AppOrigamiBack

Legal

Privacy Policy

Quickfill – Gmail OTP & 2FA Code Autofill

Which version applies to you

Quickfill changed how it reads email in version 0.3.1. The two versions handle your data very differently, so this policy describes both. You can check your version at chrome://extensions.

  • Version 0.3.1 and later — reads Gmail entirely inside your browser. No Google sign-in, no server, no stored credentials.
  • Version 0.3.0 and earlier — used Google OAuth and stored an encrypted refresh token on our backend. See the legacy section below, including how to delete that data.

Overview

Quickfill (the “Extension”) finds one-time passcodes (OTP / 2FA codes) in your Gmail and fills them into login forms on your request. We aim to collect as little data as possible. We do not sell your data, and we do not track your browsing activity.

Version 0.3.1 and later

The Extension reads your Gmail using the session your browser already has — the same one that logs you in when you visit Gmail. It requests https://mail.google.com/mail/u/<N>/feed/atom, Gmail’s own feed of unread inbox messages.

What this means for your data:

  • No server involved. Your email is read and parsed inside your browser. It is never sent to us or to any third party.
  • No account and no credentials. There is no sign-in step, no password, and no OAuth token. We hold nothing that could access your mailbox.
  • We cannot see your inbox or your codes. Not by policy alone — the Extension has no channel to send them to us.
  • No Gmail API and no OAuth scopes. The Extension requests no Google account permissions.

What is read:

  • Unread messages in the Gmail inbox of each account you are signed into in this browser: subject line, a short preview snippet (roughly 150–200 characters), sender name and address, and the date received.
  • Read messages, spam, archived mail, attachments, and full message bodies are not available to the Extension through this feed.

What is stored on your device (in chrome.storage.local, never transmitted):

  • The email addresses of the Gmail accounts detected in your browser, so codes can be labelled with the inbox they came from.
  • A short-lived cache of extracted codes with sender and subject — about one minute in normal use, up to about five minutes when you manually refresh.
  • Your settings, such as which sites you have enabled autofill for.

Uninstalling the Extension removes all of it. Because nothing leaves your browser, there is no server-side data to request deletion of for this version.

Version 0.3.0 and earlier (legacy)

Earlier versions signed in with Google via chrome.identity.launchWebAuthFlow against the AppOrigami backend at apporigami.com, using the openid, email, profile and https://www.googleapis.com/auth/gmail.readonly scopes.

Google user data accessed, only when you connected Gmail or requested a code:

  • Google account ID (sub) and email address, from Google Sign-In.
  • A filtered list of recent inbox or spam messages matching OTP-related search terms.
  • Message metadata: From, Subject and Date headers.
  • Message body text, solely to extract one-time passcodes.

What was never accessed: we did not read your whole mailbox or scan mail in the background; did not send, modify or delete email; did not access Google Contacts, Calendar, Drive or other Google services; did not store full message bodies on our servers; and did not sell or share Google user data with advertisers or data brokers.

Retention on our backend:

  • Google OAuth refresh token: stored encrypted with AES-256-GCM in Google Cloud Firestore until you sign out or remove the account. Encryption keys are held as server-side secrets, not in application source code. Firestore security rules deny all direct client access; only server-side Cloud Functions read this data.
  • Google access token: cached server-side until near expiry, typically up to about one hour.
  • Session JWT: valid for up to 30 days unless revoked earlier.
  • OAuth state and one-time exchange codes: expire automatically within 5–10 minutes.
  • Message bodies and metadata: never stored on our servers; processed in memory and discarded.

If you used a legacy version, your refresh token remains on our backend until you remove it. To delete it, open Settings or Inboxes in the Extension and choose Sign out or Remove account. This deletes the encrypted tokens and your user record from our servers and clears local session data. You may also email contact@apporigami.com and we will delete it for you. Upgrading to 0.3.1 or later does not by itself remove data already stored on the backend.

Permissions

  • Host permission for mail.google.com: to read the Gmail feed in your browser (0.3.1 and later).
  • Storage: to save settings and detected accounts locally.
  • ActiveTab and Scripting: to fill the code into the page you are using, when you trigger it.
  • Context menus: to offer the right-click fill action.
  • Identity, and host permissions for googleapis.com and apporigami.com: used only by the legacy OAuth path.

Data protection

  • Encryption in transit: all network requests use HTTPS (TLS).
  • Minimal network surface: in 0.3.1 and later the Extension talks only to mail.google.com, in your own authenticated session.
  • Local storage: settings, detected account emails, and a small OTP cache (extracted code, sender, subject, timestamp — never full message bodies) are stored in chrome.storage.local on your device.
  • Legacy backend: encryption at rest, least-privilege Firestore rules, short-lived tokens and rate limiting, as described above.

Third parties

In 0.3.1 and later the Extension communicates only with Google, as your browser already does when you use Gmail. Legacy versions also communicated with the AppOrigami backend for OAuth session management. We do not share your data with any other third party.

Quickfill is not affiliated with or endorsed by Google. Gmail is a trademark of Google LLC.

Changes to this policy

We may update this Privacy Policy from time to time. Any changes will be posted here with an updated date.

Contact

If you have questions about this Privacy Policy, contact us at contact@apporigami.com.

Last updated: September 7, 2026