Back to Heimdall

Privacy Policy

Last Updated: February 17, 2026

Heimdall ("we", "our", or "the extension") is a Chrome browser extension that helps users manage their Gmail inbox by identifying subscription and promotional emails and providing tools to unsubscribe from unwanted senders. This Privacy Policy explains how Heimdall accesses, uses, stores, and protects your data.

Google API Services User Data Policy Compliance

Heimdall's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

1. Information We Access

When you sign in with Google and grant permission, Heimdall accesses the following Gmail data through the Gmail API:

Heimdall does not access or read the body/content of your emails. We only access the metadata and headers listed above.

2. How We Use Your Data

Your Gmail data is used exclusively for the following purposes:

3. Data Storage

Heimdall processes your email data locally in your browser. Specifically:

4. Data Sharing & Transfer

We do not sell, trade, rent, or share your Google user data with any third parties. Specifically:

Data may only be transferred in the following limited circumstances:

5. Human Access to Data

No humans (including Heimdall employees, agents, contractors, or successors) read your Gmail data, unless:

Limited Use Disclosure

Heimdall's use of Google user data is limited to providing and improving the user-facing features described in this policy — specifically, scanning for subscription emails and providing unsubscribe functionality. We do not use Google user data for any purpose other than providing and improving these features that are prominent in the Heimdall extension interface.

6. Permissions We Request

Heimdall requests the following Google OAuth scopes:

We follow the principle of minimum required access and only request the scopes necessary for Heimdall to function.

7. Authentication & Security

8. Payment Information

Subscription payments are processed by Stripe. Heimdall does not collect, store, or process any payment card information. All payment data is handled directly by Stripe in accordance with their privacy policy and PCI compliance standards.

9. In-Product Privacy Notifications

Heimdall displays a privacy notice within the extension interface when you first sign in, including a link to this Privacy Policy. This ensures you are aware of how your data is handled before granting access to your Gmail account.

10. Data Retention & Deletion

11. Children's Privacy

Heimdall does not collect or store personal data on external servers from any user. Additionally, Heimdall is not intended for use by anyone under the age of 13, in compliance with the Children's Online Privacy Protection Act (COPPA).

12. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Continued use of Heimdall after changes constitutes acceptance of the updated policy.

13. Contact

If you have questions about this Privacy Policy or how Heimdall handles your data, please contact us: