Privacy Policy
Effective date: August 28, 2026 · Product: Email Tracking (SentCue) Chrome extension · Draft for CWS
A signal is not proof that a particular person read a message. Email providers, scanners, caching, sender-side opens and disabled images can affect the result.
1. What we process
- A random tracking token, send/arm/cancel timestamps, and qualifying image-request timestamps.
- A coarse client class only (
google_image_proxy,sender_chrome,scanner,other). We do not persist recipient IP, raw User-Agent, or full HTTP headers in the application database. - Locally in Chrome only: To, subject, fingerprint, Gmail thread ids for the Sent row. These are not sent to the backend in v1.
We do not collect message bodies, attachments, passwords, auth cookies, or Gmail API/OAuth data.
2. Recipients
Recipients do not install SentCue. Opening a tracked message (or a provider fetching the image) may produce a token, timestamp, and transient network metadata at Cloudflare’s edge. We use this only to show the sender an activity signal and to operate the service. We do not sell this data or use it for ads.
3. Service providers (current pre-production stack)
- Hosting/API: Cloudflare Tunnel (
pixel.sentcue.com, aliast.sentcue.com) to an origin process on the operator’s machine. Not Cloudflare Pages Functions and not D1. - Database/backups: SQLite file on that origin until a hosted database is chosen.
- CDN/security: Cloudflare (proxy/TLS for the pixel hostname and this site).
- Monitoring: none beyond Cloudflare and local logs (no raw UA/IP persistence in app DB).
This site is Cloudflare Pages. Pages does not store tracking tokens.
4. Retention and cancellation
Token and event rows are retained at most 90 days from send_at, then deleted by the retention job. Cancelled tokens never count as an open signal and are removed with the same retention (or sooner on install deletion).
5. Deletion
Senders can delete server records for this Chrome install from the extension popup: Delete tracking data for this install. That calls authenticated POST /delete-install. No Google account is required. You can also email privacy@sentcue.com.
6. Controls
Tracking is Off until in-product disclosure is accepted and the toggle is On. The remote kill switch is fail-closed. Recipients may disable remote images in their mail client.
7. Children and sensitive uses
Not for monitoring children, employees, medical or similarly sensitive communications, stalking, or covert surveillance. See Terms.
8. International / launch perimeter
Traffic may be processed on Cloudflare’s network. Initial Chrome Web Store geography is not finalized pending privacy counsel. This policy will be updated before CWS submission.
9. Contact
Privacy: privacy@sentcue.com
Website: https://sentcue.com
Publisher / legal entity: to be stated before CWS submission.