Privacy policy
Last updated: 21 September 2026. Operator and contact: Sergio González, Portugal, sergio@givetoreach.com. The data controller for everything on this page that leaves your account is Sergio González; where European data protection law applies, the supervisory authority is Portugal's CNPD. This policy exists only in English. The Portuguese, Spanish, French and German pages of this site summarise it for convenience; where a summary differs from this text, this text is the one that applies.
Give to Reach is a Gmail add-on built and run by Sergio González. It is free, and nobody is paid for any part of it. Once an hour it looks at new mail in your inbox, sets aside mail from people you have never dealt with who are pitching you, replies once in that thread with a link to give $2 to GiveDirectly, puts the email back in your inbox when the gift lands, and keeps a log of what happened. This page says exactly what it reads, what leaves your Google account and where it goes, what is kept for how long, and what it never does. It is written for two audiences: people who install the add-on ("you"), and people who write to them and receive the automated reply ("senders", see For senders).
1. In one paragraph
The add-on runs on Google's servers, inside your own Google account, as you. No server of Sergio's ever holds a permission to your mailbox. Mail from people you know is never read beyond its headers. Mail from a first-time sender is read in full, and its text is sent straight from your account to an AI model, which answers what kind of email it is and, for a cold pitch, how well it was researched; the text is then discarded. That answer is what decides whether an email is set aside, so every first-time email is read. Only a cold pitch is set aside. Everything else a stranger sends you — a job application, an investor, a customer, the press, a personal note — stays in your inbox, unread, with a label saying what it looked like. What Sergio's relay receives about an email is a set of scores, a category, a one-line description of what was being sold, short excerpts with names, companies and links replaced by placeholders, which price and wording was shown, a one-way hash of the sender's address, and timestamps of what happened. Never the message itself. Nothing is ever deleted from your mailbox, and nothing about your mail is sold, used for advertising, or used to train AI models.
2. The permissions it asks for, one by one
These are the five Google permissions (OAuth scopes) the add-on declares. All of them are declared from the first version so that a later update never has to ask you for more. Each heading below is the permission's exact identifier, the one your Google account lists at myaccount.google.com/permissions. Where Google publishes its own description of a permission, it is quoted; the rest is what the add-on does with it and what it does not do.
https://www.googleapis.com/auth/gmail.addons.execute
Run as a Gmail add-on. Lets the add-on appear inside Gmail, on the web and in the Gmail app, and show its cards: a homepage card with this week's counts and the held list, a card next to an open message with that message's verdict, and a settings card. This permission carries no data by itself.
https://www.googleapis.com/auth/gmail.addons.current.message.metadata
See the open message's metadata while the add-on is running.
Google calls it: View your email message metadata when the add-on is running.
When you open an email with the add-on's panel open, this lets the card know which message you are looking at (its id, sender and subject) so it can show the right verdict from the add-on's own record. Access is temporary and limited to the message you opened.
https://www.googleapis.com/auth/gmail.modify
Read, label, archive, restore and send in your mailbox.
Google calls it: Read, compose, and send emails from your Gmail account. This scope does not allow immediate, permanent deletion of threads and messages, bypassing the trash.
This is the working permission for the hourly job, and it is the one Google classes as restricted. The add-on uses it to: list mail that arrived in your inbox since its last pass and read the headers of each message (sender, recipients, subject, date, message id, authentication results, mailing-list and auto-reply headers, Gmail's category); read the text of a message from a first-time sender, to have it scored and to recognise a sender who has come back under a new address; create its own labels and apply them; move a held thread out of the inbox and back in, star it and mark it unread; send one reply in your name inside the sender's thread; read your own email address and, among your settings, only your send-as aliases, so replies come from the right one; and notice when you have replied in a thread whose sender gave. It never deletes anything, never touches the trash, reads only your send-as aliases among your settings and changes no setting, never reads your filters or contacts through this permission, and never sends anything except the one reply per gated thread and, when something needs your attention, a note to you.
https://www.googleapis.com/auth/script.external_request
Call outside services from your account. The add-on uses it to send a first-time sender's email to be scored and to receive the scores back, and, from a later phase, to send those scores on to the Give to Reach relay. Section 4 says exactly what each one receives. It can reach only the few hosts named in its manifest, never the open internet, and it never sends anything at all about mail from people you know.
https://www.googleapis.com/auth/script.scriptapp
Create its own hourly timer. The add-on creates one time-driven trigger, running once an hour, and removes it when you switch the add-on off. Uninstalling revokes this permission, so the timer can no longer act. That timer is what makes it work without you opening Gmail.
