Privacy Policy
Effective date: August 13, 2026
Operator: Blink Development & Consulting, LLC (“we”, “us”)
Product: Enchilada Chrome extension and heyenchilada.com
Contact: support@heyenchilada.com
Summary
Enchilada helps you see relationship context inside Gmail. Gmail, Calendar, and Contacts data is processed on-device: it is fetched live from Google’s APIs to your Chrome extension and is never stored on our servers. We do not sell Google user data and do not use it for advertising. A small backend (Neon) stores only account identifiers, billing/plan status, and notes you type.
Information we process
From Google (with your OAuth consent)
Read-only access to Gmail, Google Calendar, and Google Contacts as needed to show contact cards, conversations, meetings, attachments, and links. This data is fetched live from Google’s APIs and processed on-device in the Enchilada Chrome extension. It is cached locally in Chrome storage on your device for performance (default window on the order of tens of minutes) and is never stored on our servers.
What we store on Neon
Our license and notes database (Neon Postgres) stores only:
- Your Google account identifier (
sub) and email - Stripe / plan / trial status and related billing identifiers
- Notes you type, plus the contact email those notes are attached to
We do not store Gmail message bodies, Calendar events, or Contacts records on Neon or any other server we operate.
Google access tokens
When the extension talks to our license or notes API, it sends your Google access token in the request so we can verify who you are. That token is used only momentarily server-side to verify identity via Google’s tokeninfo endpoint. The access token is not saved in the database.
Website
If you visit heyenchilada.com, standard host logs and privacy-friendly analytics (Vercel Analytics) may apply. Contact form or email contents you send to support, and waitlist emails you submit, are processed to respond to you.
Chrome Web Store / Google
Google may process install and account data under their policies when you install or authorize the app.
Data protection
We protect sensitive Google user data (Gmail, Calendar, and Contacts) and other personal data with the following mechanisms:
Sensitive Google user data (Gmail, Calendar, Contacts)
- Encryption in transit: All requests to Google APIs and to our license/notes API use HTTPS / TLS.
- On-device processing: Message, calendar, and contact content is fetched live from Google’s APIs into the Enchilada Chrome extension and is processed on your device to populate the sidebar. This sensitive Google user data is never written to our servers, Neon, Stripe, or any other backend we operate.
- Local cache controls: A short-lived performance cache may be stored only in Chrome’s extension storage on your device (on the order of tens of minutes). That cache stays in your browser profile, is not synced to our servers, and is cleared when it expires, when you clear that profile’s extension data, or when you uninstall Enchilada.
- Access control: Google access tokens are obtained through Chrome Identity / OAuth and are used only to call Google APIs for features you use and to verify identity with our API. Tokens are not persisted in our database. Token lifetime and revocation are controlled by Google Account permissions and by uninstalling the extension.
- Least privilege: We request only read-only scopes (
gmail.readonly,calendar.readonly,contacts.readonly). We do not request send, modify, or delete permissions.
Account, billing, and Notes data we store
- Encryption in transit: API and database connections use TLS.
- Encryption at rest: Account identifiers (Google
sub/ email), Stripe/plan/trial status, and user-typed Notes stored in Neon Postgres are encrypted at rest using AES-256 at the Neon storage layer. - Access control: Backend access is limited to our operators and hosting providers under contract. Authenticated API requests require a valid Google access token verified via Google’s
tokeninfoendpoint; that token is used only momentarily and is not saved. - No advertising SDKs: We do not run advertising SDKs in the extension or on the product API.
How we use information
- Provide Enchilada features to you
- Enforce trial and subscription status
- Sync and display Notes you create
- Respond to support and waitlist requests
- Operate and improve the marketing site using aggregated traffic metrics
Google API Services User Data Policy
Enchilada’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide or improve user-facing features. We do not sell Google user data, use it for advertising, or use it for credit decisions or unrelated profiling.
What we do not do
- Sell Google user data, including Gmail, Calendar, or Contacts content
- Use restricted Google user data for advertising
- Run advertising SDKs in the extension or product API
- Store Gmail, Calendar, or Contacts data on our servers
Sharing
Third parties involved are limited to Stripe (payments), Vercel and Neon (hosting), and legal disclosure if required by law. We do not sell personal information and do not share Google user data with advertisers.
- Stripe - payment processing when you subscribe
- Vercel - website and license API hosting
- Neon - database hosting for account, billing, and notes records
- Legal - if required by law
Retention
- Gmail, Calendar, and Contacts data: not stored on our servers. A short local cache may exist only on your device and is cleared when it expires, when you clear that Chrome profile’s extension data, or when you uninstall.
- License / billing records: kept while your account may need entitlement or tax/audit history, then deleted or anonymized when no longer needed.
- Notes: retained until you delete them in-product or request account/data deletion.
- Support and waitlist email: retained as needed to resolve requests or notify you about products you opted into.
Your choices & deletion
You can revoke Enchilada’s access to your Google account at any time via Google Account permissions, or by uninstalling the extension.
- Revoke access anytime in Google Account → Security → Third-party access (or Google Account permissions)
- Uninstall the extension to revoke local use and remove the on-device cache on that browser profile
- Cancel subscription via Manage billing (Stripe customer portal)
- Request deletion of Notes and license/account records by emailing support@heyenchilada.com from the Google account email associated with Enchilada. Include “deletion request” in the subject. We will verify the request and delete or anonymize retained account data within 30 days, except where we must retain limited records for legal, security, or accounting reasons.
Children
Not directed at children under 13.
Governing law
Privacy practices for this product are administered under the laws of the State of Florida, USA, where applicable.
Changes
We may update this policy; the effective date will change. Material changes will be posted on this page.
Contact
Blink Development & Consulting, LLC
support@heyenchilada.com
Working policy for product launch - not formal legal advice. Have counsel review before relying on it for regulated use cases.