Privacy Policy.
Last updated: July 2026
This Privacy Policy explains how MailViewed collects, uses, stores, and protects your information when you use our website, browser extension, and email-tracking service. By using MailViewed, you agree to the practices described here.
What we collect
- Account info: your name and email from Google sign-in, used to identify your account.
- Tracked-email metadata: the subject, recipients, and send time of emails you choose to track. We store zero message content — no body, no attachments, and not even a preview snippet. When you send through Compose, the body is held only transiently and encrypted while the message is being sent, then hard-deleted; attachments are never written to disk. (You can see the exact record we keep for any email under “What we store about this email” on its detail page.)
- Open & click events: when a tracking pixel or link is loaded — timestamp, IP address, and user-agent — used to detect opens and classify whether they're human or automated.
- Gmail connection (optional): if you choose to send tracked emails from MailViewed, we store an encrypted Google refresh token and your connected Gmail address. We never store your password.
Gmail access — sending on your behalf
If you connect Gmail to send tracked emails (the Compose feature), MailViewed requests a single Google permission: gmail.send. We use it for one purpose only: to send the emails you compose, from your own Gmail account, with the tracking pixel included.
- We cannot read, search, or download your inbox or any of your email —
gmail.sendgrants send-only access. - We keep only the subject, recipient, and open events — no message content at all. The email body is held only briefly and encrypted while it is being sent, then deleted; attachments are held in memory just for the send and never written to disk — exactly as private as extension-tracked email.
- You can revoke MailViewed's access anytime at myaccount.google.com/permissions or by disconnecting in the app.
What we don't do
- We never read, search, or download your inbox or other emails.
- We never retain the full body or attachments of the emails you track (during a Compose send the body is held only transiently, encrypted, then deleted).
- We never add a visible tracking footer or branding to your emails.
- We don't sell your data or use it for advertising.
- We never use Google user data to develop, improve, or train generalised AI or machine-learning models, and never transfer it to any service that would.
Limited Use of Google user data
MailViewed's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained through Google APIs (the gmail.send scope) is used only to provide and improve the email-sending feature you requested; is never used for advertising; is never sold or transferred to third parties except as needed to provide the service, for security or legal reasons, or with your consent; is never used to develop, improve, or train generalised AI or machine-learning models; and is never accessed by humans except with your consent, for security or abuse prevention, to comply with the law, or in aggregated/anonymized form.
Data about the people you email
When you track an email, an invisible pixel records when it is opened. This is standard email-tracking behaviour, used by mainstream email tools for many years. Here is exactly what that means for the people you write to:
- What we hold about a recipient: the name and email address you entered when sending, and open or click events on the emails you sent them (a timestamp plus the technical signals we use to tell humans from bots).
- What we never hold: their inbox, their replies, their contacts, or a location profile. We do not geolocate readers.
- Gmail readers stay extra private: Gmail loads images through Google's proxy, so for Gmail recipients we typically never see the reader's own IP address at all.
- Who is responsible: you, the sender, decide to track your own correspondence and act as the data controller for your recipients' data. MailViewed processes it on your instructions, based on your legitimate interest in knowing whether the messages you send are received and read.
If someone used MailViewed to email you and you would like the data about you removed, write to [email protected] from the affected address and we will delete it.
How we protect your data
- In transit: every connection to MailViewed runs over HTTPS/TLS, so data moving between your browser, the extension, and our servers is encrypted on the wire.
- At rest: your Google connection is stored as an encrypted token (AES-256-GCM); the encryption key lives only on our server, never in the database. Email bodies you send through Compose are never written to disk unencrypted — they are held briefly in encrypted form and deleted the moment the email is sent.
- Access control: least-privilege permissions, per-account data isolation, rate limiting, hardened HTTP security headers, and parameterized database queries. No secrets ship in any code sent to your browser.
How long we keep data
- Message previews (removed): earlier versions kept a short first-line preview to help you identify an email. We no longer store any message content. Previews are purged from the live database immediately, and any copies that remain in our encrypted operational backups age out within 30 days.
- Tracking activity: tracked-email metadata and open or click events are kept while your account is active, for a maximum of 12 months from the date the email was sent. Older activity is deleted automatically.
- Individual emails: you can stop tracking and delete any single tracked email from your dashboard at any time, with immediate effect.
- Account deletion: deleting your account removes your data within 7 days, including recipient data attached to your tracked emails. Copies in short-term operational backups expire on a rolling basis shortly after.
Your rights (GDPR, UK GDPR, CCPA/CPRA)
Wherever you are, you can exercise these rights directly from the app or by emailing us:
- Access and portability: export everything we hold about you as a file, anytime, from Settings.
- Deletion: delete individual tracked emails or your entire account from Settings, no questions asked.
- Correction and objection: email us and we will correct inaccurate data or stop a specific processing activity.
- California residents: you have the right to know, the right to delete, and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information as defined by the CCPA/CPRA, and we never will. We do not discriminate against anyone who exercises their rights.
- EU/UK residents: our legal bases are contract (to provide the service you signed up for) and legitimate interest (to detect bots and keep open counts accurate). You may also lodge a complaint with your local supervisory authority.
Contact
Questions about privacy? Email [email protected].