Last Updated: January 2026
Authentication
We use Zoho OAuth 2.0 for secure authentication. You authorize our extension through Zoho's official login page - we never see or store your password.
What We Store
- Zoho Account ID - A unique identifier from Zoho OAuth to link your refresh token
- Refresh Token - Stored securely on our backend server to fetch your unread count
- Unread Count - Cached temporarily (60 seconds) to minimize API calls
- Mail Metadata - Sender name, subject, and snippet of unread messages (cached locally in your browser for 30 seconds)
What We DO NOT Store
- Your email address or username
- Email content or body
- Attachments
- Passwords or credentials
- Contact lists
- Any personally identifiable information beyond the Zoho Account ID
Data Security
All communication between the extension and our backend uses HTTPS encryption. Refresh tokens are stored securely in an encrypted database. We implement rate limiting and JWT authentication to prevent unauthorized access.
Our backend services are hosted on cloud infrastructure (Render).
Third-Party Sharing
We never sell, share, or distribute your data. The only third-party service we interact with is Zoho Mail API, which is necessary for the extension to function.
Data Retention
Your data is retained only while you have the extension connected. You can disconnect anytime through:
- Extension settings β Sign Out
- Zoho Account Settings β Connected Apps
Upon disconnection, we delete your refresh token and all cached data within 24 hours.
Permissions Explained
The extension requests the following Zoho API scopes:
ZohoMail.accounts.READ - To identify your Zoho Mail account
ZohoMail.folders.READ - To access folder information (future feature)
ZohoMail.messages.READ - To fetch unread counts and message metadata
Contact
For privacy concerns or data deletion requests, contact:
Email: cheekatlamukesh@gmail.com (Mukesh DevWorks)
Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date.