Browser Extension — Privacy Policy

Privacy Policy

Last updated: March 19, 2026  ·  Version 3.0

Version History Version 1.0 — March 7, 2026 · Initial published policy
Version 1.1 — March 7, 2026 · Clarified permission usage and added user rights section
Version 1.2 — March 7, 2026 · Added legal compliance statement and audit trail
Version 2.0 — March 8, 2026 · Major update — added Search Automation, Bulk URL Automation, MX Validation, 7-language support, host permission justification and full feature coverage
Version 3.0 — March 19, 2026 · Full update — added Google Sheets integration, Cloudflare Worker license verification, wit.ai CAPTCHA audio solving, WHOIS/RDAP lookup, declarativeNetRequest, alarms, identity permission, CRM meta extraction, crawl depth system and freemail domain query system

📋 Overview

MailHarvest Pro is a Chrome and Edge browser extension that extracts, validates, scores and exports email addresses from webpages, PDF documents, spreadsheets, Word documents, search engine results and bulk URL lists. We are fully committed to protecting your privacy.

This policy covers MailHarvest Pro extension version 4.5.15 and above.

Core principle: MailHarvest Pro does not collect, transmit, or store any personal data on our servers. All extracted email data remains exclusively on your local device at all times.

The extension includes the following features, all of which operate entirely within your browser except where explicitly noted below:


⚖️ Legal Compliance

This extension complies with applicable data protection and privacy laws including GDPR and CCPA where relevant. Since no user email data ever leaves your device to our servers, no personal data is processed, stored remotely, or shared with any third party by us. MailHarvest Pro operates entirely within your local browser environment.

Users are responsible for complying with CAN-SPAM, GDPR, CASL and any other applicable regulations when contacting email addresses extracted using this tool. We recommend only contacting publicly listed business email addresses for legitimate outreach purposes.


💾 Data Storage

All extracted email addresses, AI scores, MX validation results, CRM metadata, settings, language preference, theme, session history, saved keywords, saved URLs, search state and user preferences are stored locally on your device using your browser's built-in local storage (chrome.storage.local).

This data never leaves your browser and is never sent to any server, database, or third party by us. You have full control over this data at all times and can clear it instantly using the Clear button inside the extension.


🔍 MX Record Validation

MailHarvest Pro validates email addresses by checking whether the domain has real mail servers (MX records). This is done using two public DNS over HTTPS services: Google Public DNS at dns.google and Cloudflare DNS at cloudflare-dns.com.

⚠️ MX validation sends only the domain part of an email address (e.g. "gmail.com") to these public DNS APIs — never full email addresses, never personal data, never browsing information. This is the same DNS lookup any mail server performs when delivering email.

DNS results are cached locally within your browser session to avoid repeated lookups for the same domain. Google's DNS service is subject to Google's privacy policy. Cloudflare's DNS service is subject to Cloudflare's privacy policy.


🔎 Search Automation

The Search Automation feature opens Google and Bing search pages in browser tabs based on keywords you provide. This works exactly like you manually typing a search query into your browser.

MailHarvest Pro does not operate any proxy, relay or data collection server. Search activity is indistinguishable from normal manual browsing.


🤖 CAPTCHA Auto-Solving

When a reCAPTCHA challenge is detected during automated search, MailHarvest Pro attempts to solve it automatically using audio transcription. This feature uses the wit.ai speech recognition API operated by Meta Platforms, Inc.

⚠️ When CAPTCHA audio solving is active, the reCAPTCHA audio challenge MP3 file (a short audio clip of spoken words — not your voice, not any personal data) is sent from your browser to wit.ai's speech API for transcription. The request is made from your own IP address. The transcribed text is used solely to answer the CAPTCHA and is not stored by us.

📊 Google Sheets Integration

MailHarvest Pro optionally integrates with Google Sheets to autosave extracted emails in real time. This feature requires Google OAuth authentication and is entirely optional — it is not enabled by default.


🔑 License Verification

MailHarvest Pro uses a Cloudflare Worker hosted at mhp-verify.cohengroups.workers.dev to verify license keys and manage trial eligibility. This is the only communication between the extension and our infrastructure.


🔍 WHOIS / RDAP Domain Lookup

In domain search mode, MailHarvest Pro optionally performs a WHOIS lookup using ICANN's free public RDAP protocol at rdap.org. This lookup queries publicly available domain registration records.


🤖 Bulk URL Automation

The Bulk URL Automation feature opens URLs you provide in browser tabs and extracts email addresses from those pages.


📄 PDF and Document Processing

When extracting emails from PDF documents, all processing happens locally in your browser using an embedded PDF library (PDF.js by Mozilla). When extracting from CSV, XLSX, TXT or Word documents, all processing also happens entirely locally. No document contents are ever uploaded or transmitted to any server.


🧠 CRM Meta Extraction

MailHarvest Pro attempts to enrich each extracted email address with contextual data (first name, last name, company name and source URL) by analysing the surrounding text on the page being scanned. This analysis happens entirely locally in your browser. No page content is transmitted to any external server for this purpose.


