Privacy Policy
Effective date: August 14, 2026
SentSonar is a Chrome extension that adds read tracking to email you send from Gmail. This policy describes exactly what data the extension and our servers process. We wrote it to be read, not skimmed.
The short version
- We never see your email content, subjects, or recipient addresses.
- We record the IP address of each open on our server, and never show it to anyone — the app only ever displays a coarse network (/24 or /48) and, where it belongs to the reader rather than to their mail provider, a city.
- The extension has no accounts and no analytics — it never reports your activity anywhere but our own open-tracking API.
- We never access the Gmail API or request Gmail OAuth scopes.
What the extension does in your browser
The extension runs only on mail.google.com. When you send a tracked email, it inserts a one-pixel image into the message body. Everything it knows about your messages — subjects, threads, which badge belongs where — stays in your browser’s local extension storage. On first run the extension generates a random install identifier and a cryptographic keypair used to sign its requests to our API. No name, no email address, no account.
What our servers receive
When a recipient’s mail client loads the tracking pixel, our server (Cloudflare Workers) receives a standard HTTP image request. From it we derive and store:
| Stored | Detail |
|---|---|
| Message token | An opaque random identifier. It reveals nothing about the email. |
| Timestamp | When the open occurred. |
| Classification | human confirmed / human likely / machine / unknown, plus a machine reason. |
| IP address | The address the pixel was fetched from, stored with the open event. It is what lets us tell a mail provider’s scanners and prefetchers apart from a person, and separate two readers behind one network. It is never returned to the extension, never shown in the app, and never sold or shared. |
| Network prefix | The same address reduced to a /24 (IPv4) or /48 (IPv6) prefix. This is the only form of it the app ever displays. |
| Network owner, country & city | ASN, network organization name, country code, and city. Location is only recorded when the fetch is attributable to the reader: when an open arrives through a relay such as the Gmail image proxy, the location is the relay’s, so we store none and the app shows none. |
| Client family | A reduced user-agent family (e.g. “Gmail image proxy”, “Apple Mail privacy proxy”). The raw user-agent string is discarded. |
What we never collect
- Email subjects, bodies, attachments, or headers.
- Recipient email addresses or names.
- Your own IP address, or any record of where you send from.
- Street-level location, GPS coordinates, or a recipient’s device identity.
- Raw user-agent strings or browser fingerprints.
- Your browsing history or anything outside mail.google.com.
Recipients’ data
Recipients of tracked email are the people whose opens we process. We minimize this to the network and client data in the table above. Because your open history is unlimited, open events are retained for as long as you use the service, and are deleted on request (see “Your choices”). Unmatched open events — fetches we cannot tie to a message — are deleted after 7 days. If you want your recipients to know about tracking, the extension offers a disclosure footer; it defaults to on for EU/UK recipient domains.
Notifications
Notifications are delivered by Web Push and fire only for human-classified opens. Machine and unknown opens never generate notifications.
This website
This site is static and fonts are self-hosted. It uses Google Analytics (measurement IDG-PTBZG19KP3) to count page views, which sets Google Analytics cookies in your browser. That is the only third-party code on the site, it is not present in the extension, and it is never joined with email open data.
Chrome Web Store limited use
Our use of data obtained through the extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is used solely to provide the read-tracking feature you see, is never sold, never used for advertising, and never transferred except as required to operate the service (Cloudflare, our hosting provider) or to comply with law.
Your choices
- A global kill switch in the extension popup disables all tracking instantly.
- Per-account toggles disable tracking for individual Gmail accounts.
- Uninstalling the extension stops all data collection immediately.
- To delete server-side data for your install, contact us with your install ID (shown in the popup) at admin (at) sentsonar (dot) com.
Changes
If this policy changes materially, the extension will show a notice before the change takes effect. The current version is always at this URL.
Contact
admin (at) sentsonar (dot) com