Privacy Policy
Last updated: September 13, 2026. This policy describes what QuillReply does today. If it changes, the date above changes with it.
The short version
- QuillReply reads an email when you click one of its buttons on it, from the page already open in your browser, and, for a follow-up you armed, it re-reads that one thread in your browser on the day you chose, to see whether they replied. It requests no Gmail permission and cannot browse, search, or read the rest of your mailbox at any time.
- Email content you act on is used to produce the one thing you asked for, a draft reply or a task suggestion, and is then discarded. We do not store the content of your emails.
- Reply detection ("remind me only if they have not replied") happens entirely in your browser. The thread is never sent to our servers for checking.
- We do not use your data to train or improve any AI model. Message text you act on is sent to Anthropic to generate that one draft or task, and we neither keep it nor use it for anything else. Anthropic handles it under their own API terms.
- We never send email on your behalf. Every draft waits for you to review and send it.
- You can delete everything we hold, at any time, from the extension's settings.
What the extension can and cannot see
QuillReply is a browser extension. A fresh install has one host permission: our own API. Connecting Todoist or Microsoft To Do asks you, at that moment, for permission to reach that one service, and nothing is granted before you press Connect. Someone who only uses Apple Reminders is never asked, and neither is someone who uses Basecamp: the extension never contacts Basecamp directly, so it needs no such permission (see the Basecamp section below). It requests no Gmail OAuth scope of any kind: not read, not modify, not compose. When you click a QuillReply button on an open email, the extension reads that message from the page you are already looking at, the same way you do. If you never click a button on an email, QuillReply never sees it.
What happens to an email you act on
When you ask for a draft reply or a task suggestion, the subject and body of that one message are sent over TLS to our servers, passed to our AI provider (Anthropic) to generate the result, and returned to you. The content is then discarded: not written to a database and not written to a log. Quoted history from older messages in the thread is stripped in your browser before anything is sent.
Anthropic is not a black box we can make promises on behalf of, so here is theirs. Under their commercial API terms, Anthropic does not train any model on what we send, and automatically deletes API inputs and outputs from their systems within 30 days. So "discarded" above describes us: we never write your email down at all. For up to 30 days it also exists on Anthropic's side, under their retention policy, and then it is gone. You should know both halves rather than only ours.
Your writing voice
When you teach QuillReply your voice from an email you wrote, we derive a short style description: roughly how formal you write, typical reply length, whether you use contractions, and the shape of your greeting and sign-off, stored as patterns rather than text addressed to anyone real. The description contains no message text, names, companies, or subject matter.
The description is stored in your own browser and sent to us with each drafting request. It is not kept on our servers between requests.
Voice by recipient. When you tap a steering chip (warmer, shorter, more formal) while drafting to someone, QuillReply remembers that adjustment for that person and for their email domain, so later drafts to them start from it. These adjustments are stored in your browser under a one-way hash of the address and of the domain, never the address itself. Only the adjustments for the person you are currently writing to are sent with that one drafting request, labelled with the recipient's address or with an audience name you chose in Settings. You can also name audiences in Settings (for example "Clients", matching your clients' domains) with notes on how you write to them; those names, domains, and notes are typed by you, stored in your browser, and sent only with drafts to a matching recipient. None of this is retained on our servers between requests, and none of it involves reading your mailbox.
What we store on our servers
| Data | Purpose | Retention |
|---|---|---|
| An opaque account identifier | Identify your subscription and usage. Not your email address. | Until you delete your account |
| Subscription status and Stripe ids | Billing | Until deletion, then as long as tax law requires |
| Counts of actions used | Enforce the free allowance and detect abuse | Until you delete your account |
| A session token (stored hashed) | Keep you signed in without holding any Google credential | Expired sessions are deleted automatically |
| Queued Apple Reminders items (title, note, due date, list name) | Hold the reminder until your device collects it | Deleted when your device confirms it, or automatically after 30 days |
| Reminders list names your device reports | Show you an accurate list picker | Until you disconnect |
| A random install identifier | Count how many people who install QuillReply go on to sign in, and how many remove it. It is generated by the extension on your own computer, is not derived from you, your account or your machine, and is not connected to any account until you sign in. | The link to your account is deleted with your account. The install record itself is kept with no link to anyone, so past install counts do not change as people leave |
| Product events: installed, signed in for the first time, took an action, reached the free allowance, subscription changed, removed | See which parts of the product get used and where people get stuck | Until you delete your account |
| Your answer to the one question on our uninstall page, if you choose to answer it | Understand why people stop using QuillReply | Kept with the anonymous install record above, with no link to you |
We do not store: your email address, your name, the body of any message, generated drafts, prompt logs, or your task manager credentials.
The product events in the table record that something happened and when. Each one carries a short label taken from a fixed list inside our own code, such as "draft.reply" or "chrome". Nothing you type can appear in that label: a value our code does not recognise is stored as the word "other". We do not record your IP address or your browser details alongside these events.
Two things outlive your account, and neither can be traced to you. When your account is deleted we remove the link between it and the install record, but we keep the anonymous record that an install happened, along with your uninstall answer if you gave one. Nothing in either can be connected to you, to your account, or to your email address. We keep them so that counts of how many people installed QuillReply in the past do not silently change every time somebody leaves.
