SendlySendly
Legal

Browser extension privacy policy

What the Sendly: Email API Debugger, Delivery Inspector & Domain Health Check Chrome extension stores, sends and shares, and how to delete it

Effective date: 3 October 2026

This policy covers the Sendly: Email API Debugger, Delivery Inspector & Domain Health Check Chrome extension (the "extension"), published by Devino Solutions, which also operates Sendly. It describes every kind of user data the extension handles, why, where it is kept, how long, who it is shared with, and how you delete it. It applies only to the extension; the Sendly service itself is covered by Sendly's privacy policy.

The short version

  • The extension keeps two things on your own computer: your Sendly API key and a log of the last 50 API calls it made for you. The log contains the full response text of those calls, which includes real recipient email addresses and subject lines.
  • It sends your API key to exactly one server, https://api.sendly.now, only when you ask it to fetch or send something. That is the whole data flow.
  • The extension sends data nowhere except api.sendly.now, which is the Sendly service run by the same publisher, Devino Solutions. The extension itself contains no analytics, telemetry, crash reporting, advertising or tracking. The Sendly service handles the calls you trigger under Sendly's privacy policy, including a 30-day request log (section 2.1).
  • We never sell your data and never use it for anything except showing it to you in the extension. It reaches only the Sendly service and the processors named in section 2.1.

1. Data the extension handles

1.1 Your Sendly API key (authentication information)

  • What: the API key you paste in, which starts with sk_.
  • Why: it is the credential that proves to api.sendly.now that a request is yours. Without it the extension cannot read your project.
  • Where: chrome.storage.local in your browser profile, on your device. Never chrome.storage.sync, so it is not replicated through your Google account or to other devices.
  • Shown as: masked in the interface (first 11 and last 4 characters).
  • Never recorded: it is replaced with Bearer sk_live_***REDACTED*** before any request is written to the request log, and "Copy as curl" emits the shell variable $SENDLY_API_KEY instead of the key.
  • Retention: until you press "Forget key" or uninstall the extension.

1.2 The request log (personal communications and personally identifiable information)

  • What: the last 50 API calls the extension made, newest first. For each one it stores the request line, request headers (with the key redacted), request body, response status, response headers, the full response body exactly as received, the time, and the duration.
  • What that contains in practice: the responses are your own Sendly project data, so the log can include recipient email addresses, sender addresses, email subjects and delivery status, delivery-event payloads (bounces, complaints, opens, clicks and their error messages), event records tied to emails and contacts, including any custom event payload your own code recorded, and your sending domains with their DKIM, SPF and MAIL FROM DNS records. When you use "Send test", the log also holds the test message you wrote and the single recipient address (your own verified account address).
  • Why: this log is the extension's purpose. The request inspector shows you the raw request and response behind each call so you can debug your integration.
  • Where: chrome.storage.local, on your device only. Never chrome.storage.sync.
  • Retention: bounded at 50 entries; the oldest entry is discarded when a new one is added. It stays until you press "Clear" in the Inspector tab or uninstall the extension.

1.3 Data displayed but not stored

The Emails, Events and Domains tabs display what the API returns (the same kinds of data as section 1.2). The displayed lists are held in the popup's memory while it is open and are discarded when it closes. The only copy that persists is the request log in section 1.2, which holds the raw response of each call, not a separate database of your emails.

1.4 Interface preference

The light or dark theme you pick is saved by the popup in its own localStorage on your device. It contains no personal information.

1.5 What the extension does not handle

It does not read the pages you visit or your browsing history, and it requests no tabs, activeTab, scripting or webRequest permission and has no content script. It does not collect your name, location, health or financial information, passwords other than the Sendly API key you choose to enter, or any usage statistics.

2. Where data goes

One destination: https://api.sendly.now. This is the only entry in the extension's host_permissions, so the browser itself blocks any other destination. Requests are made only when you act (opening a tab, pressing Refresh or Re-check, or pressing Send test), and nothing is sent in the background.

