Your data is yours. We only touch what we need to stop threats.
Zero-human access to your email. No ad tracking. No AI training on your data. Here's exactly what we collect, how we use it, and how you stay in control.
Last updated: May 19, 2026
Quick Summary
- We never sell your data. Period.
- No human at Spoof Defense can read your emails — only automated scanners.
- Email content is analyzed in memory and immediately discarded — never stored.
- You can disconnect, export, or delete your data at any time.
- AI email analysis is optional and under your control.
For a non-technical overview, see our Data Protection page.
1. Information We Collect
Information You Provide
- Account information (name, email, company)
- Payment information (processed securely by Stripe — we never see your card number)
- Domain lists and vendor information you upload
- Support requests and communications
- Detection feedback (your verdict on whether a flagged email is safe or a threat, and an optional reason category)
Gmail / Google Workspace Data
When you connect your Google Workspace account, our automated scanners access the following data to detect phishing and business email compromise threats:
What We Access
- Email headers (From, Subject, Date)
- Authentication results (SPF, DKIM, DMARC)
- Email body content (for threat analysis only)
- Embedded URLs and link destinations
- Attachment metadata (filename, type, hash)
- Workspace user directory (read-only) — enrolled mailbox email addresses and display names only
- Workspace domain list (read-only) — to confirm administrator ownership and detect alias domains
What We Never Store
- Email body or message content
- Email subject lines (SHA-256 hash only)
- Attachment file contents
- Your contact list or recipients
- Full email headers
How it works: Email content is loaded into our scanner's temporary memory, analyzed for threats, and immediately discarded — typically within seconds. Only the scan result (who sent it, threat level, action taken) is saved. The email itself is never written to disk, database, or logs.
Google OAuth Scopes Requested
When connecting a Google Workspace tenant, Spoof Defense requests the following OAuth scopes:
gmail.modify— read incoming messages (headers, body, attachments) for phishing analysis, apply security labels, and optionally move detected phishing to quarantine or spam per administrator policy. We never compose or send mail.gmail.labels— create and maintain theSuspectedSpooflabel and any administrator-configured quarantine labels.admin.directory.user.readonly— enumerate enrolled mailboxes during tenant onboarding so the administrator can pick which to protect.admin.directory.domain.readonly— verify the administrator owns the claimed Workspace domain and discover alias domains.userinfo.email— identify the administrator account that authorized the integration.
We do not request gmail.send, gmail.compose, or any directory-write scope. When you disconnect, Spoof Defense calls Google's OAuth revoke endpoint to invalidate the refresh token immediately.
Modifications We Make to Your Mailbox
When a malicious message is detected, Spoof Defense modifies the affected message using the Gmail or Microsoft Graph API by:
- Adding a label (e.g.,
SuspectedSpoof) so the recipient and any downstream filters can identify the threat. - Optionally moving the message to a quarantine label or the spam/junk folder, per the tenant administrator's configured policy.
- Optionally inserting administrator-configured trust banners on legitimate vendor email so end users can identify authentic senders.
We never compose new messages, never send mail on behalf of users, and never delete email. Alert notifications about detected threats are sent from Spoof Defense's own email infrastructure (noreply@spoofdefense.com), not from your tenant.
Microsoft 365 Data
The same access, usage, retention, and sharing policies described above for Google data apply equally to Microsoft 365 connections. Microsoft Graph API tokens are stored encrypted and revoked upon disconnection.
Information Collected Automatically
- Log data (IP address, browser type, pages visited)
- Usage data (API requests, features used)
- Device information (operating system, device type)
- Cookies and similar technologies
2. How We Use Your Information
- Provide and maintain the email protection service
- Detect phishing, spoofing, and business email compromise threats
- Process payments and manage subscriptions
- Send important service notifications
- Respond to support requests
- Improve and optimize threat detection accuracy
- Improve detection accuracy based on your feedback and anonymized, aggregate patterns across all customers
- Detect and prevent fraud or abuse of our platform
- Comply with legal obligations
We never use your data for: advertising, ad targeting, selling to third parties, or training AI models. Your data is used solely to protect you from email threats.
