Legal · Privacy
Privacy Policy
The short version
- ✓We verify email addresses — we don't harvest or sell them.
- ✓Addresses you check via our API are processed in real time and never stored — the results stay on your side.
- ✓We keep only your account (login email + plan); you can access, export, or delete it anytime.
- ✓EU data residency is available, and we're GDPR-aligned.
1. Scope
This policy explains how EmailLabs, operated by EmailLabs("we", "us"), handles personal data when you use our website, dashboard, and API. It covers both the data of our account holders and the email addresses that account holders submit for verification.
2. What we collect
Account data (the only data we store)
When you create an account we collect your name, login email, and authentication details, plus the plan you're on. If you subscribe, our payment processor handles card data — we never store it. This account information is essentially all the personal data we retain.
Submitted addresses — not stored
To verify an email, you send us the address through the API. We process it in memory to return a deliverability result and immediately discard it. We do not store the addresses you submit or the results we return — that output lives on your side. There is no verification history or list of checked addresses in our systems.
Usage metadata
To bill your plan, enforce rate limits, and prevent abuse, we keep minimal operational metadata such as request counts and timestamps. This does not include the addresses you verify or their results.
3. How we use data
- To process verification requests and return results in real time.
- To maintain, secure, and improve the service.
- To bill for your plan, enforce quotas, and prevent fraud or abuse.
- To send service-related communications about your account.
We do not sell submitted addresses, we do not retain them, and we never use them to build marketing lists.
4. Legal basis (GDPR)
Where GDPR applies, we process personal data under one of these bases: performance of a contract (delivering the service you signed up for), legitimate interests (security and abuse prevention), and consent where required.
6. Retention
Account data is kept for the life of your account and deleted on request or after closure.
Submitted addresses and verification results are not retained at all— they're processed transiently and discarded once the response is returned. Operational metadata (request counts, timestamps) is kept only as long as needed for billing and abuse prevention.
7. Your rights
Depending on your region, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing.
- Access & portability — request a copy of your data.
- Correction — fix inaccurate details.
- Deletion — ask us to erase your data.
- Objection — object to processing based on legitimate interests.
To exercise any right, contact us at privacy@emaillabs.io.
8. Security
We use encryption in transit and at rest, scoped API keys, and access controls. No system is perfectly secure, but we work to protect your data and disclose incidents as required by law.
Report a vulnerability at security@emaillabs.io.
10. Contact
Questions about this policy or your data? Reach our team at privacy@emaillabs.io.