Privacy policy
Last updated September 30, 2026.
Keytray is a browser extension that runs on your device. This policy describes the Google user data it accesses and what happens to that data. The developer does not operate a server that receives your mail, codes, links, or tokens.
Who this applies to
This policy applies to the Keytray extension published from github.com/MehdiMamas/multi-gmail-auth-copier. The application home page is mehdimamas.dev/gmail-otp-copier.
Google data the extension accesses
When you connect a Gmail account, you grant these OAuth scopes:
-
https://www.googleapis.com/auth/gmail.readonlyโ read mail so the extension can look for verification codes and sign-in links. -
https://www.googleapis.com/auth/userinfo.emailโ read the email address of the account you signed in with, so it can label that mailbox.
Using those scopes, the extension requests from Google APIs:
- Your Gmail address.
- A short-lived OAuth access token.
- Your Gmail profile history id, used only to ask for messages added since the last check.
- Recent inbox messages (headers and body) so it can search the subject and body for a verification code or a verification or sign-in link. Message bodies are processed in memory in the browser and are not written to storage.
The extension cannot send, delete, label, or otherwise change your mail.
How that data is used
Gmail data is used only to provide the feature you turned on:
- Find a verification code or a verification or sign-in link in a new message.
- Show that code or link host in the extension popup.
- Optionally fill a code into a code field on the active tab, copy it to the clipboard, or show a local notification.
- Open a stored verification or sign-in link in a new tab only when you press Open link or click its notification.
- Open the original message in Gmail when you choose that action.
The extension does not use Gmail data for advertising, does not sell it, and does not transfer it to the developer or to other apps. Page content is not uploaded. The content script looks for a verification-code field on the page you are viewing and can fill a code that is already stored locally.
Keytray's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What is stored on your device
Data is stored in the browser's local extension storage (chrome.storage.local or
the equivalent in Edge or Brave). It stays on that browser profile.
- Connected account email addresses, access tokens, token expiry, a Gmail history id, and the last sync error message.
- Up to 50 extracted codes and links, each with the sender, subject, and time. A link entry stores the full URL. Email bodies are not stored.
- Ids of messages already processed, so the same code or link is not handled twice.
- Your settings (fill, copy, or do nothing; notifications; polling; auto-submit; fill chip).
- Whether extra Gmail accounts are unlocked.
What is not collected by the developer
- No account is created with the developer.
- No analytics, advertising, or tracking scripts run on these pages or inside the extension.
- Mail, codes, links, and tokens are not sent to a server operated for this project.
Requests to Google (sign-in, the userinfo endpoint, and the Gmail API) are made from your browser to Google. Google's handling of those requests is covered by Google's privacy policy.
One Gmail account is free. More accounts require a one-time purchase. Checkout and the customer login are ExtensionPay and Stripe. A login is created with ExtensionPay only if you pay or sign in there. That is not an account with the developer. The extension asks ExtensionPay whether that login has paid. ExtensionPay's library stores that result in this browser, including the email on the login when there is one. Card numbers are not handled by the extension. Mail, codes, links, and Google tokens are not sent to ExtensionPay or to a server operated for this project. Card payments are covered by Stripe's privacy policy.
How long data is kept
Tokens last about an hour and are refreshed while that Google account stays signed in in the browser. Codes and links are capped at 50 entries. You can clear stored codes and links in the extension settings, remove an account, or uninstall the extension, which removes its local storage. You can also revoke the extension's access at Google Account permissions.
Sharing
The developer does not share your Gmail data with third parties. A code is copied to the clipboard or typed into a page only when you have enabled that behavior, or when you press Copy or Fill yourself. A verification or sign-in link is opened in a tab only when you press Open link or click its notification. Anyone who can use that browser profile can see the codes and links stored by the extension.
Children
The extension is not directed at children under 13, and it does not knowingly collect their data.
Changes
If this policy changes, the updated text will be posted on this page with a new date. Continued use of the extension after a change means you accept the updated policy.
Contact
Questions about this policy: open an issue on GitHub.