Your data stays yours.
When you check an email through EmailSheriff, the address itself never sits in our database in plaintext. At the entry point of our worker - before audit logic runs, before logs are written, before anything is persisted - the email is put through HMAC-SHA256 with a secret key that only our server holds. Only the irreversible keyed hash remains. The domain portion (e.g. example.com) is kept in plaintext (it's public infrastructure, not personal data), so we can build deliverability intelligence at the domain level. Free list checks run in your browser, and only domains are looked up. When you ask for something that has to leave your browser, like a live mailbox check or reading a screenshot, it goes to a named partner for that one task and is not kept by us in readable form. Even if we get breached, even if we get subpoenaed, even if we get acquired, the email addresses you checked cannot be recovered from us.
1. Who we are
EmailSheriff is operated as an independent service, provided "as is" through the website at emailsheriff.com. There is no parent company, no investor, and no affiliated marketing entity.
For the purposes of GDPR, we are the data controller. For DPDP, we are the data fiduciary. For CCPA, we are the business.
2. What we collect (and what we don't)
What we never collect in plaintext: The email addresses you paste into our tools. At the entry point of our worker, each address is put through HMAC-SHA256 (a keyed, one-way hash) before any audit logic runs - we compute a hash of the full address and, separately, a hash of the local part (the portion before @), so checks can be matched without ever retaining the address itself. The plaintext address is held only in volatile memory for the duration of the request (milliseconds for format and domain checks, up to a few seconds when a live mailbox check runs) and is never written to logs, never written to our database, never written to backups.
Mail-server (domain) checks: to tell you whether a domain can receive email at all, our tools send the domain (for example example.com), never the address, to our worker, which looks up its public DNS records. Nothing about that lookup is stored against you.
Screenshots you upload to the CRM DNS Verifier: the image is sent to our worker and then to one text-recognition (OCR) provider listed in section 6, so the DNS records in it can be read and filled in for you. The image is processed in memory and is not stored by us. We log only operational metadata: image size, which provider handled it, how long it took, and your country. Please crop out anything you don't want processed before uploading.
Email headers you analyse in the Deliverability Score: the body of your test email is read in your browser. The sending domain and the message headers are sent to our worker so it can read the authentication results (SPF, DKIM, DMARC and routing). They are processed in memory and not stored. The AI rewrite feature on the Spam Score tool and in your dashboard sends the subject and body you choose to rewrite to the AI providers listed in section 6, only when you click it.
What we do store in plaintext (and why): The domain portion of email addresses (e.g. example.com from [email protected]). Domains are public infrastructure - they're resolvable via DNS, listed in WHOIS, and not considered personal data under GDPR Article 4 or DPDP §2(t). We store domains in plaintext for a specific reason: it lets us detect deliverability patterns at the domain level (e.g. identifying domains with frequent authentication failures) without ever storing identifying user data. The result is more useful audits for everyone, no compromise on individual privacy.
What we collect when you use the free anonymous tier: The keyed hashes of the emails you submit (used to remember validity results and enforce rate limits - no other purpose), the domains of those emails (per the explanation above), the IP address that sent the request (used for abuse prevention only, then truncated/purged within 30 days), and standard server access logs (request path, response code, timestamp, user agent - retained 30 days).
What we collect if you create an account: Your account email address (we need it in usable form to send you magic-link sign-in emails), your name if you provide one, your sign-up IP and country, a consent timestamp, your audit history (the keyed hashes of what you've checked, plus the domain and verdict - never the plaintext address), and your account preferences.
What we collect for paid tier: Billing is processed by Razorpay (for customers in India) and Dodo Payments (for the rest of the world). Those processors collect payment details directly - we never see, store, or have access to your full card information. We retain only the customer/payment ID, subscription or credit status, and invoice history.
3. Hashing & the no-plaintext rule
This is the core of how this product works, so it deserves precision:
- Every email address you submit is put through HMAC-SHA256 at the entry point of our Cloudflare Worker. HMAC is a keyed hash: it combines the input with a secret key that lives only on our server (never in our code repository, never exposed to the browser, never sent anywhere). We compute a hash of the full address and a separate hash of the local part (everything before
@). - The domain portion is normalized (lowercased, trimmed) and stored in plaintext. This is not personal data - it's a public identifier that any DNS resolver can verify. Storing it lets us aggregate deliverability signals per domain without identifying any individual.
