Privacy Policy
Last updated: March 19, 2026 · Version 3.0
Version History
Version 1.0 — March 7, 2026 · Initial published policy
Version 1.1 — March 7, 2026 · Clarified permission usage and added user rights section
Version 1.2 — March 7, 2026 · Added legal compliance statement and audit trail
Version 2.0 — March 8, 2026 · Major update — added Search Automation, Bulk URL Automation, MX Validation, 7-language support, host permission justification and full feature coverage
Version 3.0 — March 19, 2026 · Full update — added Google Sheets integration, Cloudflare Worker license verification, wit.ai CAPTCHA audio solving, WHOIS/RDAP lookup, declarativeNetRequest, alarms, identity permission, CRM meta extraction, crawl depth system and freemail domain query system
📋 Overview
MailHarvest Pro is a Chrome and Edge browser extension that extracts, validates, scores and exports email addresses from webpages, PDF documents, spreadsheets, Word documents, search engine results and bulk URL lists. We are fully committed to protecting your privacy.
This policy covers MailHarvest Pro extension version 4.5.15 and above.
Core principle: MailHarvest Pro does not collect, transmit, or store any personal data on our servers. All extracted email data remains exclusively on your local device at all times.
The extension includes the following features, all of which operate entirely within your browser except where explicitly noted below:
- Email extraction from any webpage, PDF, CSV, XLSX, TXT or Word document
- Cloaked email decoding — detects [at], [dot] and HTML entity obfuscation
- CRM meta extraction — first name, last name, company and source URL from page context
- MX record validation via Google DNS and Cloudflare DNS over HTTPS
- Hot / Warm / Cold AI email scoring
- AI predictive scoring using local pattern analysis
- Search automation across Google, Bing, LinkedIn, GitHub and WHOIS/RDAP
- Freemail domain queries — Gmail, Hotmail, Outlook, Yahoo, Live, iCloud, ProtonMail
- Deep crawl — follows internal links up to 10 levels deep
- Bulk URL automation — up to 1,000 URLs per session
- CAPTCHA auto-solving via audio transcription using wit.ai (Meta)
- Google Sheets autosave with OAuth authentication
- WHOIS / RDAP domain lookup via ICANN's public RDAP protocol
- License verification via Cloudflare Worker
- Session history, deduplication and search state persistence
- CRM-ready CSV export — HubSpot and Pipedrive compatible
- 7-language interface including Arabic RTL
- Dark and light theme
⚖️ Legal Compliance
This extension complies with applicable data protection and privacy laws including GDPR and CCPA where relevant. Since no user email data ever leaves your device to our servers, no personal data is processed, stored remotely, or shared with any third party by us. MailHarvest Pro operates entirely within your local browser environment.
Users are responsible for complying with CAN-SPAM, GDPR, CASL and any other applicable regulations when contacting email addresses extracted using this tool. We recommend only contacting publicly listed business email addresses for legitimate outreach purposes.
💾 Data Storage
All extracted email addresses, AI scores, MX validation results, CRM metadata, settings, language preference, theme, session history, saved keywords, saved URLs, search state and user preferences are stored locally on your device using your browser's built-in local storage (chrome.storage.local).
This data never leaves your browser and is never sent to any server, database, or third party by us. You have full control over this data at all times and can clear it instantly using the Clear button inside the extension.
🔍 MX Record Validation
MailHarvest Pro validates email addresses by checking whether the domain has real mail servers (MX records). This is done using two public DNS over HTTPS services: Google Public DNS at dns.google and Cloudflare DNS at cloudflare-dns.com.
⚠️ MX validation sends only the domain part of an email address (e.g. "gmail.com") to these public DNS APIs — never full email addresses, never personal data, never browsing information. This is the same DNS lookup any mail server performs when delivering email.
DNS results are cached locally within your browser session to avoid repeated lookups for the same domain. Google's DNS service is subject to Google's privacy policy. Cloudflare's DNS service is subject to Cloudflare's privacy policy.
🔎 Search Automation
The Search Automation feature opens Google and Bing search pages in browser tabs based on keywords you provide. This works exactly like you manually typing a search query into your browser.
- Search queries are formed from keywords, platforms and country filters you configure yourself
- Freemail domain queries (Gmail, Hotmail, Outlook, Yahoo, Live, iCloud, ProtonMail) are added automatically to broaden results
- The extension opens search result pages in background tabs and scans visible email addresses
- No search queries, keywords or results are stored on any external server by us
- Saved keywords are stored locally in your browser only
- All search activity happens through your own browser and your own IP address — exactly as if you searched manually
MailHarvest Pro does not operate any proxy, relay or data collection server. Search activity is indistinguishable from normal manual browsing.
