Browser extension privacy policy
What the Sendly: Email API Debugger, Delivery Inspector & Domain Health Check Chrome extension stores, sends and shares, and how to delete it
Effective date: 3 October 2026
This policy covers the Sendly: Email API Debugger, Delivery Inspector & Domain Health Check Chrome extension (the "extension"), published by Devino Solutions, which also operates Sendly. It describes every kind of user data the extension handles, why, where it is kept, how long, who it is shared with, and how you delete it. It applies only to the extension; the Sendly service itself is covered by Sendly's privacy policy.
The short version
- The extension keeps two things on your own computer: your Sendly API key and a log of the last 50 API calls it made for you. The log contains the full response text of those calls, which includes real recipient email addresses and subject lines.
- It sends your API key to exactly one server,
https://api.sendly.now, only when you ask it to fetch or send something. That is the whole data flow. - The extension sends data nowhere except
api.sendly.now, which is the Sendly service run by the same publisher, Devino Solutions. The extension itself contains no analytics, telemetry, crash reporting, advertising or tracking. The Sendly service handles the calls you trigger under Sendly's privacy policy, including a 30-day request log (section 2.1). - We never sell your data and never use it for anything except showing it to you in the extension. It reaches only the Sendly service and the processors named in section 2.1.
1. Data the extension handles
1.1 Your Sendly API key (authentication information)
- What: the API key you paste in, which starts with
sk_. - Why: it is the credential that proves to
api.sendly.nowthat a request is yours. Without it the extension cannot read your project. - Where:
chrome.storage.localin your browser profile, on your device. Neverchrome.storage.sync, so it is not replicated through your Google account or to other devices. - Shown as: masked in the interface (first 11 and last 4 characters).
- Never recorded: it is replaced with
Bearer sk_live_***REDACTED***before any request is written to the request log, and "Copy as curl" emits the shell variable$SENDLY_API_KEYinstead of the key. - Retention: until you press "Forget key" or uninstall the extension.
1.2 The request log (personal communications and personally identifiable information)
- What: the last 50 API calls the extension made, newest first. For each one it stores the request line, request headers (with the key redacted), request body, response status, response headers, the full response body exactly as received, the time, and the duration.
- What that contains in practice: the responses are your own Sendly project data, so the log can include recipient email addresses, sender addresses, email subjects and delivery status, delivery-event payloads (bounces, complaints, opens, clicks and their error messages), event records tied to emails and contacts, including any custom event payload your own code recorded, and your sending domains with their DKIM, SPF and MAIL FROM DNS records. When you use "Send test", the log also holds the test message you wrote and the single recipient address (your own verified account address).
- Why: this log is the extension's purpose. The request inspector shows you the raw request and response behind each call so you can debug your integration.
- Where:
chrome.storage.local, on your device only. Neverchrome.storage.sync. - Retention: bounded at 50 entries; the oldest entry is discarded when a new one is added. It stays until you press "Clear" in the Inspector tab or uninstall the extension.
1.3 Data displayed but not stored
The Emails, Events and Domains tabs display what the API returns (the same kinds of data as section 1.2). The displayed lists are held in the popup's memory while it is open and are discarded when it closes. The only copy that persists is the request log in section 1.2, which holds the raw response of each call, not a separate database of your emails.
1.4 Interface preference
The light or dark theme you pick is saved by the popup in its own localStorage on your
device. It contains no personal information.
1.5 What the extension does not handle
It does not read the pages you visit or your browsing history, and it requests no tabs,
activeTab, scripting or webRequest permission and has no content script. It does not
collect your name, location, health or financial information, passwords other than the Sendly
API key you choose to enter, or any usage statistics.
2. Where data goes
One destination: https://api.sendly.now. This is the only entry in the extension's
host_permissions, so the browser itself blocks any other destination. Requests are made only
when you act (opening a tab, pressing Refresh or Re-check, or pressing Send test), and nothing
is sent in the background.
| Request | When |
|---|---|
GET /api/emails | You open or refresh the Emails tab |
GET /api/emails/{id} | You open one email's delivery timeline |
GET /api/v1/events | You open or refresh the Events tab |
GET /api/domains | You open or refresh the Domains tab |
GET /api/domains/{id}/verify | You press "Re-check" on a domain |
POST /api/v1/emails/test | You press "Send test" (a sandbox send only) |
Each request carries your API key as a bearer token. The response comes back to your browser
and is stored as described in section 1. api.sendly.now is operated by Devino Solutions, so the
key and these requests are received by the Sendly service, which processes them under
Sendly's privacy policy.
