Privacy Policy
1What StealthShield Does
StealthShield protects users from credential leaks and phishing attacks across their browser and email. Its single purpose is to warn you before sensitive information is exposed—whether you are entering passwords on an unencrypted website or opening a dangerous link in your inbox.
We collect only the minimum information required to deliver this protection and never touch data outside our security scope.
2Chrome Extension (Runs Locally on Your Device)
The Chrome extension operates entirely inside your local browser runtime to verify that sensitive data is submitted securely.
- We Never See Your Passwords: The extension detects whether password or credential input fields exist on unencrypted (HTTP) web pages. It never reads, records, copies, or logs what you type.
- No Browsing History Collected: We do not track the websites you visit, your browsing habits, or your search history.
- 100% On-Device Warnings: Security warnings are generated locally within your browser tab and dismissed states stay in your temporary browser session. No browsing traffic is sent to our servers.
3Gmail & Outlook Add-ins (Server-Side Email Scanning)
Our email add-ins inspect messages on demand to protect you from spoofed senders, fake links, and phishing attempts.
- Only Opened Messages: The add-in evaluates only the specific email currently open on your screen. It never scans your mailbox history, unread messages, or sent folders.
- In-Memory, Temporary Analysis: When you open an email, its message content—sender header, subject line, and body—is sent securely to our backend and evaluated in memory solely to calculate a safety verdict. Attachments are not uploaded; the add-in only checks attachment file names locally for suspicious mismatches (for example, a file that looks like a PDF but is really an executable). We never save, store, or archive your email body or attachments to permanent databases or disks. All message content is discarded immediately after the score is generated.
- Sidebar Verdicts Only: Risk scores and warnings appear exclusively in your native inbox sidebar card. StealthShield never modifies, alters, or injects content into your actual emails.
4Web Dashboard & Account Management
When you create an account to manage your subscription, we store basic profile details (such as your name, business email address, encrypted password, and team settings).
- Threat History & Summary: The web console displays high-level activity summaries from your email scans—such as total scans performed, safety verdicts (Safe, Suspicious, Malicious), sender addresses, subject lines, a short explanation of why an email was flagged, and remaining daily quotas.
- No Message Archives: The dashboard shows only high-level security outcomes, never the raw contents of your emails.
- Browser Activity Stays Local: Chrome extension activity is never transmitted to or displayed on the dashboard.
5Third-Party Services & Marketplace Compliance
We do not sell, rent, monetize, or share your personal data, email content, or threat telemetry with data brokers or advertising networks.
A. Link Safety Verification
To confirm whether suspicious URLs lead to known malware or phishing attacks, our secure backend queries trusted threat intelligence sources, including the Google Cloud Web Risk service and a domain-registration lookup service (used to flag newly created, high-risk domains). In both cases, only the domain or web link is checked—no personal information, sender details, or email message text are ever shared with these services.
B. Google API Limited Use Disclosure
StealthShield’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Data accessed via Google Workspace APIs is used solely to provide user-facing email threat detection.
- We never transfer or use this data to serve advertisements.
- We never use user communications or scan data to develop, improve, or train generalized artificial intelligence (AI) or machine learning (ML) models.
C. Microsoft 365 Standards
The Outlook add-in operates via official Microsoft Office JavaScript APIs, respecting all permissions and security policies established by your Microsoft 365 administrator.
6Data Retention & Deletion
We keep only the minimal information required to provide your service:
- Email Bodies & Contents: Stored for zero seconds. Discarded immediately after safety scoring.
- Scan Metadata: Basic event summaries (timestamp, verdict, sender address, subject line, and the reason an email was flagged) remain in your account console for security auditing until you choose to remove them.
- Account Deletion: You can delete your account, team workspace, and all associated scan history at any time from your account settings or by submitting a request to our support team.
7Contact & Privacy Inquiries
If you have questions regarding this Privacy Policy, your data, or our security practices, contact our privacy team:
We respond to all privacy inquiries within 2 business days.
privacy@stealthshield.ai