Lead Generation
Hunter
Rest of world Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Hunter Web Services, Inc. · hunter.io
Compare with Snov.io → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Hunter is an email finder and verifier built on public web sources, sold by Hunter Web Services, Inc., a Delaware company with servers in Belgium, an EU representative in Ireland, and transfers outside the EEA on Standard Contractual Clauses. The bench scores it strongest on data provenance, crediting plainly named sourcing — addresses published on public pages plus pattern-generated ones — a Legitimate Interest Assessment, a self-service claim page, and profile removal within 3 months. Weakest is visitor identification: we found no public information on identifying companies behind website visits, only a Signals line with per-plan counts on the pricing page. CRM sync and export scores cluster at 4, on native sync to HubSpot, Zoho, Salesforce and Pipedrive plus a public API. Pricing transparency is where the judges genuinely split: most score 4 for published credit allowances and unlimited users on all plans, while the skeptic scores 2 because the pricing page never states the euro price of the Starter, Growth and Scale tiers and gives different figures for the free plan's monthly credits.
Speaks for it
- Sourcing is stated plainly — emails collected from pages where they were published or pattern-generated from public sources, with a Legitimate Interest Assessment and DPIA conducted
- People in the database get a self-service claim page to update or delete their record, and profiles are removed within 3 months of leaving their source pages
- Native sync to HubSpot, Zoho, Salesforce and Pipedrive, plus 5,000+ Zapier endpoints, CSV export, a public API and an MCP server
- Generated emails are validated for technical deliverability and carry confidence scores
- Free plan at 0€ with no credit card and no trial, and unlimited users on all plans
Held against it
- We found no public information on website visitor identification — the pricing page carries a Signals line with per-plan counts and no captured description of what it does
- The pricing page gives credit allowances for Starter, Growth and Scale without stating euro prices, and the captured pages give different figures for the free plan's monthly credits
- The terms seat the customer as an independent controller, and we found no public information on a suppression or do-not-contact list or do-not-call register checks
- The terms reserve the right to modify or discontinue API access with or without notice, and upgrade fees are non-refundable
- The contracting entity is Hunter Web Services, Inc. of Delaware under Delaware law, and AI email writing runs through OpenAI with API data retained up to 30 days
Best for
- You build outbound email lists from public B2B web sources and want the sourcing and legal basis documented — data provenance scored 5-7, the strongest category on the bench
- You run cold-email sequences from Gmail or Outlook and sync results to HubSpot, Salesforce, Zoho or Pipedrive — CRM sync and export scores cluster at 4
- You want a no-cost start without seat math — the free plan is 0€ with no credit card and no trial, and all plans include unlimited users
Avoid if
- You need to identify the companies visiting your website — visitor identification scored 0-1, and the only trace is an undescribed Signals line on the pricing page
- You must compute your annual invoice before committing — the pricing page publishes credit allowances but not the euro prices of the paid tiers
- You require an EU contracting entity — you would sign with Hunter Web Services, Inc. of Delaware under Delaware law, with AI email writing processed by OpenAI
- You expect the vendor to carry outreach compliance — the terms make you an independent controller for what you do with the contacts
The scores
Coverage, accuracy & freshness
Show reasoningHide reasoning
How this is scored
How much of the target market the database actually covers — judged on DACH and EU coverage as much as North American — and what the vendor documents about verification and refresh, because accuracy claims cannot be checked from outside.
0 — No stated coverage, no refresh cadence, no verification method; accuracy asserted as a percentage with nothing behind it.
3 — Headline record counts for the whole database, thin or unstated European coverage, and no description of how often records are re-verified.
5 — Coverage stated per country or region including DACH, email verification described, a stated refresh cadence, and firmographics beyond name and domain.
8 — Coverage broken down by country, industry and data type (email, direct dial, mobile), verification method and refresh cadence documented, company data drawn from official registers where available, and a bounce or credit-back guarantee with stated terms.
10 — The vendor is accountable for its data: per-country coverage and accuracy methodology published, every field carrying a last-verified date visible to the user, register-sourced company data, and credit-back terms that make inaccuracy the vendor's cost rather than the buyer's.
