Email tracker security: what Openn stores, and what it never touches

Openn works without access to your Gmail mailbox: Google Sign-In only shares your identity. It never stores the subject or body of your emails, your recipients' addresses or raw IP addresses, and your account and tracking data are stored in the European Union.

Last updated

01

What Openn asks for

PermissionWhat it is used for
Google Sign-Inopenid, email, profile: your identity and verified address only. No Gmail API access: Openn cannot read, send or change your email through Google.
Sites the extension runs onmail.google.com only.
storageKeeps your settings and your session in Chrome's extension storage.
identityRuns Google Sign-In.
scriptingLets the Gmail integration library load its helper into the Gmail tab.
notificationsShows Pro notifications for opens and clicks.

The extension runs inside the Gmail page, which is why Chrome asks for access to mail.google.com; nothing from your mailbox is sent to Openn except link destinations.

The extension reads the subject and recipients of a sent email in the Gmail page to show you its result, and compares recipient domains with the global exclusion list. None of this leaves your browser.

02

What we store

Your account

Google account identifier and verified email address of each Gmail address you attach; session tokens, stored hashed

Each tracked email

A random identifier, the time it was sent, and the destinations of the links that were rewritten

Each open or click

Its kind and time, the link concerned, its class, a coarse mail-client family, a coarse network family, and the country

Your settings

Excluded domains; on Pro, your tracking subdomain

Billing (Pro)

Plan, invoices and payment status. Card details are held by Stripe, never by Openn

Never stored

The subject or body of your emails, the recipient list, recipients' email addresses or names, raw IP addresses and raw User-Agents.

IP address and User-Agent are used for a fraction of a second to classify an event, then discarded.

03

Where the data is

Your account and your tracking events are stored in the European Union: the database and the application run in Germany, and backups are held by Cloudflare under EU jurisdiction.

To redirect clicks quickly anywhere, link destinations are also copied to Cloudflare's global network.

One step happens elsewhere, briefly. Image loads and link clicks are answered by the Cloudflare location closest to the recipient, so a request from New York is handled in New York before the resulting event, without its IP address, is sent to Germany. Openn keeps nothing at that step: request logging is turned off, and our error logs contain no IP address or User-Agent.

04

How it is protected

  • All traffic is encrypted in transit. The application is not exposed to the internet: it can only be reached through an authenticated tunnel.
  • Session tokens are stored hashed. Requests from the extension to the tracking service are signed with short-lived tokens.
  • The redirect service only sends people to destinations recorded when the email was sent: it cannot be used to redirect anywhere else.
  • Accounts are isolated from each other, and every endpoint is tested for it.
  • Backups run daily and are kept 30 days, with a scripted restore test. Security updates are applied automatically.

05

How long we keep it

Open and click events

12 months, then deleted automatically

Your account

Until you delete it, or after 24 months without any activity, with an email 30 days before

Backups

30 days

Deleting your account from your account page deletes your data and deactivates every tracked link at once: a recipient who clicks an old link sees a “link expired” page, not the destination.

06

Recipients of your emails

Openn stores no name, email address or IP address of the people you email. What it keeps about an open or a click (time, country, link, coarse mail-client family) is attached to your email, not to a person.

A company that does not want emails to its domain tracked can ask for it to be added to a global exclusion list, applied by every Openn user's extension. Details are in section 5 of the Privacy Policy.

07

Documents and contact

The full detail is in the Privacy Policy and, for customers, the Data Processing Agreement, which lists our sub-processors.

Shared tracking domain (used unless you set up your own subdomain on Pro): t.almarososy.com.

Send the email.
Know what happened next.

Useful email signals, without the surveillance theatre.

Add to ChromeSoon

Built for Gmail. Hosted in Europe.