Privacy Policy
Last updated October 4, 2026
In short: Inboxless reads recent Gmail messages inside your own browser to find one-time codes and verification links. Your email is never sent to us or anyone else. Codes are kept in memory for a few minutes and then deleted. We don’t run analytics, show ads or sell data.
Who we are
Inboxless (“Inboxless”, “we”) makes the Inboxless extension for Google Chrome. You can reach us at support@codecatch.site.
What Inboxless accesses
Your Gmail messages (read-only). When you connect a Gmail account, Google asks you to allow Inboxless to “read your email” (the gmail.readonly permission). Inboxless uses it only to:
- read the email address of the connected account, so it can show which inbox a code came from;
- list messages received in the last 15 minutes (not sent mail, drafts, chats or trash);
- read the sender, subject, date and text of those messages to find a one-time code or a verification link.
Inboxless does this only while a website shows a code field, when you press the Inboxless keyboard shortcut, or when you open the Inboxless popup. It never downloads attachments, never changes, deletes or sends email, and never searches older mail.
The websites you visit. To recognise code fields, Inboxless looks at the form fields on the page you’re on, and it uses the website’s address (for example github.com) to check whether a code’s sender matches that site. It doesn’t record your browsing, read other page content, or send any of it anywhere.
How we use it
Only to show you codes and verification links, copy a code to your clipboard, and fill it into the page you’re on, as you’ve chosen in the settings. We do not use your data for advertising, profiling, credit decisions or training AI models, and we do not sell it.
Where your data lives, and for how long
Everything stays on your device. Inboxless has no server that receives your email or your Google access.
- Codes and the emails they came from: held in Chrome’s in-memory extension storage and deleted after at most 20 minutes, or when you close Chrome.
- Google access passes (OAuth access tokens): held in memory only and expire after one hour. Inboxless doesn’t use refresh tokens or a client secret.
- Your connected Gmail addresses and your settings (including paused sites): stored locally in Chrome until you remove them.
- Clipboard: if “Copy the code” is on, a new code is placed on your clipboard. Your operating system may keep clipboard history. You can turn this off in settings.
Sharing
We don’t share, transfer or sell your data. Data moves only between your browser and Google’s Gmail service, over encrypted connections. We never receive it, so we have nothing to hand over.
Google API Services User Data Policy
Inboxless’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Nobody at Inboxless reads your email. The only exceptions the policy allows (your explicit consent for a specific message you send us, security investigations, or legal requirements) don’t arise, because your email never reaches us.
Your choices
- Remove any connected account in the Inboxless popup or settings. This also withdraws Google’s permission.
- Pause Inboxless on specific websites, or turn off auto-fill, copying and the popup.
- Use Settings → Delete all my data to disconnect every account and erase everything Inboxless stored. Uninstalling the extension also erases what it stored; to withdraw Google’s permission as well, use the link below or remove the accounts first.
- Review or revoke access at any time at myaccount.google.com/permissions.
Data protection: how we protect your Google user data
Your Gmail data is sensitive data, and Inboxless protects it with these mechanisms:
- Encryption in transit. Inboxless talks only to Google, and every request to Google sign-in and the Gmail service goes over an encrypted HTTPS (TLS) connection.
- No copy outside your device. Gmail data is processed inside your browser and is never transmitted to, or stored on, any server, database or cloud service of ours or of any third party. There is no copy elsewhere that could be leaked, breached or requested.
- Memory-only storage. Google access tokens, codes and the emails they came from are kept only in Chrome’s in-memory extension storage. They are never written to disk, never synced to another device, and are erased when you close Chrome.
- Access control. That storage is isolated by Chrome and limited to Inboxless’s own trusted pages. Websites, other extensions and Inboxless’s own in-page script cannot read it. A web page receives a code only when Inboxless fills it in or you choose to paste it.
- Least privilege. Inboxless requests one read-only Gmail permission. It cannot send, change or delete email, and it reads only messages from the last 15 minutes.
- Short-lived credentials. Access tokens expire after one hour. Inboxless stores no passwords, refresh tokens or client secrets.
- Automatic deletion. Codes and email content are deleted after at most 20 minutes. Removing an account, or using “Delete all my data”, erases what is stored and revokes the Google permission.
- No human access. Because your data never leaves your device, nobody at Inboxless and no contractor or service provider can view it.
- Protected code. Inboxless runs inside Chrome’s extension sandbox, under Chrome’s content security policy for extensions, and contains no remotely loaded code. Codes shown on web pages are drawn in an isolated area that the page’s own scripts can’t read.
- Phishing protection. A code is filled in automatically only when the email’s sender matches the website you are on.
If you find a security problem, please tell us at support@codecatch.site.
Children
Inboxless is not directed to children under 13 and we don’t knowingly process their data.
Changes
If we change how Inboxless handles data, we’ll update this page and the date above before the change takes effect.
Contact
Questions or requests: support@codecatch.site.