Privacy Policy

Privacy Policy for Mail2WhatsApp.

Effective date: July 14, 2026. Mail2WhatsApp is a Chrome extension that helps users turn Gmail customer enquiry emails into reviewed WhatsApp reply drafts.

Summary

Mail2WhatsApp is designed for user-controlled communication. The user connects Gmail, selects or loads customer enquiry emails, generates a WhatsApp-ready draft, reviews the message, and opens WhatsApp with the message prefilled. The user manually presses Send in WhatsApp.

Mail2WhatsApp does not sell Google user data, Gmail content, customer phone numbers, or generated drafts. Mail2WhatsApp does not use Google user data for advertising.

The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google User Data Access

Mail2WhatsApp requests the Gmail read-only OAuth scope:

https://www.googleapis.com/auth/gmail.readonly

This scope is used only so the user can read customer enquiry emails from their own Gmail account and prepare WhatsApp reply drafts. Mail2WhatsApp does not request permission to send, delete, archive, label, modify, or organize Gmail messages.

Raw Google user data accessed by Mail2WhatsApp may include the sender, subject, date, snippet, and body of Gmail messages selected or loaded by the user. Mail2WhatsApp does not create aggregated, anonymized, or de-identified Google user data sets from Gmail content.

Gmail data accessed

Email sender, subject, date, snippet, and body of emails selected or loaded by the user for the enquiry-to-WhatsApp workflow.

Gmail data not changed

Mail2WhatsApp does not modify Gmail messages, labels, settings, contacts, filters, or mailbox organization.

How Google User Data Is Used

  • To display selected or matching Gmail enquiry emails inside the extension workflow.
  • To generate a short WhatsApp-ready reply draft from the selected email content.
  • To help the user identify the customer context, such as sender name, enquiry topic, booking request, quotation request, property lead, or service request.
  • To support user-configured Gmail search queries for finding relevant enquiry emails.

Google user data is not used to train AI models, build advertising profiles, sell leads, or monitor users outside the Mail2WhatsApp customer-response workflow.

Mail2WhatsApp uses Gmail data only to provide or improve the user-facing Gmail-to-WhatsApp draft workflow requested by the user.

Data the Extension May Process

Gmail enquiry data

Sender, subject, date, snippet, and body of loaded or selected Gmail messages.

WhatsApp draft data

Generated draft text, user-edited draft text, and the customer WhatsApp number entered by the user.

Local settings

Gmail query, session token, backend URL, and draft preferences stored in Chrome extension storage.

Connection data

Server-side OAuth tokens needed to keep the user connected to Gmail after user-approved OAuth.

Storage and Retention

The Chrome extension stores local settings in Chrome extension storage, including Gmail query, session token, backend URL, and draft preferences. The extension does not store Gmail OAuth client secrets, Gmail refresh tokens, WhatsApp API tokens, or WhatsApp phone number IDs in Chrome extension storage.

The backend stores Google OAuth tokens needed to perform Gmail read-only requests after the user authorizes access. These tokens are linked to the user's Mail2WhatsApp session, stored in encrypted backend storage in production, and used only for the Gmail-to-WhatsApp draft workflow.

Generated WhatsApp drafts are created for user review. Mail2WhatsApp is designed to avoid retaining generated draft text longer than needed for the active user workflow, except where browser fields or local extension state temporarily hold the text during the session.

OAuth connection data is retained while the user keeps Gmail connected. If the user revokes Google access, uninstalls the extension, or requests deletion, Mail2WhatsApp will no longer use that Gmail connection and will delete backend connection data that is no longer needed to provide the service, unless retention is required by law or security obligations.

Sharing and Disclosure

Mail2WhatsApp does not sell, rent, or trade Google user data. Gmail content is sent only to the configured Mail2WhatsApp backend to support Gmail read-only access and message loading after user authorization. WhatsApp is opened through a wa.me link with user-reviewed message text.

Mail2WhatsApp may disclose data only if required by law, to protect the security of the service, or to operate the core Gmail-to-WhatsApp workflow requested by the user.

Raw or derived Google user data is not transferred to advertisers, data brokers, lending providers, or unrelated third parties. Mail2WhatsApp does not transfer Google user data to third-party AI or machine learning services for model training.

Security and Data Protection

Mail2WhatsApp protects Google user data by using HTTPS for communication with the Mail2WhatsApp backend, storing Google OAuth tokens in encrypted backend storage instead of inside the Chrome extension, restricting backend browser origins, and limiting access to data needed for the Gmail-to-WhatsApp draft workflow.

Local extension data is stored through Chrome extension storage. Users should protect their browser profile and Google account because anyone with access to the user's browser profile may be able to access extension settings.

Limited Use and AI/ML Restrictions

Mail2WhatsApp's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Mail2WhatsApp does not use raw, derived, aggregated, anonymized, or de-identified Gmail data to develop, improve, or train generalized AI or machine learning models. Mail2WhatsApp does not sell Google user data and does not use Google user data for advertising, credit decisions, lending decisions, or unrelated analytics.

If AI-assisted drafting is added or changed in the future, this policy will be updated before release to explain what provider is used, what data is sent, and how Google user data is protected from prohibited model training uses.

Message Sending

Mail2WhatsApp does not silently send WhatsApp messages. The extension opens WhatsApp with a message prefilled, and the user must review the message and press Send in WhatsApp. Businesses are responsible for contacting customers on WhatsApp only when they have appropriate consent and a legitimate reason to respond.

Data Not Collected

  • Passwords
  • Payment information
  • Authentication cookies
  • Browser history unrelated to Gmail use
  • Full inbox exports or email backups
  • Entire WhatsApp history
  • Data for advertising or resale

User Control and Deletion

Users control which Gmail account is connected, which Gmail query is used, which messages are loaded, which WhatsApp number is entered, and when a WhatsApp message is sent.

Users can remove local extension settings by clearing Chrome extension data or uninstalling the extension. Users can revoke Google access at any time from their Google Account permissions page. After revocation, Mail2WhatsApp can no longer use Gmail read-only access for that account.

For deletion requests related to backend session data or OAuth connection data, use the contact method shown on the Mail2WhatsApp website or Chrome Web Store listing.

Policy Changes

This policy will be updated if Mail2WhatsApp changes how it accesses, uses, stores, shares, or deletes Google user data. Material changes will be reflected on this page before or when the change is released.

Contact and Product Links

Mail2WhatsApp is not affiliated with Google, Gmail, Meta, or WhatsApp.