Privacy policy
Last updated: 15 August 2026
Who we are
Eyemail is a service of Eneko Seriola Segura, Calle Señorío de Egulbati 2, 3º A, 31016 Pamplona, Spain, who is the data controller for the information described here. For any question about this policy or your data, contact eneko@evolv.es.
What we store
For each tracked message we keep a tracking identifier, the Gmail thread identifier, the address of the mailbox that sent it, and the time it was sent. When a message is opened we record the time, the requesting user agent, and whether it came through an image proxy.
Your account record holds the email address and identifier supplied by Google when you sign in, plus your subscription status.
Tracker blocking
When the extension blocks a tracking pixel in mail you receive, we store the hostname it belonged to, whether it was blocked, and when. We keep only the hostname and never the full URL: a tracker's URL usually carries an identifier for the recipient, which is precisely what this feature exists to defeat.
This data is linked to your account so we can show you who tracks you and count your monthly allowance. It says nothing about who sent you the message.
What we deliberately do not store
We do not store subject lines, message bodies, attachments, or the addresses you send to. Gmail already displays those to you beside our label, so we hold no copy — particularly not of recipients, who are not our users and have not agreed to anything.
We do not record the IP address of whoever opens a message. Gmail serves images through its own proxy, so the address would be Google's rather than the reader's.
How tracking works
When you send a tracked message, the extension adds a 1×1 transparent image to it. Loading that image tells us the message was displayed. Mail clients that block images will not register an open, Gmail's proxy sometimes loads the image more than once, and opening the message yourself in Sent produces the same request a recipient would, so counts are indicative rather than exact.
Recipients are not identified individually by this mechanism: the record links to your message, not to a person.
Legal basis and your rights
We process this data to provide the service you asked for (Article 6(1)(b) GDPR). You may request access, correction, export or deletion of your data at any time by writing to the address above. Deleting your account removes your messages and their open records.
If you track messages in a professional capacity, you are responsible for informing your recipients where the law where you operate requires it.
Where your data is held
The data controller is established in Spain, and our database is hosted in the European Union, where Sentry stores its error data too. Some of our processors are established outside the European Economic Area; where they process your data there, the transfer is made on the basis of the European Commission's Standard Contractual Clauses.
You can request a copy of everything we hold, or delete it entirely, from your dashboard at any time.
Processors
We use Supabase for database and authentication, Vercel for hosting, Stripe for payments, and Sentry for error reporting. Card details are handled by Stripe and never reach our servers. Sentry stores its data in the European Union.
Vercel Analytics and Vercel Speed Insights measure page views and loading performance. Both are cookieless and aggregate: they do not profile you, do not follow you across sites, and collect no personal data, which is why this site shows no cookie banner.
Cookies and local storage
Signing in to this website sets a session cookie so the server knows who you are. It is strictly necessary for the service and is not used for advertising or analytics.
The browser extension keeps its own session in the browser's extension storage, and remembers which mailbox you last used. None of that leaves your machine except as the requests described above.