Privacy disclosure
Last updated: October 4, 2026.
Kaytos, LLC operates and distributes newtab.email. For support, privacy questions, or deletion requests, contact hello@qorsoftware.com. The public policy is available at qorsoftware.com/newtab/privacy/.
This policy describes the current development build. Google OAuth verification and Chrome Web Store review have not been completed. The storage limitations below must be addressed before public release.
Data and purpose
After you agree and connect Google, the extension reads Gmail account identity, message metadata, bodies and attachments needed for reading, local search, classification, and triage. It sends messages you compose and updates read state and labels when you use those features. Contact autocomplete sends your query to Google's People API and receives matching names and email addresses.
Google Calendar uses the same Google account and the same sign-in as mail; the one consent screen at sign-in lists calendar with the mail and contact permissions. The extension reads the events of the calendars you show in Calendar, and which calendars those are, with two read-only permissions. It cannot create, change or delete events. It keeps each event's title, time, location and meeting link in your Chrome profile so the new tab can show today at once; it does not keep descriptions or guest lists. Reminders are created on your device from that cache. When you add an event with quick add, the text you typed is placed in a Google Calendar address that opens in a new tab; Google Calendar handles it from there. Turn the calendar off in the extension's settings (this removes the calendar cache), and remove the Google access at Google account connections.
Mail cache, drafts, local classifications, corrections, preferences, and decision history are stored in your Chrome profile. Previous versions' saved notes remain in the local database. Current preferences use local storage rather than Chrome Sync; the upgrade removes known legacy preference copies from Sync after copying them locally. Historical synchronized copies or device backups may remain under your control.
Clips (typed notes, saved pages and quotes, parcels, videos, posts and shopping items) are stored only in the local database. Saving reads the clicked tab's address, title, description, the text you selected and, on a product page, its price and picture address, and only when you choose to save. Cleared clips are deleted after 30 days. If picture previews are on (Settings), the clips page loads the picture of a saved video or product from the site that hosts it, which can disclose your IP address to that site; turn them off to load nothing. "Send" on a clip opens a new Gmail message in a tab, filled in; nothing is sent until you press Send in Gmail.
Connections and sharing
Gmail, contact and (if connected) calendar requests go directly to Google over HTTPS using Chrome-managed OAuth tokens. There is no newtab.email server receiving your mailbox, and no analytics, advertising, or crash-reporting upload in this source build. User data is used only to provide the visible mail, contact, and calendar features; it is not sold or used for advertising. The developer does not receive mail for human review or general model training.
Email images are blocked by default. If you choose to load them or trust a sender, image requests contact the image host and can disclose your IP address and image URL identifiers. Following a link opens its destination normally. Exporting a correction backup or downloading an attachment writes a local file that you control.
Optional Chrome AI is disabled until enabled in settings. Chrome may download a model from Google. The app submits bounded mail text and examples to Chrome's on-device API; it has no cloud-model fallback. Explicit corrections and decision history stay local.
Retention and protection
Routine maintenance prunes eligible old cache entries and limits downloaded bodies. Kept/snoozed mail, drafts, unresolved sends, corrections, and other user-owned state can remain until explicitly handled or the extension is removed. A cache is not a backup of Gmail or unsent drafts.
This build does not apply encryption to IndexedDB, local preferences, or exported files. Someone with access to your Chrome profile may be able to read them. Public-display mode hides the screen; it does not secure the stored data.
Disconnect and delete
To stop access, remove the extension in Chrome and remove its Google connection at Google account connections. Removing the extension deletes its local extension storage. Delete exported backups/downloads and operating-system backups separately. Removing the extension does not delete Gmail messages or reverse messages sent and labels changed in Gmail. Save any unsent drafts you need before removal. Developer previews use separate localhost storage, which must be cleared separately in Chrome site settings.
Limited use
newtab.email uses Google user data only to deliver its user-facing mail, contact, and calendar features, consistent with the Chrome Web Store User Data Policy and Google API Services User Data Policy, including their Limited Use requirements. This statement describes intended and implemented data use; it is not Google verification or approval.
Public website
The notices at qorsoftware.com/newtab are hosted by Cloudflare. Visiting those pages sends your IP address, requested URL, and browser/network headers to the hosting provider to deliver and protect the website. The pages do not include analytics scripts, advertising, forms, or third-party embeds. Hosting providers may process request and security data under their own policies; see Cloudflare's privacy policy. These website requests do not include your mailbox contents. Website hosting is separate from the extension's direct Google API connections described above.
Policy changes
Kaytos will update this notice when the product's data practices change. The date above identifies the current notice. Material new access or use must be explained and consent obtained where required before it begins. Contact hello@qorsoftware.com with questions about this policy.