Last Updated: February 17, 2026
Heimdall ("we", "our", or "the extension") is a Chrome browser extension that helps users manage their Gmail inbox by identifying subscription and promotional emails and providing tools to unsubscribe from unwanted senders. This Privacy Policy explains how Heimdall accesses, uses, stores, and protects your data.
Heimdall's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When you sign in with Google and grant permission, Heimdall accesses the following Gmail data through the Gmail API:
Heimdall does not access or read the body/content of your emails. We only access the metadata and headers listed above.
Your Gmail data is used exclusively for the following purposes:
Heimdall processes your email data locally in your browser. Specifically:
chrome.storage.local) and is only used to authenticate API requests to Gmail.We do not sell, trade, rent, or share your Google user data with any third parties. Specifically:
Data may only be transferred in the following limited circumstances:
No humans (including Heimdall employees, agents, contractors, or successors) read your Gmail data, unless:
Heimdall's use of Google user data is limited to providing and improving the user-facing features described in this policy — specifically, scanning for subscription emails and providing unsubscribe functionality. We do not use Google user data for any purpose other than providing and improving these features that are prominent in the Heimdall extension interface.
Heimdall requests the following Google OAuth scopes:
https://www.googleapis.com/auth/gmail.readonly — Allows Heimdall to read email headers to identify subscription and promotional emails.https://www.googleapis.com/auth/gmail.modify — Allows Heimdall to modify emails, such as moving unwanted subscription emails to trash when you click "Unsubscribe."https://www.googleapis.com/auth/userinfo.email — Allows Heimdall to retrieve your email address to verify your subscription status.We follow the principle of minimum required access and only request the scopes necessary for Heimdall to function.
Subscription payments are processed by Stripe. Heimdall does not collect, store, or process any payment card information. All payment data is handled directly by Stripe in accordance with their privacy policy and PCI compliance standards.
Heimdall displays a privacy notice within the extension interface when you first sign in, including a link to this Privacy Policy. This ensures you are aware of how your data is handled before granting access to your Gmail account.
Heimdall does not collect or store personal data on external servers from any user. Additionally, Heimdall is not intended for use by anyone under the age of 13, in compliance with the Children's Online Privacy Protection Act (COPPA).
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Continued use of Heimdall after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or how Heimdall handles your data, please contact us: