Privacy Policy

Last updated: 2026-08-16

Email Scam Checker is a Chrome extension that detects scam and phishing emails in Gmail, Outlook, Yahoo Mail, and Proton Mail. This page explains what data the extension processes, what it stores, and what it never collects.

Email analysis happens entirely on your device

When you open an email, the extension extracts the sender, subject, body, and links directly from the page and runs its checks locally in your browser. No email content — subject, body, links, or attachments — is ever sent to any external server for analysis. This applies both to the automatic heuristic checks and to the optional on-device AI Deep Scan, which downloads a small phishing-detection model once (about 67 MB) and then runs completely offline.

Permissions we request, and why

  • mail.google.com (Gmail), outlook.live.com / outlook.office.com / outlook.cloud.microsoft (Outlook), mail.yahoo.com (Yahoo Mail), mail.proton.me (Proton Mail) — needed so the content script can read the currently open email's sender, subject, body, and links from the page and display the scam-risk badge directly in your inbox.
  • huggingface.co and cdn.jsdelivr.net — used once to download the on-device AI Deep Scan model files. No email data is sent to these hosts; they only serve the static model.
  • activeTab — lets the extension identify the mail tab you're actively viewing.
  • storage — needed to save your settings, anti-phishing codes, and marked-sender lists locally in your browser.

The extension does not request access to any other website, your browsing history, or any Gmail/Outlook/ Yahoo/Proton account API — it only reads what's already rendered on the page you have open.

What we store, and why

To keep your stats and recent-scams list available even if you switch computers or clear your browser data, a short summary of each scam email is backed up to a private store tied to your installation:

  • Sender — the email address of the message that was flagged (i.e. the suspected scammer's address, not your own)
  • Subject line of the flagged message
  • Verdict — the risk classification the extension assigned

The email body, links, and attachments are never included. This backup is scoped to an anonymous identifier generated on your device — it is not linked to your name, your own email address, or any account, and no other installation of the extension — including other users — can read it.

Data retention and deletion

The backup keeps your most recent scam records (up to the last 20) plus your aggregated stats for as long as the extension remains installed. Uninstalling the extension does not automatically delete this backup, since it's keyed to an anonymous installation identifier rather than an account. To request deletion of your backed-up data, email us at the address below with the approximate date you installed or uninstalled the extension, and we will erase the matching record.

What stays only on your device

The following are stored locally in your browser and are never sent anywhere:

  • Your anti-phishing codes (personal secret phrases you configure for services like Proton Mail, Coinbase, Gate, or Binance)
  • Your list of senders marked "safe" or "reported as scam"
  • The extension's on/off setting
  • The local cache of recently scanned emails, used to avoid re-scanning the same message

What we never collect

We do not collect your name, your own email address or account identity, browsing history, or the full content of any email (body, links, or attachments). We do not sell or share data with advertisers, and we do not use any data for advertising or purposes unrelated to detecting scam emails. The extension does not require an account or sign-in.

Third-party infrastructure

The anonymized scan-summary backup described above is stored using Google Firebase (Cloud Firestore), with an anonymous Firebase Authentication identity generated per installation. Firebase only ever receives the anonymized summary data described in "What we store, and why" — it never receives raw email content, and server-side security rules restrict access to each installation's records to that installation alone. See Google's Firebase privacy and security policy for how Google handles this infrastructure.

This website

This landing page (emailscamcheck.com) uses Google Analytics to measure aggregate, anonymous visitor statistics (page views and approximate region). Google Analytics sets cookies for this; it never receives email content or anything that identifies you personally. See Google's privacy policy and how Google uses information from sites.

Children's privacy

Email Scam Checker is not directed at children and does not knowingly collect information from children under 13.

Changes to this policy

If this policy changes, we will update this page and revise the "Last updated" date above.

Contact

Questions about this policy or your data? Email [email protected].