The SDR Team Lead
The headline numbers are sources and campaign volume — 650M+ public sources, 1.2B+ leads contacted — with no per-country breakdown, and we found no public information on DACH figures or a re-verification cadence. Email quality is at least documented: deliverability validation, confidence scores, and auto-verified lead data on all plans, though the terms are "as is" with no refunds when bounces land on my list. For my team the bigger gap is phones — we found no public information on direct dials or mobile numbers. 1 2 3 4
The RevOps Manager
Headline numbers exist (650M+ public sources of data, 1.2B+ leads contacted), but there is no country-level or DACH coverage statement and no re-verification cadence; the nearest freshness fact is that profiles are removed within three months of leaving their source pages. Generated emails carry confidence scores and deliverability validation, yet we found no public information on accuracy methodology, register-sourced company data, or credit-back terms for inaccurate records. 1 3 4
The Data Protection Officer
The headline figures — 650M+ public sources of data and a B2B database with basic or advanced filters — are the scale evidence we have; we found no public information on coverage by country, on DACH coverage, or on any re-verification or refresh cadence. Verification is described in method terms (confidence scores, technical deliverability checks, auto-verified lead data), but the terms disclaim all warranties and treat upgrade fees as non-refundable, so the cost of a bad address stays with the buyer. 1 2 3 4
The ABM Marketer
The public pages give one headline figure — 650M+ public sources — and I found no public information on DACH or wider European coverage by country or region. Verification is described only as deliverability validation with confidence scores on generated addresses; I found no public information on a refresh cadence, last-verified dates, or bounce and credit-back terms. 1 3 2
The DACH Sales Director
Headline counts of 650M+ public sources and a claim of auto-verified lead data are the whole coverage story — nothing broken down for Germany, Austria or Switzerland, no register-based company data, and no re-verification cadence beyond profiles being removed within three months of disappearing from their source pages. Deliverability validation with confidence scores is described for generated emails, but I cannot tell a Mittelstand buyer how deep DACH coverage actually is, and I found no public information on a bounce or credit-back guarantee. 1 3
The Skeptic
The homepage counts scale of operations, not market coverage — 650M+ public sources and 1.2B+ leads contacted — and we found no public information on coverage by country, DACH included, or on a stated re-verification cadence. Verification itself is described (confidence scores, deliverability checks), and the privacy policy says profiles are removed within 3 months if they leave their source pages, which is the closest thing to a freshness statement on the captured pages. We found no public information on a bounce or credit-back guarantee. 1 3
Data sources & lawful basis
Show reasoningHide reasoning
How this is scored
Where the personal data in the database comes from and on what legal basis it is processed — as evidenced on the vendor's own pages. Covers Art. 6(1)(f) legitimate interest, the Art. 14 notice to the people in the database, and whether they can find, object to and remove their record.
0 — No statement of where contact data comes from or on what legal basis; "GDPR-compliant" asserted without explanation, and no way for a listed person to object.
3 — Sources described in general terms ("public sources", "partners"), legitimate interest named without any balancing, and an opt-out request form as the only route for data subjects.
5 — Source categories named (registers, company websites, contributory networks, licensed partners), legitimate interest stated as the basis for EU records, a dedicated privacy notice for the people in the database, and a self-service opt-out or removal process.
8 — The above plus an Art. 14 notification practice described (people informed when added), contributory or browser-extension collection disclosed as such, a legitimate-interest assessment summarised publicly, and EU records handled differently from US records where the law differs.
10 — Provenance is traceable per record: the source and collection date available for each contact, Art. 14 notices sent and documented, the balancing test published, objections honoured across the whole dataset and suppressed permanently, and no data sourced by scraping behind logins or from contributors' address books without their contacts' knowledge.
