Blasts & Deals — Privacy Policy
Screen Alerts + Local Savings · Chrome & Edge Extension · v12.0.18
1. What This Extension Does
Blasts & Deals is a lightweight browser extension that delivers two things directly to your screen:
- Screen Blasts — Rich, visual alerts from senders you have explicitly opted in to receive (delivery notifications, appointment reminders, account updates, and other announcements).
- Savings Sites Deals (Blasts & Deals edition) — Local deals, coupons, and savings from businesses near you, browsable on your own schedule.
Consent is the core of the product. You decide who may send you Blasts — nobody can reach you without your explicit opt-in. This extension does NOT perform any B2B prospecting, lead generation, data scraping, or contact enrichment. It delivers opt-in screen alerts and local deals — not a sales-intelligence tool.
2. Data We Collect
We do not collect, store, or transmit your browsing data for advertising or lead generation. The extension does not scrape the websites you visit, does not inject scripts into LinkedIn or Gmail, and does not monitor your browsing for prospecting.
To display a Blast on whatever page you happen to be viewing, the extension shows a small on-screen alert surface. That surface only renders the Blasts sent to you — it does not read, collect, or transmit the content of the pages you visit. Optional CRM page helpers (Salesforce/HubSpot) only add a "log this Blast" action on your own CRM record pages when you choose; they do not read or export your CRM's contact data.
3. What Runs Automatically
- Inbox polling — The extension periodically checks for new Screen Blasts from senders you have approved. This communicates only with the Blasts delivery servers.
- Badge notifications — When new alerts arrive, a badge count appears on the extension icon. No popup ads or intrusive notifications.
- FIND ME relay — If you enable this optional feature, copies of your Screen Blasts can be forwarded to your email, phone (SMS), or webhook. Off by default. You control which destinations are active.
4. What Runs Only When You Act
- Opening the side panel — Shows your Blasts inbox or Savings Sites Deals. No data is collected from the page you are viewing.
- Browsing deals — Loads available local deals. Your ZIP code (city/zip level) is used to pick the local directory and sort nearby businesses. No precise GPS tracking.
- SNAP alerts — If you turn SNAP on (per category, subcategory, or business), the extension stores those choices on your device and syncs them to Savings Sites servers so matching local businesses can send you deal alerts. You can turn SNAP off at any time.
- Deals sign-in — Claiming deals, saving SNAP choices, or using Free $5 may sign you in with your existing Blasts account, or with an email code. A short-lived sign-in token (about 30 days) stays on this device only.
- Sending a Blast — Message content is transmitted through the Blasts delivery network only to recipients who have opted in to receive messages from you.
- Managing subscriptions — Block senders, unsubscribe, or set quiet hours at any time.
- Connecting to M365 Cockpit (optional, office users) — If you also run our M365 Cockpit desktop add-in on the same PC, the extension can check whether Cockpit is running by calling
http://localhost on your own computer, and can connect to it with one click after you approve a 6-letter code shown inside Cockpit. The connection token is stored encrypted on your device. Nothing about this leaves your PC, and the extension works without Cockpit.
Forwarding Blasts into your own Gmail — a double layer of opt-in. Auto-forwarding is entirely under the recipient's control, through two separate, explicit opt-ins:
- Opt-in #1 — who may send to you: You first decide which senders are allowed to send you Blasts at all, by accepting a pairing code. Nobody can Blast you without this approval.
- Opt-in #2 — per-sender forwarding: Separately, and individually for each approved sender, you choose whether that sender's Blasts should also be copied into your own Gmail inbox.
Only when you turn this on for a specific sender does the extension use the Gmail API — with your Google OAuth consent — to place those Blasts into your mailbox. It never reads your existing email, never sends email on your behalf to anyone else, and you can switch forwarding off for any sender at any time. Forwarding is off by default.
