ThreadRelay

Privacy Policy

Effective August 17, 2026

ThreadRelay’s single purpose is to forward Gmail messages selected by the user to destinations the user confirms.

Data the extension handles

The extension handles the connected Google account identity, selected Gmail thread content, recipient addresses, contacts used for autocomplete, and local run history. A separate ThreadRelay account contains the email address or sign-in identity supplied to Clerk, the user’s plan, and daily forwarding-count usage.

How Gmail data is used

Email content is processed locally in the browser extension and transmitted directly to Google’s Gmail APIs to perform the forwarding action the user requests. Contacts are requested from Google to provide recipient autocomplete. Run history is stored locally on the user’s device. Email bodies, attachments, recipient addresses, contact lists, and local history are not sent to ThreadRelay, Clerk, Stripe, or the subscription service.

Accounts, usage, and billing

Clerk provides ThreadRelay account sign-in, session management, and the private daily forwarding counter used for the free plan. Before a batch begins, the extension sends the signed-in account token and requested message count to ThreadRelay’s subscription service so it can verify the plan and enforce the free daily limit. Stripe processes checkout, subscriptions, and the billing portal. Stripe receives payment and billing data entered on Stripe’s hosted pages.

Sharing and sale

ThreadRelay does not sell personal information, use Google data for advertising, or allow humans to read email content. Data is shared only with Google, Clerk, Stripe, and infrastructure providers as necessary to provide the requested Gmail, account, quota, and billing functionality; to comply with law; or to protect against abuse.

Retention and deletion

Local run history and cached contacts can be cleared from the extension. The Clerk daily quota record is replaced when a new calendar day begins. Clerk account records and Stripe billing records are retained as needed for account operation, accounting, fraud prevention, and legal compliance. Users may contact support to request deletion of account-linked data where legally permitted.

Security

Network requests use HTTPS. Google OAuth and Stripe secret keys are not embedded in the public extension code. Account API requests require a verified Clerk session token, and Stripe webhooks are signature-verified.

Google API Limited Use

ThreadRelay’s use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Contact

Support contact: support@threadrelay.app. Replace this address before launch if a different support mailbox will be used.