- The plaintext address is held in volatile memory only for the duration of the request - typically under 50 milliseconds - and is then released for garbage collection.
- Only the keyed hashes + domain are passed to audit logic, checked against any cache, and persisted (together with the verdict derived from them). The address itself is never persisted.
- HMAC-SHA256 is a one-way keyed function (RFC 2104). Given a stored hash, the original address cannot be recovered without (a) a brute-force search of the entire input space AND (b) knowledge of our secret key. Because the key is required, even a leak of our hash output cannot be reversed with a precomputed "rainbow table." Without both, recovery is computationally infeasible.
- This means: even if our database is breached, even if we receive a subpoena, even if the company is acquired and the new owner wants to monetize the data - the email addresses you checked cannot be recovered from us. A leaked record would reveal only "this domain was checked at some point," which is information the domain's own MX servers could equally reveal.
Audit results - the verdicts and metadata derived from the hash + domain - may be retained briefly for caching and rate-limit enforcement. These results contain no plaintext user identifiers.
What about the List Cleaner? Today, the list you paste or the file you open in the List Cleaner is read by your own browser. The format, disposable, role, typo and test-pattern checks run there, and only the domains are sent to us for the mail-server check. If you run the optional Pro deliverability check, each address is sent individually over an encrypted connection to our worker, then to one of the email-verification partners listed in section 6, which asks the recipient's mail server whether the mailbox exists. We keep only the keyed hash, the domain and the verdict. For lists of up to 500 addresses your file itself is never uploaded or written to disk. Larger Pro deliverability checks are processed on our servers, as described in the box in section 12.
4. Legal basis (GDPR, DPDP, CCPA)
GDPR (EU / UK): Our legal basis for processing depends on the activity. Running an audit on data you paste is performed under Article 6(1)(b) - performance of a service you requested. Rate-limit enforcement and abuse prevention is performed under Article 6(1)(f) - legitimate interest in maintaining service availability. Account email storage is performed under Article 6(1)(b). Analytics is performed under Article 6(1)(a) - explicit consent via the cookie banner.
DPDP (India): Under the Digital Personal Data Protection Act 2023, you (the data principal) provide consent or the processing is for a specified legitimate purpose. We rely on consent for any non-essential processing, and on legitimate purpose for service operation. We process data lawfully, with notice, and only for the purposes stated in this policy.
CCPA (California): We do not sell personal information as defined under the CCPA. We do not share personal information for cross-context behavioral advertising. The hashes we hold do not constitute personal information once one-way-hashed in our system, but we treat them as if they were, out of an abundance of caution.
5. Cookies & analytics
EmailSheriff uses no cookies for tracking by default. Functional cookies are used only for session management when you sign in.
Analytics is OFF by default and only fires after you explicitly click "Accept all" on our cookie banner. If you choose to enable analytics, we use Google Analytics 4 in a privacy-respecting configuration - IP anonymization on, ad personalization off, demographic features off. You can withdraw consent at any time: decline (or change your choice) the next time the banner appears, install the Google Analytics Opt-out Browser Add-on, or clear site data for emailsheriff.com in your browser. Your consent choice is stored locally in your own browser (not in a tracking cookie), so clearing that site data resets it and the banner will ask again. Legal basis: consent.
6. Sub-processors
We use the following sub-processors. Each handles a specific function. We minimize what each one sees:
- Cloudflare (USA, with edge presence globally) - DNS, CDN, Workers compute, D1 database, KV cache, R2 storage, and server-side rendering of PDF/image reports. Our worker runs on Cloudflare, so an address is processed in Cloudflare's memory while a check is running; what we store with Cloudflare is keyed hashes, domains and verdicts, never plaintext third-party addresses. Cloudflare Workers AI is also one of our screenshot text-recognition providers (see below).
- Hostinger (EU) - static-site hosting for our public pages. They see your IP and basic request logs but no application data.
- Resend (USA) - sends transactional email only: magic-link sign-in messages and any report you ask us to email to yourself. They process the recipient address needed to deliver that message.
- Email-verification partners: DeBounce, MillionVerifier and Bouncer - used only for the paid live mailbox (SMTP) check, on a cache-first basis and in that order of preference. When a live check is needed, the single address being verified is sent to one partner for that check. They do not receive your name, your account details or the rest of your list.
