LocalPulse · Open source · MIT

Know what this server does.

This optional service records only requests for a tracking image. It encrypts each request timestamp for your extension; your extension decrypts timestamps and counts them.

Your email content stays out

The API rejects subjects, bodies, recipient addresses, message text and destination links. Your private encryption and signing keys stay in your extension. Backups are encrypted with your password.

Encrypted while waiting. Deleted when collected.

Queued values contain random IDs, an ephemeral public key, a nonce and encrypted timestamp. The extension saves decrypted results locally, then signs an acknowledgement that deletes those events. Tracking images and uncollected events have no expiry. Up to 1,000 events can wait per image; a full queue can miss activity.

Code and policies are public. Anyone with a mailbox capability can inspect its encrypted events. There is no browsable mailbox directory. Publishing ciphertext everywhere would still expose timing and traffic patterns.

Activity is an estimate

Mail apps can preload images, block them or serve cached copies. An image request cannot prove that a person read an email, identify a recipient or prove delivery.

Hosting is part of the privacy picture

Runtime: Vercel. Queue: Upstash Redis. This application sets no cookies, analytics or access logs. Hosting providers still handle network metadata and may retain platform logs under their policies.

Vercel privacy · Upstash privacy

Inspect the implementation

Public source for this deployment · Machine-readable disclosure · Change history

Commit: 5860288bbc9ccbc6a0f6eb78ea539a0594e67333