Email Extraction and Privacy: What You Should Know
On this page
Extracting an email address does not establish permission to collect, store or contact its owner. Privacy depends both on how the tool handles your input and on how you use the resulting list.
What Email Extractor processes locally
Files and pasted text are parsed in your browser. The app does not upload those inputs or the extracted email list to our server. Browser history keeps the latest 30 result lists on your device; original files are not saved in that history. You can remove saved lists through History.
Local processing still requires care on shared computers. Someone with access to your browser profile may be able to access saved results or downloaded files. Review the privacy notice for the current product policy.
Webpage loading uses our server
When you use Webpages, entered URLs are sent to our server to request public page content. The response is returned to your browser for extraction. Load content added by JavaScript uses a server-side browser, not your personal browser session.
Do not enter URLs containing passwords or private tokens. The target website sees a request from the server. Hosting and security infrastructure may also process request information; browser-local file processing should not be confused with a claim that all website activity stays on your device.
The optional extension reads accessible loaded content when you request it. Its website mode makes additional page requests. Captures and results can be downloaded or imported into the main app; handle those files as contact data.
Public availability is not permission
An address on a public page can still be personal data. Check your authority to collect it, the source's terms, the intended purpose and the rules applying to your organization and recipients. A business email address is not automatically exempt from privacy or marketing rules.
UK and EU considerations
The UK ICO explains that publicly available business contact data can fall under UK GDPR. A lawful basis, transparency and respect for objections may be required. Legitimate interests requires an assessment; it does not override consent requirements under PECR. Sole traders and corporate subscribers can be treated differently. See the ICO's business-to-business marketing guidance.
EU requirements also depend on GDPR and the relevant national electronic-marketing rules. Do not treat UK guidance as a complete statement of every EU country's law.
United States
The FTC's CAN-SPAM guide describes requirements for commercial email, including accurate headers, non-deceptive subjects, sender identification, a postal address and an opt-out method. Opt-outs must be honored within 10 business days. Other applicable laws may impose additional duties.
Canada
CASL generally requires consent for commercial electronic messages, alongside identification and unsubscribe requirements. Publishing an address does not grant unrestricted permission to contact it. The CRTC's implied-consent guidance explains the conditions for relying on conspicuous publication, including relevance to the person's role and the absence of a statement refusing unsolicited messages.
A practical review before using a list
- Keep the source and purpose of collection clear.
- Collect only the contacts you need and limit access to the list.
- Establish the applicable legal basis and marketing requirements before sending.
- Record and respect objections and opt-outs.
- Set an appropriate retention period and remove unnecessary data.
- Check the policies of any verification, CRM or mailing service before sharing a list.
Extraction does not verify mailboxes or make outreach lawful. This guide introduces questions to review; obtain advice for your specific circumstances when needed.