Privacy Policy
Last updated August 5, 2026
HitSend is built privacy-first. Your email content is analyzed on your own device and is never sold. This policy explains exactly what we collect, why, and the choices you have.
Who we are
HitSend (“we”, “us”) provides a spam-risk checker for email, available as a web tool and a browser extension at hitsend.vercel.app. For any privacy question, reach us through our contact page.
What we collect
- Account data - if you create an account: your email address and authentication details.
- Billing data - handled by our payment processor (Stripe). We never see or store your full card number.
- Product usage - anonymous, aggregated events (e.g. “a check was run”) to improve the product. No email content is included.
- Email content - the text of emails you check is scored locally, on your device. We do not transmit, store, or read the content of your emails.
Google user data & Limited Use
If you connect the HitSend extension to Gmail, its use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only access Gmail data needed to score the email you are composing.
- We do not transfer or sell Google user data to third parties.
- We do not use Google user data for advertising.
- No humans read your Google user data, except where you explicitly ask us to for support, or where required by law.
How we use data
- To operate the checker and show you results.
- To provide, secure, and improve the service.
- To communicate with you about your account and updates you opt into.
Sharing
We do not sell your personal data. We share it only with the service providers that run our product (e.g. hosting, Stripe for payments) under contracts that require them to protect it.
Retention
We keep account data while your account is active and delete it within a reasonable period after you close your account, unless we must keep it to meet a legal obligation.
Your rights
Depending on where you live (e.g. under GDPR or CCPA), you may have the right to access, correct, export, or delete your data, and to object to certain processing. To exercise any of these, reach us through our contact page.
Security
We use industry-standard measures to protect your data. Because email content is processed locally, the most sensitive data usually never leaves your browser. No system is perfectly secure, but we work hard to keep yours safe.
Changes
We may update this policy. If we make material changes, we’ll update the date above and, where appropriate, notify you.
Contact
Questions? Reach us through our contact page and we’ll help.