Privacy policy

Last updated: 8 August 2026

Who we are

eyemail is operated from Spain. For any question about this policy or your data, contact privacy@eyemail.app.

What we store

For each tracked message we keep a tracking identifier, the Gmail thread identifier, the address of the mailbox that sent it, and the time it was sent. When a message is opened we record the time, the requesting user agent, and whether it came through an image proxy.

Your account record holds the email address and identifier supplied by Google when you sign in, plus your subscription status.

What we deliberately do not store

We do not store subject lines, message bodies, attachments, or the addresses you send to. Gmail already displays those to you beside our label, so we hold no copy — particularly not of recipients, who are not our users and have not agreed to anything.

We do not record the IP address of whoever opens a message. Gmail serves images through its own proxy, so the address would be Google's rather than the reader's.

How tracking works

When you send a tracked message, the extension adds a 1×1 transparent image to it. Loading that image tells us the message was displayed. Mail clients that block images will not register an open, Gmail's proxy sometimes loads the image more than once, and opening the message yourself in Sent produces the same request a recipient would, so counts are indicative rather than exact.

Recipients are not identified individually by this mechanism: the record links to your message, not to a person.

Legal basis and your rights

We process this data to provide the service you asked for (Article 6(1)(b) GDPR). You may request access, correction, export or deletion of your data at any time by writing to the address above. Deleting your account removes your messages and their open records.

If you track messages in a professional capacity, you are responsible for informing your recipients where the law where you operate requires it.

Processors

We use Supabase for database and authentication, Vercel for hosting, Stripe for payments, and Sentry for error reporting. Card details are handled by Stripe and never reach our servers. Sentry stores its data in the European Union.