Privacy Policy
We believe your data is yours. Here is how we securely process your emails to keep you safe from threats while respecting your privacy.
Data We Collect
To provide you with top-tier threat detection, we collect the bare minimum needed for our systems to function:
- Account Information: Basic profile information (name, email) provided through Google Auth.
- Email Metadata: Senders, subjects, and timestamps required for behavioral analysis.
- Email Content: Evaluated dynamically and securely in memory; never permanently stored unless you explicitly request a copy.
Google OAuth Integration
SecuraMail integrates seamlessly with Gmail using industry-standard OAuth 2.0. We request specific scopes solely to fetch and analyze incoming mail for potential threats.
Strict Boundaries: We do not sell your data, nor do we use it to train any public language models. We adhere strictly to the Google API Services User Data Policy, ensuring your inbox remains private.
Threat Analysis & Local ML
To analyze sensitive content without compromising your privacy, we deploy Local Machine Learning Models directly on our infrastructure. Your email bodies are never routed to third-party commercial LLM endpoints.
We do query reputation databases (like VirusTotal or Google Safe Browsing) strictly using anonymous indicators, such as file hashes or domain strings, rather than raw payload files.
Data Retention
Threat reports and basic metadata are stored in our secure databases for historical analysis. Full email payloads are kept purely in-memory during scans and flushed immediately after analysis. When you delete your account, all associated data is purged.
Your Rights
You have full control. You can access, correct, or request deletion of your data at any time. Revoking OAuth access instantly terminates our ability to read your inbox. We comply fully with modern privacy regulations.