3. Information Sharing
We do not sell your personal information. We may share limited information with:
| Third Party | What We Share | Why |
|---|---|---|
| Stripe (payments) | Billing info | Process your subscription payments |
| Anthropic (AI analysis) | Email content for threat review (opt-in only) | AI peer review of suspicious emails |
| Splunk (telemetry) | Threat metadata + funnel events (no email content) | Security monitoring and aggregate reporting |
| Cloudflare (CDN + Web Analytics) | Request headers, UTM, aggregated page metrics | Content delivery + traffic baseline (no cross-site tracking) |
| PostHog (self-hosted product analytics) | Funnel events + hashed visitor ID (no PII, no session replay on forms) | Product funnel analysis — data remains on our infrastructure |
| GrowthBook (self-hosted A/B testing) | Variant assignment cookie + anonymous ID | Landing-page experiments — no PII, no 3rd-party transmission |
| Law enforcement | As required by law | Legal compliance |
Anthropic AI Peer Review is disabled by default. The tenant administrator must enable it explicitly in tenant settings. When enabled, only a redacted excerpt of suspicious messages is sent to Anthropic under a zero-retention data processing agreement; Anthropic does not store or train on the data.
Limited Use of Google API Services User Data
Spoof Defense's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google user data is used only to provide and improve user-facing features within the Spoof Defense product (phishing detection, labeling, quarantine).
- Google user data is not transferred to any third party other than as necessary to provide or improve user-facing features, comply with applicable law, or for security purposes (e.g., investigating abuse).
- Google user data is not used for serving advertisements, including personalized or retargeted advertising.
- No human at Spoof Defense reads Google user data unless: (a) we have the user's explicit affirmative consent, (b) it is necessary for security purposes (e.g., investigating a bug or abuse), (c) it is necessary to comply with applicable law, or (d) the data is aggregated and used for internal operations in compliance with the Limited Use requirements.
Google Data Restrictions
- Google user data is never sold to third parties
- Google user data is never used for advertising or ad targeting
- Google user data is never used to train AI models
- No human reviews email content unless explicitly requested by the account holder
- If AI Peer Review is enabled (opt-in only, off by default), a sanitized excerpt is sent to Anthropic under their zero-retention data processing agreement
- Threat-intelligence providers (VirusTotal, CrowdStrike) supply data inbound to Spoof Defense — they do not receive customer email content or hashes derived from customer data
4. Data Security
We implement industry-standard security measures to protect your data:
5. Data Retention
| Data Type | How Long | Details |
|---|---|---|
| Email body content | Never stored | Processed in memory, discarded within seconds |
| Email subject | Never stored | Only irreversible SHA-256 hash kept for dedup |
| Scan results (metadata) | 90 days | Threat scores, signals, actions — then auto-deleted |
| Detection feedback | 90 days | Your verdicts on flagged emails — then auto-deleted |
| Account data | While active | Deleted within 30 days of account closure |
| OAuth/API tokens | Until revoked | Encrypted in Vault, deleted on disconnect |
| Payment data | Per Stripe policy | We never store credit card numbers |
| Marketing funnel events (PostHog) | 395 days | Anonymized visit/conversion data — no PII |
| Marketing funnel events (Splunk aggregate) | 7 years | Aggregate counts only — no individual identifiers retained past 395 days |
You may request deletion of all your data at any time by contacting support@spoofdefense.com. We process deletion requests within 30 days.
6. Your Rights
Depending on your location, you have the right to:
7. Cookies
We use first-party cookies only for authentication, security, and product analytics. We do not use third-party cookies, advertising cookies, or cross-site tracking.
| Cookie | Purpose | Duration |
|---|---|---|
| session_id | Authenticated session (essential) | Session + 30 days |
| anonymous_id | Visitor deduplication for product analytics | 2 years |
| gb_variant | A/B test variant assignment (landing pages) | 30 days |
| __cf_bm | Cloudflare bot protection (essential) | Session |
| privacy_choice | Remembers your analytics opt-out | 1 year |
You can opt out of product analytics while keeping essential cookies by visiting Your Privacy Choices. Browser-level controls also work.
8. International Transfers
Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses where required.
9. GDPR & CCPA Compliance
For EU Residents (GDPR)
We act as a data controller. Our legal basis for processing includes contract performance, legitimate interests, and consent where applicable. You may exercise your GDPR rights by contacting support@spoofdefense.com.
For California Residents (CCPA / CPRA)
You have the right to know what personal information is collected, request deletion, limit sensitive information use, and opt out of any sharing of personal information for cross-context behavioral advertising. We do not sell personal information and we do not engage in cross-context behavioral advertising. Exercise your rights at Your Privacy Choices.
Children's Privacy
The Service is not intended for children under 13 (under 16 in the EU). We do not knowingly collect information from children under those ages.
10. Contact Us
For questions about this Privacy Policy or to exercise your rights:
Spoof Defense Inc.
Email: support@spoofdefense.com
Compliance Alignment
Zero-retention architecture: email body content and attachments are inspected in-memory during scan and never stored, which supports your HIPAA and GLBA safeguards. If your organization requires a Business Associate Agreement, contact us. HIPAA-covered customers remain responsible for their own policy (for example, that employees do not transmit medical records by email).