Privacy Policy

Last updated 22 August 2026

The short version. The Dandelion browser extension has no server. Your API key and your drafts never reach us, because there is nothing of ours for them to reach. Page content goes directly from your browser to the AI provider you chose, using your own key. We run no analytics and no tracking of any kind.

This site's waitlist form is the one place we collect anything, and it collects one thing: an email address you typed in.

1. The browser extension

What is stored, and where

Everything Dandelion stores is stored in your own browser. Two different places, on purpose:

WhereWhatLeaves your device?
chrome.storage.local Your AI provider API key. Your Google OAuth client ID and spreadsheet ID, if you connected Google. Your outreach history, if you have not connected a Google Sheet. Your Gmail signature. No. This is device-only and is deliberately excluded from sync.
chrome.storage.sync Non-sensitive settings: what you are selling, your name, tone, CC address, reference links, saved email templates, send mode. Yes, through your own Chrome profile, so a second machine signed into the same Chrome account picks them up. This is Google's sync, not ours; we never see it.
chrome.storage.session A short-lived Google access token, only if you connected Google. No. It is discarded when Chrome restarts.

What is sent, and to whom

When you ask Dandelion to draft an email, it reads the page you are on: its visible text, any contact addresses published on it, and the About or Contact pages that page links to on the same website. That text is sent, together with the context you configured, to the AI provider you chose, authenticated with your own API key:

Only the one you configured is contacted. Your relationship for that data is with that provider, under their terms and privacy policy, on your own account. We are not a party to it and receive no copy.

If you connect Google

This is optional and Dandelion works fully without it. If you do connect it, you create an OAuth client in your own Google Cloud project and paste its ID into settings. Dandelion ships no shared Google credential, so the access it obtains is scoped entirely to your own project and your own account. With it, Dandelion can:

You can revoke that access at any time in your Google account's security settings.

What the extension does not do

2. This website

If you submit the waitlist form, we store the email address you entered, together with the date and time, so we can send you an invite. That is the only personal data this site collects. It may be passed to an email-delivery service for that purpose and nothing else.

The site sets no advertising or tracking cookies, embeds no third-party analytics, and loads no fonts, scripts, or images from other companies' servers. Our hosting provider keeps standard server logs, which include IP addresses, for security and abuse prevention.

Ask us to delete your address at any time using the contact below and we will, without asking why.

3. Children

Dandelion is a business tool and is not directed at children under 13, and we do not knowingly collect data from them.

4. Your rights

Because the extension keeps your data on your own device, you control it directly: clear it in the extension's settings, or remove the extension to delete all of it. For the waitlist address, write to us and we will delete it. Depending on where you live you may have additional rights to access, correct, or export personal data; contact us and we will honour them.

5. Changes

If this policy changes materially, the date at the top changes and the current version is always the one published here.

6. Contact

jrquintbiz@gmail.com

Dandelion is operated by JR Quint.