Coming soon: the Gmail add-on is finishing Google Workspace Marketplace review for one-click install.

Legal · Privacy

Privacy Policy

What Baitwall collects, what it deliberately never stores, and every third party that touches your data.

Last updated · 20 August 2026

01

The short version

We do not store the contents of your email. When a message is analyzed, its body is held in memory for the duration of the request, sent to an AI provider for scoring, and then discarded. It is never written to our database, log files, or backups.

We do store what the analysis produced. The sender, subject line, score, category, the list of threat indicators, and a short plain-English summary are saved so your security team has a record to work from. The summary and indicators are written by the AI model and therefore describe the message — read section 03 before assuming nothing derived from the body is retained.

Your email content is transmitted to a third party.Scoring is performed by Anthropic or DeepSeek, depending on how your deployment is configured. “We do not store it” is not the same as “it never leaves our servers.” Section 05 names every processor.

The rest of this policy states the same things precisely. If anything here conflicts with a signed agreement between us, that agreement governs.

02

Who we are and who this covers

Baitwall (“Baitwall”, “we”, “us”) is operated by Jonibek Norboev, as a sole proprietor. You can reach us about anything in this policy at privacy@baitwall.com.

This policy covers the Baitwall web dashboard, the Baitwall API, and the Baitwall Google Workspace add-on. It applies to two groups of people, and the distinction matters:

  • Administrators — the people at a customer organization who create a workspace and sign in to the dashboard. We act as a data controller for their account details.
  • Employees — the people at a customer organization who use the Gmail add-on and report messages. We act as a data processor for what passes through the add-on, on behalf of their employer, who decides to deploy Baitwall and is the controller of that data.

If you are an employee with a question about why your employer deployed Baitwall, or you want your reports removed, contact your own security or IT team first — they control that data, and we act on their instructions.

03

What we collect

Everything Baitwall stores falls into four groups. There is nothing else — no advertising identifiers, no behavioural profiling, no third-party trackers.

CategoryFields
Workspace accountOrganization name, optional email domain, security team email address, and the API key issued to your workspace.
Administrator accountEmail address, a bcrypt hash of the password (never the password itself), and role (admin or viewer).
ReportsReporter email address, sender email address and display name, subject line, message ID, phishing score, category, the list of threat indicators, an AI-written summary, workflow status, and timestamps.
Analysis logsWhen the sidebar scores a message that is then not reported, we keep the same fields minus the message ID, so your team can see scanning volume.

We also set one strictly necessary cookie holding your signed-in session. It is required for the dashboard to function and carries no analytics purpose. We do not use advertising or tracking cookies, so there is no consent banner to dismiss.

04

What we deliberately do not store

The following never reaches our database, and is not present in backups or application logs:

  • The plain-text or HTML body of any email.
  • Attachments, or the contents of attachments.
  • Full message headers beyond the sender, reply-to, and message ID.
  • Any message the employee did not open with the add-on active.

The body is read from Gmail by the add-on, sent to us over HTTPS, passed to the AI provider, and released from memory when the request completes. Our database schema has no column capable of holding it.

An honest caveat. The summary and indicators fields are generated by an AI model that has read the message, and they are stored. A summary may therefore paraphrase or quote a fragment of the email — for example, the specific urgency phrasing that made the message suspicious. If your threat model requires that nothing derived from message content is retained, Baitwall is not the right fit as currently built.

05

Why we process it, and on what legal basis

PurposeBasis
Scoring a reported message and returning a verdictPerformance of our contract with the customer organization; for employee data, the legitimate interest of that organization in protecting its systems.
Emailing the verdict to the security teamPerformance of our contract — this is the core function the customer signed up for.
Keeping the report history and dashboard statisticsLegitimate interest in giving security teams a workable record of threats against their organization.
Authenticating administratorsPerformance of our contract, and our legitimate interest in keeping accounts secure.
Diagnosing errors and abuseLegitimate interest in operating the service reliably and safely.