3. What it reads
- Message headers of new mail in your inbox: sender, recipients, subject, date, message id, authentication results (SPF, DKIM, DMARC), mailing-list and auto-reply headers, and Gmail's own category. Headers are enough to decide whether a sender is known to you and whether a message is a newsletter, a receipt, a bounce, a calendar invite or bulk mail, all of which are left alone.
- The text of mail from first-time senders only: someone the add-on has established you do not know. It is read to have the email classified and scored — which is how a cold pitch is told from a job application, an investor, a customer, the press or a personal note — and to recognise a repeat sender writing from a new domain. Mail from people you know is never read beyond its headers. Your own sent mail is searched only to answer "have I written to this address, or to anyone at this organisation, before": people you have written to first, anyone at an organisation you have written to, and anyone a known person introduces in a thread, are known senders and are left alone. The add-on does not read your contacts.
4. What leaves your account, and to whom
Everything else about your mail stays inside your Google account. These are the only three recipients, and exactly what each one receives.
An AI model, which reads every email from a first-time sender
The model is Anthropic's Claude, called through Anthropic's API; Anthropic is a United States company. If the provider ever changes, this line is updated and dated before the change ships, and the commitments quoted below are replaced by the new provider's own.
- Why it reads them: this is how a cold pitch is told from a job application, an investor, a customer or a personal note. The model's answer decides whether an email is set aside, so every email from a first-time sender is read, and there is no setting that leaves any of them unread. Mail from people you know never reaches it.
- What is sent: the text of the message, whole and never truncated, with your own name, company and email address replaced by placeholders before it leaves. The sender's text is sent as they wrote it. The add-on also sends a short profile you typed in settings (your role, company, stage and industry) so the model can judge whether the pitch fits you. Nothing is scored, held or answered until you have filled that profile in.
- What comes back: scores against a fixed nine-point rubric, a category from a fixed list, what they sell in one line, the sender's role and company size, how the email opened, and short excerpts of the opening line, the credibility claim and the ask with every real name, company and link replaced by a placeholder.
- The pitch is discarded by the add-on after scoring; only the returned fields are kept, in the add-on's own record, and a subset of them on the relay as described below. The excerpts never leave your account. They quote the sender's own sentences, and a sentence can name a third person — someone greeted or mentioned — whom neither the placeholdering of your details nor the placeholdering of the sender's can know about. They stay in your record, where the card shows them beside the original. The card shows the original next to the excerpts so you can see for yourself that the placeholders held.
- The request is made straight from your Google account to the provider's API using a key that belongs to the add-on, never to you, and it never passes through Sergio's relay. The provider is in the United States, so this is a transfer outside the EEA.
- Anthropic's own commitments for its API, quoted as they stand today: "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models" (Anthropic Privacy Center, "Is my data used for model training?"); its commercial terms state that "Anthropic may not train models on Customer Content from Services" (Anthropic Commercial Terms of Service); and "For Anthropic API users, we automatically delete inputs and outputs on our backend within 30 days of receipt or generation", with exceptions for legal obligations and investigations of abuse (Anthropic Privacy Center, "How long do you store my organization's data?", last updated 1 July 2026).
Every.org, the donation platform
- What Every.org receives, through the link the sender opens: a token unique to the one email being gated, and the sender's email address (pre-filled on the donation form so the receipt can reach them). The add-on itself makes no request to Every.org from your account. Nothing about the email's content and nothing about you beyond the fact that a gift with that token restores an email.
- What comes back: Every.org sends the add-on a notification that a gift with that token was completed, with the amount and the charity. Every.org, a registered US 501(c)(3) public charity, is the legal recipient of the gift and issues the donor's receipt; its handling of the donor's own details is governed by Every.org's privacy policy.
The Give to Reach relay, operated by Sergio González
The relay runs at give-to-reach-relay.sergigon.workers.dev on Cloudflare, in Western Europe. It will move to go.givetoreach.com later; this page will say so when it does.
