Privacy Policy
Effective date: 29 August 2026 · Product: Mail Tracking for Gmail on the web · Chrome extension hosted by SentCue
Draft for controlled testing and Chrome Web Store preparation. Not legal advice. Publisher / legal entity and launch geography will be named before CWS submission. A signal is not proof that a particular person read a message.
Contents
- Who we are
- Who is controller and who is processor
- How email tracking works
- Data we process as controller (you, the sender)
- Data we process as processor (recipients)
- Google, Chrome, and Limited Use
- How we use information
- Service providers
- Retention, deletion, and your controls
- Your rights (senders)
- If you received a tracked email
- Security
- This website and cookies
- Children and prohibited uses
- International processing
- Changes
- Contact
1. Who we are
SentCue operates Mail Tracking, a Chrome extension that can insert a 1×1 tracking image into messages you choose to track from Gmail on the web, then show you an activity signal in Sent. We do not provide Gmail, we are not affiliated with Google, and we do not use the Gmail API or Google OAuth in v1.
Privacy contact: [email protected]. Website: https://sentcue.com. Legal entity: to be stated before CWS submission.
2. Who is controller and who is processor
The same split used by Gmail tracking products such as Mailbutler and Mailsuite:
- You (the sender) decide whether to track, whom you email, and for what purpose. For personal data relating to your recipients and to tracking those messages, you are the data controller (or equivalent under applicable law).
- SentCue provides the technical feature. For token, timestamps, and coarse client class created when a tracking image is requested, we act as a data processor on your instructions, only to show you the disclosed activity-signal feature and to operate and secure the service.
- For our own records of your install (settings, disclosure acknowledgement, install identifier, support email you send us) and for this website, SentCue is the controller.
We do not currently offer a signed enterprise Data Processing Agreement. That remains open until a legal entity is designated. This policy is not a claim of “100% GDPR compliance.”
3. How email tracking works
If you accept the in-product disclosure and turn tracking On, the extension may add a small image whose URL contains a random token, for example on https://pixel.sentcue.com/p/{token}. When a mail client, image proxy, or scanner requests that image, our origin may record that the token was requested after the Gmail Undo window.
We treat that request as an activity signal, not as proof that a named person read the mail. Providers (including Google Image Proxy), security scanners, caching, disabled images, and you opening your own Sent copy can all produce or hide a signal. Opens in the first 30 seconds after Send are not counted (Undo). Scheduled Send is not supported.
Unlike some trackers, we do not store recipient city/location, do not persist recipient IP or raw User-Agent in the application database, and do not do link-click tracking in v1.
4. Data we process as controller (you, the sender)
- Install-scoped random identifiers and a hashed secret used to authenticate API calls from your Chrome install (no Google account is required for SentCue).
- Extension settings: disclosure accepted, tracking On/Off, cached kill-switch /
pixel_base. - Locally in Chrome only (not sent to our backend in v1): Gmail To, subject, a derived fingerprint, and Gmail thread/message identifiers so the circle can sit on the correct Sent row.
- If you email us: the content of that message and the address you use.
We do not collect message bodies, attachments, passwords, authentication cookies, or Gmail request bodies.
5. Data we process as processor (recipients)
Recipients do not install Mail Tracking. If a tracked image is requested, we may store:
- the random token;
- send / arm / cancel timestamps and qualifying image-request timestamps;
- a coarse client class only:
google_image_proxy,sender_chrome,scanner, orother.
Network infrastructure (Cloudflare) necessarily sees IP address, User-Agent, and basic HTTP metadata to serve the image. The SentCue application is designed not to persist recipient IP, raw User-Agent, or full HTTP headers. Origin access logs redact tokens (/p/[token]).
Recipient email address, subject, and Gmail thread id stay in the sender’s browser in v1. They are not written to the SentCue backend.
We do not use recipient activity data for advertising, profiling, credit decisions, or sale to data brokers. We do not build a marketing profile of people who did not install the product.
