Privacy Policy
Last updated: 18 September 2026
This Privacy Policy (“Policy”) explains the information collection, use, and sharing practices of Email Validator (“we,” “us,” and “our”). It covers the Chrome extension, the verification server it talks to, and this website — together, the “Services”.
Please review this Policy before you use the Services or submit any information through them. By using any part of the Services, you understand that your information will be collected, used, and disclosed as described here. If you do not agree with this Policy, please do not use the Services.
Our Principles
Email Validator has designed this Policy to be consistent with the following principles:
- Privacy policies should be human readable and easy to find.
- Data collection, storage, and processing should be simplified as much as possible, to enhance security, ensure consistency, and make the practices easy to understand.
- Data practices should meet the reasonable expectations of users.
In one paragraph. Addresses are checked in your browser first; only those needing a mailbox check are sent to our server, and they are deleted right after. We cache results as irreversible keyed hashes, never as addresses. There is no account, no cookie, no analytics and no advertising anywhere in the Services, and nothing is sent while you are not acting: an open popup and an open bulk tab make no request at all.
Information We Collect
Information you provide directly to us
The only data you give us is the email addresses you ask us to check — typed into the popup, or read out of a file you open in the bulk tab — and whatever you choose to write to us by email.
An address is sent to our server only when your browser cannot settle it on its own. Syntax, disposable domains, role addresses and dead domains are decided locally and never transmitted. Of a file, only addresses ever leave the browser: not the file, not its name, not its other columns, not the rows the browser already decided.
For the DNS part of the check, only the domain of an address is sent — to
the public resolvers dns.google and cloudflare-dns.com. The local
part, the half before the @, never leaves your device for DNS.
Information that is collected automatically
When the extension first talks to our server it is given an anonymous install id and a token. That id carries no name, no email address and no device identifier, and it is not linked to the addresses you check. Alongside it we keep the extension version and a count of how much of the daily allowance the install has used.
Our web server writes ordinary access logs. In them the client IP address is
masked before it is written — to /24 for IPv4 and
/64 for IPv6 — and the logs are rotated and kept for seven days. To throttle
abuse of the endpoint that hands out install ids, the server also keeps a salted hash of
the IP address, with the salt changing daily; the address itself is never stored.
Email addresses never appear in any log. The logger raises an error if one reaches a log field, and the journals have been searched for them.
Cookies and other tracking technologies
We do not use any. No cookies, no tracking pixels, no web beacons, no fingerprinting, no session recording — neither in the extension nor on this website. This page and every other page of this site make no third-party request at all.
Information from third parties
We do not buy, rent or receive personal information about you from data brokers, social networks, advertisers or any other third party.
How We Use Your Information
We use what we collect only to:
- answer the question you asked — whether an address is worth sending to;
- keep the per-install daily allowance and protect the Services from abuse;
- keep the Services running and secure, and diagnose faults;
- answer you when you write to us;
- comply with the law.
We do not profile you, we do not build audiences, and we do not use your data to train anything. There is no advertising in the Services.
What Happens During a Mailbox Check
When the browser cannot settle an address, our server asks the mail server responsible for
that domain whether the mailbox exists. It is an ordinary SMTP conversation that goes as far
as RCPT TO and stops there: the connection is closed before DATA,
so no message is ever sent to the address and nothing lands in that
mailbox.
We state this plainly because it has a consequence: the operator of the recipient's mail server sees the address being asked about and the IP address of our prober, the same way it would see any incoming mail connection.
When We Disclose Your Information
We do not sell your information, we do not share it with advertisers, and we do not transfer it for any purpose unrelated to the single purpose of the Services. It reaches other parties in four situations only:
- Public DNS resolvers —
dns.googleandcloudflare-dns.comreceive the domain part of an address, never the whole address. - The recipient's own mail server — during the mailbox check described above.
- Hosting — our servers are rented from Fozzy and run in the Netherlands. The hosting provider is a processor acting on our instructions.
- Our mailbox provider — mail you send us is delivered through Apple iCloud+.
We may also disclose information if we are required to do so by law, or where it is reasonably necessary to comply with legal process, to enforce our terms, or to protect the rights, property or safety of our users, the public or ourselves.