The SDR Team Lead
Sources are named concretely — addresses crawled from public web pages plus pattern-generated ones, robots.txt respected, private consumer data skipped — and the people in the database get a self-service claim page to update or delete their record, with removal inside three months. Legitimate interest is the stated basis with an assessment conducted, but the summary is only available on request, and we found no public information on notifying people when they are added. 3
The RevOps Manager
Sources are described concretely — emails collected from pages where they were published plus pattern-generated addresses from public sources, with the robot respecting robots.txt and skipping private consumer data — and a Legitimate Interest Assessment and DPIA are described, with summaries available on request. People in the database get a self-service claim-and-delete route and profiles drop within three months of leaving their sources. What is missing for a higher score: we found no public information on notifying individuals when they are added, nor per-record source and collection date traceability. 3
The Data Protection Officer
Source categories are named plainly — addresses published on public web pages and addresses generated by pattern analysis from names and affiliations — and legitimate interest comes with a published balancing conclusion, a Legitimate Interest Assessment offered on request, and a robot that respects robots.txt and skips private consumer data. People in the database get a genuine self-service route: a Claim feature to update or delete their record, removal within three months of a request or when the source page drops them. We found no public information on any Article 14 notification practice when people are added, on per-record source traceability, or on EU records being handled differently from US records. 1 3
The ABM Marketer
Sources are named concretely — addresses collected from websites where they were published plus pattern-generated addresses from public sources — with a conducted legitimate-interest assessment whose summary comes only on request, and a self-service claim route for people to update or delete their record. I found no public information on an Art. 14 notification practice or per-record source and collection date. 3 4
The DACH Sales Director
Sources are named plainly — emails collected from public web pages plus pattern-generated addresses derived from names and affiliations on public sources — with a legitimate interest assessment conducted, robots.txt respected, and a self-service claim route at hunter.io/claim to update or delete a profile. The balancing assessment is available only on request rather than published, and I found no public information on an Article 14 notification practice telling people when they are added, nor any different handling of EU versus US records. 1 3
The Skeptic
Sourcing is unusually candid: emails are either collected from pages where they were published or generated by pattern analysis from public sources, with a Legitimate Interest Assessment and DPIA said to exist, their summaries available on request rather than published. Listed people get a self-service claim page to update or delete their record, the crawler is stated to respect robots.txt and skip private consumer data, and balancing is asserted for the professional B2B context. We found no public information on an Article 14 notification practice when people are added, or on per-record source and collection date. 1 3
Visitor identification & intent signals
Show reasoningHide reasoning
How this is scored
Identifying companies behind website visits and surfacing buying intent — scored on what is identified (company or person), how the tracking works, and whether the vendor states that its script needs consent under §25 TDDDG and how it behaves without it.
0 — No visitor identification or intent data, or person-level identification of EU visitors with no statement of legal basis.
3 — Reverse-IP company identification with a cookie-setting script, no statement about consent, and match rates claimed without method.
5 — Company-level identification with filters, visit history per company, a stated position that the script requires consent where it sets cookies, and a consent-mode or cookieless option.
8 — Company-level only for EU traffic by design, cookieless operation documented, integration with common consent management platforms, intent topics or page-level signals with the source of third-party intent data named, and alerts routed to owners.
10 — Identification that survives a DPO review: no personal data of visitors stored, the TDDDG and GDPR position published and specific, third-party intent data sourced from a named co-op or panel with its consent basis stated, and scoring on intent that the user can trace back to the underlying visits.