We do not sell personal data, we do not share it with advertisers, and we do not use it to train any AI model. See section 05 for what our providers commit to on that last point.

06

Who else processes your data

Baitwall relies on the following sub-processors. Which AI provider applies depends on how your deployment is configured; your administrator can confirm which one is active.

ProviderWhat it receives, and why
AnthropicWhen configured as the AI provider: the sender, subject, reply-to, and body of a message being analyzed. Anthropic states that API inputs are not used to train its models.
DeepSeekWhen configured as the AI provider: the same fields. Review DeepSeek’s current terms and data-residency position before selecting it, particularly if your organization has restrictions on where data may be processed.
ResendThe security team email address and the alert message — which includes the sender, subject, score, indicators, and summary. Used to deliver the alert.
Google WorkspaceThe add-on runs inside Gmail and reads the open message using Google’s APIs. Google processes this as your organization’s existing Workspace provider.
Hosting and databaseHetzner (application server) and Neon (Postgres database), both in the European Union.

Because these providers may operate outside your country, personal data may be transferred internationally. Where that involves transfers out of the EEA or the UK, they are made under Standard Contractual Clauses or an equivalent approved mechanism.

07

Google API Services and limited use

The Gmail add-on requests the following OAuth scopes. Each one is used solely for the purpose stated:

ScopeUsed for
gmail.addons.executeRunning the add-on inside the Gmail interface.
gmail.addons.current.message.readonlyReading the message the employee currently has open, so it can be scored. This is the narrower, add-on-scoped version of Gmail read access — it grants nothing beyond the open message, unlike the broader gmail.readonly scope.
script.external_requestSending the analysis request to the Baitwall API.
userinfo.emailIdentifying which employee ran the scan or filed the report, so the result can be attributed to them on your security team’s dashboard. Not used to read, list, or store anyone else’s email address.

Baitwall’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data except as necessary to provide the service, we do not use it for advertising, and we do not allow humans to read it except with your explicit consent, where required for security or legal reasons, or where the data has been aggregated and de-identified.

08

How long we keep it

  • Message bodies — not retained at all. Discarded when the request finishes, typically within a few seconds.
  • Reports and analysis logs — retained for as long as the workspace is active, so historical trends remain meaningful.
  • Account records — retained while the workspace exists, and deleted within 30 days of a deletion request, except where we are required to keep records longer.

Current limitation. Automatic time-based deletion is not yet implemented. Reports stay until a workspace is deleted, at which point database cascade rules remove every associated row. If you need a specific retention window enforced today, contact us and we will action it manually.

09

How we protect it

  • Traffic is served over HTTPS.
  • Administrator passwords are hashed with bcrypt at cost factor 12. We cannot recover a password, only reset it.
  • Every database query is scoped to a single workspace, so one organization cannot read another’s reports. This is enforced in the application layer.
  • Each workspace holds its own API key for the add-on, which an administrator can regenerate at any time from Settings. Regenerating invalidates the previous key immediately.
  • Dashboard sessions are held in a signed, HTTP-only cookie.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to security@baitwall.com rather than disclosing it publicly, and we will respond promptly.

10

Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict processing of your personal data, and to object to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time.

Administrators can exercise most of these directly: organization details and the security contact are editable in Settings, and reports can be dismissed or the workspace deleted. For anything else, write to privacy@baitwall.com and we will respond within 30 days.

If you are an employee rather than an administrator, your employer controls your reports; we will forward your request to them. You also have the right to lodge a complaint with your local supervisory authority — in the EEA or UK, your national data protection authority.

11

Children

Baitwall is a workplace tool sold to organizations. It is not directed at anyone under 16, and we do not knowingly collect their data. If you believe a child’s data has reached us, contact us and we will delete it.

12

Changes to this policy

We will update this page when our practices change, and revise the date at the top. For changes that materially affect how we handle your data — a new sub-processor, a new category of stored data — we will notify workspace administrators by email before the change takes effect.

Questions about any of this go to privacy@baitwall.com. Our Terms & Conditions cover the commercial relationship.