Security & privacy

Your emails stay yours.

A read receipt shouldn't mean handing over your inbox. MailViewed is built so that it physically can't read your mail — here's exactly how, in plain English.

We never read your inbox

The extension has no permission to read, search, or download your emails. It only adds an invisible pixel to messages you send and shows your read receipts — it cannot open your inbox. The only Gmail permission MailViewed ever requests is the optional, send-only gmail.send scope used by Compose, and send-only means exactly that: it cannot read any mail either.

Your email content never leaves Gmail

We store zero message content — no body, no attachments, not even a preview snippet. A tracked email is identified only by its subject, recipients, and time. For sends through Compose, the body transits our server encrypted for the seconds it takes Gmail to send it, then is hard-deleted.

We never see your password

Sign-in uses Google's official OAuth. It grants us only your name and email address — never your Google password, and no ability to read your mailbox. Connecting Gmail for Compose is a separate, optional grant of the send-only gmail.send permission. You can revoke either from your Google account at any time.

Encrypted in transit

Every connection to MailViewed runs over HTTPS/TLS. Data moving between your browser, the extension, and our servers is encrypted end to end of the wire.

Encrypted at rest

Your Google connection is stored as an encrypted token (AES-256-GCM), and email bodies you send through Compose are never written to disk unencrypted — they're held only briefly, encrypted, and deleted the moment the email goes out. The encryption key lives only on our server, never in the database.

Your data, your control

Export everything you've tracked as JSON, or delete your account in one click — which permanently wipes your data within 7 days. No retention games.

Built defensively

Least-privilege permissions, per-account isolation, rate limiting, hardened HTTP security headers, parameterized database queries, and no secrets in any code that ships to your browser.

What MailViewed can — and can't — see

What we can see
  • The subject line of emails you choose to track
  • The recipient's email address
  • When a tracked email is opened, and whether it was a real human or an automated scanner
What we never see
  • The body, attachments, or any content of your emails — we store none of it
  • Anything in your inbox or other emails
  • Your Google password or account credentials
  • Emails you didn't choose to track

How the tracking pixel actually works

A tracking pixel is just a tiny (1×1) invisible image with a unique link. When your recipient's email opens and loads images, their device requests that image — and that request is the “opened” signal. It reports the time, and (unless the client proxies it, as Gmail does) a rough network location.

The important part: a pixel cannot read, scan, or access the text of the email. It has no view into what was written — it's an image request, not a content reader. The uniqueness comes from the ID in the link, which is how we know which email was opened, not what it said.

We never collect the recipient's message content, and the only thing we learn about a reply is a yes/no plus a timestamp — spotted in your own Gmail by the extension, never by reading anyone's mail.

Still not sure? Revoke us in two clicks.

You stay in control. Remove MailViewed from your Google account at myaccount.google.com/permissions anytime, or uninstall the extension — and we keep nothing we shouldn't. For the legal details, see our Privacy Policy.