The uninstall page asks one question and offers five buttons. There is no text box on it, by design: your answer is stored as one of those five choices and nothing else. Answering is optional and the page works the same if you close it.
The one exception is the queue above. A reminder you file to Apple Reminders waits on our servers until your device collects it, and the note we hold contains the subject line of the email it came from and a link back to it. That is what makes the reminder useful when it arrives. It is deleted as soon as your device confirms it has created the reminder, and automatically after 30 days if no device ever does.
Apple Reminders
Apple provides no way for a web service to write to Apple Reminders. Some tools work around this by asking for your Apple ID and an app-specific password. We do not, and we will not. Instead, something running on your own device collects your queued reminders under a random token, and Apple's own Reminders engine writes them locally. We never receive or store any Apple credential.
That something is either QuillReply for Mac, a small free app we publish, or a Shortcut on your iPhone. The Mac app is signed and notarized by Apple. It stores one thing on your machine: the relay token, in a file only your account can read. It asks macOS for access to Reminders so it can create them and read your list names, and it receives nothing from us but a title, a note, a due date and a list name, never your mail. Removing it is dragging it to the Trash; disconnecting the device revokes its token.
Other task managers
Todoist and Microsoft To Do do require an account with those companies. When you connect one, the resulting access token is kept in your browser's own extension storage and used only from your browser. We do not store it, and it is never written to our database or to any log.
Todoist is a partial exception and it is worth stating plainly rather than glossing. Todoist requires an application secret to finish signing in and does not support the browser-only method that would let us avoid that. A secret shipped inside a browser extension can be read by anyone who installs the extension, so the last step of a Todoist connection passes through our server: your browser sends us the one-time authorisation code, we apply our secret, and we hand the resulting token straight back to you. Nothing from that exchange is stored or logged, and our server never calls Todoist afterwards and never reads your tasks. Microsoft To Do needs no such step, so its sign-in never touches our server at all.
Basecamp, which works differently
Basecamp is the one destination whose requests are made by our server rather than by your browser. We are telling you this specifically instead of quietly widening the sentences above, because it is a real difference.
Basecamp's makers require every program using their API to identify itself with a header that web browsers do not allow an extension to set. There is no way to comply from inside your browser. So when you use Basecamp with QuillReply, your browser asks our server to make the request, and our server makes it with the identification Basecamp requires.
- Your Basecamp access token is sent to our server with each Basecamp request. For every other destination your token never reaches us at all.
- We do not store it. It is used for that one request and is gone when the response comes back. It is not written to our database and not written to any log.
- What passes through is what you asked for: your projects and their to-do lists, the people on a project so you can choose who to assign, and the to-do being created (title, note, due date, assignee). We never read your Basecamp for any other reason, and never on our own initiative.
- Our server can only reach Basecamp. It builds every Basecamp address from your own choices and cannot be pointed anywhere else.
If you would rather no third party handled your Basecamp token, do not connect Basecamp. Every other destination keeps its token in your browser.
Google user data
The only Google user data QuillReply receives is the result of your one-time sign-in (openid email): an opaque account identifier, which we keep, and your email address, which we deliberately do not store. QuillReply's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to authenticate you and operate your subscription.
- We do not use Google user data to develop, train, or improve any generalized artificial intelligence or machine learning model. Message text you act on is sent to Anthropic to generate that one draft or task; we neither keep it nor use it for anything else, and Anthropic handles it under their own API terms.
- We do not sell, rent, or transfer Google user data for advertising, retargeting, credit assessment, or lending purposes.
- We do not permit humans to read your data, except where you have given us specific documented consent, where required by law, or where necessary to investigate an active security incident.
Who else processes data
| Processor | What it handles |
|---|---|
| Anthropic | Generates drafts and task suggestions from message text you act on, under their API terms |
| Our hosting provider | Runs our servers and database |
| Todoist and Microsoft To Do | If you file a reminder to them, your browser sends them the task title, the note and the due date. The note we build includes the subject line of the email and a link back to it. That request does not pass through our servers; those companies handle it under their own privacy policies. |
| Basecamp | Same information, but sent by our server rather than your browser, for the reason given above. Your Basecamp token passes through our server on each request and is not stored. 37signals handle what they receive under their own privacy policy. |
| Stripe | Payment processing. Stripe holds your payment details; we never see a card number. |
| Google Analytics | Counts visits to the quillreply.com website: pages viewed, referring source, coarse location. It runs on the website only, never inside the extension, and it sees nothing about your email or your reminders. |
We do not sell your data or share it with anyone else.
Deleting your data
Open the extension's settings and choose Delete my data. This revokes any Apple Reminders relay token, deletes queued reminders, and marks your account for deletion; everything is purged within 30 days, with billing records retained only as long as tax and accounting law requires. Uninstalling the extension alone does not signal our servers, so use the settings option.
Security
TLS in transit, encryption at rest. Apple Reminders relay tokens are stored hashed and are scoped so they can do nothing except collect that one user's queued reminders. If we discover a breach affecting your data, we will notify you and the relevant authorities as required by law.
Children
QuillReply is not directed to anyone under 16 and we do not knowingly collect their data.
Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict processing of your personal data. Contact us at the address below and we will respond within 30 days.
Changes and contact
Material changes will be posted here with an updated date. Questions and requests: hello@quillreply.com.