Privacy & security

Your evidence is personal.
We treat it that way.

We use submitted messages to provide your requested assessment, secure the service, and maintain your private reports. We do not sell your evidence or use it for advertising.

Before analysis

We parse submitted content statically to identify the message and check for abuse. New email addresses must be verified before AI analysis. We may require confirmation again when the authenticity of a forwarded delivery is uncertain. Website users confirm consent before submitting.

AI processing

The selected message text, link destinations, relevant headers, and supported screenshots may be sent to OpenAI for automated assessment. Requests disable stored response history. This does not mean every provider security or abuse-monitoring record has zero retention. Do not submit information you are not authorized to share. Links are not opened and attachments are not executed.

What we retain, and for how long

Unconfirmed submissions expire after one hour. Confirmed introductory reports and raw evidence are scheduled for deletion after seven days. The planned Personal plan uses 30 days. The deletion process removes original uploads, extracted personal indicators, report contents, follow-up messages, and exposure answers. Automated processing runs periodically, so deletion may occur shortly after the scheduled time.

Until deletion, sender names, subjects, and analysis text may contain personal information and remain private to the account owner. They are not described as anonymous safety indicators.

Delete sooner

Use Delete in My checks to remove a report and its evidence. The report becomes inaccessible immediately; stored content is erased and interrupted deletion is retried. A minimal deletion receipt and non-content usage record remain to enforce allowance and audit completion. Deleting content does not replenish completed usage. Account identity and any billing records are separate from report deletion.

Access and sign-in

Private reports require a verified email session. Sign-in links expire after 60 minutes and can be used once. You confirm on the website; an email scanner opening the link does not sign you in. Sessions use secure HTTP-only cookies and expire after 30 days. Signing out revokes your sessions across devices.

Operational records

Inbound delivery metadata is retained for up to 30 days for deduplication and abuse controls. Completed job records are removed after seven days. Report deletion removes associated personal delivery fields. Non-content usage records, account records, and minimal deletion receipts are retained for service administration; raw messages and access tokens are not included in application diagnostics.

Limits that matter

No automated check guarantees authenticity. We currently make no measured accuracy claim. We do not offer complimentary human review, phone support, or chat escalation. For sensitive requests, verify through an independently trusted channel.

Updated September 11, 2026.