If the Services are ever transferred to another owner, information held by them would be part of that transfer; we would say so here before it took effect. That is a change of owner, not a sale of your data.
Legal Basis for Processing
Where the GDPR applies, our legal grounds are:
- Performance of a contract — checking the address you asked about is the service you came for.
- Legitimate interests — keeping the Services available and free of abuse, and answering your messages. We have weighed these against your rights and limited what we keep accordingly.
- Legal obligation — where the law requires us to keep or disclose something.
If You Check Other People's Addresses
A list of addresses belongs to the person who uploads it. For that list you are the controller and we are your processor: we check the addresses on your instruction and for no other purpose, and we delete them as described below. You are the one who needs a lawful basis for holding the list in the first place.
We do not notify the owners of the addresses being checked. There is no way for us to do so without contacting them — which is precisely what the check avoids doing — and no message is ever delivered to them. Where the GDPR applies, we rely on Article 14(5)(b): providing that information would involve disproportionate effort, and would require creating contact that the design of the Services deliberately does not make.
Online Analytics
There are none. We use no analytics service, in the extension or on this website, and we send no telemetry of any kind.
Data Retention
These are the only places anything is kept, and for how long:
| What | Where | How long |
|---|---|---|
| The addresses being checked, in clear | Our server, while the check runs | Deleted 30 minutes after the batch finishes, and in every case no later than 2 hours after it started — whatever state it is in |
The result of a check, as HMAC-SHA256 of the address under a secret
key — the address itself is not stored |
Our server's cache | 72 hours, or until you ask us to erase it |
| Anonymous install id, token hash, extension version, salted daily IP hash | Our server | While the install exists |
| Allowance counters for an install | Our server | 90 days |
Web server access logs, with the IP masked to /24 or
/64 |
Our server | 7 days |
| Service journals — they contain no addresses | Our server | 30 days |
| Your install id and token, the DNS cache and the rows of a run | Your own browser, in extension storage | Until you remove the run or uninstall the extension |
The key that turns an address into a cache entry is held outside the database, is not included in backups, and is never written to a log. A cached result carries no install id, so there is no record anywhere that links an address to the person who checked it.
Your Choices and Data Subject Rights
There is no account to manage and no marketing email to unsubscribe from — we do not send any.
Where the GDPR or a comparable law applies, you have the right to confirm whether we hold information about you, to access it, and to have it corrected or erased; to object to or restrict our processing; and to complain to your supervisory authority. To exercise any of these, write to privacy@emailvalidator.app.
What erasure means here, stated honestly: we can delete a cached result for an address you name, and we will. We cannot search our records by person, because no such link exists — an address that is checked again after erasure is simply checked again from scratch. If you want everything associated with your install removed, say so and we will delete the install record and its counters; uninstalling the extension removes everything held in your browser.
International Transfers
Our servers are in the Netherlands. The public DNS resolvers we query and the recipient mail servers we contact are operated wherever their owners run them, and a check inherently reaches the mail server of the domain being checked. Where we send information outside the EEA, we rely on the appropriate safeguards required by applicable law.
Security Measures
We have implemented technical and organisational measures appropriate to what we hold: the Services are served over TLS; the link between our own machines is mutually authenticated; addresses in clear exist only for the minutes a check needs and the database is rewritten after they are deleted, so they cannot be read back out of free pages; cached results are keyed hashes; and administrative access is limited to named keys. No system can be made perfectly secure, and we do not claim otherwise.
Children
The Services are intended for adults and are not directed at children. We do not knowingly collect personal information from children under 13, or personal data from children under 16 where the GDPR applies. If we learn that we have, we will delete it.
Third-Party Links
This site links to the Chrome Web Store listing for the extension. We are not responsible for the content or the privacy practices of sites we link to, and their policies, not this one, govern what they collect.
Changes to this Policy
We will keep evaluating this Policy as the Services change, and we may update it. Changes are posted on this page and the date above is revised. If a change materially affects what is sent or what is kept, we will say so here.
Questions About this Policy
Write to privacy@emailvalidator.app.