Skip to content
Mailshade
Home Terms Refund Install

Privacy Policy

Last updated: 2026-07-14

Mailshade is a browser extension that blocks requests to known email-tracking pixel domains, detects tracking resources in supported webmail pages, warns before recognized tracking redirects, and keeps a local report for the user. Supported webmail clients are Gmail, Outlook, Office 365, Superhuman, Yahoo Mail, and Proton Mail.

Scope and user choice

Mailshade does not request access to every website. Each supported webmail client is disabled until the user enables it and grants that client's specific Chrome host permission. Mailshade's inbox content scripts then run only on the enabled webmail origins. Until that grant exists, Mailshade installs no network-block rules for the client origin and performs no DOM inspection, attribution, or reporting there. Chrome manages those permission grants.

For Outlook and Office 365, Mailshade also requests optional webNavigation access with the client enable action so it can target only eligible Outlook frames during fallback injection. When that API access is not available, injection uses a top-frame-only fallback; the Outlook host grant is still required before any inbox processing. This permission is not used to build or transmit browsing history.

Mailshade has no product-analytics service or inbox-data backend. It does not intentionally transmit core tracker-event history or inbox metadata. The optional network features described below are paid-account operations, filtered crash reporting, and the separate public-website newsletter.

Data handled on enabled webmail pages

To detect a tracker and attach an indicator to the correct message, the extension handles locally:

  • sender name, email address, and email domain when the webmail UI exposes them;
  • opaque message and thread identifiers exposed by the webmail provider;
  • image and link resource URLs in the rendered message; and
  • the current supported-webmail location and a numeric Chrome tab id for local execution context.

Subject and body text are not extracted for attribution, stored, or transmitted. On Outlook, Superhuman, and Yahoo, Mailshade may locally parse a sender-bearing row accessibility label that can also contain a subject. Attachments and recipient lists are not read or stored. Full page, image, tracking-link, and decoded destination URLs are used in memory for detection and link handling; they are not stored as readable event fields. They may contribute to derived local event or occurrence identifiers.

Data stored by the extension

Tracker events and sender statistics are stored in Mailshade's local IndexedDB. An event can contain:

  • timestamp and event type (pixel or link);
  • supported mail client and numeric tab id;
  • tracker origin, domain, and identified vendor (not the URL path, query, or fragment);
  • sender name, email address, and email domain, when available;
  • opaque provider message/thread identifiers; and
  • a local occurrence identifier used to avoid duplicate records for the same rendered message view.

Free retains a rolling seven days of event history. An active trial or Pro license retains the available history until the user clears it, the extension is uninstalled, or browser storage is otherwise removed.

Preferences, client-enable intent, appearance, crash-report choice, and user-created muted-sender, strict-scan-sender, and tracker-domain allow lists are stored in chrome.storage.sync. Chrome may sync that data across browser instances when the user has Chrome Sync enabled. A synced client value is only enablement intent: Chrome host-permission grants stay local to each browser profile and are never copied through Mailshade sync. Runtime content-script and DNR decisions require both enabled intent and a live host-grant check in that profile. Trial, onboarding, license, and pending checkout state are stored in chrome.storage.local. Paid state can include the selected plan, one-time token, checkout id, license key, Polar product/customer identifiers, activation/validation times, expiry, and entitlement flags.

Paid features

Paid features are optional. Chrome requests only the host access needed for the user-initiated paid action. Direct license activation requests Polar; customer-portal access requests Mailshade auth; starting checkout requests Polar, Mailshade auth, and an optional https://mailshade.org/* host grant for the first-party success bridge. Declining leaves Free features available. Paid actions do not transmit inbox content, sender lists, or tracker-event history.

  • For direct license validation, the extension sends the license key and the Mailshade Polar organization id to Polar.
  • To start checkout, the extension sends the selected plan and a locally generated one-time activation token to auth.mailshade.org. After payment, it sends the Polar checkout id and that token to exchange the matching checkout for its issued license key.
  • To open the customer portal, the extension sends the locally stored license key to auth.mailshade.org so the service can create a Polar portal session.

After the user explicitly starts checkout and grants the optional https://mailshade.org/* host access, background dynamically registers a small first-party content script with the Chrome match pattern https://mailshade.org/upgrade-success*. The trailing wildcard is used only so the checkout query string matches. The content bundle immediately does nothing unless the origin/path are exactly https://mailshade.org plus /upgrade-success or /upgrade-success/; background independently repeats the sender-origin/path validation before activation. The registration is removed if the Chrome host grant is revoked, and other Mailshade paths are not processed.

auth.mailshade.org uses the request IP address for abuse-rate limiting on paid operations and passes the buyer IP to Polar when creating a checkout. Polar is the Merchant of Record and processes payment and customer data under its own privacy policy. Mailshade does not receive or store card numbers or other payment-card details.

Optional crash reports

Crash reporting is off by default and is sent to Hawk only after explicit opt-in. A report may contain the error message and stack, Mailshade version, extension scope, browser user agent, window dimensions, and ordinary network metadata such as the source IP seen by Hawk.

Before sending, Mailshade filters URL-, email-, Polar-token-, and license-shaped strings. Console capture and automatic click, navigation, fetch, and other breadcrumbs are disabled. Filtering reduces accidental exposure but is not presented as a guarantee of anonymity. Mailshade does not intentionally attach inbox metadata or tracker-event history to crash reports. The SDK uses the same product-level identifier for all reports instead of a generated persistent per-install identifier.

Public website and newsletter

Using the extension does not require the newsletter. If a visitor subscribes to release notes on mailshade.org, the site sends the submitted email address and signup metadata to EmailOctopus for subscription and campaign delivery. The embedded form uses Google reCAPTCHA for spam protection. Subscribers can unsubscribe using the link in each email.

Mailshade release-note campaigns must be sent without open or click tracking where EmailOctopus provides those controls.

Service providers

Depending on the optional feature used, data may be processed by:

  • Google Chrome Sync — syncing extension settings according to the user's browser account and sync choices;
  • Polar — checkout, payment, customer portal, and license validation;
  • Hawk — crash reporting after explicit opt-in;
  • EmailOctopus — optional newsletter subscription and delivery; and
  • Google reCAPTCHA — spam protection for the public newsletter form.

Access, export, and deletion

  • Export all data: Settings → Privacy → Export all data downloads JSON with the current IndexedDB data plus Mailshade-owned sync/local storage. Because this is a complete portability export, it may contain the local license key and pending checkout state and should be handled accordingly.
  • Clear history: deletes tracker events and sender statistics but keeps settings, onboarding, and paid state.
  • Clear all data: deletes Mailshade's IndexedDB and sync/local storage. Chrome-managed host-permission grants remain under Chrome's permission controls.

Chrome Web Store Limited Use

Mailshade's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Mailshade does not sell user data, use it for advertising, creditworthiness, or purposes unrelated to its tracker-protection function.

Corresponding release source and checksums are published at https://mailshade.org/source/.

Contact

  • privacy@mailshade.org for privacy questions and data-rights requests
  • security@mailshade.org for security disclosures

Changes

The current policy and its last-updated date are published at https://mailshade.org/privacy/. Material product changes are also recorded in the Mailshade changelog.

← Back to home

© Mailshade — privacy-first email protection.
Privacy Terms Refund Install