Skip to main content
Docs/Privacy & data
Privacy & data

How we protect checked emails.

Why third-party addresses are hashed, never stored raw - and how that protects everyone.

3 min read · Updated May 2026

When you use EmailSheriff to check email addresses, those addresses usually belong to other people - your subscribers, customers, or leads. They haven't agreed to be stored in our database. So we don't store them. This guide explains exactly how we handle that data, in plain English.

The short version

Every third-party email address you check is converted to a keyed cryptographic hash (HMAC-SHA256) before anything is written to our database. The "keyed" part is what matters: the hash is computed using a secret key that lives only on our server, so the same address always produces the same hash (we can recognise it on a future check) but it cannot be reversed back into the original address - not by guessing, not with a precomputed "rainbow table." We store the keyed hash, never the address.

Plain-text third-party addresses are never stored. Not in logs, not in the database, not anywhere. Only the irreversible hash is kept.

Why hashing, not just "deleting later"

Hashing lets us do something genuinely useful while holding zero personal data: when an address is checked again - by you or anyone - we hash the new input and compare fingerprints. If they match, we can return what we already learned about that address's validity, without ever having stored who it belongs to. You get faster, smarter checks; the address owner's privacy is fully intact.

Your own data is different

The email you sign up with is your data, and you've consented to it by creating an account. That's stored normally (in plain text) so we can sign you in and contact you. It's kept in a separate place from the hashed third-party addresses - the two never mix.

Why this matters legally

Storing other people's email addresses without their consent runs into privacy law - GDPR in Europe, UK GDPR, CCPA in California, and India's DPDP Act, among others. By hashing third-party addresses, we get the full utility of historical check data with none of the legal exposure of holding personal data we weren't given permission to keep. It's privacy by design, not privacy as an afterthought.

Want the formal version? Our privacy policy spells out exactly what's collected, how it's stored, and your rights over it.