6. Google, Chrome, and Limited Use
v1 does not call Google Workspace APIs, does not use Gmail OAuth, and does not receive Gmail data through Google’s API. The extension uses a content script on https://mail.google.com/* plus storage and host access to our pixel origin.
Any user data the extension handles is used only to provide or improve its disclosed single purpose (activity signals for mail you send from Gmail on the web), for security and operations, or where required by law, consistent with the Chrome Web Store Limited Use requirements. We do not use that data to train generalized AI/ML models. Details: Google and Chrome disclosure.
7. How we use information
- Provide the activity-signal feature you enabled;
- Hide signals during the Undo window and honour cancel;
- Deduplicate repeats within 10 minutes;
- Operate the kill switch, rate limits, and deletion;
- Comply with law and valid legal process.
Where data-protection law requires a legal basis for processing we control: contract (providing the extension you installed), legitimate interests (security, abuse prevention, site operation), and consent (in-product disclosure before the first pixel). You must have a lawful basis for tracking your recipients (consent, legitimate interests with a balancing test, or another basis that applies to you). Some jurisdictions, including parts of the EU, treat tracking pixels as requiring prior recipient consent. We do not currently geo-block EU recipients automatically (unlike some sales tools). Launch geography is not finalized.
8. Service providers
We use infrastructure needed to serve the site and the tracking image. Their policies apply to data they process as our providers:
- Cloudflare — TLS/proxy for
sentcue.com,pixel.sentcue.com, and aliast.sentcue.com; named Tunnel to our origin; this website on Cloudflare Pages (Pages does not store tracking tokens). - Origin HTTP process + SQLite file on the operator machine or a VPS you deploy (not Pages Functions, not D1). Until always-on hosting is live, the origin may run on the operator’s computer.
No advertising networks. No product analytics vendor on this site today.
9. Retention, deletion, and your controls
Token and event rows are kept at most 90 days from send_at, then deleted by the retention job. Cancelled tokens never count as a qualifying signal. Tracking is Off until you accept disclosure. Toggle Off stops new pixels. Kill switch fail-closed: no successful remote config → no pixel.
Delete server rows for this Chrome install from the popup: Delete tracking data for this install (POST /delete-install). Local Sent marks on this computer are cleared. Email [email protected] if the control fails.
10. Your rights (senders)
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal data we hold as controller, and to complain to a supervisory authority. Contact [email protected] with subject “Data deletion request” or “Access request”. We do not operate a SentCue user account; install deletion is the primary self-serve path.
We do not sell personal information and we do not share it for cross-context behavioural advertising.
11. If you received a tracked email
Contact the person who emailed you. They chose to use tracking. We do not decide who is emailed and we usually cannot map a token back to your identity (we do not store your address on the server).
You can reduce image requests by disabling remote images in your mail client. You can also object to the sender. If you write [email protected], we will try to help the sender if we can identify an install; we cannot promise to fulfil a recipient request ourselves the way the sender can.
More: Support — how tracking works.
12. Security
HTTPS between the extension, pixel hostname, and origin. Random tokens instead of putting subject or To in the image URL. Install bearer tokens hashed at rest. No method of transmission is completely secure. We do not claim ISO 27001 or a named EU data-centre exclusive to SentCue.
13. This website and cookies
sentcue.com is static documentation. We do not currently set advertising or analytics cookies on this site. Cloudflare may process connection data as described in their policy.
14. Children and prohibited uses
Not directed at children. Do not use SentCue to monitor children, covertly monitor employees without a lawful basis and required notice, stalk, harass, or treat medical or similarly sensitive mail as a surveillance tool. See Terms.
15. International processing
Traffic may be processed on Cloudflare’s global network and on the origin host. Initial Chrome Web Store geography is not finalized pending privacy counsel. This policy will be updated before CWS submission.
16. Changes
We may update this policy when the product, infrastructure, or law changes. Material new data practices require in-product disclosure again before pixels are added, consistent with Chrome Web Store rules.
17. Contact
Privacy: [email protected]
Website: https://sentcue.com
Publisher / legal entity: to be stated before CWS submission