Email Ferret logo
Email Management · Security Fraud

Email Ferret

Email Ferret is a Gmail and Google Workspace add-on that scores incoming mail, labels the AI-generated cold outreach ordinary spam filters let through, and files everything else into smart folders — all without ever storing message bodies.

Active GDPR compliant Free trial Subscription No public API 13+ Verified by Guidaio
Overview

What is Email Ferret?

Email Ferret is a filtering layer that sits on top of Gmail and Google Workspace and answers one narrow question about every message that arrives: was this written for you, or generated and sent to a list?

The problem it targets is not classic spam. AI-written cold outreach passes SPF, DKIM and DMARC, arrives from warmed-up domains with good reputation, and reads as though a person wrote it — so Gmail delivers it. Email Ferret ignores reputation and scores behaviour instead: whether the sender is new with no conversation history, whether the message carries sales framing and a call to action, whether it looks like one step in a timed follow-up cadence, whether the personalisation is a name dropped into a template, and whether it bears the fingerprints of known sending platforms. Apollo, Instantly and Outreach are named among the tools it recognises. More than fifteen signals feed a transparent score, and messages sitting in the ambiguous middle get a second pass from a language model before anything is labelled.

What happens next is deliberately unspectacular. Flagged mail gets a Gmail label and, if you ask for it, an archive — nothing is ever deleted and every action is reversible. Everything that survives the check is filed into more than ten smart folders (Important, Calendar, Billing, Recruiting, Updates, Finance, Socials, News, Shopping), which you can switch on or off, rename, or extend with your own routing rules. Sensitivity is adjustable per mailbox, the allowlist always wins over detection, and a one-click correction feeds back into later decisions.

Privacy is the other half of the pitch. Message bodies are analysed in memory and discarded; only subject lines and message ids are kept, encrypted with AES-256-GCM and isolated per user with row-level security. The app asks for gmail.modify, gmail.labels and userinfo.email — no permission to send, compose or reply exists at all. Setup is a Google sign-in with nothing to install, and an optional Chrome extension surfaces scores inside Gmail.

What it does

  • Score every incoming Gmail message against more than 15 behavioural cold-outreach signals
  • Label the AI-generated sales outreach that Gmail's own spam filter delivers
  • Show the exact signals behind each score, with no black box
  • Sort legitimate mail into 10+ smart folders such as Important, Calendar, Billing and Recruiting
  • Archive flagged mail on request — never delete it, never modify it
  • Learn from allowlist entries, blocklist entries and one-click corrections
  • Run a language-model second pass on the genuinely ambiguous messages
Audience

When to use Email Ferret / When not to

A quick filter to help you decide if Email Ferret is the right fit.

When to use Email Ferret

  • Founders and startup executives buried under investor, partner and vendor pitches
  • Engineering leads and developers who want GitHub and CI alerts visible under the recruiter noise
  • Recruiters and HR managers separating candidate mail from staffing-agency and HR-tech pitches
  • Lawyers, consultants and other billable professionals whose attention is the product they sell
  • Solo operators and freelancers on personal Gmail who want one cheap tool rather than a tiered suite

When not to use Email Ferret

  • Anyone on Outlook, Yahoo or iCloud — Email Ferret connects to Gmail and Google Workspace only
  • People wanting a one-off cleanup of an old backlog; scoring applies to incoming mail, not to what is already sitting there
  • Teams that need centralised billing, an admin console or shared lists today — the team plan is still announced as coming soon
  • Developers looking for an API or webhooks to build on: no public API and no developer documentation is published
  • Anyone who needs a permanently free tier, since past the 14-day trial there is only the paid plan
Get started

How to use Email Ferret

A typical end-to-end flow, from setup to results.

  1. Open the Get Started link and create an account
  2. Connect your Gmail or Google Workspace mailbox through Google OAuth — one click, no password typed
  3. Let Email Ferret create its labels; filtering starts on the next message that arrives
  4. Choose which of the 10+ smart folders to enable, and add custom folders or routing rules if you want them
  5. Set the sensitivity threshold for that mailbox
  6. Decide what happens to flagged mail: label only, archive, or a daily digest
  7. Build the allowlist for senders you always want through, and the blocklist for those you never do
  8. Correct any mistake from the dashboard with the Report button — corrections feed later scoring
  9. Optionally install the Chrome extension to see scores and allowlist senders without leaving Gmail
  10. Add a payment method before day 14 if you are keeping it; reminders arrive 7, 3 and 1 day out
Quick read

Pros & Cons

Pros

  • One flat price, 5 USD per mailbox per month, everything included and no tiers
  • Fourteen-day trial with no card required, and no automatic charge if you never add one
  • Message bodies are never stored — only encrypted subject lines and message ids
  • Every flag is explained signal by signal instead of simply asserted
  • Nothing destructive: labelling and optional archiving only, all of it reversible
  • Adds to Gmail rather than replacing it, and your existing Gmail filters still run first
  • Setup is a Google sign-in, with no rules to write and nothing to install

