Last updated: 1 October 2026
Privacy policy
Local Export for Gmail reads the conversations you choose and builds your export on your device.
This policy covers Local Export for Gmail version 0.2.1, provided under the Sami Studio brand. For privacy questions, contact hello@samistudio.nl.
What the extension handles
To prepare your export, the extension handles your Gmail account address, selected conversation and message identifiers, email headers and bodies, attachment filenames and bytes, and image references. Emails and attachments can contain personal, financial, health, address or other sensitive information.
It also observes two native Gmail session headers needed to read the selected conversations through your existing Gmail sign-in. These are held in browser memory and are not included in logs, downloads or exports. The extension does not ask for your password, read authentication cookies directly, or request a separate Google OAuth grant.
How that information is used
Selected messages are read, converted into PDFs and packaged with their original attachments in a ZIP. The report records exported counts, filenames, file sizes, checksums, failures and rendering notices. The extension does not send, delete, label or mark your Gmail messages as read.
Sami Studio does not receive the emails or attachments processed by the extension. There is no developer-operated export server, analytics, advertising, data sale or profiling. Data is used only for the export you request.
Requests to Google and email images
The extension makes HTTPS requests to Gmail using the existing Gmail browser session. Google handles these requests under its own privacy practices.
External images are enabled by default. Supported images are fetched only from Gmail-supplied proxy links on ci3.googleusercontent.com through ci6.googleusercontent.com. Those image fetches omit credentials and referrers, reject redirects and do not fall back to the sender's website. Google may retrieve an image from its sender, so loading external images is not a guarantee against tracking.
You can turn off Include external images in Export details before exporting. Explicit unlabeled external 1-by-1-pixel images are omitted. Unavailable images are marked in the PDF and counted in the report. Original inline attachment files are preserved independently of external image loading.
Storage and deletion
The extension uses browser memory for the active selection, reader and export. Gmail content and session headers are not saved in persistent extension storage. Purchase licenses, a random browser-installation identifier and pending checkout state are stored locally in Chrome, restricted to trusted extension contexts. Clear session does not remove the license. Uninstalling removes this local license state, so save your key first. Closing the export tab or using Clear session releases its export data and reader connection. Gmail session headers can remain in the originating Gmail document's memory until that document closes or refreshes. Pending worker caches are bounded and short lived.
ZIPs and extracted files remain wherever Chrome saves them until you delete them. They are not password-protected or encrypted by the extension. Your operating system, browser download records, backups and any cloud-synced download folder may retain copies independently. Uninstalling the extension does not delete exported files or change messages stored in Gmail.
Purchases and activation
Stripe collects the purchase email and payment or billing information needed for checkout. Payment details are handled by Stripe, not entered in the extension. Stripe order records are used to fulfill purchases and check refunds or disputes. We do not pass your Gmail address, selections or message content to Stripe or the license service.
The Vercel-hosted license service processes purchase references, license keys and a random browser identifier to activate Pro and enforce the 2-browser limit. The Neon Postgres registry stores the license reference, a hash of that random identifier and activation dates. It does not use device fingerprinting or receive Gmail data. Purchase records are retained as needed to provide the license, handle refunds and meet applicable obligations. Contact support about access or deletion. Starting a Pro batch checks that the browser activation and purchase remain active.
Permissions
Gmail access identifies selections and reads chosen conversations. The webRequest permission observes the two Gmail session headers without blocking or changing requests. Access to the four Google image-proxy hosts preserves supported external images. The downloads permission saves and checks this extension's ZIP and opens its location when you ask. The storage permission keeps the purchase license and checkout recovery state. Access to gmail-local-export.vercel.app verifies purchases; only its approved purchase pages can send narrowly scoped activation messages to the extension. No all-sites, cookie, geolocation or browsing-history permission is requested.
Support and this website
If you email support, we receive your address and whatever you choose to send. We use that correspondence to answer your request and keep it while needed for that purpose or applicable obligations. Our email provider processes the correspondence. Please avoid sending private email contents or attachments unless needed and explicitly agreed. You can contact us about access to or deletion of support correspondence.
These pages contain no analytics, advertising or third-party assets. Purchase pages use local scripts and temporary session storage for checkout recovery. Stripe hosts the payment form separately. The hosting provider may process ordinary request metadata such as IP address, requested URL and browser information to deliver and secure the website. The website does not receive your Gmail exports.
Limited Use and changes
Local Export for Gmail's use of user data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Email data is not used or transferred for advertising, resale, creditworthiness or lending decisions.
Changes to data practices will be described here with an updated date and disclosed in the product when required. Questions can be sent to hello@samistudio.nl.