FpFontpost

Privacy policy

Last updated July 19, 2026.

Local use

Fontpost processes typography locally on supported webmail pages. It does not collect or transmit email bodies, subjects, browsing history, or analytics, and it does not use provider mail APIs. Sender and recipient addresses are inspected locally to apply Pro automatic-font rules. An address or domain is stored only when the user deliberately enters it as a rule; that rule is included in encrypted Pro settings sync and is not otherwise transmitted.

Stored on your device

Settings, presets, favorites, contact and workflow rules, offline-font selections, session information, and catalog metadata use Chrome extension storage. Font files you upload use extension-scoped IndexedDB. Google Fonts downloaded for offline use are kept in extension-scoped Cache Storage.

Network requests

Fontpost loads catalog metadata and selected font assets from Google Fonts. Free use does not contact the Fontpost service. When a user chooses Google Sign-In for Pro, Chrome requests only basic account identity and email scopes. Fontpost verifies that the Google token belongs to Fontpost, stores the stable Google account identifier and email, and then discards the Google credential. Fontpost also stores hashed session identifiers, subscription status, and billing-customer identifiers. Stripe processes payment details.

Automatic encrypted backup

For an active Pro account, Fontpost automatically syncs settings and uploaded fonts after changes and restores the latest successful copy after the same Google account signs in again. Content is encrypted in the browser with AES-GCM before upload. The service stores encrypted settings versions, encrypted font objects, size and time metadata, and their account association.

To restore after removal or loss of browser data, Fontpost separately stores the account's sync key encrypted with a server-held key. The key is returned only to an authenticated, active Pro session. Because the service can recover this protected key, this is encrypted cloud backup, not zero-knowledge or end-to-end encryption. The latest 20 settings versions are retained.

Limited use

Fontpost's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Fontpost does not use the Gmail API.

Control and contact

Users can disable Fontpost, delete local fonts and caches, export or reset settings, sign out, and manage subscriptions through Stripe's portal. Fontpost attempts to finish pending changes before sign-out. Removing the extension does not cancel a subscription or erase server records. For access or deletion requests, use the support contact on Fontpost's Chrome Web Store listing.