1. Least privilege
We request only the permissions needed for Gmail UI, browser storage, Google sign-in, and the Mailshu API. Other websites are not read or changed.
2. Data minimization
Subjects and recipients stay in the browser. The server stores only the stable Google identifier, tracking IDs, timestamps, status, confidence, and count—not bodies, attachments, raw IP addresses, or access tokens.
3. Transport and storage
Traffic uses HTTPS, data is kept in access-controlled managed storage, and tracking records are removed after up to 90 days.
4. Code integrity
Executable extension code is included in the package; no executable code is downloaded remotely.
5. False-positive reduction
Known security scanners and immediate self-loads are classified, though image proxies and privacy features may still affect results.
6. Vulnerability response
Report security issues without sensitive data to gajungssamzzang@gmail.com. We assess impact and may restrict features, release fixes, and notify users.
7. Responsible disclosure
Do not exploit issues or access other users’ data, and allow reasonable time for remediation.