Политика приватности для «Gmail One-Click Cleaner»
Gmail One-Click Cleaner от SecPlusMastery
This policy is also published at https://gmail-cleaner-pro.netlify.app/privacy
Effective 2026-09-26.
The extension has no analytics, no telemetry, no error reporting, no account system, and no ability to send your mail anywhere: the extension itself issues no network requests at all. Below is the precise version, including the few places where information does move and exactly why.
• The extension sends nothing. Cleanup, scanning, suggestion ranking and unsubscribing all run locally, in your own browser session, against the Gmail interface. No email content, subject, address or credential is ever transmitted to us. We operate no service that could receive your mail, and we cannot read your mailbox.
• What stays on your device. Your recovery log, cleanup history, run statistics and the results of subscription, storage, sender census and suggestion scans are held in the extension's local storage. Those scans build an on-device index of who emails you, how much storage each sender uses, how much of their mail you leave unread, and which senders you have already acted on; Smart Suggestions and Auto-Pilot rank suggestions from it, and it reads your Sent mail to notice senders you actually reply to. The sender census stores the addresses and display names it measured, and the senders you tick in that list are stored too, because a cleanup run uses them. Each census replaces the one before it, and a census also ages out on its own. Once it is a month old the extension stops printing what a clear would take from each sender, because another month of mail has crossed the six month line it clears on and that stored figure now understates it. The list, the ticks and each sender's own volume are kept and still shown; it is the number attached to the delete button that goes. Once it is three months old it is not used at all: it stops being read, the senders you had ticked in it are dropped, scheduled cleanups stop clearing them, and the record is overwritten with an empty value the next time the extension runs its daily housekeeping. None of it is transmitted, and it is removed when you uninstall.
• Unsubscribe receipts. A successful unsubscribe also writes a dated receipt on the device: the sender's address, a display name if one is already known, and the time, plus a later verdict if you check whether they stopped. The newest 200 receipts are kept and older ones drop off. This is the one thing here that is meant to be kept rather than refreshed, because the whole point of a receipt is to still be there weeks later when the check runs, so no receipt is ever deleted for being old. What expires is the answer, not the receipt. A verdict is a measurement of one search taken on one day, so once a receipt is due to be checked again the extension drops the count beside the verdict and marks the answer as the last one it took: "Ignored your unsubscribe when last checked" rather than a figure that would now be counting a different span of mail. The receipt stays, its date is unchanged, and it stays in the queue to be checked. None of it is transmitted. Uninstalling removes it, unsubscribing from the same sender again replaces that sender's receipt, and the erase control below removes the whole ledger on demand.
• Sender Triage decisions. As you sort senders one by one, every decision gets saved on your device right away. It includes the sender's address, any display name a scan already found, which choice you made, when you made it, and later whether it was carried out. Decisions not yet run are kept as well, as are the senders you skipped, so a popup that closes doesn't lose anything. A decision is dropped 90 days after you made it. Keep also adds the sender to your whitelist, which your browser syncs as described below. None of this is sent anywhere. Uninstalling removes all of it, and so does the erase control below.
• Erasing it yourself. The Options page has an Erase Stored Sender Data button. As of 9.6 it removes every store in this browser that holds an address, in one write: the sender census, the unsubscribe receipt ledger, the four lists of senders you have ticked in the census, storage, suggestion and subscription panels, the mailbox report with the top senders it found, the storage X-ray, the suggestion scan, the subscription scan, the record of which suggestions you approved or dismissed, and the three markers naming the senders a run was part way through acting on. Before 9.6 it removed the first six of those and left the rest, which is why earlier versions of this page listed them as surviving. It asks you to confirm first, and it tells you the consequences you would otherwise find out later: scheduled cleanups stop clearing the census senders you had ticked, and the four scans go back to asking for a scan, so the mailbox report the popup opens on comes back empty until you run one.
As of 9.7 the same write also empties the top senders list the Stats page draws, which is sampled from the mail every cleanup deletes and was named nowhere on this page, and it removes the search queries from your cleanup history and run history. A census clear or a receipts clear is an ordinary cleanup run whose query is a list of addresses, so until 9.7 those queries outlived the erase. The history keeps each run's counts, totals, mode and timing; only the search strings go.
As of 10.0 the same write also removes your Sender Triage decisions and the marker naming the senders a triage run is partway through.
What it does not reach, named rather than counted, because this is the kind of list that grows. Your recovery log keeps the search query each run used, so it can contain the addresses a census clear or a receipts clear acted on. It is left alone on purpose: it is what restores mail from Trash, and an erase that quietly gave up your last thirty days of recoverable cleanups would be a worse surprise than anything it removed. It has its own Clear button on the Stats page. Exporting your settings does not back any of this up, so an export is not a way to undo the erase and a settings backup is not a way to get it back.
