Privacy Policy

Effective date: September 25, 2026
Last updated: September 26, 2026

This Privacy Policy explains how Email Tracker (the “Service”), including the Email Tracker Chrome extension and related server components, collects, uses, stores, and shares information. The Service is operated by John Smith in Estonia (“we”, “us”, or “our”).

Short version: tracking is optional and is off until you enable it. When enabled, the Service processes limited message metadata and tracking-pixel requests to show open activity. It does not send message bodies, attachments, or your email password to our servers. We do not sell personal data or use it for advertising.

1. Information we process

Account and installation information. We process an installation identifier, platform, extension version, activation status and timestamps, internal user/account identifiers, and the email address and display/account name associated with activation.

Google authorization information. If Chrome enrollment requires Google authorization and you choose “Continue with Google”, the extension requests only OpenID identity and your verified Google Account email address. The Google access token is sent to our server only after that explicit action, used transiently to validate the token with Google and retrieve the verified email address, and is not stored in our database. We do not request access to Gmail messages, contacts, files, or your Google password.

Tracked-message metadata. For a message you choose to track, we process:

To insert the tracking pixel, the extension temporarily processes the HTML of the message draft locally in your browser and returns the modified HTML to Gmail for sending. The message body is not placed in extension storage. The Service does not transmit or store the message body, attachments, or your email account password on our servers.

Tracking-pixel request data. A tracked message contains a small remote image with a random identifier. When that image is requested, we process the request time, a truncated user-agent string, and limited technical header signals indicating a proxy or prefetch. Like any internet service, our server necessarily receives the connecting IP address; it is used transiently for connection handling, security, and rate limiting and is not attached to the open-event record in the application database.

An image request is only a technical signal. It may be generated by an email provider, privacy proxy, security scanner, prefetcher, or automated system, and therefore does not always prove that a person read the message. The Service classifies signals to help communicate this limitation.

Usage and diagnostic information. We process limited events needed to operate and improve the Service, such as installation/start, activation, dashboard and settings use, tracking enabled or disabled, tracked-message and open events, notification events, synchronization outcomes, extension version, random session/correlation identifiers, and restricted technical error details. Server validation rejects telemetry fields whose names indicate message bodies, HTML, attachments, passwords, tokens, subjects, recipients, senders, or email addresses.

Information stored locally. The extension stores settings, consent choice, installation credentials, tracking tokens, and operational state in browser extension storage. This local data normally remains until it is cleared or the extension is removed.

2. How we use information

We use information only to:

We do not sell personal data, rent it, use it for targeted advertising, create advertising profiles, or transfer it to data brokers.

3. Legal bases and your choices

Where the European Economic Area rules apply, we rely on your consent for optional email tracking and related disclosures, performance of the Service you request, and our legitimate interests in securing and maintaining the Service. Tracking is off before consent. You may decline it, disable it in settings, choose not to track an individual message, turn off notifications, delete individual history entries, clear extension storage, or uninstall the extension.

Google authorization is requested only when needed for enrollment and only after you press the Google authorization button. You may revoke the extension’s Google access through your Google Account settings.

4. Sharing and service providers

We disclose information only as needed to operate the Service, comply with law, protect rights and security, or complete a merger, acquisition, or sale of assets after obtaining the user's explicit prior consent. Current infrastructure includes:

Service providers process information only to provide their contracted infrastructure or authentication function. We do not permit them to use Email Tracker data for advertising.

5. Google API and Chrome Web Store Limited Use

Email Tracker’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The extension also adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.

6. Retention and deletion

You can delete individual tracked-message history in the dashboard. To request deletion of account or installation information, email us at the address below. We may ask for reasonable verification before acting on a request.

7. Security

We use HTTPS in transit, access controls, hashed installation and tracking credentials where applicable, restricted network access, private storage, client-side encryption of backups before upload, and provider-side storage encryption. No system is completely secure, but we use reasonable technical and organizational measures appropriate to the nature of the data.

8. International processing

The primary Service is hosted in Amsterdam, the Netherlands. Backups are stored in Backblaze’s EU Central region. Google or Backblaze may process limited information in other locations under their applicable terms and data-transfer safeguards.

9. Your privacy rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of your personal data, and to withdraw consent. Withdrawal does not affect processing already performed lawfully. You may also complain to your local data-protection supervisory authority. Contact us to exercise these rights.

10. Children

The Service is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided data, contact us so we can investigate and delete it where appropriate.

11. Changes to this policy

We may update this policy when the Service or legal requirements change. We will publish the revised policy at this URL and update the date above. If a change materially expands how Google user data or other personal data is used, we will provide appropriate notice and request consent where required before applying the new use.

12. Contact

Controller: John Smith
Country: Estonia
Email: johnmailtrack1211@gmail.com