TrailMail (Chrome extension) · Last updated: 14 July 2026
TrailMail ("the extension") helps you predict likely work-email addresses from public company email patterns, request referrals from a job posting, and, optionally, send emails from your own Gmail account. This policy explains exactly what the extension does and does not do with data, including data obtained through Google APIs.
TrailMail integrates with Google only so that you can send prediction-generated emails from your own Gmail account, with your explicit, revocable authorization via Google Sign-In (OAuth). TrailMail requests exactly three scopes, each used for a single, narrow purpose:
https://www.googleapis.com/auth/gmail.send — used only to transmit the messages you compose and click "send" on, one at a time, directly to Gmail's API. This scope is send-only: TrailMail cannot read, search, list, label, delete, forward, or otherwise access any email already in your mailbox, your contacts, or your drafts.email (Google userinfo) — used once per sign-in, purely to look up and display which Gmail address is currently connected inside the extension's popup, so you know which account will be used to send.openid — used as part of the standard Google Sign-In handshake to authenticate the connection; no separate profile data is requested or stored.Beyond these three narrow uses, TrailMail does not:
TrailMail's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
gmail.send scope to send emails you compose from your own account. It sends one message per recipient on your action. The extension cannot read, search, delete, or modify your mailbox, because gmail.send grants send only access. Your email address is read once (via Google's userinfo endpoint) only to display which account is connected.Because Gmail access is a sensitive permission, TrailMail is built to minimize what could ever be exposed, even in principle:
www.googleapis.com, gmail.googleapis.com, oauth2.googleapis.com) happens over HTTPS/TLS.chrome.identity API. TrailMail's code never sees, stores, or transmits your Google password, and the access token is kept in Chrome's own secure token cache, not in our extension storage.chrome.storage.local, which is sandboxed to the extension and inaccessible to websites, other extensions, or us.All of the following is stored locally in your browser via chrome.storage.local and never leaves your device except as described above:
The Gmail access token is managed by Chrome's identity system, not stored by us. You can disconnect Gmail at any time from the extension, which revokes the token.
If you enable tracking, the extension adds an invisible pixel and/or rewrites links so that opens and clicks are recorded. You may use the built-in endpoint or your own self-hosted endpoint. When tracking is enabled, open/click events (an opaque token and timestamp) are recorded at that endpoint so you can see whether your emails were opened. You are responsible for disclosing tracking to recipients where the law requires it (e.g., GDPR). Tracking is off unless you turn it on.
Predicted emails are not verified and may be inaccurate. You are responsible for complying with all applicable laws when contacting people (including consent, sender identity, and unsubscribe requirements such as GDPR and CAN-SPAM).
Removing the extension, or clearing its storage, deletes all locally stored data. Disconnecting Gmail revokes the access token.
Questions about this policy: manan.hiren.shah@gmail.com.