5. Data Storage
- Account credentials — By default stored only in
chrome.storage.local on your device (encrypted at rest; not synced to any cloud). Optional cloud sync (off by default): if you turn on "Sync sending accounts to secure cloud for mobile portal access" in the extension, the sending credentials for your bulk Email and Text Blasts — OAuth refresh tokens, provider/CPaaS API keys, and any bring-your-own OAuth client ID/secret — are transmitted over TLS and re-encrypted at rest on our servers using AES-256-GCM envelope encryption. They are decrypted only in memory during an active campaign send, are never exposed through any read interface, and are used solely to send your own campaigns from the online portal. You can erase the cloud copy at any time by turning the toggle off.
- Preferences — UI/notification settings in
chrome.storage.sync. Display preferences only — no sensitive data.
- Cached Blasts — Recently received alerts cached locally for offline viewing; pruned over time.
- Keys you provide — Any optional API keys (e.g., your own AI or CRM keys) are stored locally and encrypted, and are never shared with us or third parties.
- Hard-bounce suppression list — When Email Blasts detects a hard bounce (a permanent delivery failure, such as an address that no longer exists), the bounced email address and the bounce reason are automatically reported to our servers to maintain a shared suppression list, so undeliverable addresses are removed from future campaigns and data downloads. No message content, no recipient identity beyond the dead address itself, and no information identifying you as the sender are transmitted.
6. What This Extension Does NOT Do
- ❌ Does NOT scrape websites or collect browsing data for lead generation
- ❌ Does NOT inject scripts into LinkedIn, Gmail, or arbitrary sites for data harvesting
- ❌ Does NOT perform B2B lead generation or prospecting
- ❌ Does NOT enrich, harvest, or buy contact data via Apollo, Hunter, ZoomInfo, or similar prospecting APIs
- ❌ Does NOT read your email, messages, or form inputs
- ❌ Does NOT sell your data to anyone
7. Third-Party Services
The extension contacts the Blasts service for its core function. The following are optional and are only contacted when you enable a feature or connect an account with your own credentials:
- Blasts delivery network — Sending and receiving Screen Blasts (operated by Tips Marketing Services, Corp).
- Savings Sites servers — Loading local deals and coupons; recording deal claims, Free $5 credits, and referral rewards when you are signed in; and (only if you turn SNAP on) storing your SNAP alert preferences so businesses can reach you. Sign-in uses a token kept on your device.
- Your own email provider — Google Workspace / Gmail and Microsoft 365, via OAuth, so you can send Blasts from your mailbox and (if you enable per-sender forwarding) place your opted-in Blasts into your own inbox.
- Your own CRM — Salesforce, HubSpot, Pipedrive, and others — to log Blast engagement when you connect one, using credentials you provide.
- OpenAI (optional) — Help composing a Blast, only if you add your own API key.
- DeepL (optional) — Translating a Blast, only if you add your own API key.
- DNS-over-HTTPS (Google / Cloudflare) — Verifying a recipient's email domain is a genuine Google/Microsoft workspace during pairing.
- Internet Archive (optional) — Saving a public snapshot of a Blast you sent, for your records.
- Twilio (optional, via Twilio Connect) — SMS/voice relay, billed to your own Twilio account.
- Stripe — Payment processing for licensing and credits.
None of these are advertising or analytics networks. We use no third-party trackers.
8. Permissions Explained
sidePanel — Display the Blasts inbox, composer, and Deals browser in the browser side panel.
storage, unlimitedStorage — Save your preferences, approved-sender list, cached Blasts, and any keys you provide (encrypted); unlimited supports long Blast history offline.
alarms — Periodic inbox polling and scheduled delivery.
notifications — Desktop alerts when Blasts arrive (if enabled).
activeTab — Used only when you take an action on the current tab (e.g., capture a selection to send as a Blast).
tabs — Open/focus the secure pairing ("connect") page and the side panel.
scripting — Render the on-screen Blast alert surface and the optional CRM "log this Blast" helper.
identity — Google/Microsoft sign-in (OAuth) so you can send from — and forward to — your own mailbox. Gmail features may request gmail.insert (inbox forwarding) and gmail.settings.basic (safe-list filter); see Section 9.
contextMenus — Right-click "Send as Blast".
nativeMessaging — Optional license check (reads a stable machine ID) only if you install our desktop helper. The extension works without it.
http://localhost/* (optional) — Requested only at the moment you click Connect to M365 Cockpit, so the extension can talk to the Cockpit add-in running on your own PC. Never requested at install; the extension works without it.
offscreen — Runs a local analytics database of your own send history, entirely on your device.