- What is sent, for every email the model read, whether it was set aside or left in your inbox with a label: the rubric scores, the category, what they sell in one line, the sender's role and company size, the opening style, which price and wording variant was shown, a salted one-way hash of the sender's address, and events with timestamps (reply sent, payment page fetched, link clicked, gift made, thread restored, you replied, sender asked to stop, sender said they know you).
- What is never sent: the message, its subject, the sender's name or address in clear, your own address, your contacts, or anything at all about mail the model did not read, which is everything from people you know.
- What the relay knows about you: an anonymous participant id the add-on derives from its own private key, never from your address, the settings that shape which variants you are in, a daily heartbeat so a silent install is noticed, and the profile you type yourself on the relay's onboarding page (your name, role, company, its stage and industry, and a few public facts about you a sender could cite), which the add-on fetches back into your account so the scorer can judge fit. The profile is yours: edit it on the same page, or ask for it to be deleted. It holds no Google permission and cannot reach your mailbox.
- The relay also serves the payment page a sender lands on before Every.org, and records that page fetch with the visitor's browser type, the seconds since the reply was sent, and a hashed IP address, so that clicks by link-scanning security software can be told apart from a person.
- The add-on delivers this at the end of each hourly pass. If the relay cannot be reached, the delivery waits inside your account and is retried on the next pass; if it stays unreachable for days, the oldest waiting items are dropped rather than kept for good. The link in the reply goes straight to Every.org and never through the relay.
5. What it never does
- No human other than you reads your mail. Not Sergio, not anyone. No message body is stored by the add-on, by the relay, or by Sergio, anywhere.
- Nothing is deleted. Held mail is moved out of the inbox under a visible label in your own mailbox and listed on the add-on's card. A restore only ever touches a thread the add-on itself held.
- No advertising, no sale or rental of personal data, no data brokers, no credit or lending use, and no use of your mail or anyone's mail to train AI or machine-learning models, general or otherwise.
- No server reads your mail. The add-on runs on Google's servers as you; the relay holds no Google permission; Sergio never holds a token to your account.
- No permission beyond the five above, and none of them is used for anything this page does not describe. If that ever needs to change, you will be asked to consent again first.
- It never replies to mail older than two days, never replies to the same sender more than once, ever, or to the same thread more than once, and stops itself at 20 replies an hour and 60 a day.
6. Your controls
- Your profile is the switch. Nothing is read, scored, held or answered until you have filled in the four profile fields on the settings card. Until then the add-on does nothing to your mail.
- The held list. Every held email is on the add-on's card, one by one or in bulk, with four rulings: restore it, mark the sender known, never gate them, or mark them a liar (a sender who claimed to be a client to get past the gate; their address is blocked for good and their organisation's domain for a month).
- Scoring has no switch. The model's answer is what decides whether an email is set aside (section 4), so there is no setting that turns it off; removing the add-on is what stops it. A local-only setting keeps counts flowing to the relay without any scores or excerpts.
- Kill switch. One switch on the settings card stops all activity at once: no holding, no replies, no calls to any outside service.
- Uninstall. Uninstalling the add-on revokes every permission above. You can also revoke them at any time from your Google account at myaccount.google.com/permissions. Either way your mail simply arrives as normal, and anything still held stays under its label in your mailbox for you to restore by hand.
- Your numbers. The add-on keeps no ledger in your account beyond its operating memory. Your own figures (share of commercial outreach that reached your inbox, mix by category, trends, and how you compare with the pool) are on your page at go.givetoreach.com once the relay is running.
- Your relay data. Write to the contact address with your participant id (shown on the settings card) to have your scores and events deleted from the relay's ledger or excluded from future publication.
7. What is kept, where, and for how long
- In your Google account: the labels on held and restored threads, and the add-on's own bookkeeping (your settings, your profile, which messages it has already looked at, which senders it has replied to, as one-way hashes), held in Google's storage for the add-on inside your account and never on a server. No spreadsheet, no file. Uninstalling revokes access to all of it.
- At the AI provider: the message text, for at most the retention period in the provider's own policy quoted in section 4 (today, 30 days for API traffic, with the stated exceptions). The add-on keeps no copy.
- At Every.org: whatever a donation normally creates there, under Every.org's own policy.
- At the relay: scores, categories, excerpts, variant and hashed sender identifiers are kept, because they are the data the published results are built from; your profile is kept for as long as you take part and deleted when you ask. Hashed IP addresses from payment-page fetches are purged after 30 days. Sender addresses exist there only as a salted one-way hash. Message bodies are never stored there at all.
