Privacy Policy
OpenShield is a crowdsourced anti-spam platform. This Privacy Policy describes how we collect, use, and protect your information when you use our platform, including our website, browser extension, Gmail add-on, and API.
We collect the sender domain and structured metadata extracted from the email headers you choose to report: SPF/DKIM/DMARC results, the sending IP, and a hash of the raw headers for de-duplication.
We never store the raw, unredacted body of any message, under any reporting path. Raw email headers you submit are parsed to extract the metadata above and then discarded - we do not keep a copy of the original header block.
If you report a message through the browser extension or the Gmail add-on, we additionally capture the message body to strengthen the evidence available for enforcement and legal-notice purposes. Before that content is ever written to storage, we automatically strip personal information from it - email addresses other than the sender's, phone numbers, physical addresses, and payment or financial identifiers - and retain only the redacted result. This body capture applies only to reports filed through the extension or Gmail add-on; reporting directly through the website stays header-only, with no body ever read or stored. An administrator can disable this capture platform-wide at any time.
Authentication is handled by Supabase, via a magic link or Google sign-in. We never see your email password. Your login information is secure and not shared with third parties.
Enhanced Protection is a separate, opt-in feature: connecting your Gmail account requests read-only access to your Spam folder (the "gmail.readonly" scope) as an incremental grant on top of your Google sign-in. We never request or use permission to modify, label, or delete anything in your mailbox - the only action this feature ever takes is filing an OpenShield report on your behalf. To assess whether a message is dangerous, we read the full message, but we retain only the subject, a short snippet, and the sender's email address for messages in your own Spam folder - never the message body - visible only to you in your supporter portal, and permanently deleted the moment you disconnect Gmail or delete your account.
The browser extension only reads page content on Gmail and Outlook web, and only when you open or report a message - it does not run on any other site. It stores your sign-in session locally in the browser (chrome.storage) so you don't have to sign in again on every page load.
We do not collect personally identifiable information beyond what you voluntarily provide. We do not sell data, and we do not run third-party advertising trackers.
You can permanently delete your account and everything tied to it at any time from your supporter portal. Deletion cascades immediately to your reports, votes, Enhanced Protection connection, and contributions - no support request needed.
For questions about this Privacy Policy, contact us at the email address listed below or through our website.