The SDR Team Lead
We found no public information on identifying companies behind website visits — no tracking-script description, no consent statement under the German telemedia tracking rules, no match-rate method. A Signals line appears in the pricing table with per-tier counts, but nothing captured describes what it identifies or how it works. 2
The RevOps Manager
We found no public information on website visitor identification, company-level or otherwise, on intent data, or on any tracking script and its consent position. The pricing table carries a line called Signals with plan limits, but the captured pages include no description of what it does. 2
The Data Protection Officer
The pricing page carries a per-plan Signals allowance and the privacy policy retains a Visitor Data category for up to fourteen months, but we found no public information describing what visitor identification exists — company or person, or how any tracking works — nor any statement that a script needs consent under the German telecommunication-telemedia data protection law or how it behaves without it. An unexplained counter and a retention line do not document a capability. 2 3
The ABM Marketer
This is the deal-breaker for my 300-account list: I found no public information on company-level visitor identification, reverse-IP tracking, intent topics with a named third-party source, or alerts routed to account owners. The only trace is a Signals line on the pricing page with per-plan counts and no description anywhere captured of what a signal is. 2 1
The DACH Sales Director
I found no public information on any website visitor identification or intent product — no reverse-IP company matching, no statement on consent under the TDDDG, no cookieless mode. A plan line called Signals appears in the pricing with no description of what it identifies or how it tracks, and for a DACH buyer that is not visitor identification. 1 2
The Skeptic
We found no public information on identifying the companies behind website visits — no captured page describes a tracking script, reverse-IP matching, or a consent position under the German cookie-and-tracking rule. What is evidenced is email-level engagement tracking (opens, links, custom tracking domain) inside sequences, plus a tiered "Signals" feature and AI "proactive suggestions" with no captured description of what they measure or where it comes from. Neither is website visitor identification. 2 3
Prospecting workflow & outreach rules
Show reasoningHide reasoning
How this is scored
Search, list building and outreach — and whether the product helps the buyer stay within UWG §7 and the GDPR once the list exists, rather than leaving the legal risk entirely with the customer.
0 — A search box and an export button; nothing on the pages about what the buyer may lawfully do with the contacts.
3 — Filters on firmographics and job title, saved lists, and a terms clause making the customer solely responsible for compliance.
5 — Advanced filters including technographics and triggers, company-level lists and alerts, a global suppression or do-not-contact list, and guidance on cold outreach rules in the main EU markets.
8 — The above plus country-aware handling (for example flagging German contacts where cold calls and emails require consent), phone numbers checked against national do-not-call registers where they exist, and opt-outs from outreach synced back to the database.
10 — Compliance is part of the workflow: outreach channels restricted or flagged per country and contact type by default, suppression shared across the whole account and every export, the Art. 14 notice supported at first contact, and a documented record of how each contact entered the buyer's pipeline.
The SDR Team Lead
Filters, saved leads and automated sequences are all there, and the terms put the outreach risk squarely on me by making every customer an independent controller. We found no public information on a do-not-contact suppression list, per-country cold outreach rules for Germany and the other EU markets, or do-not-call checks — the homepage line is that they help you comply, with nothing behind it. 1 2 3 4
The RevOps Manager
Search filters, saved leads and built-in cold sequences are all there, and the vendor says it will "help you comply with data protection regulations", but the terms make the buyer an independent controller and that is where the compliance support appears to end. We found no public information on a global suppression or do-not-contact list, country-aware flagging of German or EU contacts, checks against do-not-call registers, or guidance on cold outreach rules in the main EU markets. 1 2 3 4
The Data Protection Officer
The outreach machinery is real — saved leads up to thirty million, bulk tasks, sequences with AI writing, email rotation and open tracking, managed mailboxes and warm-up — with filters reaching technographics through TechLookup. But the terms make the customer an independent controller, the compliance help is one sentence about sourcing data transparently, and we found no public information on a suppression or do-not-contact list, opt-outs syncing back to the database, or guidance on cold outreach rules in Germany and the other main EU markets. 1 2 3 4
The ABM Marketer
List building is real — saved leads in the millions, Advanced filters in the AI search, a TechLookup tool, and cold-email sequences with managed inboxes — but the terms make me the independent controller for everything I do with the contacts. I found no public information on a suppression or do-not-contact list, country-aware flags for German consent rules, or checks against do-not-call registers. 1 2 4
The DACH Sales Director
Search filters, saved leads and the full cold-email machinery are there — sequences, account rotation, even managed mailboxes bought for cold outreach — but the legal question is left to the customer, who is told they remain an independent controller. I found no public information on a suppression or do-not-contact list, checks against do-not-call registers, or any country-aware flagging of German contacts where a cold call or email requires consent under UWG §7. 1 2 3 4
The Skeptic
Firmographic filters, saved leads and cold-email sequences sent through Gmail or Outlook are all evidenced, and the terms seat the customer as an independent controller for what they do with the contacts. We found no public information on a suppression or do-not-contact list, on do-not-call register checks, or on guidance for cold outreach rules in any EU market — the closest the pages come is the homepage's line that Hunter helps you comply with data protection regulations. 1 2 4
CRM sync, enrichment & export
Show reasoningHide reasoning
How this is scored
Getting the data into the systems where sales works — CRM sync, enrichment of existing records, API — and what happens to exported data, and to the buyer's access to it, when the subscription ends.