• What your browser syncs. Your settings, cleanup rules, custom rules, protected keywords, schedules, Auto-Pilot configuration, your sender whitelist and your Pro license key are kept in your browser's sync storage. That means Chrome or Firefox copies them to your browser account and on to your other signed-in browsers. Your whitelist contains real email addresses and domains. None of it comes to us: it goes to your browser vendor, under their privacy policy. Turning off extension sync in your browser keeps all of it on the one device.
• Unsubscribing asks the sender to stop. Bulk unsubscribe drives Gmail's own built-in Unsubscribe control, so Gmail contacts that sender or its list host on your behalf, exactly as it would if you clicked the button yourself. That request identifies you to a sender who already has your address. We are not part of it and never see it.
• The purchase website is separate from the extension. Buying, activating and recovering a key all happen on gmail-cleaner-pro.netlify.app, never inside the extension, and no Gmail data is involved at any point. Payments are processed by Stripe under the Stripe privacy policy; we never see your card details. There is no database anywhere in this flow.
• This policy can be found on that same website. The privacy policy, the terms of use and the changelog are pages on gmail-cleaner-pro.netlify.app, built from files in the source repository, and the extension's privacy link opens them there. Links to the source code and the issue tracker lead through gmail-cleaner-pro.netlify.app/go/, where the site asks GitHub whether it is serving the page you want. If GitHub is, it sends you there; if not, it sends you to a support page on the same site. That request travels from the website's server to GitHub, not from your browser, and carries nothing about you. As with the uninstall page, the site only learns what any web request discloses, and it does not store anything. Netlify hosts the site and handles its requests like any other web host would.
• Key recovery uses your email address for one lookup. If you lose your key you can enter the address you paid with. That address is sent to our recovery endpoint, which asks Stripe whether it has a completed purchase of this product and returns a key if it does. The address is used for that lookup and nothing else: it is not stored, not logged to a database, and never added to any mailing list. Your IP address is held in that endpoint's memory for a few minutes purely to limit how many attempts one visitor can make, and is not written down anywhere.
• Those pages keep a copy of your key in your browser. The activation and recovery pages save the issued key in that website's own browser storage so a return visit can show it to you again. That copy belongs to the website rather than the extension, so uninstalling the extension does not remove it; clearing site data for that domain does.
• Which feature sent you to checkout. Each "Get Pro" link carries a fixed label naming the feature it was clicked from, and Stripe records it on the purchase. It holds no personal, device or mailbox information, it travels only if you choose to click through to checkout, and it is recorded only if you complete a purchase. Nothing at all is recorded for anyone who does not buy. We use it to decide which features are worth building on.
• Removing the extension opens one page. When you uninstall, your browser opens gmail-cleaner-pro.netlify.app/uninstall.html. This is the browser's own runtime.setUninstallURL mechanism, and the extension is already gone by the time it happens, so the extension sends nothing. The address is fixed: no query string, no identifier, no version, and nothing derived from your mailbox. The site therefore learns only what any web request tells any server, which is that a browser at your IP address loaded a page at that moment. Nothing is stored, and that site has no database. The page exists to tell Pro buyers their lifetime key still works if they reinstall. It is pinned in tests/uninstall-page.test.js so a parameter cannot be added to it quietly later.
• Nothing is sold, rented or shared. The only third parties involved anywhere in this product are Stripe, for payments, your own browser vendor, for sync, and Netlify, which hosts the website, each under their own privacy policy. There is nobody else, and there is no advertising.
• Exporting your settings is your file to look after. The export feature writes a plain, unencrypted file to your computer containing your rules and your whitelist addresses. Once it leaves the extension it is outside our control and unaffected by uninstalling.
VERIFYING THE FIRST CLAIM YOURSELF
The claim this whole policy rests on is that the extension issues no network requests. The source is public and you do not have to take our word for it:grep -rE 'fetch\(|XMLHttpRequest|sendBeacon|WebSocket|EventSource' *.js *.html
That returns nothing, and a test in the suite fails the build if it ever stops returning nothing. As of 8.21 that test reads its file list from build.js, so it covers every file that actually ships, including the HTML, rather than a list kept by hand beside it.
CONTACT
Questions about this policy: email support@secplusmastery.com, or see the support page at https://gmail-cleaner-pro.netlify.app/support.
The terms of use are at https://gmail-cleaner-pro.netlify.app/terms.