GDictate

Privacy policy

7 October 2026

GDictate is a Chrome extension (store name: Gmail Dictation - GDictate) that types what you say into a Gmail draft. This policy says what the extension and its polish API handle, what they keep, and who else receives it. It is the privacy policy linked from the Chrome Web Store listing.

Personal communications

The words you dictate are the text of an email: personal communications. They are also text you created. The extension inserts that text into the Gmail compose box you are writing in. That draft stays in Gmail, on your Google account.

If you select text and click Polish or Structure, we transmit that selected text so a model can return an edit. We process it for that request. We do not store the email text. It is not written to our database, it is not kept in a log of message contents, and it is not included in abuse alerts.

What the extension handles on your computer

The extension runs only on https://mail.google.com. It does not run on other sites and it does not read your inbox. In the compose box it inserts recognized speech at the cursor, and it reads the selection only when you click Polish or Structure.

What is sent when you click Polish or Structure

Only after that click, the extension sends an HTTPS request to https://api.gdictate.com/v1/polish with:

Our server also sees the IP address of the request, because the connection comes from your network. Cloudflare hosts that API.

The server forwards the text to OpenRouter (https://openrouter.ai/privacy) so the configured language model can return an edit. At the date of this policy the model is Google Gemini, reached through OpenRouter. We may change the model. Changing it does not change what we store: we still do not keep the email text. OpenRouter’s privacy policy describes what they do with API inputs. We do not use your email text to train models.

Polish fixes punctuation and fillers such as um and uh and is meant to keep your words. Structure splits the selection into paragraphs and plain lists and is meant not to rewrite the wording. You still read the draft and you press Send in Gmail.

What we store on the server

We store metadata for rate limits and abuse control, not the message:

Abuse alerts go to the developer in Telegram. An alert contains the event type, a shortened install id, IP address, extension version, and counts. It does not contain the email text.

We do not sell this data. We do not use it for advertising, retargeting, or profiles for ads. We do not have accounts, and we do not ask for your email address.

Limited Use

GDictate’s use and transfer of user data comply with the Chrome Web Store User Data Policy, including the Limited Use requirements (https://developer.chrome.com/docs/webstore/program-policies/user-data-faq).

How long we keep it

Email text is held in memory only long enough to get the edit back, then dropped. We do not write it down.

The metadata rows above are kept so limits and bans still work. They are not linked to your Google account. We do not delete them on a fixed schedule. Uninstalling the extension deletes the install id from your browser and stops new requests. It does not delete the metadata row already on the server. That row still has no email text.

Security

The extension transmits the selected text only over HTTPS. The API transmits it to OpenRouter only over HTTPS.

Your choices

Children

GDictate is not directed at children under 13, and we do not knowingly collect their data.

Changes

If this policy changes, the date at the top of this page changes. The Chrome Web Store listing points at https://gdictate.com/privacy/.

Contact

Questions about this policy: use the support contact on the GDictate Chrome Web Store listing, https://chromewebstore.google.com/detail/hfgnhknjemdkilkeakcblplmecbnpfja.