RequestWhen
GET /api/emailsYou open or refresh the Emails tab
GET /api/emails/{id}You open one email's delivery timeline
GET /api/v1/eventsYou open or refresh the Events tab
GET /api/domainsYou open or refresh the Domains tab
GET /api/domains/{id}/verifyYou press "Re-check" on a domain
POST /api/v1/emails/testYou press "Send test" (a sandbox send only)

Each request carries your API key as a bearer token. The response comes back to your browser and is stored as described in section 1. api.sendly.now is operated by Devino Solutions, so the key and these requests are received by the Sendly service, which processes them under Sendly's privacy policy.

2.1 What the Sendly service does with these calls

  • Request log: for every API call it records the HTTP method, the route, the response status, the duration, your project, user and API key identifiers, how the call was authenticated, a request identifier, your IP address, your browser's user agent, any error code and message, and the request and response sizes in bytes. It does not record request or response bodies in this log. These rows are deleted automatically after 30 days.
  • Send test: the message is queued as an ordinary email in your Sendly project (kept as your other project emails are, while your account is active) and delivered to your own verified address through Amazon Web Services (SES). For some accounts the subject and body are first checked by an automated content-review classifier that runs through OpenRouter, which routes the request to an underlying AI model provider. The result is used only to block phishing. Reading the Emails, Events and Domains tabs is not scanned.
  • Other processors: the Sendly service runs on Amazon Web Services and self-hosted Devino Solutions infrastructure. Sendly's privacy policy lists all of its subprocessors.

3. Use, sharing and sale

  • Use: all data is used only to provide the extension's single purpose: inspecting your own Sendly project's emails, events and domain health and showing the raw API calls behind them.
  • No sale, no sharing: we do not sell or rent this data, and the extension discloses it to no one except the Sendly service at api.sendly.now and the processors named in section 2.1. The extension has no server of its own; the only data the publisher holds is what the Sendly service already holds for your project.
  • No advertising or profiling: it is not used for ads, for determining creditworthiness or for lending, and not transferred for any purpose unrelated to the single purpose.
  • Local data stays local: the extension never uploads its stored copy of your key or request log to the publisher, and no one at the publisher can read that copy, because it exists only in your browser profile. What reaches the Sendly service is handled under Sendly's privacy policy.

4. Limited Use

The use of information received from Chrome Web Store user data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. In particular, the extension only uses the data to provide its user-facing single purpose, does not transfer it except as needed for that purpose (the calls to api.sendly.now that you trigger), does not use or transfer it for advertising, does not use it to determine creditworthiness or for lending, and does not allow humans to read the data it stores, which leaves your device only in the API calls you trigger.

5. Security

The extension executes no remote code (its content security policy pins script-src 'self'), talks only over HTTPS, and redacts the API key at capture time rather than at display time. Data in chrome.storage.local is readable by anyone with access to your browser profile on your device, so use a device and profile you trust, and delete the API key in the Sendly dashboard if a device is lost. Data held by the Sendly service is protected as described in Sendly's privacy policy (encryption in transit and at rest, and access controls).

6. Your choices and deleting your data

  • Forget key removes the API key.
  • Clear in the Inspector tab removes the request log.
  • Uninstalling the extension removes everything it stored, including the theme preference.
  • Revoke the key in the Sendly dashboard to make any copy of it useless.

Data held by Sendly. The controls above remove what the extension stores on your device. To delete data the Sendly service holds (your project's emails and events, and the request logs in section 2.1), email support@sendly.now from your Sendly account address and we will delete it within 30 days, except what the law requires us to keep. Request logs are also deleted automatically after 30 days.

7. Children

The extension is a developer tool and is not directed at children under 13.

8. Changes to this policy

If the extension ever handles data differently, this policy will be updated before the new version ships, and the effective date above will change. Material changes will be noted in the extension's store listing.

9. Contact

Questions or requests: support@sendly.now. Sendly is operated by Devino Solutions, Halifax, Nova Scotia, Canada.

Verifying any of this

The extension is part of the Sendly codebase. The permissions it requests are listed with a justification for each in apps/extension/wxt.config.ts, the key and log storage is in src/lib/credentials.ts and src/lib/requestLog.ts, and a continuous integration check (scripts/ci/check-extension-manifest.mjs) fails the build if the packaged extension ever requests a permission, a host or a content script beyond the ones described here.

On this page