- Text-recognition (OCR) providers: Microsoft Azure AI Document Intelligence, Google Cloud Vision, Google Gemini and Cloudflare Workers AI - used only when you upload a screenshot to the CRM DNS Verifier, to read the DNS records in it. One provider handles each image, chosen automatically for availability and cost.
- AI providers (Google Gemini, with Groq as fallback) - used only for the optional AI copy-rewrite feature, and only on the text you explicitly submit to that feature.
- Google Analytics 4 (USA) - only if you opt in via the cookie banner. Default is off.
- Razorpay (India) and Dodo Payments (Merchant of Record, global) - payment processing. They handle payment details directly; we never see full card data.
7. Retention & deletion
Keyed-hash validity data: the irreversible HMAC hashes, domains, and validity verdicts may be retained indefinitely to improve the accuracy of our deliverability intelligence. Precisely because these records cannot be reversed to a person, they carry no individual privacy risk - there is no plaintext address to delete.
Generated reports (PDF / image): on free accounts, reports you export are stored so you can re-download them for 7 days, after which the download link expires and the backend copy is permanently deleted within 30 days. On paid accounts, saved reports are retained for as long as your account is active, because re-downloading past reports is part of the paid plan. You can delete any individual report at any time, and all of them are removed when you close your account.
IP addresses & server logs: retained up to 30 days for abuse prevention and diagnostics, then automatically purged.
Account data: retained for the life of the account. On a deletion request, your account and associated personal data are scrubbed within 30 days. Financial records required by tax law (e.g. invoices) are retained for the period the law requires.
8. Your rights
Signed-in users can download a machine-readable copy of their own account data at any time from account settings, without waiting on a request. Under GDPR, DPDP, and CCPA, you have the right to:
- Access a copy of any personal data we hold about you.
- Rectify inaccurate data.
- Delete ("right to be forgotten") - we will scrub your account and associated data within 30 days.
- Restrict processing pending resolution of any dispute.
- Port your data to another service.
- Object to processing based on legitimate interest.
- Withdraw consent at any time, where consent was the legal basis.
- Lodge a complaint with your local data protection authority (e.g., ICO in the UK, CNIL in France, the Data Protection Board in India under DPDP, the California Attorney General).
To exercise any of these rights, email [email protected]. We respond within 30 days. There is no fee for reasonable requests.
9. Security
We use industry-standard security practices: TLS in transit, encryption at rest provided by our infrastructure (Cloudflare) for any data we hold, HMAC-SHA256 keyed hashing of email addresses at ingress, short-lived in-memory handling of plaintext during a request, least-privilege access controls, and version-controlled deployment.
If you discover a security vulnerability, please report it to [email protected]. We follow responsible-disclosure norms and will acknowledge within 48 hours.
10. International transfers
Some of our sub-processors are based outside India / the EU / California. When data is transferred internationally, we rely on Standard Contractual Clauses (SCCs) for GDPR-applicable transfers, and on the equivalent legal mechanisms under DPDP and CCPA.
Because the personal data we store is hashed, the practical risk of international transfer is materially reduced. The exceptions are the moments described above where a single address or an image must be processed by a partner (a live mailbox check, or reading a screenshot); those transfers happen over encrypted connections, for that one task, under the partner's own data-processing terms.
11. Children's data
EmailSheriff is not directed at children under the age of 16 (under GDPR), 18 (under DPDP), or 13 (under COPPA). We do not knowingly collect data from children. If you believe a child has provided data to us, please contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. Material changes will be flagged on the homepage and (if you have an account) emailed to you 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Server-side processing for large deliverability checks. Checking a large list from your browser is slow and stops if you close the tab. So when you run a Pro deliverability check on more than 500 addresses, we process it on our servers instead: you can close the tab, and we email you when it's done. To do that, the addresses you chose to check are stored briefly. Here is exactly how: they are stored encrypted in Cloudflare R2, in small batches, and each batch is deleted as soon as it has been checked. Addresses with format errors are never uploaded. The results file is kept for 7 days so you can download it, then permanently deleted. You can delete a job and its files at any time before that. Addresses are still retained long-term only as keyed HMAC hashes with their domain and verdict, exactly as described in section 3. Everything that runs in your browser today keeps running in your browser.
Older versions of this policy are available on request - email [email protected].
13. Contact
For privacy-related questions, requests, or complaints: [email protected].
For all other matters: [email protected] or use the contact form.