← QuillReply

Privacy Policy

Last updated: September 13, 2026. This policy describes what QuillReply does today. If it changes, the date above changes with it.

The short version

What the extension can and cannot see

QuillReply is a browser extension. A fresh install has one host permission: our own API. Connecting Todoist or Microsoft To Do asks you, at that moment, for permission to reach that one service, and nothing is granted before you press Connect. Someone who only uses Apple Reminders is never asked, and neither is someone who uses Basecamp: the extension never contacts Basecamp directly, so it needs no such permission (see the Basecamp section below). It requests no Gmail OAuth scope of any kind: not read, not modify, not compose. When you click a QuillReply button on an open email, the extension reads that message from the page you are already looking at, the same way you do. If you never click a button on an email, QuillReply never sees it.

What happens to an email you act on

When you ask for a draft reply or a task suggestion, the subject and body of that one message are sent over TLS to our servers, passed to our AI provider (Anthropic) to generate the result, and returned to you. The content is then discarded: not written to a database and not written to a log. Quoted history from older messages in the thread is stripped in your browser before anything is sent.

Anthropic is not a black box we can make promises on behalf of, so here is theirs. Under their commercial API terms, Anthropic does not train any model on what we send, and automatically deletes API inputs and outputs from their systems within 30 days. So "discarded" above describes us: we never write your email down at all. For up to 30 days it also exists on Anthropic's side, under their retention policy, and then it is gone. You should know both halves rather than only ours.

Your writing voice

When you teach QuillReply your voice from an email you wrote, we derive a short style description: roughly how formal you write, typical reply length, whether you use contractions, and the shape of your greeting and sign-off, stored as patterns rather than text addressed to anyone real. The description contains no message text, names, companies, or subject matter.

The description is stored in your own browser and sent to us with each drafting request. It is not kept on our servers between requests.

Voice by recipient. When you tap a steering chip (warmer, shorter, more formal) while drafting to someone, QuillReply remembers that adjustment for that person and for their email domain, so later drafts to them start from it. These adjustments are stored in your browser under a one-way hash of the address and of the domain, never the address itself. Only the adjustments for the person you are currently writing to are sent with that one drafting request, labelled with the recipient's address or with an audience name you chose in Settings. You can also name audiences in Settings (for example "Clients", matching your clients' domains) with notes on how you write to them; those names, domains, and notes are typed by you, stored in your browser, and sent only with drafts to a matching recipient. None of this is retained on our servers between requests, and none of it involves reading your mailbox.

What we store on our servers

DataPurposeRetention
An opaque account identifierIdentify your subscription and usage. Not your email address.Until you delete your account
Subscription status and Stripe idsBillingUntil deletion, then as long as tax law requires
Counts of actions usedEnforce the free allowance and detect abuseUntil you delete your account
A session token (stored hashed)Keep you signed in without holding any Google credentialExpired sessions are deleted automatically
Queued Apple Reminders items (title, note, due date, list name)Hold the reminder until your device collects itDeleted when your device confirms it, or automatically after 30 days
Reminders list names your device reportsShow you an accurate list pickerUntil you disconnect
A random install identifierCount how many people who install QuillReply go on to sign in, and how many remove it. It is generated by the extension on your own computer, is not derived from you, your account or your machine, and is not connected to any account until you sign in.The link to your account is deleted with your account. The install record itself is kept with no link to anyone, so past install counts do not change as people leave
Product events: installed, signed in for the first time, took an action, reached the free allowance, subscription changed, removedSee which parts of the product get used and where people get stuckUntil you delete your account
Your answer to the one question on our uninstall page, if you choose to answer itUnderstand why people stop using QuillReplyKept with the anonymous install record above, with no link to you

We do not store: your email address, your name, the body of any message, generated drafts, prompt logs, or your task manager credentials.

The product events in the table record that something happened and when. Each one carries a short label taken from a fixed list inside our own code, such as "draft.reply" or "chrome". Nothing you type can appear in that label: a value our code does not recognise is stored as the word "other". We do not record your IP address or your browser details alongside these events.

Two things outlive your account, and neither can be traced to you. When your account is deleted we remove the link between it and the install record, but we keep the anonymous record that an install happened, along with your uninstall answer if you gave one. Nothing in either can be connected to you, to your account, or to your email address. We keep them so that counts of how many people installed QuillReply in the past do not silently change every time somebody leaves.