🤖 CAPTCHA Auto-Solving
When a reCAPTCHA challenge is detected during automated search, MailHarvest Pro attempts to solve it automatically using audio transcription. This feature uses the wit.ai speech recognition API operated by Meta Platforms, Inc.
⚠️ When CAPTCHA audio solving is active, the reCAPTCHA audio challenge MP3 file (a short audio clip of spoken words — not your voice, not any personal data) is sent from your browser to wit.ai's speech API for transcription. The request is made from your own IP address. The transcribed text is used solely to answer the CAPTCHA and is not stored by us.
- Only the reCAPTCHA-generated audio challenge file is sent — never any personal data
- Requests are made directly from your browser using your own IP address
- We do not store, log or process the audio or the transcript
- wit.ai's service is subject to Meta's / wit.ai's privacy policy
- You can disable CAPTCHA auto-solving at any time in the Settings tab — the toggle is ON by default
📊 Google Sheets Integration
MailHarvest Pro optionally integrates with Google Sheets to autosave extracted emails in real time. This feature requires Google OAuth authentication and is entirely optional — it is not enabled by default.
- When you connect Google Sheets, an OAuth access token is obtained via Chrome's identity API and stored locally in your browser
- The token is used solely to write email data to the specific Google Sheet ID you provide
- Extracted emails, scores, AI scores, domain and date are sent to the Google Sheets API and written to your personal sheet
- We never see, store or have access to your Google account credentials, OAuth token or sheet data
- Your sheet ID is stored locally in your browser only
- Google Sheets API calls are subject to Google's privacy policy
- You can disconnect Google Sheets at any time in the Settings tab
🔑 License Verification
MailHarvest Pro uses a Cloudflare Worker hosted at mhp-verify.cohengroups.workers.dev to verify license keys and manage trial eligibility. This is the only communication between the extension and our infrastructure.
- On first install, a one-way device fingerprint (SHA-256 hash of your extension ID and install timestamp — no personal data) is sent to the Worker to check trial eligibility and prevent abuse
- When you activate a license key, the key and fingerprint are sent to the Worker for verification against Gumroad's license API
- The Worker returns only a validity status, plan tier and expiry date — nothing else
- We do not collect your name, email address, IP address or any personally identifiable information during license verification
- A periodic 24-hour heartbeat alarm checks license validity silently in the background
- All verification responses are stored locally in your browser only
🔍 WHOIS / RDAP Domain Lookup
In domain search mode, MailHarvest Pro optionally performs a WHOIS lookup using ICANN's free public RDAP protocol at rdap.org. This lookup queries publicly available domain registration records.
- Only the domain name you enter is sent to the RDAP service — no personal data
- Results are used solely to extract publicly listed registrant contact emails
- RDAP results are processed locally and never stored on our servers
- WHOIS lookup is optional and only fires when the WHOIS engine is selected in the Search tab
🤖 Bulk URL Automation
The Bulk URL Automation feature opens URLs you provide in browser tabs and extracts email addresses from those pages.
- URL lists are entered by you and stored locally in your browser only
- Pages are opened in your browser exactly as if you visited them manually
- Downloadable files (PDF, CSV, XLSX, TXT, DOC) encountered during automation are processed locally
- No URL lists or extracted data are transmitted to any external server by us
- Search state (current position in queue) is saved locally so automation can resume after interruption — it expires after 45 minutes
- You can pause, resume or stop automation at any time
📄 PDF and Document Processing
When extracting emails from PDF documents, all processing happens locally in your browser using an embedded PDF library (PDF.js by Mozilla). When extracting from CSV, XLSX, TXT or Word documents, all processing also happens entirely locally. No document contents are ever uploaded or transmitted to any server.
🧠 CRM Meta Extraction
MailHarvest Pro attempts to enrich each extracted email address with contextual data (first name, last name, company name and source URL) by analysing the surrounding text on the page being scanned. This analysis happens entirely locally in your browser. No page content is transmitted to any external server for this purpose.
