High Data Privacy

Privacy policy

Mail2Contact is built around local processing, data minimisation and deliberate sharing.

Last updated: 19 September 2026

Privacy policy

This privacy policy transparently describes local processing, optional server mode, technical connection data and data-minimised usage statistics in Mail2Contact.

1. Controller

The controller for this Mail2Contact installation is Jonas Beseler, Sudetenweg 38, 21614 Buxtehude, Germany, email: jonas@beseler.org.

2. Data and purposes

Depending on how you use the service, Mail2Contact processes technical connection data to deliver and secure the website, local settings for operation, voluntarily submitted email signatures or files for contact recognition, an email address voluntarily supplied to unlock server mode, and usage events without visitor identifiers to improve usability. It creates editable contact data, vCards, QR codes and prepared emails.

3. High Data Privacy mode

When High Data Privacy is active, pasted text is processed in your browser. The analysis does not call the /extract server endpoint and vCards are generated locally as a file. This mode is recommended for sensitive emails.

4. Optional server mode

Only when you deliberately disable High Data Privacy is entered text or an uploaded file sent to and analysed by the Mail2Contact server. Providing it is not legally or contractually required. Without transmission you can use local recognition, although individual file formats may be limited. Server responses use Cache-Control: no-store, and upload and text sizes are limited.

5. QR codes

QR codes are generated entirely in the browser and contain a vCard built from the contact details currently shown. No QR endpoint or external QR service is called, and contact details are not placed in a URL.

6. Email

The email action creates a local mailto link with the contact as a prepared message body. The draft is handed to the selected email client only after an active click; Mail2Contact does not send or store the email.

7. Reset

Clear data discards the input, visible results and the associated short-lived session. Opening the analysis again starts with an empty workspace.

8. Cookies and local settings

Mail2Contact stores the selected language and the High Data Privacy switch locally in your browser. In server mode, a technically necessary session cookie limited to 30 minutes may associate detected contacts with exports. After successful email confirmation, a technically necessary HTTP-only cookie stores the unlock state for no more than 90 days. These storage operations are necessary for functions you explicitly request and are not used for tracking. Analytics sets no cookies or other browser identifiers.

9. Email confirmation

Local browser recognition works without an email address. Server processing and uploads may require one-time email confirmation to limit automated abuse. The plain address is held in memory only while the link is sent and is not stored in the Mail2Contact database. Only an HMAC identifier created with a secret server key is retained. It is pseudonymous, not anonymous. The link contains a random one-time token stored only as a hash and expiring after 30 minutes. Sending and delivery use the email provider configured for the production environment.

10. Data-minimised usage statistics

The browser loads no Umami script and never connects to analytics.beseler.org. It sends only an allowlisted event name, a normalised page path and the language code to Mail2Contact. The server forwards these values to the self-hosted Umami instance using the fixed IP address 0.0.0.0 and a fixed technical user agent. Visitors therefore cannot be distinguished. Referrers, query parameters, screen data, location, contact, input, QR and form contents are not transmitted. Do Not Track and Global Privacy Control suppress these events completely.

11. AI-assisted analysis (optional)

AI analysis is available only when explicitly enabled on the server and the relevant button is displayed. Entered text is sent to the named provider OpenAI or DeepSeek only after your active click. This may involve a third-country transfer. No AI transfer occurs without that click or while High Data Privacy is active.

12. Hosting and technical logs

The app runs on a virtual server at IONOS SE (Elgendorfer Str. 57, 56410 Montabaur, Germany), which acts as a processor under Art. 28 GDPR. To deliver the site and defend against attacks, the server and upstream proxy process technically necessary connection data such as IP address, timestamp, URL and user agent. The app process does not write access logs. Any infrastructure security logs are deleted within seven days unless a specific security incident requires longer retention.

13. Fonts

All fonts (Inter, Manrope) are served directly from the Mail2Contact server. No Google Fonts or other external font services are loaded, so no IP address is transmitted to third parties when a page loads.

14. Security measures

The app uses security headers such as Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and no-store Cache-Control, as well as rate limits and size limits for inputs and uploads.

15. Recipients

IONOS receives technical connection data as hosting processor. The configured email provider receives the email address only to send the confirmation link. The self-hosted Umami instance is operated by the same controller and receives only the non-user-specific values described in section 10. Contact contents reach the Mail2Contact server only in deliberately selected server mode and reach the displayed AI provider only after a separate active AI request.

16. Retention

Contacts recognised in server mode remain only in application memory and are discarded within 30 minutes; they are not backed up. Email one-time tokens expire after 30 minutes, the unlock cookie after 90 days and the pseudonymous email HMAC identifier no later than 180 days after confirmation. Technical security logs are generally deleted within seven days. Umami events without visitor identifiers are kept for no more than 90 days. Local language settings remain until you delete them in your browser.

17. Other people's contact data

Pasted or uploaded emails may contain other people's data. Use local mode when server processing is unnecessary. If you use server mode for business purposes, you must have your own legal basis for transmission and determine whether a data processing agreement is required. Mail2Contact does not use the contents for its own purposes.

18. Legal bases

Delivery, security, email confirmation for abuse prevention and short-term technical processing rely on the legitimate interest in a secure, functional service under Art. 6(1)(f) GDPR. Voluntarily requested server analysis provides the function you request under Art. 6(1)(b) GDPR. Events forwarded to Umami contain no visitor identifier; the connection technically handled by the Mail2Contact server also relies on Art. 6(1)(f) GDPR. Optional AI transmission occurs only after a separate active request.

19. Your rights and objection

You have rights including access, rectification, erasure, restriction, data portability and objection. You may object on grounds relating to your particular situation to processing based on Art. 6(1)(f) GDPR. Do Not Track or Global Privacy Control immediately stops usage events. Send requests or objections to jonas@beseler.org.

20. Right to complain

Under Art. 77 GDPR you may complain to a data protection supervisory authority. The authority regularly responsible for this controller is the State Commissioner for Data Protection of Lower Saxony, Prinzenstraße 5, 30159 Hanover, Germany, poststelle@lfd.niedersachsen.de.

21. Automated decisions

Mail2Contact makes no decisions producing legal or similarly significant effects and performs no profiling.