Privacy policy
This privacy policy explains which data Mail2Contact processes, when data stays local in your browser and when data is sent to the app server or to services you choose.
High Data Privacy
Mail2Contact is built around local processing, data minimisation and deliberate sharing.
Last updated: 12 July 2026
This privacy policy explains which data Mail2Contact processes, when data stays local in your browser and when data is sent to the app server or to services you choose.
The controller for this Mail2Contact installation is Jonas Beseler, Sudetenweg 38, 21614 Buxtehude, Germany, email: jonas@beseler.org.
Mail2Contact processes email signatures, pasted email text and uploaded email files in order to detect contact details, display confidence scores and create vCards, web business cards, CSV or JSON exports.
When High Data Privacy is active, pasted text is processed in your browser. The analysis does not call the /extract server endpoint and vCards are generated locally as a file. This mode is recommended for sensitive emails.
When High Data Privacy is disabled, the entered text or uploaded file is sent to the Mail2Contact server and analysed there. Server responses are delivered with Cache-Control: no-store. Uploads and text lengths are limited.
QR codes are generated by this Mail2Contact app via its own /qr.svg endpoint. No external QR service is contacted. In High Data Privacy mode the QR code is created in your browser and contains a vCard directly, so scanning does not open a web link.
Share links are built locally from the detected contact details. Data is only handed to WhatsApp, an SMS app, an email client or other services when you actively open the respective link.
In server mode a web business card can be generated from a URL containing contact parameters. This URL may contain personal data. Only share it deliberately with recipients who should receive that data. Web business cards are not stored on the server.
Mail2Contact stores the selected language and the High Data Privacy switch locally in your browser. A technically necessary session cookie may be used to briefly associate detected contacts with exports. This serves operating the app, not tracking.
Mail2Contact counts page views on the server only in aggregate by hour, path, language, referrer host, coarse browser or bot family and HTTP status. No analytics cookies are set, no user ID is created and no IP address is stored in the statistics. In addition, the self-hosted, cookieless analytics tool Umami (umami.beseler.org, operated by the same controller) is used; it works without cookies and without personal profiles.
If an AI provider is configured on the server, you can additionally trigger an AI-assisted analysis (the "Analyze with AI" button). Only then – and only after your active click – is the entered text sent to the configured provider (DeepSeek or OpenAI) and analysed there; this may involve a transfer to a third country (e.g. the USA). Without your click no AI transfer takes place, and regular detection runs exclusively via the local rule-based parser. High Data Privacy mode never uses AI.
The app runs on a virtual server at IONOS SE (Elgendorfer Str. 57, 56410 Montabaur, Germany), which acts as a processor under Art. 28 GDPR. When the site is accessed, the server processes technically necessary connection data such as IP address, timestamp, requested URL and browser information in server and proxy logs. These serve delivery, security and error analysis and are deleted at short notice (guideline: a few days).
All fonts (Inter, Manrope) are served directly from the Mail2Contact server. No Google Fonts or other external font services are loaded, so no IP address is transmitted to third parties when a page loads.
The app uses security headers such as Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and no-store Cache-Control, as well as rate limits and size limits for inputs and uploads.
Analysis results are not stored permanently. Recently detected contacts are held only in the app process memory for a maximum of 30 minutes to enable exports within the same session, after which they are discarded automatically. There is no permanent storage on disk and no backup of this content.
When pasting or uploading emails you may process personal data of other people. You as the user are generally responsible for this processing; Mail2Contact merely provides the tool. Web business cards are not stored on the server but generated solely from the parameters of the URL you share.
The legal basis for providing the website and the aggregated usage statistics is the legitimate interest in secure, functional operation (Art. 6(1)(f) GDPR). Server mode processes the content you submit to provide the function you requested.
Depending on applicable law, data subjects may request access, rectification, erasure, restriction of processing, data portability and objection. Because content processed in server mode is only held transiently (max. 30 minutes), it is usually already deleted before a request arrives. Requests can be sent to jonas@beseler.org.
This statement does not constitute legal advice. Before broader public SaaS use it should be reviewed by a qualified party and reconciled with the imprint, data processing agreements, hosting, logs and any payment services.