Email Validator

Privacy Policy

Last updated: 18 September 2026

This Privacy Policy (“Policy”) explains the information collection, use, and sharing practices of Email Validator (“we,” “us,” and “our”). It covers the Chrome extension, the verification server it talks to, and this website — together, the “Services”.

Please review this Policy before you use the Services or submit any information through them. By using any part of the Services, you understand that your information will be collected, used, and disclosed as described here. If you do not agree with this Policy, please do not use the Services.

Our Principles

Email Validator has designed this Policy to be consistent with the following principles:

In one paragraph. Addresses are checked in your browser first; only those needing a mailbox check are sent to our server, and they are deleted right after. We cache results as irreversible keyed hashes, never as addresses. There is no account, no cookie, no analytics and no advertising anywhere in the Services, and nothing is sent while you are not acting: an open popup and an open bulk tab make no request at all.

Information We Collect

Information you provide directly to us

The only data you give us is the email addresses you ask us to check — typed into the popup, or read out of a file you open in the bulk tab — and whatever you choose to write to us by email.

An address is sent to our server only when your browser cannot settle it on its own. Syntax, disposable domains, role addresses and dead domains are decided locally and never transmitted. Of a file, only addresses ever leave the browser: not the file, not its name, not its other columns, not the rows the browser already decided.

For the DNS part of the check, only the domain of an address is sent — to the public resolvers dns.google and cloudflare-dns.com. The local part, the half before the @, never leaves your device for DNS.

Information that is collected automatically

When the extension first talks to our server it is given an anonymous install id and a token. That id carries no name, no email address and no device identifier, and it is not linked to the addresses you check. Alongside it we keep the extension version and a count of how much of the daily allowance the install has used.

Our web server writes ordinary access logs. In them the client IP address is masked before it is written — to /24 for IPv4 and /64 for IPv6 — and the logs are rotated and kept for seven days. To throttle abuse of the endpoint that hands out install ids, the server also keeps a salted hash of the IP address, with the salt changing daily; the address itself is never stored.

Email addresses never appear in any log. The logger raises an error if one reaches a log field, and the journals have been searched for them.

Cookies and other tracking technologies

We do not use any. No cookies, no tracking pixels, no web beacons, no fingerprinting, no session recording — neither in the extension nor on this website. This page and every other page of this site make no third-party request at all.

Information from third parties

We do not buy, rent or receive personal information about you from data brokers, social networks, advertisers or any other third party.

How We Use Your Information

We use what we collect only to:

We do not profile you, we do not build audiences, and we do not use your data to train anything. There is no advertising in the Services.

What Happens During a Mailbox Check

When the browser cannot settle an address, our server asks the mail server responsible for that domain whether the mailbox exists. It is an ordinary SMTP conversation that goes as far as RCPT TO and stops there: the connection is closed before DATA, so no message is ever sent to the address and nothing lands in that mailbox.

We state this plainly because it has a consequence: the operator of the recipient's mail server sees the address being asked about and the IP address of our prober, the same way it would see any incoming mail connection.

When We Disclose Your Information

We do not sell your information, we do not share it with advertisers, and we do not transfer it for any purpose unrelated to the single purpose of the Services. It reaches other parties in four situations only:

We may also disclose information if we are required to do so by law, or where it is reasonably necessary to comply with legal process, to enforce our terms, or to protect the rights, property or safety of our users, the public or ourselves.

If the Services are ever transferred to another owner, information held by them would be part of that transfer; we would say so here before it took effect. That is a change of owner, not a sale of your data.

Legal Basis for Processing

Where the GDPR applies, our legal grounds are:

If You Check Other People's Addresses

A list of addresses belongs to the person who uploads it. For that list you are the controller and we are your processor: we check the addresses on your instruction and for no other purpose, and we delete them as described below. You are the one who needs a lawful basis for holding the list in the first place.

We do not notify the owners of the addresses being checked. There is no way for us to do so without contacting them — which is precisely what the check avoids doing — and no message is ever delivered to them. Where the GDPR applies, we rely on Article 14(5)(b): providing that information would involve disproportionate effort, and would require creating contact that the design of the Services deliberately does not make.

Online Analytics

There are none. We use no analytics service, in the extension or on this website, and we send no telemetry of any kind.

Data Retention

These are the only places anything is kept, and for how long:

WhatWhereHow long
The addresses being checked, in clear Our server, while the check runs Deleted 30 minutes after the batch finishes, and in every case no later than 2 hours after it started — whatever state it is in
The result of a check, as HMAC-SHA256 of the address under a secret key — the address itself is not stored Our server's cache 72 hours, or until you ask us to erase it
Anonymous install id, token hash, extension version, salted daily IP hash Our server While the install exists
Allowance counters for an install Our server 90 days
Web server access logs, with the IP masked to /24 or /64 Our server 7 days
Service journals — they contain no addresses Our server 30 days
Your install id and token, the DNS cache and the rows of a run Your own browser, in extension storage Until you remove the run or uninstall the extension

The key that turns an address into a cache entry is held outside the database, is not included in backups, and is never written to a log. A cached result carries no install id, so there is no record anywhere that links an address to the person who checked it.

Your Choices and Data Subject Rights

There is no account to manage and no marketing email to unsubscribe from — we do not send any.

Where the GDPR or a comparable law applies, you have the right to confirm whether we hold information about you, to access it, and to have it corrected or erased; to object to or restrict our processing; and to complain to your supervisory authority. To exercise any of these, write to privacy@emailvalidator.app.

What erasure means here, stated honestly: we can delete a cached result for an address you name, and we will. We cannot search our records by person, because no such link exists — an address that is checked again after erasure is simply checked again from scratch. If you want everything associated with your install removed, say so and we will delete the install record and its counters; uninstalling the extension removes everything held in your browser.

International Transfers

Our servers are in the Netherlands. The public DNS resolvers we query and the recipient mail servers we contact are operated wherever their owners run them, and a check inherently reaches the mail server of the domain being checked. Where we send information outside the EEA, we rely on the appropriate safeguards required by applicable law.

Security Measures

We have implemented technical and organisational measures appropriate to what we hold: the Services are served over TLS; the link between our own machines is mutually authenticated; addresses in clear exist only for the minutes a check needs and the database is rewritten after they are deleted, so they cannot be read back out of free pages; cached results are keyed hashes; and administrative access is limited to named keys. No system can be made perfectly secure, and we do not claim otherwise.

Children

The Services are intended for adults and are not directed at children. We do not knowingly collect personal information from children under 13, or personal data from children under 16 where the GDPR applies. If we learn that we have, we will delete it.

Third-Party Links

This site links to the Chrome Web Store listing for the extension. We are not responsible for the content or the privacy practices of sites we link to, and their policies, not this one, govern what they collect.

Changes to this Policy

We will keep evaluating this Policy as the Services change, and we may update it. Changes are posted on this page and the date above is revised. If a change materially affects what is sent or what is kept, we will say so here.

Questions About this Policy

Write to privacy@emailvalidator.app.