MailBoy — Privacy Policy
Last updated: 8 September 2026
MailBoy is a Chrome extension that shows you what is filling up your Gmail mailbox and lets you clear it out in bulk. It runs entirely inside your own browser.
There is no MailBoy server. The extension talks to Google's APIs directly from your browser. No mailbox data, and no account data, is ever sent to the developer or to any third party. We cannot see your mail, because there is nowhere for it to arrive.
Who is responsible
MailBoy is developed and published by Jerry Raju, an independent developer, under the name General Software Solutions. That is who is responsible for the data described below. Questions about this policy, or a request about your data, can be sent to generalsoftwaresolutionspvt@gmail.com.
What MailBoy accesses
When you connect MailBoy, Google shows you a consent screen listing the permissions below. Each Gmail permission has its own checkbox and any of them can be declined — MailBoy works with whatever you grant, and the features that need a declined permission simply ask again if and when you press them.
| Permission | What MailBoy uses it for |
|---|---|
Your name, profile picture and email addressuserinfo.profile, userinfo.email
|
Showing which account is signed in, and keeping each mailbox's locally cached data separate from any other account's. This is the one permission MailBoy cannot run without. |
View your email messages and settingsgmail.readonly
|
Listing your folders, counting the emails in each, adding up their sizes, grouping them by sender, and — when you open one — showing a message. |
Read, compose, send and permanently delete
(MailBoy never deletes permanently — see below)gmail.modify
|
Creating and deleting folders, moving selected emails into a folder, sending them to Trash, and restoring them from Trash. |
Manage your basic mail settingsgmail.settings.basic
|
Reading, creating and deleting Gmail filters — the "rules" and "block" features. |
MailBoy never deletes email permanently. Everything it
removes goes to Trash, where Gmail keeps it for 30 days and you can put
it back. The extension deliberately does not request
https://mail.google.com/, the scope that would permit
permanent deletion, so it is not technically capable of it. Google's
wording on the consent screen for gmail.modify is Google's
own generic description of that permission, not a description of what
MailBoy does. MailBoy also never composes or sends mail.
What is stored, and where
Everything MailBoy keeps is stored locally in your browser, using Chrome's extension storage. Nothing is uploaded anywhere.
Kept on your device (chrome.storage.local)
- Per-email facts: the message ID, its size in bytes, the date it arrived, and the sender's email address. This is the data behind every count, size and sender breakdown you see. It is kept because none of it can change, which is what makes reading your mailbox a one-time cost instead of something repeated every time you open the panel.
- Which folders hold which emails (message IDs per folder), and a marker for MailBoy's position in Gmail's change log so it can catch up cheaply next time.
- Your account identity: Google account ID, email address, display name and profile picture URL.
- Which permissions you granted, so MailBoy can renew its access without asking again for something you declined. This is a list of permission names, not a credential.
- A record of any bulk job in progress (which folders or emails an action is working through), so it can be resumed if the browser closes mid-way. A record is removed once its job finishes, or as soon as you stop the job yourself.
Kept only in memory (chrome.storage.session)
- Your Google access token. It is never written to disk and is discarded when the browser closes. MailBoy does not receive or store a refresh token.
Never stored at all
Email subjects, previews, bodies, recipients and attachments are fetched only for the handful of messages on screen and are dropped the moment you leave that screen. The same applies to your Gmail filters, which are re-read each time you open the Rules tab. None of it is ever written to disk.
Attachments are listed by name and size but never downloaded. Message bodies are shown as plain text: MailBoy does not load a sender's images, styles or scripts, so opening an email does not tell the sender you opened it.
Who your data is shared with
Nobody. The only party MailBoy sends anything to is Google — the same Gmail account the data came from, over Google's own APIs. Specifically, MailBoy contains:
- no backend, server or database of ours;
- no analytics, telemetry or crash reporting;
- no advertising, tracking or fingerprinting;
- no third-party code loaded at runtime — every script, style and font it uses ships inside the extension package.
Your data is not sold, rented, shared, or transferred to anyone, for any purpose, including under a change of ownership.
Google API Services User Data Policy
MailBoy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, data obtained from Google APIs is used only to provide and improve the features described above. It is:
- never transferred to others, except as required by law;
- never used for advertising, ad targeting or marketing;
- never used to develop, improve or train generalized artificial intelligence or machine-learning models; and
- never read by a human, other than you — there is no server-side copy for anyone to read.
How long it is kept, and how to remove it
Cached data is kept for as long as you use MailBoy, and for 7 days after you log out, so signing back in — or moving between two mailboxes — does not mean waiting for your mailbox to be read again from scratch. After 7 days it is erased automatically.
You can remove everything at any time:
- In MailBoy: press Log out and choose Log out and erase data now. This deletes the cache immediately.
- Uninstall the extension. Chrome deletes all of its stored data with it.
- Revoke MailBoy's access to your Google account at myaccount.google.com/permissions. MailBoy can then no longer reach your mailbox.
Removing MailBoy does not undo changes it made in Gmail on your instruction. Folders you created, mail you moved or sent to Trash, and filters you made stay in your Gmail account, where you can change them yourself.
Security
MailBoy holds no credentials of yours. Sign-in goes through Google's own hosted consent screen, so your password is never seen by the extension. The resulting access token lives in memory only, expires after about an hour, and is discarded when you log out or close the browser. Because there is no server, there is no remote copy of your data to be breached.
Children
MailBoy is not directed at children under 13, and is not intended for use by them.
Changes to this policy
If this policy changes, the updated version will be published at this address with a new date at the top. Any change that widens what MailBoy accesses would also require a new permission from you on Google's own consent screen.
Contact
Questions, or a request about your data: generalsoftwaresolutionspvt@gmail.com.