our server and is never sent to the extension.
Contact
Questions about this policy: privacy@emailknow.com