🔐 Permissions Explained

MailHarvest Pro requests the following browser permissions. Each permission is used solely for its stated purpose:

storage
Saves extracted emails, AI scores, MX results, CRM metadata, settings, language preference, theme, session history, search state, saved keywords and license data locally on your device. No data is sent to any external server by us.
unlimitedStorage
Allows the extension to store larger volumes of extracted email data locally without hitting Chrome's default storage quota. Used for Pro and Business plans handling high-volume extractions.
activeTab
Reads the content of the page you are currently viewing to find and extract email addresses. Not used to collect browsing history or personal data.
scripting
Runs the email extraction script on pages during automation and crawl. Also used to interact with reCAPTCHA elements during CAPTCHA handling. Not used to inject tracking or advertising code.
tabs
Opens and manages background tabs for bulk URL automation, search automation and crawl features. Monitors tab navigation to detect CAPTCHA pages and auto-resume after solving. Not used to monitor general browsing activity.
identity
Used exclusively to obtain a Google OAuth access token for the optional Google Sheets integration. Only requested when you click "Connect Google Sheets" in Settings. Not used for any other purpose.
downloads
Used to detect and intercept downloadable files (PDF, CSV, XLSX, DOC) that are triggered during automation so their contents can be scanned for email addresses instead of saved to disk.
declarativeNetRequest
Used to ensure Bing search results return 50 results per page (instead of the default 10) and to force English-language results during automated search. No browsing data is collected or intercepted.
alarms
Used to keep the background service worker alive during long automation runs, poll for CAPTCHA solving results from third-party APIs, and run the 24-hour license heartbeat check. No user data is involved.
host permissions <all_urls>
Required so the content script can extract emails from any website the user chooses to scan, and so the background worker can fetch audio files and make DNS/API calls during automation. The script only activates when the user explicitly triggers it — it never runs automatically on pages you browse normally, never collects data silently, and never transmits anything to our servers. This broad permission is essential because the extension must work on any website by design.

🌐 Third-Party Services

The following third-party services receive limited data as described. We have no control over their privacy practices — please review their policies directly.

Google Public DNS — dns.google
Receives domain names only (e.g. "gmail.com") for MX record validation. No email addresses or personal data sent.
Cloudflare DNS — cloudflare-dns.com
Receives domain names only for MX record validation as a fallback to Google DNS. No email addresses or personal data sent.
wit.ai (Meta Platforms, Inc.)
Receives the reCAPTCHA audio challenge MP3 file for speech-to-text transcription when CAPTCHA auto-solving is enabled. The audio is a computer-generated spoken word — not your voice. Requests are made from your own IP address. Only active when a CAPTCHA challenge occurs during automated search.
Policy: wit.ai/privacy — Can be disabled in Settings → Auto-solve: OFF
Google Sheets API — sheets.googleapis.com
Receives extracted email addresses, scores and metadata to write to your personal Google Sheet. Only active when you have connected Google Sheets in Settings. Optional feature — disabled by default.
Cloudflare Workers — mhp-verify.cohengroups.workers.dev
Receives a device fingerprint (non-reversible SHA-256 hash) and license key for verification. Returns plan status and expiry only. No personal data, email addresses or browsing data transmitted.
Gumroad
License keys purchased via Gumroad are verified server-side through our Cloudflare Worker. We do not directly communicate with Gumroad from within the extension — verification is proxied through our Worker.
ICANN RDAP — rdap.org
Receives the domain name you enter in domain search mode for WHOIS/RDAP lookup. Returns publicly available domain registration data. Only active when WHOIS engine is selected.
ICANN public service — no account or key required

👤 User Rights

🗑️ Right to Delete
Clear all stored data instantly at any time using the Clear button inside the extension. Uninstalling the extension removes all locally stored data completely.
🔒 Right to Privacy
The extension does not share any information with third parties beyond what is explicitly described in this policy.
📴 Right to Disable
You can disable or uninstall the extension at any time via your browser's extension management page.
⚙️ Feature Control
CAPTCHA auto-solving and Google Sheets integration can each be independently enabled or disabled in the Settings tab at any time.
🔑 License Portability
Your license key is yours. You can activate it on any supported browser at any time by entering it in the Settings tab.
📬 Contact Us
For any privacy-related questions or requests, contact us at [email protected] and we will respond promptly.

👁️ No Tracking Policy

✅ No ads · No analytics · No telemetry · No tracking pixels · No cookies · No behavioural tracking · No data collection · Ever.

We have zero visibility into how you use the extension, what websites you visit, what searches you run or what emails you extract. We do not use any third-party analytics services (Google Analytics, Mixpanel, etc.) anywhere in the extension.


🔄 Changes to This Policy

If we make material changes to this privacy policy, we will update the version history at the top of this page and update the "Last updated" date. Continued use of the extension after changes constitutes acceptance of the updated policy.


📬 Contact

If you have any questions about this privacy policy or the extension, please contact us at:

[email protected]