1. Overview
GuardScope is a Chrome extension that analyzes emails in Gmail for phishing and social engineering threats. We are committed to your privacy. This policy explains exactly what data we collect, what we do not collect, how we use data, and your rights.
2. What We DO Collect
- Account data: Your email address and hashed password when you create an account (stored in Supabase Auth).
- Usage counts: The number of analyses you run each month — not the content, just the count.
- Account tier: Free, Pro, or Team.
- Timestamps: When your account was created and when you last signed in.
- Payment data: Handled entirely by Stripe or Paystack. We store only your subscription status — never card numbers.
- Promo code leads: Name, email address, and country — collected when you request an early access promo code.
3. What We Do NOT Collect or Store
- Email content: The body, subject, and headers of emails you analyze are NEVER stored. Discarded immediately after analysis.
- Email addresses of your contacts (senders or recipients)
- URLs extracted from emails — only checked against threat databases, never persisted
- Browsing history or any data outside of Gmail
- Gmail credentials — we use Gmail's own DOM (not your password or API tokens)
- Attachment content — only filename and type are noted (never uploaded)
4. Third-Party Services
To provide security analysis, we use the following third-party services. Each receives only the minimum data required:
- InceptionLabs Mercury-2 AI: Receives sanitized email content for analysis. Does not retain data per our API agreement.
- VirusTotal: Receives URLs (not email content) to check against malware databases.
- Google Safe Browsing: Receives URLs to check against Google's threat database.
- PhishTank / URLhaus (Abuse.ch): Receives URLs to check against phishing databases.
- Cloudflare DNS: Receives sender domain for SPF/DKIM/DMARC lookup.
- RDAP (rdap.org): Receives sender domain to check registration age.
- Supabase: Hosts our database (account and usage data only). Located in the EU.
- Stripe / Paystack: Process payments. We never see your full card number.
- Vercel: Hosts our analysis API. Located in the US.
5. Data Retention
- Usage counts are retained for 13 months (to support monthly limit tracking).
- Account data is retained until you delete your account.
- Email analysis data is never retained — not even for 1 second after the analysis response is returned.
- Promo code lead data (name, email, country) is retained for 90 days after the promo period ends.
6. Your Rights
You have the right to:
- Access: Request a copy of your account data (email, tier, usage count).
- Deletion: Delete your account at any time. All associated data is permanently deleted within 30 days.
- Correction: Update your email address or account information.
- Portability: Export your account data in JSON format on request.
To exercise these rights, email us at privacy@guardscope.io
7. NDPR 2023 Compliance (Nigeria)
GuardScope complies with the Nigeria Data Protection Regulation (NDPR) 2023 and the Nigeria Data Protection Act. As a data controller, we process your personal data lawfully, fairly, and transparently. Nigerian users may lodge complaints with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
8. GDPR Compliance (EU/EEA)
For users in the European Union and EEA, our legal basis for processing is your explicit consent (given during onboarding) and the performance of our service contract. You may withdraw consent at any time by deleting your account. Our data processor (Supabase) is hosted in the EU and has signed a Data Processing Agreement.
9. Cookies
The GuardScope Chrome extension does not use cookies. Our website may use minimal session cookies for authentication. We do not use third-party advertising cookies or tracking pixels.
10. Children
GuardScope is not directed to children under 13. We do not knowingly collect data from children.
11. Changes to This Policy
We will notify you of material changes via email. Continued use of GuardScope after the effective date constitutes acceptance.
12. Contact
Privacy questions: privacy@guardscope.io General support: support@guardscope.io
© 2026 GuardScope. All rights reserved.