0 — Manual CSV export only; no CRM integration and no API.
3 — A one-way push to one CRM, CSV export, and no statement on whether exported data may be kept after cancellation.
5 — Native sync with the major CRMs including field mapping and deduplication, enrichment of existing CRM records, and a documented API with stated limits.
8 — Bidirectional sync with scheduled re-enrichment, update and deletion propagated when a record changes or a person objects, webhook or API access with credit costs per call published, and data retention rights after cancellation stated plainly.
10 — The vendor treats the buyer's CRM as the system of record: objections and corrections propagated into synced records automatically, full change history per field, a versioned API with a deprecation policy, and exit terms that say exactly which data the customer may keep and for how long.
The SDR Team Lead
The getting-data-out side is covered — sync to HubSpot, Salesforce, Zoho and Pipedrive, Zapier, a public API, an MCP server, CSV export, and pay-as-you-go credits for API and bulk tasks. But we found no public information on field mapping, deduplication or sync direction, the terms reserve the right to cut API access with or without notice, and nothing says what happens to exported data when the subscription ends. 1 2 4
The RevOps Manager
There is native sync to HubSpot, Salesforce, Zoho and Pipedrive plus CSV export, a public API and an MCP server — more than a one-way push to a single CRM. But we found no public information on field mapping, deduplication, or whether re-enrichment updates records rather than duplicating them; and the terms reserve the right to discontinue API access with or without notice, while we found no statement on what data a customer may keep after cancellation. 1 2 4
The Data Protection Officer
Sync to HubSpot, Zoho, Salesforce and Pipedrive, 5,000+ Zapier endpoints, a public API, an MCP server, a Sheets add-on and CSV export make a broad integration surface, with the vendor acting as processor for the enrichment tasks. We found no public information on field mapping, deduplication, bidirectional update or deletion propagation, or on whether exported records may be kept after cancellation — and the terms reserve the right to modify or discontinue API access at any time with or without notice. 1 2 3 4
The ABM Marketer
Sync to HubSpot, Salesforce, Zoho and Pipedrive plus 5,000+ Zapier endpoints, CSV export, and a public API drawing on the same credits give me the pipes my team needs. I found no public information on field mapping or deduplication in the CRM sync, stated API limits, or what happens to exported data and my access after cancellation — and the terms reserve the right to discontinue API access with or without notice. 1 2 4
The DACH Sales Director
Native sync to HubSpot, Zoho, Salesforce and Pipedrive, a public API, and CSV export put this solidly mid-table, with enrichment tasks run by Hunter as processor. I found no public information on field mapping, deduplication, bidirectional updates when a person objects, or what happens to exported records after cancellation — and the terms reserve the right to modify or discontinue API access with or without notice. 1 2 4
The Skeptic
Sync to HubSpot, Zoho, Salesforce and Pipedrive plus 5,000+ Zapier endpoints, CSV export, and a public API with an MCP server clear the single-CRM bar comfortably. But we found no public information on field mapping, deduplication, or bidirectional propagation of updates and objections, and the API terms reserve the right to modify or discontinue access "with or without notice, for any or no reason". We also found no public information on whether exported contacts may be kept after cancellation. 1 2 4
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where a database of EU residents' personal data is held, who the contracting entity and controller are, and which subprocessors see it. Independently sourced by the sovereignty pipeline; weighted heavily here, because the product itself is personal data about people who never chose the vendor.
0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and EU residents' contact data processed outside the EU with no stated transfer basis.