Network/API access is limited to the specific services listed in Section 7. The optional "all sites" permission is not requested at install — it is requested only at the moment you add a custom delivery webhook, on a per-site basis.
9. Google API Services — Restricted Scope Disclosure & Limited Use
When you connect a Google account, and only for the optional features you explicitly enable, the extension may request these Gmail scopes:
https://www.googleapis.com/auth/gmail.insert — used solely to place the Screen Blasts from senders you approved into your own Gmail inbox (per-sender forwarding; off by default). It is never used to read, modify, send, or delete any of your other email.
https://www.googleapis.com/auth/gmail.settings.basic — used solely to create, at your explicit request, a single Gmail filter that keeps a chosen sender's mail out of Spam (a "never send to Spam" / safe-list filter). It is not used to change any other Gmail setting.
Blasts & Deals' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Google user data is used only to provide or improve these user-facing features.
- We do not sell Google user data, and do not use or transfer it for advertising, profiling, or creditworthiness.
- We do not transfer Google user data to third parties except as needed to provide the feature you enabled, to comply with law, or as part of a merger/acquisition with notice.
- We do not allow humans to read your Google user data, except: with your explicit consent (e.g., support you request), where required for security or to comply with applicable law, or where the data has been aggregated and anonymized.
This extension's use of information received from Chrome APIs also adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.
10. No Tracking
This extension contains no analytics, no telemetry, no advertising, and no tracking pixels. We do not collect usage data. There are no calls to Google Analytics, Mixpanel, Segment, or any other analytics service from extension code.
10a. Blasts Deals Mobile App (Android & iOS)
The Blasts Deals mobile app is the phone companion to this product. Everything above applies equally to the app; the following covers what is specific to mobile:
- Account email — Collected to create and operate your Blasts inbox (the same consent-based system described above). Required for the app to function.
- Messages (Screen Blasts) — End-to-end encrypted on your device before upload. We store only ciphertext and cannot read your messages. A local, readable copy of blasts you send stays on your own phone (your Sent box).
- Location (optional, two ways) — The app uses location only to show you what is nearby, and only to our own servers. Deals: if you grant the location permission, your device position — rounded to roughly a one-kilometer area before it leaves your phone — is used to sort nearby deals by distance. Fun (local events): you type a ZIP code, and that ZIP is sent to our servers to look up events in that area; it is a ZIP you chose to enter, not a reading from your device. In both cases location is used at the moment you browse; it is not tracked in the background, not stored as a location history, never used for advertising, and never sold or shared with third parties. Deny the permission and the app still works — Deals simply won't sort by distance.
- Sign-in approvals (LoginBlasts) — The Approvals tab lets connected companies ask you to approve a sign-in on your phone. When a request arrives and when you approve or decline it, we record the decision with the request's network address and device details so you can see who is really using your seats. Approving shares only a pseudonymous, per-company identifier with that company — never your email address.
- Push notifications (optional) — If you allow notifications, the app registers a push token (Google Firebase Cloud Messaging on Android; Apple Push Notification service on iOS) with our servers so we can notify you when a new Blast arrives. The notification contains only the sender's email address — never message content, which stays end-to-end encrypted until you open the app. Deleting your account or declining the permission removes/avoids the token.
- On-device security — Your session, encryption keys, invite codes, and saved contacts are stored in hardware-backed secure storage (Android Keystore / iOS Keychain) on your phone.
- Account deletion — Available in-app (Settings tab → "Delete my account permanently") or on the web at blasts.app/delete-account.html. Deletion permanently erases your account, inbox, invite codes, connect ID, and push tokens from our servers.
- No ads, no analytics SDKs — The mobile app contains no advertising or analytics frameworks.
11. Contact
For privacy questions, contact support@blasts.app
Website: blasts.app
Publisher: Tips Marketing Services, Corp
Last updated: September 12, 2026 · one-click M365 Cockpit connect