Privacy policy

Last updated 30 September 2026. Covers extension version 1.8.1.

1. The short version

Gmail Labels and Search Queries as Tabs ("the extension") reads your Gmail page to draw a tab bar and to count unread messages. It does that entirely inside your browser. It has no database, no account, no analytics and no advertising, and it never sends your mail, your contacts, your label names or your tab names anywhere. The one thing about your mail that can leave is a sender's domain, and only if you turn website icons on (section 4c). The one server of ours the extension ever talks to is the feedback relay described in section 4, which is reached only when you press Send and which stores none of your message.

Exactly three things can ever leave your browser, and all three are listed in full in section 4. One happens only when you press a button. One happens only after you have already uninstalled. The third happens only if you turn on two settings that are off by default, and it sends a sender's domain and nothing else.

2. What the extension stores, and where

  • Your tabs and automation rules are stored in chrome.storage.sync, keyed per Gmail account. Chrome syncs that between your own signed-in Chrome browsers, the same way it syncs your bookmarks. It goes to Google, under your own Google account, and never to us.
  • Your theme preference is stored in chrome.storage.local, which stays on the one device.
  • Two diagnostic records are also kept in chrome.storage.local: whether the parts of the extension that reach into Gmail worked the last time they were tried, and the names Gmail's page used for its inbox rows the last time sender icons drew them. Neither holds anything about your mail, and neither is ever sent.
  • Nothing else is stored. No message, subject, sender, address or attachment is written to storage at any point.

You can see everything the extension holds, export it as a JSON file, or delete it, from the extension's own Settings page. Removing the extension removes its storage.

3. What the extension reads from Gmail

To draw the bar and keep unread counts current, the extension reads Gmail's page, its own unread Atom feed and the responses to Gmail's own network requests, all on mail.google.com. This is how it learns your label list and how many unread messages each label has.

That reading happens in your browser and stops there. It is not logged, not stored and not transmitted. The extension has no Gmail API access, no OAuth token and no API key.

4. The three things that can leave your browser

a. Feedback you choose to send. If you fill in the Support & Feedback form inside the extension and press Send, we receive your message, the category you picked, and the reply address only if you typed one. A tick box, on by default and clearly labelled, also attaches the extension version, your browser build, and the number of tabs, rules and accounts you have. Never label names, tab names, contacts or mail. Untick the box and none of that is attached. It is sent to our own relay at gmail-tabs-feedback.sunmooncal.workers.dev, which runs on Cloudflare. The relay passes it to Resend, an email delivery service, which delivers it to our support mailbox, support@palworks.ai. The relay stores no message content. To limit abuse it keeps a count of messages per network for up to a day, under a keyed hash of your IP address rather than the address itself, and Cloudflare sees the IP address as it does for any site it serves. Resend keeps a copy of sent messages for a limited period under its privacy policy. Nothing is sent if you do not press Send.

b. A page that opens after you uninstall. When you remove the extension, Chrome opens a short feedback form hosted by Tally at tally.so, so we can learn why people leave. The extension sends nothing itself: Chrome navigates you to a plain form link that carries no email address, no settings and no identifier, so Tally learns only that somebody uninstalled, never who. Answering is optional and closing the tab sends nothing. If you do fill it in, Tally processes it under their privacy policy.

c. Website icons, only if you turn them on. Sender icons, added in 1.8.0, put a small chip in each inbox row naming the organisation the mail is from. They are off by default, and turned on they draw a coloured letter and request nothing. Only if you also turn on Load website icons does the extension ask Google's icon service for each sender's website icon, at t0.gstatic.com, or at www.google.com if that cannot be reached. What it sends is the sender's domain alone, such as example.com: never the address, the name, the subject or anything in the message. The request carries no referrer, and each domain is asked once and remembered for the session. Google handles those requests under its own privacy policy.

5. Permissions, and why each one exists

  • storage: save your tabs, rules, preferences and theme.
  • downloads: write the JSON backup file when you press Export.
  • management: let the Uninstall button in Settings remove the extension.
  • scripting: start the tab bar in a Gmail tab you already had open. Chrome only runs an extension in pages opened after it is installed or updated, so without this you would have to reload Gmail by hand before the bar appeared. Added in 1.7.3.
  • host permission for https://mail.google.com/*: run inside Gmail, which is the whole point.

There is no <all_urls> and no access to any other site. The scripting permission injects one file, the extension's own content script, and only into mail.google.com: it cannot run on any page other than Gmail, and it never loads code from anywhere else.

6. Automation rules run under your account, not ours

The automation feature generates Google Apps Script code and shows it to you. You choose whether to paste it into your own Google account and run it. It executes as you, on Google's infrastructure, and we never see it run, never receive its output, and cannot trigger it.

7. This website

This site is measured, and the extension is not. The distinction matters, so here is exactly what runs on the pages you are reading now:

  • Google Analytics (GA4), which counts visits, pages and referrers.
  • Microsoft Clarity, which records how pages are used: clicks, scrolling and mouse movement, replayed as anonymised sessions and aggregated into heatmaps. It is a usability tool, and we use it to see which parts of a page people give up on.
  • Google Fonts, which serves the typefaces, so your browser asks Google for them as it would for any site that uses them.
  • YouTube, only if you press play on the homepage video. Until then the page shows a picture we host, and nothing is fetched from YouTube. Pressing play loads YouTube's privacy-enhanced player, from youtube-nocookie.com, under Google's privacy policy.

The contact form. When you press Send on the contact page, your name, email address, topic, subject, message and any files you attached go to our own relay at gmail-tabs-contact.palworks.ai, which runs on Cloudflare. The relay checks the message and passes it to Resend, an email delivery service, which delivers it to our support mailbox, support@palworks.ai. Your address is used as the reply address, so that we can answer you, and for nothing else: we send no newsletter and add you to no list. The relay stores none of it. To limit abuse it keeps a count of messages per network for up to a day, under a keyed hash of your IP address rather than the address itself, and Cloudflare sees the IP address as it does for any site it serves. Resend keeps a copy of sent messages for a limited period under its privacy policy. We keep your message in the support mailbox for as long as it takes to deal with it, and delete it when you ask.

Before you press Send, the form does a small amount of work in your browser to prove it is not an automated script. That work involves no tracking, no cookie and no third-party service.

None of this is in the extension. The extension contains no analytics, no session recording and no third-party script of any kind. If you install it and never visit this site, nothing on this list ever runs.

8. Your data, and your rights

We hold personal data only when you send it to us: a feedback message from inside the extension, or a message through the contact form. You can ask us what we hold, ask us to correct it, or ask us to delete it, by writing to support@palworks.ai. Everything else the extension keeps is in your own browser, where you can see it, export it or delete it from the extension's Settings page, and removing the extension removes it.

The extension and this site are not directed at children under 13, and we knowingly collect nothing from them.

9. Changes to this policy

If what the extension does changes, this page changes with it, and the date and version at the top move. Material changes are also recorded in the changelog.

Contact

PalWorks publishes the extension and this site. Questions, corrections or a deletion request: use the Support & Feedback page inside the extension, write to support@palworks.ai, or get in touch here.