Legal
What this app can see, what it keeps, how long it keeps it, and how to make it stop. Written to be checked against the consent screen you saw when you installed it.
Last updated: 25 Aug, 2026
This service is operated by Mailer123, Sector 74, Mohali, India. For any question about this policy or your data, write to contact@mailer123.com.
When you start your first campaign the add-on asks for eight permissions. These are all of them, in the tiers Google sorts them into, with what we do with each. Nothing is requested that is not listed here.
Read the draft you chose, and find delivery failures
https://www.googleapis.com/auth/gmail.readonlyReads the single Gmail draft you select as the template for a campaign, and its attachments. Its subject, body and attachments are not transmitted to us and are not stored on our servers. Separately, because Gmail provides no bounce webhook, the add-on looks in your mailbox for the delivery-status reports produced by messages it sent for you; from such a report it records the failed address, the status code and the diagnostic text, and writes them into your spreadsheet. No other message is read, and the content, subject, sender or recipients of your other mail are never stored.
Send the merged messages
https://www.googleapis.com/auth/gmail.sendSends the personalised copies of your draft to the addresses in your spreadsheet. It grants no read access of any kind: under this permission the add-on cannot open, alter or delete anything in your mailbox.
Keep sending after you close the sheet
https://www.googleapis.com/auth/script.scriptappCreates the hourly trigger behind scheduled campaigns and the “keep sending with the sheet closed” option. It grants no access to any data of yours.
Show the dialogs and the sidebar
https://www.googleapis.com/auth/script.container.uiDraws the campaign form, the quota read-out and the progress sidebar inside the spreadsheet. It grants no access to any data of yours.
Reach this dashboard
https://www.googleapis.com/auth/script.external_requestLets the add-on call this site to check your plan, record campaign totals, and register a spreadsheet for open and click tracking. It is the only route by which anything leaves your Google account, and what travels it is set out under “What we receive” below.
The one sheet you have open
https://www.googleapis.com/auth/spreadsheets.currentonlyReads the rows of the spreadsheet you open the add-on in, to personalise each message, and writes the six status columns back as the campaign runs. Scoped to that single spreadsheet — it grants no access to your other spreadsheets. The rows are read and merged inside Apps Script; they are not transmitted to us.
Show which address mail is sent from
https://www.googleapis.com/auth/userinfo.emailReads your account's email address, shown before the first send so you can see which mailbox will do the sending. Stored, as the identifier for your account here.
Prove which account is calling
openidIdentifies your Google account to this dashboard, so your plan and your campaign totals are yours and not someone else's. It grants access to nothing.
The homepage sets out the same list with the reason each permission exists — see every permission we ask for.
This app's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
In particular: we do not use Google user data to develop, improve or train generalised artificial intelligence or machine learning models; we do not transfer it to third parties except as necessary to provide the service, for security purposes, or to comply with applicable law; we do not use it for advertising; and no human reads it except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.
Only these leave your Google account, and only over the connection the script.external_request permission allows:
The merge happens inside your Google account. Your list is read from the spreadsheet and the messages are built there, so these never reach our servers at all — there is no setting to change, and no copy for us to lose:
A row number is only meaningful against your own spreadsheet, which is the point: we can tell you that row 42 was opened twice, and we cannot tell anyone who row 42 is. It is also why we cannot answer “who did I send this to” on your behalf — only your spreadsheet knows.
When you run a campaign you are asking us to process personal data about the people in your spreadsheet. You remain responsible for having a lawful basis to contact them. We act on your instructions, hold only the engagement records and suppression entries described above, and delete them when you delete the campaign or your account.
Campaign records are kept until you delete the campaign or your account. Per-row engagement records are deleted automatically twelve months after their last recorded activity — a nightly job removes them, and the campaign's totals remain. Deleting your account removes all of it, including your stored Google tokens, within 30 days.
Suppression entries outlive campaign deletion, because forgetting that someone unsubscribed would mean contacting them again. You can remove an entry yourself from the dashboard if someone asks to be re-subscribed.
You can revoke this app's access to your Google account at any time at myaccount.google.com/permissions. Doing so stops all sending immediately.
Your Google refresh token is stored encrypted at rest and is used only to obtain short-lived access tokens for the purposes set out above. Traffic between the add-on, this site and your browser is encrypted in transit.
We use Vercel for hosting, Neon for the database, and Stripe for payments. Each processes data only to provide its part of the service. Stripe holds your billing details; card numbers are entered on Stripe's own checkout and never pass through this site or the add-on.
Depending on where you live you may have the right to access, correct, export or erase your personal data, and to object to its processing. Write to contact@mailer123.com and we will respond within 30 days.
Please do not send us recipient email addresses when you write. We hold none beyond the do-not-send list and do not want any — describe the spreadsheet row instead.