Caselist-Site

Privacy Policy for Caselist Mailer

Last updated: September 19, 2026

Caselist Mailer (listed as “Caselist” on the Chrome Web Store) is a Chrome extension that automates disclosure on openCaselist, the site where competitive debaters publish the rounds they have debated and the documents they read in them.

This policy explains what the extension accesses, why, and where that information goes.

Summary

Caselist has no backend server. There is no account to create, no analytics, and no telemetry. Everything the extension reads is processed inside the user’s own browser. The only time information leaves the user’s device is when the user deliberately publishes a round or a document to openCaselist — the destination they chose, using their own openCaselist account.

What the extension accesses

Gmail (read-only). With the user’s explicit Google sign-in consent, Caselist requests the gmail.readonly scope and reads the user’s own mailbox to locate two things:

The only Google scope requested is https://www.googleapis.com/auth/gmail.readonly; no other Google data is accessed.

The extension only reads mail. It cannot send, delete, or modify messages, and the read-only scope makes that technically enforced rather than a promise. Mail is searched for the specific messages described above; the extension does not index, copy, or retain the user’s mailbox.

When the user adds a partner’s address in setup, the extension also checks whether any mail from that address exists in the mailbox, to catch typing mistakes. This is a count only; no message content is read for it.

On a round’s email chain, the extension reads the From, To, and Cc headers of the messages on it to identify who was on the chain — for example, to suggest the judge’s name. On those chains, it does not read the body of any message other than the user’s own and their partner’s. The only other message bodies it reads are Tabroom pairing emails, as described above.

openCaselist. The extension reads caselist data — schools, teams, rounds, and cites, all of which are published publicly by debaters on openCaselist — and writes new rounds and documents when the user chooses to publish. It also asks openCaselist for the user’s current Tabroom rounds, where openCaselist makes them available, to fill in round details.

Local storage. The extension uses chrome.storage.local to hold the following, and nothing else: the caselist, school, and team code chosen in setup; the partner email addresses the user entered; the mail look-back window; the user’s display and behaviour preferences, such as the Autoselect choice and the tournament numbering style; which half of the extension (mailer or searcher) was last open; the signed-in Gmail address, so it can tell the user apart from other people on a mail chain; a cached index of the schools and teams on the chosen caselist, so searching is fast and works offline; and a record of the rounds the user has published (the Gmail message id and attachment id of the file, and the caselist, school and team it went to, with no mail content, limited to the 200 most recent), so the panel can mark a document as published and never post it twice. All of this stays in the user’s browser.

What the extension does not do

Credentials

Caselist is designed so that it never holds a credential.

The Google OAuth token is issued by Chrome through chrome.identity and stays on the device; it is used only for requests to the Gmail API and is never transmitted anywhere else.

openCaselist authenticates with a session cookie scoped to its own origin. Rather than asking for a password or storing a session token, the extension relays its openCaselist requests through a content script in the user’s already signed-in openCaselist tab, so the browser attaches the cookie itself. The extension never reads or stores that token.

Google API Services User Data Policy

Caselist’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Data retention and deletion

The extension retains nothing on any server, because there is no server. Locally cached data can be cleared at any time by using the extension’s “Rebuild the index” option or by removing the extension from Chrome, which deletes its local storage.

Access to Gmail can be revoked at any time at myaccount.google.com/permissions, independently of whether the extension is installed.

Rounds and documents that the user has published to openCaselist are governed by openCaselist’s own policies and can be edited or removed through that site.

Children’s privacy

Caselist is used by high school and college debaters. It collects no information beyond what is described above, requires no account with the developer, and does not build user profiles.

Changes

If this policy changes, the updated version will be posted at this URL with a revised date above.

Contact

Questions about this policy can be sent to jinah0620@gmail.com.