8. Published results
Aggregated statistics about the cold email received by participants will be published on a public results page. Four rules govern what appears there.
- Pooled aggregates only: counts, rates and distributions across all participants, never a line per participant unless that participant has agreed to an anonymous line of their own.
- No slice with fewer than about ten emails behind it; until a slice has enough, the page says "too early" instead of showing a number.
- Per-variant breakdowns (which price or wording did better) only after that test has closed.
- Excerpts only as a few hand-picked examples, genericized further by hand, never as a feed, and never tied to a date, a participant or a sender.
Your personal data is never sold, licensed or shared with anyone. Participants agree to this pooled publication when they install; the anonymous per-participant line is a separate, optional consent.
9. Google API Services User Data Policy and Limited Use
In plain words, that means: data obtained through the permissions above is used only to provide the add-on's own user-facing features described on this page; it is transferred to others only as listed in section 4 (the AI provider named there, Every.org, and the relay), for security purposes, or to comply with the law; it is never used or transferred for advertising of any kind, never sold to data brokers or information resellers, never used to determine credit-worthiness or for lending; no human reads it other than you, with the sole exceptions of your own explicit request for help and of data that has been aggregated and anonymized; and it is never used to develop, improve or train generalized artificial intelligence or machine-learning models.
10. For senders
This section is for someone who emailed a Give to Reach user and received the automated reply. It exists so that you are told, at the moment your data is first handled, who handles it and why.
- Who. The person you wrote to runs the add-on inside their own mailbox and is responsible for what happens to your email there. Sergio González (sergio@givetoreach.com) operates the add-on and the relay and is responsible for the relay's ledger and the published results.
- What is used, and why. Your email address: to reply to you in your own thread, to pre-fill the donation form so Every.org can send you a receipt, and, as a salted one-way hash rather than the address itself, to make sure the same person always sees the same offer and to count repeat senders. Your message: sent from the recipient's account to the AI provider named in section 4, read there to decide what kind of email it is and, if it is an unsolicited pitch, to score it against a rubric, and then discarded; the recipient keeps the scores and short placeholdered excerpts in their own log (and, once the relay described in section 4 is running, the relay keeps them with your address hashed). Your message itself is not kept by the add-on, the relay or Sergio, and no human other than the person you wrote to reads it.
- The link. The reply carries one link, unique to your one email, to Every.org. Opening it is not recorded by the add-on; giving records that a gift with that token was completed. The gift goes to GiveDirectly through Every.org, a US 501(c)(3) public charity, which sends you the receipt; neither the recipient nor Sergio receives any money.
- Stopping. Each mailbox sends you this note at most once, ever, whether or not you give, so there is nothing to unsubscribe from. If you reply STOP it is honoured all the same. A stop link, an "I know you" link and the recording of link opens exist only when the payment page on the relay is in use, which is not the case in the current version; this section will say so when that changes.
- Your rights. Write to the contact address with the token from your link, or with your email address, to ask what is held about that email outside the recipient's own mailbox, to have it deleted, or to object to its use. Where European data protection law applies, the basis for this handling is the recipient's legitimate interest in managing unsolicited mail and Sergio's in running the service and publishing its results, and you have the rights of access, erasure and objection described above.
11. The waitlist
The form on the home page collects your email address, your LinkedIn profile, how much unsolicited email you get, why you want this, and the language of the page you used. No name, no account, no payment details, no cookies, no analytics.
Sergio González uses it to decide who gets a place and to tell you when one is ready, and for nothing else. It is stored on Cloudflare in Western Europe, is never sold or shared, and a salted one-way hash of your IP address is kept for one day to stop repeat submissions; it is not kept on your entry.
Your entry is deleted when you take a place, when you ask, or when the waitlist closes. Write to the contact address to see it, correct it or remove it; removal is immediate and needs no reason. The basis is your consent, given by submitting the form, and you can withdraw it at any time.
12. Changes to this policy
If the way the add-on uses Google user data changes, this page will be updated first and you will be asked to consent to the change inside the add-on before any data is used in the new way. The date at the top is the date of the current version.
Sergio González, sergio@givetoreach.com.
Back to Give to Reach · Terms
Back to Give to Reach · Terms