Privacy policy
Last updated 19 August 2026
EmailTrackApp tells senders when their email was opened. This page explains exactly what we collect, from whom, and why. Two groups of people are involved and they are treated differently: users, who install the extension, and recipients, who receive a tracked email and never agreed to anything.
What we collect from users
| Data | Why |
|---|---|
| Email address and password hash | To create and secure your account |
| Subject line and recipient addresses of tracked emails | So your dashboard can show which email an open belongs to |
| Hashed IP addresses you connect from | To recognise and exclude your own opens of your own sent mail |
| Plan and billing status | Payment is processed by Stripe; we never see your card details |
What we never collect
- The body of your email. It never leaves your browser. The extension inserts a tracking pixel into the compose window locally.
- Your mailbox. We request no Gmail API access. We cannot read, search or send mail on your behalf.
- Your other browsing. The extension runs only on mail.google.com.
What we collect from recipients
When a recipient's mail client loads the tracking pixel, our server records:
- The time of the request
- The browser or mail-client identification string
- An irreversible hash of the IP address — never the address itself
- An approximate country and city derived from that address at the moment of the request
We do not build profiles of recipients. Events belong to the user who created them and are never combined across accounts. We do not sell or share this data.
How a recipient can refuse
Anyone can enter their address on our opt-out page. From that moment no EmailTrackApp user can add a read receipt to mail sent to that address, and existing tracking records for it are deleted. No account is required and it does not expire.
Retention
Detailed open events are deleted after 24 hours for filtered events, and after your plan's history window for counted opens. Aggregate counts are kept with the email record. Deleting your account removes everything associated with it.
Sub-processors
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication and serverless functions |
| Google Firebase Hosting | Serving this website |
| Stripe | Payment processing |
Contact
Questions, access requests or deletion requests: privacy@emailtrackapp.com.