What a Check-In Email Reports Back
When a companion reaches out to you by email, that email can report two things back to us, and they do not weigh the same. One is an open, which is recorded and then deliberately kept out of every decision the product makes. The other is a click on the button, which counts. The Record of What You Did read out the record the app keeps. This is its sibling: the one record that starts in your inbox, read out of the code that writes it, with the controls that reach it.
The Image at the Bottom of the Email
The check-in email ends with an image one pixel square, the kind usually called a tracking pixel. It is the last thing in the message, it carries empty alt text and is marked as presentation so a screen reader passes over it, and the plain-text version of the email has none. It is also the only email we send that carries one: its address is built by the check-in sender and handed to the check-in template, and no other sender passes one. It has been there since September 19, 2026, the same day the privacy policy gained a section about it.
The image's address carries a signed token for that one check-in, separate from the token on the button, so the image cannot be passed off as a click. When something requests the image with a valid token, the server does two things, and only the first time: it stamps the check-in with the time of that first fetch, and it writes one event, named outreach_opened, into the same record the earlier article described. This is everything that event holds:
| Field | What it is |
|---|---|
| When | The moment of the first fetch |
| Whose | Your account, because the check-in belongs to it |
| Which check-in | The id of the check-in the image came from |
| Channel | |
| Seconds after sending | How long after the email went out the image was first fetched |
| User-agent | The first 120 characters of the user-agent string the request carried: the label a mail app, or a mail service's image proxy, announces itself with |
| A proxy marker | If that label matches a short list of mail services and security scanners whose machines fetch images by themselves, which one it matched; otherwise empty |
Later fetches of the same image change nothing: the time stays the first one, and no second event is written. A request with a bad token, or one that fails partway, still gets the image back, so a broken link never shows up as a broken-image icon in your inbox. It simply records nothing.
Why an Open Changes Nothing
Once the open is recorded, it is kept out of every decision the product makes about check-ins. It does not mark the check-in as seen. It does not change the check-in's status. It does not count as a response from you, and it does not change when, or whether, your companion reaches out again. The function that records an open is written to set the open time and nothing else, and no part of the code that chooses or schedules a check-in reads that time.
The reason is written into the code's own comments, and the privacy policy gives it in plain words: “many mail providers (including Apple Mail and Gmail) automatically load images before you ever see the message.” A mail program fetching an image proves that the email reached a mail program. It does not prove that a person read it. So an open is treated as what it can actually show, which is delivery, and the policy names that as its only use: telling whether check-in emails are arriving at all.
If an open counted
Then a machine's automatic fetch would speak for you: a note nobody looked at would be filed as seen, and your companion's check-ins would take a mail server's housekeeping for your interest. Recording the open and refusing to act on it is the honest version.
The Button, Which Does Count
The second thing a check-in email can report is a click on its button. The button's link carries its own signed token for the same check-in, and when it is followed the server marks the check-in clicked and seen, counts the note as welcome for that companion, writes one outreach_clicked event holding which check-in it was and the channel, and then opens your conversation with that companion. What a welcome note means for later check-ins belongs to the outreach feature, not to this page.
Once the chat opens, the page may also note that you arrived from a check-in, as it notes any screen you open. That note comes from the page, so unlike the two records above it follows your Product Analytics switch, the consent prompt where one applies, and Global Privacy Control.
Two honest qualifications. The code's own notes allow that a mail security scanner, which follows the links in incoming mail to check them, can register a click before any person does, so a click is strong evidence that someone was there, not proof. And both links belong to the check-in rather than to whoever holds the email: if you forward a check-in, the recipient's open or click is recorded as yours.
What Reports Nothing
Short of its unsubscribe link, which is a control rather than a signal and comes next, nothing else you can do with a check-in email reports anything. Reading it with images switched off, reading it after something has already fetched the image, leaving it unread, archiving it, deleting it: none of it adds anything to the record. Ignoring an email check-in is not recorded at all; the only check-ins the product ever treats as ignored are notes inside the app, which are the outreach feature's territory.
The Controls, Narrowest First
Three controls reach a check-in email, and they differ in how much they stop. Every check-in email carries a Manage check-in settings link near the bottom, which opens the dashboard settings where two of them live.
Turn off remote images: the open stops, the email stays
Your mail app's setting for remote images, sometimes called external images or remote content, decides whether your app asks for the pixel at all, and an image nobody asks for writes nothing. The privacy policy names this as the control: “Blocking remote images in your mail app prevents this entirely and does not affect the email's content.” The second half you can check against the template, because the pixel is the only image the email carries. The words and the button are untouched, and a click still counts.
Unsubscribe from check-in emails: no email, no image
The unsubscribe link at the bottom of a check-in email turns off check-in emails and nothing else. It is the same as switching off Email Check-Ins in your dashboard, under Settings, then Companion Check-Ins, and if your mail app shows its own unsubscribe button on a check-in email, that does the same thing. With no check-in email there is no image to fetch. Check-in notes inside the app carry on, and so does every other email.
Switch off Marketing Emails: no check-ins at all
Marketing Emails, under Settings, then Email Preferences, is the widest switch. Turned off, it stops check-ins on both channels, the notes inside the app as well as the emails, because it is read before the product decides how a check-in would travel. It stops the digest and campaign mail too. Its label talks about product updates, tips and offers and never mentions check-ins, which is why every email InnerHaven can send you spells out what it reaches.
What the Analytics Switch Does Not Reach
The Product Analytics switch, under Settings, then Privacy, and the Global Privacy Control signal your browser can send both govern what pages send. Each is checked in your browser before an event is built, and checked again on the server before one is written.
The honest limit
The open is not sent by a page. The server writes it at the moment the image is fetched, and the code that writes it checks neither the switch nor the signal, so neither one stops it. The same goes for the click's record. The privacy policy says it plainly: because the record is part of delivering email rather than product analytics, “the analytics switch above does not turn it off; blocking remote images, or turning check-in emails off, does.”
Where to See It, and How It Goes
Both halves are in your data export: Settings, then Your Data, then Download my data. The check-in itself is a row in the companion outreach events section, carrying when it was sent and, if they happened, the time of the first open and the time of the click. The opened and clicked events are rows in the product events section: the opened event with the fields in the table above, the clicked event with the check-in and the channel. Delete your account and both go with everything else. The image is also listed beside the rest of what we collect in Your Privacy, Your Control.
The short version
Two things report back. An open records the first fetch of a one-pixel image, how long after sending, and the first 120 characters of the user-agent string, then changes nothing, because a mail program can fetch an image before anyone reads. A click on the button counts as your answer. Apart from the unsubscribe link, nothing else reports anything. Remote images off stops the open, the unsubscribe link or Email Check-Ins stops the emails, Marketing Emails off stops check-ins altogether, and the Product Analytics switch reaches neither record. Your export shows both.
Choose What Reaches You
Settings, then Companion Check-Ins, for the email channel. Settings, then Email Preferences, for the widest switch.
Open Your Settings