SendLock stores only the bare minimum required to work:
That is it. Nothing else.
SendLock never reads, collects, or stores the content of your emails — including email bodies, subject lines, attachments, recipient addresses, or any other Gmail content of any kind. Your messages never leave your browser.
We also never collect:
All settings are stored locally using chrome.storage.sync so your preferences follow you across Chrome profiles. There are no third-party data lakes. No mysterious servers. Just your browser.
Some Chrome permissions sound alarming. Here is exactly why we use each one:
We do not request any permission we do not need.
Nothing. We do not sell, rent, trade, or share your information with anyone. The only exception is if a court order legally requires us to — in which case we would have almost nothing to provide anyway, since we do not store your email content.
SendLock is developing an optional SendLock AI feature that analyzes email tone, emotion, and potential mistakes before sending. This feature is opt-in only and is not yet active. When it launches, here is exactly how it will work:
About Anthropic's API: SendLock uses Anthropic's commercial Claude API — not the consumer Claude.ai product. Under Anthropic's commercial API terms, your data is never used to train AI models, and API logs are retained by Anthropic for a maximum of 7 days before being permanently deleted. You can review Anthropic's API data policy at anthropic.com/legal/privacy.
Enabling SendLock AI will require separate explicit consent and agreement to additional terms specific to this feature.
SendLock has passed Google's Computed Attack Surface Analysis (CASA) security assessment on the first attempt with zero vulnerabilities. All settings are encrypted at rest using AES-256 and in transit using TLS 1.2+. Our full codebase was audited by an enterprise-grade security firm personally recommended by Google.
SendLock does not store Gmail message content or Google user data on its servers. All email processing occurs locally within your browser.
If you uninstall SendLock or revoke access, all OAuth tokens and locally stored extension data are immediately removed. Because we do not store your email content anywhere, there is nothing to delete.
You can revoke SendLock's access at any time at: myaccount.google.com/permissions
If we change what we collect or how we handle your data, we will update this page and the "Last updated" date at the top. No hidden changes. Ever.
Questions about this policy? Email us at support@sendlock.com. We are based in Milwaukee, WI, USA.