Privacy Policy

Last updated: September 2026

MailPulse runs inside Gmail as a Chrome extension and only modifies tracked emails you choose to send. We don't need access to your entire inbox to tell you what happens after you send an email - MailPulse does not use the Gmail API and does not request Gmail mailbox scopes.

What we collect

What we don't collect

Why we collect it, and our legal basis

Each item above exists to make a specific part of the Service work: the account email authenticates you and lets us associate tracked messages with your dashboard; the hashed recipient identifier lets us group activity by contact without storing who that contact actually is; the subject-line preview lets your Sent & Tracked list show you which email an event belongs to; activity events and the hashed IP are what let MailPulse show opens, clicks, and engagement at all - that is the core function of the product. If you subscribe to a paid plan, your Paddle customer ID, subscription ID, and status are what let MailPulse know which plan's features to grant you and let the Manage billing button in Settings open the right Paddle billing portal for your account. We collect only what each feature needs to function, and process it on the basis that it is necessary to provide the Service you sign up for and requested (i.e. performance of our contract with you), or our legitimate interest in operating and securing the Service.

Tracking limitations

An activity event is a technical signal, not proof a person read your email. Image proxying, privacy relays, security scanners and email-client prefetching can all generate activity without a human involved. MailPulse never claims a message was definitely read, and never claims a forward was definitely detected - see the honesty guidelines in our product copy.

How long we keep data

We retain tracked message and activity data for as long as your account is active, so your dashboard, history, and Follow-Up Radar keep working. If you delete a specific tracked message or your entire account from Settings, the corresponding data is removed as described in Data deletion below. We don't currently apply a separate fixed retention schedule beyond that; if that changes (for example, to automatically age out very old activity data), we will update this policy first.

Data deletion

You can delete your tracking history or your entire account at any time from Settings. Account deletion permanently removes your tracked messages, events, contacts, follow-ups, and our own billing records (your Paddle customer/subscription IDs and status). It does not by itself cancel an active paid subscription with Paddle - cancel it first from Settings > Plan & Billing > Manage billing (or contact Paddle directly) if you don't want it to keep renewing. Canceling a subscription, on its own, does not delete your MailPulse data - your account simply reverts to the Free plan; use account deletion separately if you want your data removed too.

Your rights

Depending on where you're located, you may have rights to access, correct, export, or delete the personal data we hold about you, and to object to or restrict certain processing. You can exercise access, export, and deletion yourself at any time from Settings; for anything Settings doesn't cover, contact us using the address below and we will respond within a reasonable time.

Signing in with Google

MailPulse uses Google Sign-In only to authenticate your dashboard account. When you sign in, Google shares your email address and basic profile information (name, profile photo) with us - nothing else. We do not request, and never receive, access to your Gmail messages, contacts, calendar, or any other Google data through this sign-in. We use this information solely to create and secure your MailPulse account, and we do not share it with any third party except the service providers listed below, who process it on our behalf to operate the Service.

Third-party services

Authentication and data storage are provided by Supabase. If product analytics (e.g. PostHog) is enabled, only anonymized product usage events are sent - never email content. We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.

Payments for paid plans are handled by Paddle.com Market Ltd ("Paddle"), acting as Merchant of Record - see the Subscriptions and billing section of our Terms of Service. Paddle processes your payment and collects the billing information (name, email, card details, billing address) it needs to do so directly; MailPulse only ever receives back the Paddle customer ID, subscription ID, plan, and subscription status described above, never your card or other payment details. Paddle acts as an independent controller of your payment data under its own privacy policy, not as a processor on MailPulse's behalf.

Children's privacy

MailPulse is not directed to, and is not knowingly used by, children under 18. We do not knowingly collect personal data from children.

Changes to this policy

Because MailPulse is in active beta development, this policy may change as the Service evolves. We will make a reasonable effort to flag material changes before they take effect.

Contact

privacy@mailpulse.me