Mega Outreach for Gmail — Privacy Policy
Last updated: 19 July 2026
This policy explains what the Mega Outreach for GmailChrome extension (the “Extension”) accesses, how that data is used, and the choices you have. The Extension is a companion to your existing Mega Outreach account and only works after you explicitly link that account.
What the Extension can access
- Local storage on your device (the
storagepermission): your Mega Outreach login tokens and a one-time linking nonce, so you stay signed in. - The Gmail web page (
mail.google.com): the Extension injects its own UI (buttons and panels) into Gmail. It reads the visible compose/thread content you are working on to power features such as merge previews, deliverability checks, and the reply rail. - Your Mega Outreach API and the account-link page on the Mega Outreach web app, to send requests on your behalf using the account you linked.
The Extension itself requests no Google OAuth scopes and holds no Gmail or Google Sheets credentials. All Gmail and Google Sheets API access is performed server-side by Mega Outreach using the tokens you granted when you connected your inbox / sheet in the web app — never in the browser Extension.
How Google user data is used (Limited Use)
Mega Outreach’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Gmail and Google Sheets data is used only to provide and improve the outreach features you request (composing, sending, tracking, follow-ups, list building, and reply handling).
- We do not sell this data, and we do not use it for advertising.
- We do not transfer this data to third parties except as needed to provide the service you requested, to comply with applicable law, or as part of a merger/acquisition with equivalent protections.
- Humans do not read your Gmail or Sheets data except with your explicit permission (e.g. to debug an issue you report), where required for security or to comply with law, or on data that is aggregated and anonymized.
- AI features (openers, spam-checks, drafts, list compilation) process only the content needed for that feature and are not used to train third-party models on your data beyond providing the requested output.
Data retention & deletion
Server-stored OAuth tokens are encrypted at rest and kept only while your inbox/sheet stays connected. You can disconnect an inbox or sheet, unlink the Extension, or delete your Mega Outreach account at any time; on account deletion, associated data is removed in line with our main product policy. The Extension’s local storage is cleared when you click Unlink account or remove the Extension.
Permissions, in plain terms
storage— keep you signed in on this device.host: mail.google.com— inject the Mega Outreach UI into Gmail.host: your Mega Outreach API— make requests for your linked account.externally_connectable: the Mega Outreach web app— receive your login securely during the one-time account link.
The Extension requests no other permissions — no access to other sites, browsing history, tabs, or network interception.
Contact
Questions about this policy or your data? Email privacy@megaoutreach.com.