Privacy Policy
Effective date: March 5, 2026
What we collect
DraftAlert collects the minimum data necessary to deliver its reminder service:
| Data | Purpose | Storage |
|---|---|---|
| Google account email address | Reminder delivery, account identification | Firestore |
| Gmail draft metadata (draft ID, thread ID, creation date) | Detecting unsent drafts | Firestore |
| Draft subject line | Only if you enable "Show subject in reminders" | Firestore (opt-in only) |
| OAuth tokens | Authorizing Gmail API calls on your behalf | Google Cloud Secret Manager (encrypted) |
How we use your data
- To detect drafts you have not sent and schedule reminders
- To deliver reminders via your Gmail inbox or the add-on sidebar
- To maintain your preference settings (reminder interval, snooze, etc.)
We do not sell your data, use it for advertising, or share it with third parties.
Data retention
Draft records are retained until:
- You delete the draft in Gmail (detected within 15 minutes)
- You click "Don't Remind" for a specific draft
- You delete your data (see below)
User settings are retained until you uninstall the add-on or request deletion.
Deleting your data
You can delete all your data at any time:
- Open Gmail โ DraftAlert sidebar
- Click the menu (โฎ) โ "Delete my data"
- All Firestore records and stored tokens are permanently deleted within seconds.
You can also contact us at privacy@draftalert.email and we will process your deletion request within 30 days.
Security
- OAuth refresh tokens are stored in Google Cloud Secret Manager with automatic replication and access audit logging.
- Access tokens cached in Firestore are encrypted with AES-256-GCM using a key stored separately in Secret Manager.
- All services use Google Cloud IAM with least-privilege service accounts.
- Tokens are never included in application logs.
Third-party services
DraftAlert uses the following Google services to operate:
- Google Gmail API โ to read draft metadata and deliver inbox reminders
- Google Firestore โ to store user settings and draft records
- Google Cloud Secret Manager โ to securely store OAuth tokens
- Google Cloud Tasks โ to schedule and deliver reminder notifications
No data is shared with any other third parties.
Children's privacy
DraftAlert is not directed to children under 13. We do not knowingly collect personal information from children under 13.
Changes to this policy
We may update this privacy policy from time to time. We will notify users of material changes by updating the effective date at the top of this page. Continued use of DraftAlert after changes constitutes acceptance of the updated policy.