Privacy

Last updated September 6, 2026.

Email checks

EmailValidly processes the address or domain you submit so it can return validation results. Public single and anonymous bulk checks do not create a saved address history. Accounts store your email address, a salted password hash, a hashed recovery code, session records, saved lists, verification results and credit transactions. Authenticated API requests retain their input fingerprint and result to support safe retries.

Server and abuse-prevention data

Like most web services, hosting infrastructure may process request metadata such as IP address, timestamp, route, browser information and operational logs. EmailValidly also uses temporary in-memory request counts and daily bulk-use counters associated with a hashed IP address to enforce rate limits and reduce automated abuse.

External infrastructure

Verification can involve public DNS queries and a lightweight connection to a receiving mail server. No email message is sent by the verification process. The disposable-domain detector loads a public community-maintained blocklist into server memory.

Accuracy

Receiving mail systems can deliberately obscure mailbox existence. EmailValidly therefore reports some mailbox signals as unknown rather than inferring a definitive result.

Storage and account controls

Account data is stored in a persistent database on Railway. Saved lists remain until you delete them or delete your account. You can export list results from your workspace. Sessions expire after 30 days. API keys and recovery codes are stored as hashes; keep your original credentials private. Deleting an account removes its lists, sessions, API keys and credit history from the application database. Infrastructure backups may retain older copies according to the hosting provider’s retention settings.

Payments

Payments are not enabled yet. When activated, Stripe will process payment details. EmailValidly will store customer and subscription identifiers and billing events, not full payment-card details.

Cookies

The ev_session cookie keeps you signed in. It is HTTP-only and uses secure transport in production. The account features do not require advertising cookies.