Ding! for Gmail Privacy Policy
Effective date: 3 October 2026
Ding! for Gmail is a Chrome extension that shows how many unread conversations are in the Inbox of your Gmail accounts and plays a sound when new mail arrives. It is developed and operated by the Ding! for Gmail developer ("we"), who can be reached at contact@dingmail.dev. Its homepage is https://dingmail.dev. This policy explains which Google user data Ding! for Gmail accesses, how it uses, shares, protects, retains, and deletes that data, and how you can remove it.
Summary
- Ding! for Gmail only needs the number of unread Inbox conversations and the email address of each account you add.
- It never reads, stores, or sends the content, subjects, or senders of your email.
- Google user data is never sold, used for advertising, used to train AI models, or shared with anyone except the services needed to make the extension work: Google, and Cloudflare for accounts connected with Google.
- There are no analytics, tracking, or advertising scripts.
Data Accessed
Ding! for Gmail offers two ways to add an account. Each accesses only the Google user data listed here.
Signed-in Gmail accounts
When you choose Use signed-in Gmail accounts, your browser requests Gmail's Inbox feed (https://mail.google.com/mail/u/<n>/feed/atom) directly from Google, using the Google session already signed in to Chrome. Google's response contains the account email address, the unread conversation count, and the senders, subjects, and short snippets of recent unread messages.
Ding! for Gmail reads only the email address and the unread conversation count. The rest of the response is discarded immediately and is never stored or sent anywhere. These requests go only from your browser to Google; the Ding! backend is not involved.
Accounts connected with Google
When you choose Connect with Google, you sign in on Google's own consent screen and grant these permissions:
openidandemail: to read the account's Google account ID and email address, which identify the account and are shown in the extension.https://www.googleapis.com/auth/gmail.labels: to read the unread conversation count of the Inbox label. Google describes this permission as allowing label changes; Ding! for Gmail only reads the Inbox label and never changes labels, messages, or settings.
Because Google requires a confidential client secret to complete this sign-in, a small backend run by us on Cloudflare Workers ("the Ding! backend", api.dingmail.dev) completes the sign-in, receives a Google refresh token, and reads the unread count on the extension's behalf.
Data Use
Google user data is used only to provide the features you see in the extension:
- the email address, to label each account and open its Gmail inbox when you click it;
- the Google account ID, to recognize an account you connect again instead of creating a duplicate;
- the unread conversation count, to show per-account counts and the toolbar total and to play a sound or show a notification when the count increases;
- the Google refresh token, only to obtain short-lived access tokens for reading the Inbox unread count.
Ding! for Gmail does not use Google user data for any other purpose, including advertising, profiling, analytics, or creditworthiness or lending decisions.
Data Sharing
We do not sell, rent, or trade Google user data, and we do not share, transfer, or disclose it to any third party except:
- Google, which provides Gmail, the Inbox feed, and Google sign-in.
- Cloudflare, which hosts the Ding! backend as our service provider and processes requests to it, including your IP address. This applies only to accounts connected with Google.
- When required by law, such as a valid court order, or to protect the security of users.
Data Storage
In your browser
The extension stores the following in Chrome's local extension storage on your device. It is not synced to other devices.
- The email address and type of each account you add.
- For signed-in accounts, the account's position in Gmail's list of signed-in accounts.
- For connected accounts, a random connection token that identifies the account to the Ding! backend. It is not a Google credential.
- The latest unread counts, when they were checked, and any error shown for an account.
- Your settings: how often to check mail and how to notify you.
On the Ding! backend
This applies only to accounts connected with Google. The backend stores, in a Cloudflare D1 database:
- The account's email address and Google account ID.
- The Google refresh token, encrypted.
- A one-way hash of the connection token. The token itself is not stored.
- When the account was connected, last updated, and last used.
While a sign-in is in progress, the backend also stores a random state value and a PKCE verifier. They stop working after 10 minutes and are deleted within a day. Unread counts are held in memory for at most 15 seconds and are never written to the database.
Data Protection
- All traffic between the extension, the Ding! backend, and Google uses HTTPS (TLS).
- Google refresh tokens never reach the extension. They are encrypted with AES-256-GCM, bound to their account, before being stored, and the encryption key is held separately as a Cloudflare secret.
- Connection tokens are stored only as SHA-256 hashes on the backend, and every account request must present the matching token.
- Browsers only allow the extension itself to call the backend, and sign-in uses PKCE and single-use state values to prevent interception.
- No person reads Google user data. Access to the backend is limited to the developer for operating and securing the service.
Data Retention and Deletion
- Signed-in accounts: no Google user data leaves your browser. Removing the account in the extension's settings, or uninstalling the extension, deletes it.
- Removing a connected account in the extension's settings deletes its data from your browser, revokes the Google authorization, and deletes the account from the Ding! backend immediately.
- Unused connected accounts are revoked and deleted from the backend automatically after 30 days without use, for example after you uninstall the extension.
- Revoking access at Google Account connections stops the backend from reading your account immediately; its stored data is then deleted within 30 days.
- Deletion requests: email contact@dingmail.dev from the account's address and we will delete its backend data within 30 days.
Limited Use of Google User Data
Ding! for Gmail's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Ding! for Gmail:
- uses Google user data only to provide and improve the user-facing features described in this policy;
- does not transfer Google user data to others except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users;
- does not use or transfer Google user data for serving advertisements, including targeted, personalized, or retargeted advertising;
- does not sell Google user data to data brokers, advertising platforms, or anyone else;
- does not use Google user data to determine creditworthiness or for lending purposes;
- does not allow humans to read Google user data, unless you give explicit consent for specific data, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or it is aggregated and anonymized for internal operations;
- does not use Google user data, including data obtained through Google Workspace APIs, to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.
Permissions
- Alarms: check for new mail on a schedule.
- Notifications and offscreen document: show the new-mail notification and play the alert sound.
- Storage: keep your accounts and settings on your device.
- Access to mail.google.com (optional): requested only when you add a signed-in account, to read the Inbox feed. Chrome describes it as reading and changing data on mail.google.com because host permissions cannot be limited to a single page; the extension only requests the feed. It is removed when you remove your last signed-in account.
- Identity (optional): requested only when you connect an account with Google, to open Google's sign-in window. It is removed when you remove your last connected account.
Children
Ding! for Gmail is not directed at children under 13, and we do not knowingly collect data from them.
Changes
We will update this policy when the extension's data handling changes and change the effective date above.
Contact
Questions, access, or deletion requests: contact@dingmail.dev.