Privacy Policy
Effective: 2026-09-30 · Operator: ReadMark · Contact: cycmaking@gmail.com
ReadMark (“we”) operates ReadMark, a Chrome extension for Gmail (the “Service”). We comply with applicable laws including the EU/UK GDPR, the California CCPA/CPRA and the Korean Personal Information Protection Act, and with the Chrome Web Store User Data Policy.
1. Data we process
- You (the sender): a random account token created by the extension (only its hash is stored on the server), your sending Gmail address (for display), plan/billing status and extension settings.
- Emails you choose to track: recipients’ email addresses and names, subject, sent time, Gmail thread ID and link URLs in the email (if link tracking is on). We do not collect email bodies.
- Recipients’ open/click events: time, coarse environment (e.g. Gmail, Apple Mail, mobile/desktop) and country code (provided by Cloudflare). We do not store IP addresses or browser identifiers (User-Agent); they are used transiently for classification and discarded.
- Payments: handled by Creem as Merchant of Record. We never receive card details — only a customer ID, subscription status/expiry and license key.
2. Purposes and legal bases
To show you whether and when your emails were opened and links clicked, send notifications, detect bounces, provide reports, verify your plan, prevent abuse and fix errors (performance of contract and legitimate interests). We do not use data for any other purpose.
3. Retention and deletion
- Free: 30 days after sending (+5-day grace) · Pro: 2 years (+5-day grace). Expired records are deleted automatically every day.
- You can delete any email’s record, or everything (“Delete all”), from the dashboard at any time. Uninstalling removes the token; remaining records are deleted when the retention period ends.
- Transaction records required by law are kept by Creem under its obligations.
4. Sharing
We do not sell personal data or share it for advertising, credit-worthiness or data-brokering purposes. We disclose data only when required by law.
5. Processors and international transfers
- Cloudflare, Inc. (USA) — servers (Workers) and database (D1).
- Creem — payments, tax and receipts (paid plans only).
Data may be processed outside your country, protected by the providers’ contractual safeguards (e.g. Standard Contractual Clauses).
6. Chrome Web Store Limited Use
ReadMark’s use of the data it collects complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only for the single purpose described above (email read receipts), is never sold, never used for advertising or to determine credit-worthiness, and is not read by humans except for security, legal compliance, or with your explicit consent.
7. Notice for recipients
Recipients can block open tracking by turning off automatic image loading in their email app, and may ask the sender or us (contact below) to delete records about them. As a user, you are responsible for informing recipients of tracking where the law requires it.
8. Your rights
You may request access, correction, deletion, restriction, portability or object to processing, and withdraw consent (GDPR/CCPA). Most of this can be done directly in the dashboard; otherwise contact cycmaking@gmail.com. You may also complain to your data-protection authority. We do not discriminate against you for exercising your rights.
9. Security
HTTPS everywhere, hashed tokens, data minimisation, least-privilege access and automatic deletion.
10. Children
The Service is not directed to children under 16 (14 in Korea), and we do not knowingly collect their data.
11. Changes
We will post changes here with a new effective date and notify you in the extension of material changes.