Cons

  • Gmail and Google Workspace only — no Outlook, Yahoo or iCloud
  • No permanent free plan, and billing is per mailbox, so two accounts cost twice
  • The team plan with centralised billing, admin dashboard and shared lists is still marked coming soon
  • No public API and no developer documentation
  • The vendor is barely identifiable: no registered company name, no postal address, no named founder, and a domain only registered in November 2025
  • The site contradicts itself — the terms require a card for the trial while every other page says none is needed, and retention is 90 days in the privacy policy but 30 days after cancellation on the features page
  • Usage claims and star ratings are unaudited, and the testimonials are non-attributable
Pricing

Pricing & Plans

There is no permanent free plan. Email Ferret offers a 14-day free trial with full access and, according to its pricing pages, no credit card required. Beyond the trial, the single paid plan costs USD 5.00 per Gmail mailbox per month, each additional mailbox being billed separately. The subscription may be cancelled at any time, with access running to the end of the period already paid for.

Plan 1
  • Free trial — 14 days
  • full access to every feature
  • no credit card required
  • with reminders 7
  • 3 and 1 day before it ends
Team Plan — announced as coming soon
  • everything in the individual plan plus centralised billing
  • a team admin dashboard
  • shared allowlist and blocklist
  • volume discounts from 5 mailboxes and priority support
  • waitlist through the contact page
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Email Ferret handles your data.

GDPR overview

Compliance is asserted rather than documented. The only literal reference to the GDPR anywhere on the site is a GDPR Compliant badge in the footer, repeated on every page: there is no GDPR section, no stated legal basis, no published DPA and no Article 27 EU representative. The privacy policy, last updated on 22 November 2025, does list rights that map onto GDPR ones — access, rectification, erasure, export of allowlist data, and opting out by disconnecting the account — but it never names the regulation. No data protection officer is designated and no dedicated privacy address exists: every request, deletion included, goes to the general support mailbox. The terms place the contract under United States law and the exclusive jurisdiction of United States courts, with no carve-out for EU residents.

Who owns the data?

The terms are unambiguous on ownership: you keep every right to your Gmail data and content, and you grant Email Ferret only a limited licence to access and process it for the sole purpose of running the service. The software, its features and its code remain the vendor's property. The privacy policy states that personal information is never sold, traded or rented, and that only aggregated, anonymised data — which cannot be traced back to an individual — may be shared for service improvement. Three named subprocessors touch the data: Supabase for database storage, Vercel for application hosting and Stripe for payments. Google API data is additionally bound by Google's Limited Use requirements.

Reuse rights

You can reuse your own Gmail data freely: the terms grant you all rights to it, so nothing has to be asked of the vendor. The privacy policy adds an explicit right to export your allowlist, and the terms let you request a data export before closing the account. Access can be withdrawn at any moment from either side — disconnect the mailbox inside Email Ferret, or revoke the app from your Google account settings — and filtering stops immediately. Labels already written are ordinary Gmail labels: they stay yours to keep, rename or delete. What the terms forbid is reverse-engineering the service, sharing your account credentials, and any unlawful use.

Data retention & training

Retention summary
Message bodies are never retained: they are analysed in memory and discarded. What persists is the minimum needed to run the dashboard — subject lines and message ids, encrypted with AES-256-GCM and isolated per user. Account details and allowlist entries are kept for as long as the account is active. Beyond that the site gives two different answers: the privacy policy says message logs are held for up to 90 days for service improvement, while the features page states retention runs until account deletion or 30 days after cancellation. Deletion can be requested at any time, and deleting the account removes stored subjects, ids, allowlist, blocklist and OAuth tokens. Labels already applied stay in Gmail and can be removed by hand.
Trains on customer data
Unclear
Subprocessors disclosed
Yes

Hosting summary

Email Ferret does not say where your data lives. No hosting country and no region is named anywhere on the site; only three subprocessors are, each cited without a location — Supabase for database storage, Vercel for serverless application hosting and Stripe for payments. What is described is the treatment rather than the geography: message bodies are analysed in memory and never written to a database, only subject lines and message ids are kept, everything stored is encrypted with AES-256-GCM, OAuth tokens are encrypted before persistence, Gmail passwords are never stored, and each account is isolated by row-level security. Use of Google API data is stated to follow Google's API Services User Data Policy, Limited Use requirements included. Legally, the terms place the agreement under United States law with exclusive jurisdiction in United States courts. One technical observation, not a vendor statement: the domain resolves to an IP address geolocated in the United States, on Amazon's AS16509. For an EU buyer, the absence of any declared hosting location, alongside the absence of a DPA, is the gap to raise before signing.

Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Email Ferret.

