Security & Privacy
Google CASA Tier 2 Security Verified
Bulk-Save Gmail has passed Google's Cloud Application Security Assessment (CASA) Tier 2 — an independent, third-party security audit required for applications that access sensitive Google API scopes like Gmail and Google Drive.
This means our extension's architecture, data handling, and security controls have been reviewed and verified by Google-authorized security assessors. While competitors route your data through their servers, Bulk-Save Gmail works entirely client-side — and that's been verified by Google's own security program.
Your Data Never Leaves Your Computer
Bulk-Save Gmail processes everything locally in your browser. We cannot see, access, or store your emails or attachments.
How It Works
Local Processing
The extension runs entirely in your browser using JavaScript
Direct Downloads
Files download directly from Gmail to your device
No Calls to Our Servers
We do not send your data to our servers; only Google endpoints (Gmail/Drive) are contacted as required
Security Features
🔐 OAuth 2.0 Authentication
Uses Google's secure OAuth - we never see your password
🚫 Minimal Permissions
Requests read-only access to Gmail messages and attachments; cannot modify or delete emails
💾 Local Storage Only
Settings stored locally in your browser, not on our servers
🔍 Open Source Principles
Transparent about our data handling practices
What We DON'T Do
- ✗ Upload your attachments to any server
- ✗ Read or scan your email content
- ✗ Store your personal information
- ✗ Share data with third parties for marketing purposes
Compliance & Standards
- ✓ GDPR Compliant - No personal data collection
- ✓ CCPA Compliant - California privacy rights respected
- ✓ Chrome Web Store Policy Compliant
- ✓ Google OAuth Verification Passed
- ✓ Google CASA Tier 2 Certified — Independent third-party security audit passed
Verify Our Claims
You can verify our security claims yourself:
- Open Chrome DevTools while using the extension
- Check the Network tab - no calls to our servers; only Google (Gmail/Drive) domains may appear
- Review the extension's permissions in Chrome settings
- Monitor your network traffic with tools like Wireshark
Security Updates
We regularly update the extension to maintain security standards and patch any potential vulnerabilities. Chrome automatically updates extensions to ensure you're always protected.
Report Security Issues
Found a security concern? Please report it immediately:
security@savebulkgmailattachments.comWe take all security reports seriously and will respond within 24 hours.