Give to Reach

Privacy policy

Last updated: 21 September 2026. Operator and contact: Sergio González, Portugal, sergio@givetoreach.com. The data controller for everything on this page that leaves your account is Sergio González; where European data protection law applies, the supervisory authority is Portugal's CNPD. This policy exists only in English. The Portuguese, Spanish, French and German pages of this site summarise it for convenience; where a summary differs from this text, this text is the one that applies.

Give to Reach is a Gmail add-on built and run by Sergio González. It is free, and nobody is paid for any part of it. Once an hour it looks at new mail in your inbox, sets aside mail from people you have never dealt with who are pitching you, replies once in that thread with a link to give $2 to GiveDirectly, puts the email back in your inbox when the gift lands, and keeps a log of what happened. This page says exactly what it reads, what leaves your Google account and where it goes, what is kept for how long, and what it never does. It is written for two audiences: people who install the add-on ("you"), and people who write to them and receive the automated reply ("senders", see For senders).

Contents
  1. In one paragraph
  2. The permissions it asks for, one by one
  3. What it reads
  4. What leaves your account, and to whom
  5. What it never does
  6. Your controls
  7. What is kept, where, and for how long
  8. Published results
  9. Google API Services User Data Policy and Limited Use
  10. For senders
  11. The waitlist
  12. Changes to this policy
  13. Contact

1. In one paragraph

The add-on runs on Google's servers, inside your own Google account, as you. No server of Sergio's ever holds a permission to your mailbox. Mail from people you know is never read beyond its headers. Mail from a first-time sender is read in full, and its text is sent straight from your account to an AI model, which answers what kind of email it is and, for a cold pitch, how well it was researched; the text is then discarded. That answer is what decides whether an email is set aside, so every first-time email is read. Only a cold pitch is set aside. Everything else a stranger sends you — a job application, an investor, a customer, the press, a personal note — stays in your inbox, unread, with a label saying what it looked like. What Sergio's relay receives about an email is a set of scores, a category, a one-line description of what was being sold, short excerpts with names, companies and links replaced by placeholders, which price and wording was shown, a one-way hash of the sender's address, and timestamps of what happened. Never the message itself. Nothing is ever deleted from your mailbox, and nothing about your mail is sold, used for advertising, or used to train AI models.

2. The permissions it asks for, one by one

These are the five Google permissions (OAuth scopes) the add-on declares. All of them are declared from the first version so that a later update never has to ask you for more. Each heading below is the permission's exact identifier, the one your Google account lists at myaccount.google.com/permissions. Where Google publishes its own description of a permission, it is quoted; the rest is what the add-on does with it and what it does not do.

https://www.googleapis.com/auth/gmail.addons.execute
Run as a Gmail add-on. Lets the add-on appear inside Gmail, on the web and in the Gmail app, and show its cards: a homepage card with this week's counts and the held list, a card next to an open message with that message's verdict, and a settings card. This permission carries no data by itself.
https://www.googleapis.com/auth/gmail.addons.current.message.metadata
See the open message's metadata while the add-on is running.
Google calls it: View your email message metadata when the add-on is running.
When you open an email with the add-on's panel open, this lets the card know which message you are looking at (its id, sender and subject) so it can show the right verdict from the add-on's own record. Access is temporary and limited to the message you opened.
https://www.googleapis.com/auth/gmail.modify
Read, label, archive, restore and send in your mailbox.
Google calls it: Read, compose, and send emails from your Gmail account. This scope does not allow immediate, permanent deletion of threads and messages, bypassing the trash.
This is the working permission for the hourly job, and it is the one Google classes as restricted. The add-on uses it to: list mail that arrived in your inbox since its last pass and read the headers of each message (sender, recipients, subject, date, message id, authentication results, mailing-list and auto-reply headers, Gmail's category); read the text of a message from a first-time sender, to have it scored and to recognise a sender who has come back under a new address; create its own labels and apply them; move a held thread out of the inbox and back in, star it and mark it unread; send one reply in your name inside the sender's thread; read your own email address and, among your settings, only your send-as aliases, so replies come from the right one; and notice when you have replied in a thread whose sender gave. It never deletes anything, never touches the trash, reads only your send-as aliases among your settings and changes no setting, never reads your filters or contacts through this permission, and never sends anything except the one reply per gated thread and, when something needs your attention, a note to you.
https://www.googleapis.com/auth/script.external_request
Call outside services from your account. The add-on uses it to send a first-time sender's email to be scored and to receive the scores back, and, from a later phase, to send those scores on to the Give to Reach relay. Section 4 says exactly what each one receives. It can reach only the few hosts named in its manifest, never the open internet, and it never sends anything at all about mail from people you know.
https://www.googleapis.com/auth/script.scriptapp
Create its own hourly timer. The add-on creates one time-driven trigger, running once an hour, and removes it when you switch the add-on off. Uninstalling revokes this permission, so the timer can no longer act. That timer is what makes it work without you opening Gmail.

3. What it reads

4. What leaves your account, and to whom

Everything else about your mail stays inside your Google account. These are the only three recipients, and exactly what each one receives.

An AI model, which reads every email from a first-time sender

The model is Anthropic's Claude, called through Anthropic's API; Anthropic is a United States company. If the provider ever changes, this line is updated and dated before the change ships, and the commitments quoted below are replaced by the new provider's own.

Every.org, the donation platform

The Give to Reach relay, operated by Sergio González

The relay runs at give-to-reach-relay.sergigon.workers.dev on Cloudflare, in Western Europe. It will move to go.givetoreach.com later; this page will say so when it does.

5. What it never does

6. Your controls

7. What is kept, where, and for how long

8. Published results

Aggregated statistics about the cold email received by participants will be published on a public results page. Four rules govern what appears there.

Your personal data is never sold, licensed or shared with anyone. Participants agree to this pooled publication when they install; the anonymous per-participant line is a separate, optional consent.

9. Google API Services User Data Policy and Limited Use

Give to Reach's use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

In plain words, that means: data obtained through the permissions above is used only to provide the add-on's own user-facing features described on this page; it is transferred to others only as listed in section 4 (the AI provider named there, Every.org, and the relay), for security purposes, or to comply with the law; it is never used or transferred for advertising of any kind, never sold to data brokers or information resellers, never used to determine credit-worthiness or for lending; no human reads it other than you, with the sole exceptions of your own explicit request for help and of data that has been aggregated and anonymized; and it is never used to develop, improve or train generalized artificial intelligence or machine-learning models.

10. For senders

This section is for someone who emailed a Give to Reach user and received the automated reply. It exists so that you are told, at the moment your data is first handled, who handles it and why.

11. The waitlist

The form on the home page collects your email address, your LinkedIn profile, how much unsolicited email you get, why you want this, and the language of the page you used. No name, no account, no payment details, no cookies, no analytics.

Sergio González uses it to decide who gets a place and to tell you when one is ready, and for nothing else. It is stored on Cloudflare in Western Europe, is never sold or shared, and a salted one-way hash of your IP address is kept for one day to stop repeat submissions; it is not kept on your entry.

Your entry is deleted when you take a place, when you ask, or when the waitlist closes. Write to the contact address to see it, correct it or remove it; removal is immediate and needs no reason. The basis is your consent, given by submitting the form, and you can withdraw it at any time.

12. Changes to this policy

If the way the add-on uses Google user data changes, this page will be updated first and you will be asked to consent to the change inside the add-on before any data is used in the new way. The date at the top is the date of the current version.

13. Contact

Sergio González, sergio@givetoreach.com.

Back to Give to Reach · Terms

Back to Give to Reach · Terms