Privacy, in plain language

Your inbox is yours.

Here is what EmailAIvisor uses, where it goes, and what stays out of our database.

When you sign in

Google provides your account identifier, email address, and display name. We store account details and account timestamps to recognize you. The web app uses an HttpOnly session cookie to keep you signed in. Google sign-in does not request Gmail API permissions.

When you choose to check an email

The extension reads the last expanded message in an open Gmail thread only after you click Check. The following details are sent to our server for analysis:

  • Sender name and email address, plus a reply-to address if visible.
  • The subject and visible message text, limited to approximately 8,000 characters.
  • A limited list of visible link labels and their destinations.
  • Attachment names and file types. Attachment contents are never sent.
  • When available, SPF/DKIM/DMARC authentication results and the Message-ID/Return-Path headers from Gmail's "Show original" view. This is best-effort — it isn't always available, and its absence never blocks a check.

What is sent to TypeSafe

Our server sends the message details and computed warning signals to TypeSafe’s Jev model, a separate provider that processes this data to help classify the message. Processing on our server happens in memory only. For how TypeSafe itself handles and retains data it receives, see TypeSafe’s own terms.

If you've completed the optional context survey described below, your saved answers are also sent to TypeSafe as part of each check, labeled as optional, self-reported context that may be incomplete or outdated. They are used only as supporting context alongside a check's other signals, never by themselves to decide that a message is safe or dangerous.

What our database stores

Storage is limited to your account, aggregate counters (total messages checked and counts for each verdict category), and your optional context survey answers if you choose to complete one (see below). It does not include email subjects, senders, recipients, bodies, links, attachment names, content hashes, or individual check records. Email payloads are processed in memory and excluded from application logs.

Your optional context survey

From your dashboard, you can optionally answer a short survey about your devices, the online services you use, and the kinds of email that are normal for your inbox — for example, an "Apple Account renewal" notice reads as more suspicious if you've told us you only use Windows and have no Apple devices. This is never required to sign in or check an email.

These answers are used only as supporting context alongside a check's other signals — never by themselves to decide that a message is safe or dangerous — and are never included in application logs, the Jev prompt log, or analytics. You can review, change, or clear your answers at any time from the same survey page.

Cookies and external services

The session cookie is necessary for signed-in pages. The sign-in page loads Google Identity Services, and the website loads the Manrope font from Google Fonts. Your browser connects to Google to load these resources. A local preference remembers your chosen light or dark appearance.

Account deletion

You can permanently delete your account and all stored data — your account details, category totals, and survey answers — from a "Delete my account and data" button on your dashboard. This is immediate and can't be undone. There's nothing else to delete: we never stored email content or per-check history in the first place.

What an email check cannot tell you

A result is guidance, not a guarantee. Authentication results (SPF/DKIM/DMARC) are read on a best-effort basis and aren't always available. Checks analyze text and structured signals, not images or attachment contents. Confirm sensitive requests directly with the person or organization using a contact method you already trust.

Back to EmailAIvisor