Privacy Policy

Effective September 7, 2026 · Version 2026-09-07

This Privacy Policy explains how MailguardAI-247 (“MailguardAI”, “we”, “us”) collects, uses, and shares information when you use our Email Threat Detection & Response (ETDR) service at mailguardai247.com and related apps. It should be read with our Terms of Service.

1. Who we are

MailguardAI-247 operates the Service. Contact: support@mailguardai247.com.

2. Information we collect

  • Account identifiers from Auth0 (e.g. Google or Microsoft sign-in email, name, subject ID).
  • Mailbox connection metadata (provider, mailbox address, OAuth tokens or encrypted IMAP credentials, sync cursors).
  • Message metadata and content required for ETDR screening (headers, body snippets, attachments indicators, classification, risk scores, stamp actions).
  • Account Risk signals where entitled (e.g. forwarding rules, MFA posture where available, sign-in alerts) and Fraud Risk indicators on Elite.
  • Product telemetry (feature usage, errors, consent timestamps, experience mode).
  • Billing information processed by Stripe (we do not store full card numbers).
  • Optional Support / Trusted Helper chat content you send to our support tools.
  • Optional phishing-drill interaction data (pass/fail, quiz answers) if you opt in to quarterly training.

3. How we use information

  • Provide ETDR: Message Risk screening, mailbox stamps and quarantine/routing, Account Protection, Fraud Risk checks, Trust Registry, Audit Trail, and Insights.
  • Operate Companion and Advisor in Gmail/Outlook and SafeView previews.
  • Enforce plan limits, prevent abuse, and improve reliability and detection quality.
  • Communicate service notices, security alerts, and billing receipts.
  • Comply with law and protect users and the platform.
  • If you opt in to quarterly phishing drills: deliver the same controlled scenario to opted-in users that quarter and record click/release outcomes and quiz responses for security education only—not for advertising or selling data.

4. AI processing

When deeper Message Risk review is needed, we may send message content and related signals to Anthropic (Claude Haiku) under contractual and technical controls. AI is used only for ETDR security analysis and in-product explanations you request—not for advertising or training public models with your mail as described in our Anthropic configuration and agreements.

You provide explicit consent for AI analysis during onboarding. Without that consent we cannot provide full ETDR screening.

5. Sharing

We share data with processors who help run the Service, including Auth0 (identity), Anthropic (AI analysis), Stripe (payments), hosting providers (e.g. Railway, Vercel), and email providers you authorize (Gmail, Microsoft, IMAP hosts). We do not sell your personal information. We may disclose information if required by law or to protect rights and safety.

6. Retention

Screened message journals and related analysis are retained up to three (3) days, then deleted from our systems unless longer retention is required by law or you export first. Account settings, Trust Registry entries, Audit Trail summaries, and Account/Fraud posture records may persist while your account remains active.

7. Security

We use encryption in transit, access controls, and least-privilege integration scopes. No method of transmission or storage is 100% secure; please use strong provider MFA and review Account Protection alerts.

8. Cookies and similar technologies

We use essential cookies for authentication and session integrity. Analytics cookies, if any, are described in-product or via cookie banners where required.

9. Your choices and rights

  • Disconnect mailboxes in Profile to stop new screening.
  • Request account deletion through Profile danger zone or support.
  • Depending on your location, you may have rights to access, correct, delete, or port personal data, or object to certain processing.
  • You may withdraw AI analysis consent by disconnecting mailboxes and closing your account; withdrawal does not affect prior lawful processing.

10. International transfers

We and our subprocessors may process data in the United States and other countries. Where required, we rely on appropriate safeguards for cross-border transfers.

11. Children

MailguardAI is not directed to children under 18. We do not knowingly collect data from children.

12. Changes to this policy

We may update this Privacy Policy. Material changes will be noted by an updated effective date and, where required, renewed consent in the product.

13. Contact

Privacy questions: support@mailguardai247.com.