3 — Non-EU contracting entity with an EU representative under Art. 27, or EU hosting offered while enrichment, support or AI processing stay non-EU.
5 — EU contracting entity and EU hosting as standard, but parts of the chain — data partners, enrichment sources, tracking infrastructure — are non-EU without an explained safeguard.
8 — EU contracting entity and controller, EU hosting on named infrastructure, subprocessor and data-partner list published, and any non-EU transfer named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, controller, hosting, data partners and every subprocessor European, certification published, and a DPA covering both the customer's data and the database records the customer exports.
The SDR Team Lead
Servers sit in Belgium and transfers out of the EEA rely on Standard Contractual Clauses and the IDTA, with a subprocessor list published at a dedicated address — but the contracting entity and governing law are Delaware, and AI email writing runs through OpenAI with up to 30-day retention. That is a US vendor with an EU representative in Ireland, not a sovereign EU chain: my team's contact data moves on contractual paper rather than staying home. 3 4
The RevOps Manager
Servers are stated to be in Belgium, transfers out of the EEA are acknowledged with Standard Contractual Clauses and the International Data Transfer Agreement, and a subprocessor list is published at a stated address — real transparency. But the contracting entity is a Delaware company under Delaware law with only an Irish representative, and the AI features route content through OpenAI with retention of up to 30 days, so the chain is partly transparent without being European end to end. 3 4
The Data Protection Officer
The contracting entity and controller is a Delaware company under Delaware law, softened by an Article 27 representative in Ireland, servers stated to be located in Belgium, a published sub-processor list, and Standard Contractual Clauses plus the UK International Data Transfer Agreement named for transfers out of the EEA. OpenAI nonetheless sits in the AI chain with API data retention of up to thirty days, so a buyer of European professionals' contact data still contracts across the Atlantic. 3 4
The ABM Marketer
The contracting entity is Hunter Web Services, Inc. of Delaware with an EU representative in Ireland, servers in Belgium, and AI processing through OpenAI with transfers outside the EEA under SCCs and the UK IDTA. A subprocessor list is published by URL, which is more than most US vendors show, but the entity and controller sit outside the EU and I found no public information on ownership or certification. 3 4
The DACH Sales Director
A Delaware corporation under Delaware law with an Article 27 representative in Ireland, servers in Belgium, and transfers on Standard Contractual Clauses — a non-EU contracting entity with EU hosting, while AI writing assistance is processed by OpenAI with API data retained up to 30 days. A subprocessor list and a data processing agreement are published, which counts, but the entity my Mittelstand customer would sign with sits under US jurisdiction, and I found no public information on European certification. 3 4
The Skeptic
The contracting entity is Hunter Web Services, Inc. of Wilmington, Delaware under Delaware law, with an EU representative in Ireland and a UK representative in Brighton — the textbook non-EU vendor arrangement — even though the servers are stated to be in Belgium. Transfers outside the EEA are named with Standard Contractual Clauses and the International Data Transfer Agreement, a subprocessor list page is linked, and the OpenAI integration is disclosed with a contractual training opt-out and 30-day retention. The entity, controller and governing law remain American, which caps this below any EU-entity setup. 3 4
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual cost from public pages alone — including credits per email, phone number and mobile, credit expiry, seat pricing, visitor-identification tiers and the API — in a category where the unit of billing is often invented by the vendor.
0 — No public prices at all; every tier is a sales conversation.
3 — A monthly headline exists, but what a credit buys, whether credits expire, or the cost of an additional seat is unstated — the invoice is unknowable.
5 — Tier prices public with credit allowances given, but at least one commonly needed piece (mobile numbers, extra seats, API access, CRM sync) is unpriced or behind a sales call.
8 — Every tier priced publicly with credits per data type, credit expiry and rollover, per-seat costs, overage rates, minimum term and VAT treatment stated.
10 — Complete price computability: the annual invoice derivable for a given number of seats, exported contacts by data type, identified companies and API calls, with every credit cost and the refund rule for inaccurate data published.
