Privacy policy
Clear routes.
Limited data.
Effective September 2, 2026
Alias is an AudioFetcher Chrome extension that adds a separate custom-domain send control to Gmail. This policy explains what the extension reads, what stays in Chrome, and what is transmitted when you request delivery.
Plain-language summary
- Alias does not read or transmit your Gmail inbox, sent mail, contacts, browsing history, or unrelated websites.
- It reads supported fields from the active Gmail compose window when you press Send via alias.
- Your chosen delivery provider receives the message data necessary to send that email.
- Alias does not sell user data, build advertising profiles, or use communications for advertising.
- No employee routinely reads message content. Human access is permitted only with your specific support consent, when required for security or abuse investigation, or when legally required.
01
Gmail draft data
The content script runs only on mail.google.com so it can locate Gmail compose windows and add the Alias send control. After you explicitly press that control, it may read the active draft’s sender, To recipient, Cc/Bcc where supported by the chosen provider, subject, HTML and plain-text body, and accessible attachments where supported.
Hosted delivery intentionally accepts a smaller message: exactly one To recipient, no Cc, Bcc, attachments, custom headers, or client-supplied Reply-To. Gmail’s normal Send button remains separate. Alias leaves the Gmail draft open after an alias send.
02
Delivery providers
You choose one of these delivery routes:
- Cloudflare
- The extension sends the supported message directly to Cloudflare’s Email Sending API using the Cloudflare connection you authorize. AudioFetcher’s Hosted infrastructure does not receive that message.
- Resend
- The extension sends the supported message directly to Resend using the Resend connection you authorize. AudioFetcher’s Hosted infrastructure does not receive that message.
- Hosted (AWS SES)
- The extension sends the allowlisted message fields and a short-lived access token to AudioFetcher’s hosted API. The API validates your active account, exact sender and domain, quotas, service state, and idempotency before passing the message to Amazon SES.
Cloudflare, Resend, Amazon Web Services, and their subprocessors handle delivery data under their own agreements and privacy practices. Alias uses them only to provide the delivery route you selected.
03
Hosted access and domain verification
A Hosted access request contains your contact/login email, domain, exact sender address, sender display name, intended use case, expected monthly volume, and request timestamps/status. The request service returns a one-time private status token; the server stores only its SHA-256 hash.
If approved, Alias creates a request-bound Amazon SES domain identity and shows three DKIM CNAME records. You add those records at your DNS provider. Activation proceeds only after SES confirms ownership and DKIM. Amazon Cognito stores the login email and provides the sign-in flow.
The Hosted send service does not intentionally store recipients, message subjects, message bodies, attachments, authorization headers, provider message IDs, or SES message IDs. It stores bounded quota counters, hashed idempotency evidence, operational status, and aggregate bounce/complaint information.
04
Data stored in Chrome
Alias uses chrome.storage.local for configuration, disclosure acceptance, sender settings, provider connection material, the Hosted refresh session, Hosted request tracking, and one redacted last-send summary. The short-lived Hosted access token uses chrome.storage.session.
Chrome storage is restricted to trusted extension contexts. The Gmail content script cannot read provider credentials or Hosted tokens. Saved secrets are never written back into visible fields after saving and are excluded from diagnostics. Chrome storage is not an operating-system keychain or dedicated password manager; anyone controlling your device or Chrome profile may be able to recover locally stored material.
05
Retention and diagnostics
Local settings remain until you clear them or uninstall Alias. Hosted onboarding records normally expire after 30 days; approval may extend a request to 90 days for DNS verification, and rejected records expire 30 days after the decision. Cognito account data remains while the Hosted account is active or as required for security and legal obligations.
Diagnostics contain only bounded operational facts such as provider type, status code category, timestamp, counts, lengths, and sanitized error codes. They intentionally exclude complete addresses, recipients, subjects, bodies, attachments, credentials, tokens, and authorization headers.
Security logs and AWS delivery systems may retain limited operational records according to configured retention and provider requirements. They are used for delivery, fraud and abuse prevention, reliability, and legal compliance.
06
Your controls
- Do not enable Gmail integration until you have reviewed and accepted the in-product disclosure.
- Clear an inactive Cloudflare or Resend connection from the Sender settings.
- Sign out of Hosted mode to remove the local Hosted session.
- Clear the redacted last-send diagnostic summary.
- Uninstall Alias to remove its local Chrome storage.
- Email help@audiofetcher.com to request access, correction, or deletion of Hosted account or onboarding data, subject to necessary security and legal retention.
07
Chrome Web Store Limited Use
Alias’s use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Alias uses Gmail compose data only to provide the user-requested custom-domain send feature, related security, abuse prevention, diagnostics, and support. We do not use or transfer that data for personalized advertising, creditworthiness, or unrelated purposes. We do not sell user data.
08
Changes and contact
Material changes to data handling will be disclosed in the extension before the new handling begins, and this page’s effective date will be updated.
Privacy and security questions: help@audiofetcher.com