Privacy Policy
Last updated: June 6, 2026
Overview
FirstPass ("we", "us") provides email verification tools via our web app and this website. This policy explains what we collect, how we use it, and your choices.
Information we collect
- Account data: Email address, username, and hashed password when you sign up for a trial or paid plan.
- Verification activity: We store hashed email identifiers and verification results in a shared cache — never plaintext email addresses in the cache.
- Domain format intelligence: Aggregated email format patterns per domain (e.g.
first.last@company.com) to improve verification accuracy. - Billing: Payment processing is handled by Paddle. We receive subscription status and customer identifiers from Paddle, not full card numbers.
- Device data: Device ID and last-seen timestamps for license enforcement and security.
How we use data
We use your information to provide the service, enforce plan limits, improve shared cache and format intelligence, send account emails, and comply with legal obligations.
Data retention
Verification cache entries and domain format patterns expire automatically after 60 days unless configured otherwise. Audit logs are retained up to 90 days. Account data is kept while your subscription or trial is active and for a reasonable period afterward.
Security
Passwords are stored using industry-standard hashing. Cache keys use one-way SHA-256 hashes with a global pepper — raw emails are not stored server-side in the verification cache.
Third parties
- Paddle — payment processing and subscription management
- Resend — transactional email delivery (when configured)
- Email verification providers — you connect your own API keys in the web app; we do not store provider API keys on our servers
Your rights
You may request access, correction, or deletion of your account data by contacting support@firstpass.email.
Contact
Questions about this policy: support@firstpass.email
See also our Terms of Service.