The SDR Team Lead
The pricing page publishes credit allowances per tier (600 up to 300,000 per month), unlimited users on every plan, a 0€ tier with 50 credits and add-on starting prices like "from 10€/month", and the terms state prices exclude taxes and fees are non-refundable. But we found no public information on the euro price of the paid tiers, what a credit buys per data type, credit expiry or credit-pack pricing — so I cannot compute my team's annual invoice from the captured pages. 1 2 4
The RevOps Manager
Credit allowances per plan, what credits are spent on, unlimited users on all plans, add-on prices from 10€/month for additional email accounts and from 5.22€/mo for custom domains, VAT-excluded pricing and a 30% yearly discount are public. But we found no public information on the paid plans' monthly or yearly prices, and the captured pricing page gives different figures for the free plan's monthly credit allowance (50 versus 600). With credit expiry, rollover and overage rates also unstated, the real annual invoice is not computable from what was captured. 2 4
The Data Protection Officer
Credit allowances per plan, unlimited users on all plans, prepaid monthly or annual billing, VAT excluded and the refund rules are all stated, with a free tier at 0€. But we found no public information on the paid plan prices, on credit expiry or rollover, or on the price of Credit Packs, Enterprise is a sales conversation, and the captured material gives different figures for the free plan's monthly credits. The annual invoice is not computable from what is public. 1 2 4
The ABM Marketer
Credit allowances, connected email accounts, sequence recipients and AI searches are broken out per tier, unlimited users on all plans removes seat math, VAT treatment and the -30% yearly option are stated, and pay-as-you-go credits span API calls and bulk tasks. But I found no public information on the monthly price of the paid tiers, credit expiry or rollover, or the cost of Credit Packs — and the captured pages give different figures for the free plan's credits (50 per month on the plan card, 600 in the comparison table). 2 4 1
The DACH Sales Director
Credit allowances per tier, unlimited users on all plans, prices excluding taxes, monthly or yearly billing at -30% for yearly, and add-ons such as additional email accounts from 10€/month are public — but I found no public information on what the Starter, Growth and Scale plans cost, whether credits expire, or what an API credit pack sells for, so the annual invoice is not computable. The captured pages also give different figures for the free tier's monthly credits, 50 credits per month on the plan card against 600 credits for Email Finder, Email Verifier and Domain Search in the comparison. 1 2 4
The Skeptic
Public pieces exist — the free plan at 0€ with 50 credits a month, unlimited users on all plans, add-ons priced "from 10€/month" and "from 5.22€/mo", taxes stated as excluded — but the captured pricing page gives credit allowances for Starter, Growth and Scale without ever stating their euro prices, and we found no public information on credit expiry, credits per data type, or the cost of pay-as-you-go API credits. The captured pages also give different figures for the free plan's credits — 50 credits per month in one place and 600 in the comparison row — and while the terms make upgrades non-refundable, we found no public information on credit-back for inaccurate data. 2 4
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 22 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency, Subprocessors. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 10 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 9 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 sovereignty dimensions could not be confirmed on the vendor’s own pages and are shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (11)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage hunter.io Checked 22 Sep 2026 Details →
- 2 Pricing page hunter.io Checked 22 Sep 2026 Details →
- 3 Privacy policy hunter.io Checked 22 Sep 2026 Details →
- 4 Terms of service hunter.io Checked 22 Sep 2026 Details →
- 5 Security / trust page hunter.io Checked 30 Sep 2026 Details →
- 6 Coverage, accuracy & freshness — found from sitemap hunter.io Checked 1 Oct 2026 Details →
- 7 Coverage, accuracy & freshness — found from sitemap hunter.io Checked 1 Oct 2026 Details →
- 8 Data sources & lawful basis — found from sitemap hunter.io Checked 1 Oct 2026 Details →
- 9 Data sources & lawful basis — found from sitemap hunter.io Checked 1 Oct 2026 Details →
- 10 CRM sync, enrichment & export — found from sitemap hunter.io Checked 1 Oct 2026 Details →
- 11 CRM sync, enrichment & export — found from sitemap hunter.io Checked 1 Oct 2026 Details →