Instant transparency
Badges render entirely inside your browser. Only the technical identifiers required to score a sender ever leave your inbox, and that data is minimized and encrypted.
Mailqor attaches to the DOM and never streams message bodies to our servers.
The extension parses SPF/DKIM/DMARC, MX information and TLS fingerprints locally.
Only the domain, hashed sender identifier and badge metadata leave your device.
If you click Analyze with AI we snapshot that email, encrypt it and send it for AI-only processing.
Here is the complete list of objects that can leave your browser when using Mailqor.
Prevents us from reprocessing the exact same sender hundreds of times per day.
Entries you explicitly approve so we can show Verified instantly next time.
Used to detect abuse, rate-limit bots, and debug extension crashes.
Only exists if you click Analyze with AI on a message.
Key facts
Last updated: November 14, 2025
Mailqor is operated by Mathis Zeghouani, Auch, France.
We divide the information we process into the following categories to stay transparent with Google and Microsoft policies:
Mailqor no longer connects to Gmail via OAuth. The browser extension simply reads the Gmail tab you already opened and keeps processing local.
This means:
⢠No Gmail API scopes or refresh tokens are storedāremoving the extension instantly removes access.
⢠Gmail data never leaves the browser unless you click a badge that triggers an analysis.
⢠We never sell Gmail data or use it for advertising.
⢠When you start the AI analysis we encrypt only that specific snapshot.
- No human can access Gmail data unless you explicitly share a snapshot for support,
- or we are legally required to investigate abuse.
The DOM-only model keeps Mailqor compliant with Google API Services rules while avoiding centralized storage.
Mailqor no longer requests Microsoft Graph scopes. The extension inspects the Outlook web interface you already use and parses headers inside the browser.
⢠Data leaves the tab only when you click a badge that needs verification.
⢠Outlook information is never sold or shared with third parties.
⢠The body is analyzed only if you trigger the manual AI review.
⢠Disable/uninstall the extension anytimeāthere are no tokens to revoke at https://account.live.com/consent/Manage.
Some technical services (CDN, edge runtime, optional AI processing) may temporarily transfer data outside the EU.
When this happens we apply:
⢠EU Standard Contractual Clauses (SCCs)
⢠encryption in transit and at rest
⢠data minimization for any transfer
No Gmail or Outlook data is permanently stored outside the EU.
Transfers occur only when strictly necessary to run Mailqor (execution, CDN delivery, or on-demand AI processing).
Nous utilisons les fournisseurs suivants pour faire fonctionner Mailqor :
| Provider | Role | Primary region | Policy |
|---|---|---|---|
| Vercel | Web hosting / CDN | EU / US | https://vercel.com/legal/privacy |
| Neon (PostgreSQL) | Database | EU region | https://neon.com/privacy-policy |
| OpenRouter | On-demand AI analysis only | Region depends on configuration | https://openrouter.ai/privacy |
On-demand AI processing via OpenRouter may transit briefly through model providers (e.g., OpenAI, Anthropic, etc.). We request customer-data training opt-outs whenever available. No data is used for advertising.
Each type of data serves a different goal:
| Data | Reason |
|---|---|
| From address and domain | Classify the sender and assign the correct badge |
| Email body (manual AI) | Provide an optional AI summary when you request it |
| Usage logs and diagnostics | Improve reliability, spot abuse, and fix bugs |
| Account email and preferences | Authenticate you, send support responses, and remember your settings |
The core badge still works even if you decline content analysis.
Manage your preferences in the site settings when available.
You can exercise these rights via settings or by emailing support@mailqor.com:
We respond within 30 days and may request proof of identity when necessary.
You can also contact the competent supervisory authority (CNIL): https://www.cnil.fr/fr/plaintes
Mailqor is not intended for individuals under 16. We do not knowingly collect data about minors.
If a breach poses a high risk to your rights, we will notify you and the competent authority within the applicable timeframe.
Deleting your account removes personally identifiable data from our systems. Aggregated or anonymized security logs may be retained to prevent future abuse.
Deleting the account removes personal data within 7 days. Aggregated or anonymized data may remain for statistics or abuse prevention. Connected permissions (Google/Microsoft) are revoked and caches are purged within the same window.
We may update this Privacy Policy when our product or legal obligations change. We will notify you of significant updates via email or in-app notice.
Questions about privacy? Contact support@mailqor.com.
If translations differ, the French version prevails.