Back to home

Privacy Policy

Last updated: July 26, 2026

What MailTrail is

MailTrail is a Chrome extension that lets you run A/B tests on Gmail campaigns you compose. It sends emails through your own Gmail account using the Gmail API, stores experiment metadata on MailTrail servers, and records opens, clicks, and replies for the emails you choose to track.

What data we collect

  • Account data: your Google email address, name, and profile picture when you sign in with Google.
  • Experiment data: experiment names, subject/body variants, recipient email addresses, and the variant assigned to each recipient.
  • Tracking events: open pixel loads, link clicks, and reply detections for the specific messages MailTrail sent.
  • Extension settings: your pairing token, dashboard URL, and send throttling preferences stored locally in the browser.

Google API scopes we request

  • gmail.send — used solely to send the variant messages you composed, from your own Gmail account, when you click send.
  • userinfo.email — used to associate sends with your MailTrail dashboard account.

MailTrail requests no read scopes. We cannot read your inbox, your threads, or any message content through the Gmail API.

What we do NOT do

  • We do not read your inbox, contacts, or existing Gmail threads.
  • We do not access emails you send outside of MailTrail.
  • We do not share, sell, or rent your data to third parties.
  • We do not use tracking data for advertising or profiling.
  • We do not use Google user data to train generalized AI or ML models.

Limited Use disclosure

MailTrail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide or improve user-facing features of MailTrail, is never sold, is never transferred to third parties except as necessary to provide the service or as required by law, and is never used for advertising.

How we use the data

We use the data only to operate MailTrail for you: to split recipients across variants, send the assigned variant, record engagement metrics, and display the results on your dashboard. Reply detection happens locally in your browser while Gmail is open — the extension looks for replies to the messages MailTrail sent and reports only the fact that a reply occurred. No message content is read or stored.

Data storage and security

Data is stored in a secure backend with row-level security, so each user can only access their own experiments. Tracking URLs are signed with HMAC to prevent tampering. All dashboard traffic is served over HTTPS.

Data retention

We keep experiment and event data until you delete the experiment from your dashboard. You can delete an experiment at any time, which removes its associated recipients, variants, and events from our database.

Your rights

You can delete your experiments, revoke the extension's access from your Google Account at any time, or contact us to request account deletion.

Changes to this policy

If we make material changes, we will update the date above and notify you through the extension or dashboard.

Contact us

Questions? Email us at hello@experimently.ai.