Back to Railgun Pixel

Railgun Pixel — Privacy Policy

Applies to the Railgun Pixel browser extension, version 0.2 and later. Last updated: September 6, 2026.

The short version: Railgun Pixel has two halves with deliberately different privacy stories. Mail you receive is analysed entirely inside your browser and nothing about it is ever sent to us. Mail you send is only ever registered with Railgun when you personally switch tracking on for that message.

The two halves

Blurring these together would be the easiest way to mislead you, so they are kept apart everywhere in this policy.

Mail you receive

Tracker detection. Runs on your device, sends nothing, needs no account. This has not changed since v0.1 and will not.

Mail you send

Read receipts. Off by default. Only the messages you switch tracking on for are registered with your Railgun account.

Mail you receive: we collect nothing

When you open an email in Gmail, Railgun Pixel inspects the message already displayed in your browser and looks for tracking beacons. This inspection happens entirely on your device. The message is not copied, uploaded, or sent anywhere, and the result of the scan is not sent anywhere either.

For mail you receive we do not collect, receive, or have access to:

  • The content, subject, sender, or recipients of the message
  • Which senders are tracking you, or how often
  • Your browsing history or activity on any other site
  • Analytics or telemetry of any kind

The extension contains no code that transmits anything about a message you received.

Mail you send: what we collect, and when

Nothing at all until you switch Track on for a specific message. Tracking is off by default, and a message you do not switch it on for is never sent to us in any form.

When you send a tracked message, the extension sends us

  • Its subject line and recipient email addresses — so the dashboard can show you which message an open belongs to.
  • The hyperlinks in the message — only when you also switch on link-click tracking, so those links can be rewritten to record clicks.
  • The fact that you chose to track it, and the time you sent it.

The body of your message is never sent to Railgun — not for tracked messages, and not for any other. Attachments are never sent. Your subject lines and recipient lists are encrypted at rest.

When someone opens a tracked message, our server records

  • The time it was opened
  • The IP address the beacon was loaded from, and two things derived from it: the country and the network operator (for example “Brazil” and “Claro”). We do not resolve a city, and we do not send the address to any geolocation service to find out: the lookup runs against a database bundled on our own servers, so the address never leaves them.
  • Whether the fetch came through a mail provider's image proxy (Gmail, Apple Mail) or a hosting or VPN network. In those cases the country is the proxy's or the exit's, not the reader's, and the receipt says so. An automatic pre-fetch by Apple Mail Privacy Protection is recorded but never counted as an open, because it is not one.
  • The user agent, and the device type and mail client we infer from it
  • Which tracked links were clicked, if link tracking is on

To connect the extension to your account

Pairing uses a single-use code, which you either accept on railgun.chat or type into the extension. In exchange the extension stores a token identifying this browser to your Railgun account. That token is a credential: it is held in extension storage, never given to any web page, and you can revoke it at any time from your connected browsers.

About the people who open your mail

A read receipt records information about somebody who never installed our software and never agreed to this policy. We are not going to pretend otherwise, so plainly: when a tracked message is opened, the opener's IP address, country, network operator and mail client are recorded and shown to the sender.

We hold that data only to show the sender their own receipts. It is never sold, never shared with anyone else, never used to build a profile, and never combined across senders. A beacon cannot tell anyone who opened a message — one message carries one beacon for every recipient — and we do not present it as if it could.

If you send tracked mail, you are responsible for your own use of it. Some jurisdictions and some workplaces require you to tell people that you are tracking whether they read your email. Railgun gives you the tool; the obligation to use it lawfully is yours.

Keeping it, and getting rid of it

Tracking data is kept until you delete it. You can, at any time:

  • Stop tracking a message that is already sent — the beacon is in someone else's inbox and cannot be recalled, but we stop recording anything further from it
  • Delete a tracked message's record, which erases every open and click recorded against it
  • Disconnect a browser, which revokes its token immediately
  • Delete your Railgun account, which removes all of it

Stored on your device

Two things live in your browser's extension storage and nowhere else: the device token described above, and a running tally of how many trackers the extension has found for you. The tally never leaves your browser, is not synced across devices, and contains no message content. Clear it with Reset counts in the extension popup.

Permissions, and why

https://mail.google.com/*
To read the message you are viewing so it can be scanned for trackers, and to add the tracking toggle to the compose window.
https://api.railgun.chat/*
To register the messages you choose to track, and to read back their open status. Contacted only for those messages and for your account's own status — never about mail you receive.
https://railgun.chat/*
Pairing only. Lets the Connect page hand a single-use code to the extension, which is why the extension never needs permission to read cookies on a site you log in to.
storage
To keep the device token and the local tally described above.

Third parties, selling, and advertising

We do not sell or transfer your data to third parties. We do not use it for advertising, credit assessment, or lending, and we do not use it for anything unrelated to showing you your own read receipts. The extension loads no remote code and contains no third-party analytics or trackers of its own.

That is a statement about the extension, and it stays true. This website is a separate thing: since September 2026 its public marketing pages use Google Analytics, and only if you accept it. Nothing the extension sees ever reaches it — the extension does not talk to our servers at all. See the privacy policy for what the website collects.

The country, city and network databases used for open locations are stored on our servers and queried there. City and time-zone data is GeoLite2, created by MaxMind (Creative Commons Attribution-ShareAlike 4.0); a city from an address is approximate and is labelled as such. Country data is from ip-location-db (public domain). Network-operator data is derived from RouteViews and DB-IP (Creative Commons Attribution 4.0). No query is ever sent to any of these projects.

A disclosure most trackers won't make

Railgun sells both halves of this: we show you who is tracking you, and we let you track. We think both are legitimate — a sender is entitled to know the fate of a message they wrote, and a reader is entitled to know it is happening. But selling both only stays honest if we hold our own product to the standard we apply to everyone else's.

So: Railgun's read receipt is a 1×1 image that is deliberately not hidden. We do not use display:none to evade detection. Our own tracking domains are on the list this extension checks against, so a Railgun-tracked email arriving in your inbox is flagged by this extension exactly like anyone else's — and is catchable by other people's blockers too. A beacon we would hide from our own detector is not one we should be sending.

Changes

If the extension's behaviour ever changes in a way that affects this policy, this page is updated before that version ships, and the "last updated" date above changes with it.

Contact

Questions about this policy: railgun.chat/support.