  • The OAuth scope grants read access to the full content of every incoming message, privileged correspondence included — a wider reach than filtering strictly needs
  • False positives are inevitable and the vendor says so: a founder writing to you personally reads exactly like a good cold email, and with archiving enabled a wanted message can leave the inbox unannounced
  • Handing triage to an automation erodes the habit of checking secondary folders yourself, so the cost of a miss grows quietly over time
  • The no-body-storage promise rests entirely on the vendor's word: no SOC 2, ISO 27001 or third-party audit is published
  • With no registered entity, no address and no named officer anywhere on the site, there is nobody identifiable to address a dispute to
  • The terms impose United States law and courts with no provision for EU residents, and cap liability at twelve months of fees or 100 USD
  • A minimum age of 13 is very low for a tool that reads an entire mailbox
Setup

Setup & Integrations

Technical difficulty

Close to none. Connecting a mailbox is a Google OAuth sign-in: one click, no password typed, nothing installed on your machine, since the filtering runs server-side. There are no rules to write, no keyword lists to maintain and no training period to sit through — labels are created and the next message that arrives is scored. The site quotes setup at about a minute in its FAQ, two minutes on the features page and five on the how-it-works page. Everything beyond that, from sensitivity to active folders, routing rules and lists, is optional tuning.

Deployment

Web appBrowser extensionChrome extension

Integrations

Gmail Google Workspace

Supported languages

English
Company

Behind Email Ferret

Company name
Email Ferret
Founded
09/01/2026
Country of origin
🇺🇸 United States
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Email Ferret.

S SaneBoxS SuperhumanC Clean EmailH HEYL Leave Me AloneM MailstromA alfred_
FAQ

Frequently asked questions

Which mailboxes does Email Ferret work with?
Gmail and Google Workspace, and nothing else. Outlook, Yahoo and iCloud are not supported. The vendor presents it as a deliberate trade, because several of its strongest detection signals depend on conversation history and thread state that Gmail exposes well.
How is this different from Gmail's own spam filter?
Gmail targets mail that is malicious or fraudulent. AI-written cold outreach is neither: it passes SPF, DKIM and DMARC and comes from reputable, warmed-up domains, so Gmail delivers it. Email Ferret scores intent and behaviour instead — was this written for you, or generated and sent to a list?
Will it delete any of my email?
No. The default action is a Gmail label, which leaves the message exactly where it was. You can additionally choose to archive flagged mail, but archiving is not deletion: the message stays in All Mail, and every action is reversible.
Is my email content stored?
No. Bodies are analysed in memory and discarded, never written to a database. Only subject lines and message ids persist, encrypted with AES-256-GCM and isolated per account with row-level security.
What does it cost?
USD 5 per Gmail mailbox per month, one tier, everything included. A second mailbox — a work inbox alongside a personal one — is billed as a second mailbox.
How does the free trial work?
Fourteen days with full access. The pricing page and the FAQ state that no credit card is needed to start, with reminders 7, 3 and 1 day before it ends and no charge if no card is added. Note that the terms of service say the opposite — that a card is required — so check at sign-up.
Can I see why a message was flagged?
Yes. Each scored message shows the signals that contributed and the score they produced, so a flag can be inspected and disagreed with rather than taken on faith.
What if it flags something I actually wanted?
Remove the label and add the sender to your allowlist; mail from that address always reaches the inbox afterwards. Nothing was deleted, so the mistake costs only the seconds it takes to find the message under its label.
Do I have to install anything?
No. Filtering happens server-side, so it works in the Gmail web interface, on a phone, or in a desktop client. A Chrome extension exists as an optional convenience layer that surfaces scores and lets you allowlist a sender without leaving Gmail.
Is there a team plan?
It is announced but not released. The pricing page lists centralised billing, an admin dashboard, a shared allowlist and blocklist, volume discounts from five mailboxes and priority support as coming soon, with a waitlist through the contact page.
Conclusion

Should you pick Email Ferret?

Email Ferret does one thing, on one platform, for one price, and is unusually clear about all three. It filters Gmail and Google Workspace against AI-generated cold outreach — mail that is technically legitimate, properly authenticated and therefore delivered by every reputation-based filter — and files whatever survives into smart folders. At 5 USD per mailbox per month after a 14-day trial, it is the cheapest entry in the comparison table the vendor publishes itself.

Two design choices carry the product. The first is transparency: every flag is broken down into the signals that produced it, which turns a verdict into something you can argue with. The second is restraint: it labels and optionally archives, never deletes, and holds no permission to send, compose or reply. Existing Gmail filters still run first. Message bodies are analysed in memory and thrown away, with only encrypted subject lines and ids retained.

The reservations concern the vendor rather than the product. No registered company name, no postal address and no named founder appear anywhere on the site; the domain was registered in November 2025 and first archived in January 2026, so there is no track record to lean on. GDPR compliance rests on a footer badge, with no DPA, no Article 27 representative and United States law governing the contract. The site also contradicts itself twice: on whether the trial needs a card, and on how long message logs are kept.

For an individual Gmail user drowning in automated pitches the risk is small and bounded — fourteen days, no card, nothing destructive, cancellation from the billing page. For a regulated organisation handling client correspondence, the missing paperwork weighs more than the price, and the team plan has not shipped.