AutoFill Code Privacy Policy

Effective September 7, 2026

Summary: AutoFill Code reads a limited set of recent Gmail messages to find active verification codes and match them to OTP fields. Gmail content and codes are processed inside the browser. Opera uses a stateless authentication service to renew Google access after browser and computer restarts.

What the extension handles

  • Email addresses shown in Gmail headers or near an OTP form.
  • A short-lived Google OAuth token, an encrypted Opera renewal session, and extracted verification codes.
  • A limited set of recent Gmail headers, subjects, snippets, and message text needed to find codes.
  • The current website origin and nearby OTP field details while matching is active.
  • Extension settings, scan progress, code expiry, and temporary per-tab state.

AutoFill Code does not intentionally collect passwords, payment or financial information, health information, precise location, keystrokes, or unrelated page content.

How the data is used

  1. Connect to Gmail with read-only access.
  2. Check a limited recent-email window for active verification codes.
  3. Match a code to the current website, OTP field, recipient, and verification attempt.
  4. Offer or fill the code according to the user's selected setting.
  5. Prevent expired or previously used codes from being filled automatically.

The data is not used for advertising, analytics, profiling, lending, or any unrelated purpose.

Storage and retention

Product data is stored in extension-local or session storage on the user's device. AutoFill Code also operates a stateless authentication service for Opera token renewal. That service has no user database.

  • OAuth access tokens are short-lived and removed when Gmail is disconnected.
  • The Opera renewal session is encrypted and stored locally. Its Google renewal credential is decrypted only in memory while access is renewed or revoked.
  • Cached codes and applied-code records are removed when the code expires.
  • Website and OTP-field state is temporary and ends with browser-session or tab cleanup.

Disconnecting Gmail requests revocation and clears the local token, encrypted session, active-code cache, and Gmail scan state.

Sharing and transmission

AutoFill Code communicates with Google OAuth and the Gmail API over HTTPS. Gmail messages are read directly by the extension from Google and never pass through the authentication service.

On Opera, the temporary Google authorisation code and credentials needed for renewal pass through a stateless Cloudflare Worker operated for AutoFill Code. The service receives no Gmail messages, website content, extracted codes, or browsing activity and has no user database, advertising, or analytics.

When filling is enabled, the matched code is written into the detected field. The extension does not submit the form or execute remote code.

Your choices

You can choose automatic filling, confirmation before filling, or disabled filling. You can disconnect Gmail, remove the extension, or clear its stored data at any time.

Google API Limited Use

AutoFill Code's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. It also complies with the Chrome Web Store User Data Policy.

Contact

For privacy questions, email tajdinetajdine1@gmail.com. Do not include tokens or verification codes.