What we collect
We collect account email addresses, password hashes, session records, project details, hashed API keys, usage counts, verification outcomes, timestamps, and technical request data needed to operate and secure the service. Addresses sent through single-address checks are processed to produce a result and are not stored in our application usage database. Bulk verification temporarily stores the uploaded list, per-address working results, and completed CSV so the job can continue after you leave the page.
How we use data
We use this data to provide verification results, enforce quotas, attribute usage to the correct project, prevent abuse, support customers, improve reliability, and meet legal obligations.
Payments
Stripe processes payment and billing information. We store Stripe customer, payment-method, Checkout, and payment identifiers so we can fulfill purchases and, when you opt in, run auto top-ups. We do not store full card numbers. Stripe handles payment data under its own privacy policy.
Service providers and icons
Cloudflare hosts the service, delivers transactional account emails, stores bulk files for the retention period described below, and may process network and security logs. Addresses sent through single checks may be processed transiently by service providers needed to return a verification result and are not retained there. MX, SPF, and DMARC tool queries are resolved through Cloudflare’s public DNS service. Public domain reports may display a cached website screenshot, and public pages may load provider favicons through Google’s favicon service. Google may receive the requested domain and ordinary request metadata such as your IP address.
Retention and security
Bulk working records are removed when a job completes or permanently fails. Completed bulk files expire after seven days, and you can delete a finished job sooner from the dashboard. We retain account, session, billing, and usage data only as long as needed for service operation, dispute handling, security, and legal requirements. Passwords, API keys, verification links, and password-reset links are stored as one-way hashes. Account sessions use secure HTTP-only cookies and are revoked after a password reset.
Your choices
You may ask to access, correct, or delete personal data, subject to legal and operational retention requirements. Contact support@emailverifier.dev.