2.1 What the Sendly service does with these calls
- Request log: for every API call it records the HTTP method, the route, the response status, the duration, your project, user and API key identifiers, how the call was authenticated, a request identifier, your IP address, your browser's user agent, any error code and message, and the request and response sizes in bytes. It does not record request or response bodies in this log. These rows are deleted automatically after 30 days.
- Send test: the message is queued as an ordinary email in your Sendly project (kept as your other project emails are, while your account is active) and delivered to your own verified address through Amazon Web Services (SES). For some accounts the subject and body are first checked by an automated content-review classifier that runs through OpenRouter, which routes the request to an underlying AI model provider. The result is used only to block phishing. Reading the Emails, Events and Domains tabs is not scanned.
- Other processors: the Sendly service runs on Amazon Web Services and self-hosted Devino Solutions infrastructure. Sendly's privacy policy lists all of its subprocessors.
3. Use, sharing and sale
- Use: all data is used only to provide the extension's single purpose: inspecting your own Sendly project's emails, events and domain health and showing the raw API calls behind them.
- No sale, no sharing: we do not sell or rent this data, and the extension discloses it to no one
except the Sendly service at
api.sendly.nowand the processors named in section 2.1. The extension has no server of its own; the only data the publisher holds is what the Sendly service already holds for your project. - No advertising or profiling: it is not used for ads, for determining creditworthiness or for lending, and not transferred for any purpose unrelated to the single purpose.
- Local data stays local: the extension never uploads its stored copy of your key or request log to the publisher, and no one at the publisher can read that copy, because it exists only in your browser profile. What reaches the Sendly service is handled under Sendly's privacy policy.
4. Limited Use
The use of information received from Chrome Web Store user data complies with the Chrome Web
Store User Data Policy, including its Limited Use requirements. In particular, the extension
only uses the data to provide its user-facing single purpose, does not transfer it except as
needed for that purpose (the calls to api.sendly.now that you trigger), does not use or
transfer it for advertising, does not use it to determine creditworthiness or for lending, and
does not allow humans to read the data it stores, which leaves your device only in the API
calls you trigger.
5. Security
The extension executes no remote code (its content security policy pins script-src 'self'),
talks only over HTTPS, and redacts the API key at capture time rather than at display time.
Data in chrome.storage.local is readable by anyone with access to your browser profile on
your device, so use a device and profile you trust, and delete the API key in the Sendly
dashboard if a device is lost. Data held by the Sendly service is protected as described in
Sendly's privacy policy (encryption in transit and at rest, and access controls).
6. Your choices and deleting your data
- Forget key removes the API key.
- Clear in the Inspector tab removes the request log.
- Uninstalling the extension removes everything it stored, including the theme preference.
- Revoke the key in the Sendly dashboard to make any copy of it useless.
Data held by Sendly. The controls above remove what the extension stores on your device. To delete data the Sendly service holds (your project's emails and events, and the request logs in section 2.1), email support@sendly.now from your Sendly account address and we will delete it within 30 days, except what the law requires us to keep. Request logs are also deleted automatically after 30 days.
7. Children
The extension is a developer tool and is not directed at children under 13.
8. Changes to this policy
If the extension ever handles data differently, this policy will be updated before the new version ships, and the effective date above will change. Material changes will be noted in the extension's store listing.
9. Contact
Questions or requests: support@sendly.now. Sendly is operated by Devino Solutions, Halifax, Nova Scotia, Canada.
Verifying any of this
The extension is part of the Sendly codebase. The permissions it requests are listed with a
justification for each in apps/extension/wxt.config.ts, the key and log storage is in
src/lib/credentials.ts and src/lib/requestLog.ts, and a continuous integration check
(scripts/ci/check-extension-manifest.mjs) fails the build if the packaged extension ever
requests a permission, a host or a content script beyond the ones described here.