🔐 Permissions Explained
MailHarvest Pro requests the following browser permissions. Each permission is used solely for its stated purpose:
storage
Saves extracted emails, AI scores, MX results, CRM metadata, settings, language preference, theme, session history, search state, saved keywords and license data locally on your device. No data is sent to any external server by us.
unlimitedStorage
Allows the extension to store larger volumes of extracted email data locally without hitting Chrome's default storage quota. Used for Pro and Business plans handling high-volume extractions.
activeTab
Reads the content of the page you are currently viewing to find and extract email addresses. Not used to collect browsing history or personal data.
scripting
Runs the email extraction script on pages during automation and crawl. Also used to interact with reCAPTCHA elements during CAPTCHA handling. Not used to inject tracking or advertising code.
tabs
Opens and manages background tabs for bulk URL automation, search automation and crawl features. Monitors tab navigation to detect CAPTCHA pages and auto-resume after solving. Not used to monitor general browsing activity.
identity
Used exclusively to obtain a Google OAuth access token for the optional Google Sheets integration. Only requested when you click "Connect Google Sheets" in Settings. Not used for any other purpose.
downloads
Used to detect and intercept downloadable files (PDF, CSV, XLSX, DOC) that are triggered during automation so their contents can be scanned for email addresses instead of saved to disk.
declarativeNetRequest
Used to ensure Bing search results return 50 results per page (instead of the default 10) and to force English-language results during automated search. No browsing data is collected or intercepted.
alarms
Used to keep the background service worker alive during long automation runs, poll for CAPTCHA solving results from third-party APIs, and run the 24-hour license heartbeat check. No user data is involved.
host permissions <all_urls>
Required so the content script can extract emails from any website the user chooses to scan, and so the background worker can fetch audio files and make DNS/API calls during automation. The script only activates when the user explicitly triggers it — it never runs automatically on pages you browse normally, never collects data silently, and never transmits anything to our servers. This broad permission is essential because the extension must work on any website by design.
🌐 Third-Party Services
The following third-party services receive limited data as described. We have no control over their privacy practices — please review their policies directly.
Google Public DNS — dns.google
Receives domain names only (e.g. "gmail.com") for MX record validation. No email addresses or personal data sent.
Cloudflare DNS — cloudflare-dns.com
Receives domain names only for MX record validation as a fallback to Google DNS. No email addresses or personal data sent.
wit.ai (Meta Platforms, Inc.)
Receives the reCAPTCHA audio challenge MP3 file for speech-to-text transcription when CAPTCHA auto-solving is enabled. The audio is a computer-generated spoken word — not your voice. Requests are made from your own IP address. Only active when a CAPTCHA challenge occurs during automated search.
Policy:
wit.ai/privacy — Can be disabled in Settings → Auto-solve: OFF
Google Sheets API — sheets.googleapis.com
Receives extracted email addresses, scores and metadata to write to your personal Google Sheet. Only active when you have connected Google Sheets in Settings. Optional feature — disabled by default.
Cloudflare Workers — mhp-verify.cohengroups.workers.dev
Receives a device fingerprint (non-reversible SHA-256 hash) and license key for verification. Returns plan status and expiry only. No personal data, email addresses or browsing data transmitted.
Gumroad
License keys purchased via Gumroad are verified server-side through our Cloudflare Worker. We do not directly communicate with Gumroad from within the extension — verification is proxied through our Worker.
ICANN RDAP — rdap.org
Receives the domain name you enter in domain search mode for WHOIS/RDAP lookup. Returns publicly available domain registration data. Only active when WHOIS engine is selected.
ICANN public service — no account or key required
👤 User Rights
🗑️ Right to Delete
Clear all stored data instantly at any time using the Clear button inside the extension. Uninstalling the extension removes all locally stored data completely.
🔒 Right to Privacy
The extension does not share any information with third parties beyond what is explicitly described in this policy.
📴 Right to Disable
You can disable or uninstall the extension at any time via your browser's extension management page.
⚙️ Feature Control
CAPTCHA auto-solving and Google Sheets integration can each be independently enabled or disabled in the Settings tab at any time.
🔑 License Portability
Your license key is yours. You can activate it on any supported browser at any time by entering it in the Settings tab.
📬 Contact Us
For any privacy-related questions or requests, contact us at
[email protected] and we will respond promptly.
👁️ No Tracking Policy
✅ No ads · No analytics · No telemetry · No tracking pixels · No cookies · No behavioural tracking · No data collection · Ever.
We have zero visibility into how you use the extension, what websites you visit, what searches you run or what emails you extract. We do not use any third-party analytics services (Google Analytics, Mixpanel, etc.) anywhere in the extension.
🔄 Changes to This Policy
If we make material changes to this privacy policy, we will update the version history at the top of this page and update the "Last updated" date. Continued use of the extension after changes constitutes acceptance of the updated policy.
📬 Contact
If you have any questions about this privacy policy or the extension, please contact us at:
[email protected]