Last updated September 15, 2026
Privacy Policy
What OpenTrackMail does
OpenTrackMail adds a small, invisible remote image to emails that a user chooses to track. When an email client requests that image, OpenTrackMail records an open event and returns a transparent image.
Information we collect
For account holders, we store account identity, email address, preferences, tracked-email subject, recipients, provider metadata, and timestamps. We do not store the full email body.
When a recipient's email client loads a tracking image, we record the opaque tracking identifier, time, limited user-agent metadata, and a one-way short-lived request signature used for duplicate handling and abuse prevention. Raw IP addresses are not exposed to senders and are not stored by the application.
How information is used
We use this information only to provide open-status history, secure the service, prevent abuse, and improve duplicate-detection logic. We do not use tracking events for advertising, contact enrichment, fingerprinting, location tracking, or cross-site tracking.
Retention and deletion
Tracked-email and event data is retained until the account holder deletes individual history, all tracking history, or the account. Operational logs maintained by infrastructure providers may have separate limited retention periods.
Your responsibilities
Users are responsible for complying with applicable law and obtaining any disclosure or consent required before tracking recipients. Do not use OpenTrackMail for unlawful surveillance, harassment, or sensitive profiling.
Service providers and contact
OpenTrackMail uses Supabase for authentication and database hosting and Vercel for application hosting. Their processing is governed by their own terms and data-processing agreements. Privacy questions can be sent to privacy@opentrackmail.com.