Back to home
Legal

Privacy Policy.

This policy explains the current SafeReplies data boundary for browser-extension draft review. Read it alongside our Terms & Conditions.

Last updated: 21 June 2026

01 What SafeReplies does

SafeReplies helps review outbound workplace email drafts before the sender decides what to do. The current browser extension is built around user-triggered checks of the visible compose draft, not background mailbox monitoring.

02 Draft content reviewed by the extension

When a user clicks Scan with SafeReplies, the extension may read the visible Gmail compose subject and body in that compose window. It does not use Gmail API scopes and it does not read inbox history, sent mail, message threads, hidden drafts, or mailbox content in the background.

03 Attachment handling

The current extension does not scan attachment contents. It may detect visible attachment presence in a count-style way so a review can note that an attachment appears to be present, without collecting attachment filenames or file contents.

04 Server-side review

When configured for SafeReplies API mode, draft subject and body may be sent over HTTPS to SafeReplies servers to provide review and rewrite functionality. Current staging review uses deterministic scanning and staging-token testing; it should not be treated as full production AI or compliance readiness.

05 User control

SafeReplies does not auto-send email, does not address messages, and does not automatically mutate draft content. Users choose whether to copy a safer rewrite, edit manually, escalate, ignore, or send from Gmail.

06 What we do not collect in the current extension

The current Chrome package is not designed to collect recipients, Gmail thread IDs, inbox or sent-history data, background mailbox content, Gmail API data, attachment contents, payment data, or unrelated website activity.

07 How data is used

Draft review data is used to provide SafeReplies risk guidance, safer wording suggestions, staging review records where enabled, service diagnostics, security, and abuse prevention. We do not sell user data.

08 Retention and security

Production retention periods and operational controls should be confirmed before public-scale launch. Current staging work keeps real customer data out of scope and uses HTTPS for configured API calls.

09 Contact

Questions about privacy or data handling can be sent through the contact page or to hello@safereplies.com.

10 Legal review

This Privacy Policy is aligned with the current implementation scope, but it should receive legal review before a public-scale launch or Chrome Web Store public submission.
Book a call