The uninstall page asks one question and offers five buttons. There is no text box on it, by design: your answer is stored as one of those five choices and nothing else. Answering is optional and the page works the same if you close it.

The one exception is the queue above. A reminder you file to Apple Reminders waits on our servers until your device collects it, and the note we hold contains the subject line of the email it came from and a link back to it. That is what makes the reminder useful when it arrives. It is deleted as soon as your device confirms it has created the reminder, and automatically after 30 days if no device ever does.

Apple Reminders

Apple provides no way for a web service to write to Apple Reminders. Some tools work around this by asking for your Apple ID and an app-specific password. We do not, and we will not. Instead, something running on your own device collects your queued reminders under a random token, and Apple's own Reminders engine writes them locally. We never receive or store any Apple credential.

That something is either QuillReply for Mac, a small free app we publish, or a Shortcut on your iPhone. The Mac app is signed and notarized by Apple. It stores one thing on your machine: the relay token, in a file only your account can read. It asks macOS for access to Reminders so it can create them and read your list names, and it receives nothing from us but a title, a note, a due date and a list name, never your mail. Removing it is dragging it to the Trash; disconnecting the device revokes its token.

Other task managers

Todoist and Microsoft To Do do require an account with those companies. When you connect one, the resulting access token is kept in your browser's own extension storage and used only from your browser. We do not store it, and it is never written to our database or to any log.

Todoist is a partial exception and it is worth stating plainly rather than glossing. Todoist requires an application secret to finish signing in and does not support the browser-only method that would let us avoid that. A secret shipped inside a browser extension can be read by anyone who installs the extension, so the last step of a Todoist connection passes through our server: your browser sends us the one-time authorisation code, we apply our secret, and we hand the resulting token straight back to you. Nothing from that exchange is stored or logged, and our server never calls Todoist afterwards and never reads your tasks. Microsoft To Do needs no such step, so its sign-in never touches our server at all.

Basecamp, which works differently

Basecamp is the one destination whose requests are made by our server rather than by your browser. We are telling you this specifically instead of quietly widening the sentences above, because it is a real difference.

Basecamp's makers require every program using their API to identify itself with a header that web browsers do not allow an extension to set. There is no way to comply from inside your browser. So when you use Basecamp with QuillReply, your browser asks our server to make the request, and our server makes it with the identification Basecamp requires.

If you would rather no third party handled your Basecamp token, do not connect Basecamp. Every other destination keeps its token in your browser.

Google user data

The only Google user data QuillReply receives is the result of your one-time sign-in (openid email): an opaque account identifier, which we keep, and your email address, which we deliberately do not store. QuillReply's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Who else processes data

ProcessorWhat it handles
AnthropicGenerates drafts and task suggestions from message text you act on, under their API terms
Our hosting providerRuns our servers and database
Todoist and Microsoft To DoIf you file a reminder to them, your browser sends them the task title, the note and the due date. The note we build includes the subject line of the email and a link back to it. That request does not pass through our servers; those companies handle it under their own privacy policies.
BasecampSame information, but sent by our server rather than your browser, for the reason given above. Your Basecamp token passes through our server on each request and is not stored. 37signals handle what they receive under their own privacy policy.
StripePayment processing. Stripe holds your payment details; we never see a card number.
Google AnalyticsCounts visits to the quillreply.com website: pages viewed, referring source, coarse location. It runs on the website only, never inside the extension, and it sees nothing about your email or your reminders.

We do not sell your data or share it with anyone else.

Deleting your data

Open the extension's settings and choose Delete my data. This revokes any Apple Reminders relay token, deletes queued reminders, and marks your account for deletion; everything is purged within 30 days, with billing records retained only as long as tax and accounting law requires. Uninstalling the extension alone does not signal our servers, so use the settings option.

Security

TLS in transit, encryption at rest. Apple Reminders relay tokens are stored hashed and are scoped so they can do nothing except collect that one user's queued reminders. If we discover a breach affecting your data, we will notify you and the relevant authorities as required by law.

Children

QuillReply is not directed to anyone under 16 and we do not knowingly collect their data.

Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict processing of your personal data. Contact us at the address below and we will respond within 30 days.

Changes and contact

Material changes will be posted here with an updated date. Questions and requests: hello@quillreply.com.