Coming soon: the Gmail add-on is finishing Google Workspace Marketplace review for one-click install.
Legal · Privacy
What Baitwall collects, what it deliberately never stores, and every third party that touches your data.
Last updated · 20 August 2026
We do not store the contents of your email. When a message is analyzed, its body is held in memory for the duration of the request, sent to an AI provider for scoring, and then discarded. It is never written to our database, log files, or backups.
We do store what the analysis produced. The sender, subject line, score, category, the list of threat indicators, and a short plain-English summary are saved so your security team has a record to work from. The summary and indicators are written by the AI model and therefore describe the message — read section 03 before assuming nothing derived from the body is retained.
Your email content is transmitted to a third party.Scoring is performed by Anthropic or DeepSeek, depending on how your deployment is configured. “We do not store it” is not the same as “it never leaves our servers.” Section 05 names every processor.
The rest of this policy states the same things precisely. If anything here conflicts with a signed agreement between us, that agreement governs.
Baitwall (“Baitwall”, “we”, “us”) is operated by Jonibek Norboev, as a sole proprietor. You can reach us about anything in this policy at privacy@baitwall.com.
This policy covers the Baitwall web dashboard, the Baitwall API, and the Baitwall Google Workspace add-on. It applies to two groups of people, and the distinction matters:
If you are an employee with a question about why your employer deployed Baitwall, or you want your reports removed, contact your own security or IT team first — they control that data, and we act on their instructions.
Everything Baitwall stores falls into four groups. There is nothing else — no advertising identifiers, no behavioural profiling, no third-party trackers.
| Category | Fields |
|---|---|
| Workspace account | Organization name, optional email domain, security team email address, and the API key issued to your workspace. |
| Administrator account | Email address, a bcrypt hash of the password (never the password itself), and role (admin or viewer). |
| Reports | Reporter email address, sender email address and display name, subject line, message ID, phishing score, category, the list of threat indicators, an AI-written summary, workflow status, and timestamps. |
| Analysis logs | When the sidebar scores a message that is then not reported, we keep the same fields minus the message ID, so your team can see scanning volume. |
We also set one strictly necessary cookie holding your signed-in session. It is required for the dashboard to function and carries no analytics purpose. We do not use advertising or tracking cookies, so there is no consent banner to dismiss.
The following never reaches our database, and is not present in backups or application logs:
The body is read from Gmail by the add-on, sent to us over HTTPS, passed to the AI provider, and released from memory when the request completes. Our database schema has no column capable of holding it.
An honest caveat. The summary and indicators fields are generated by an AI model that has read the message, and they are stored. A summary may therefore paraphrase or quote a fragment of the email — for example, the specific urgency phrasing that made the message suspicious. If your threat model requires that nothing derived from message content is retained, Baitwall is not the right fit as currently built.
| Purpose | Basis |
|---|---|
| Scoring a reported message and returning a verdict | Performance of our contract with the customer organization; for employee data, the legitimate interest of that organization in protecting its systems. |
| Emailing the verdict to the security team | Performance of our contract — this is the core function the customer signed up for. |
| Keeping the report history and dashboard statistics | Legitimate interest in giving security teams a workable record of threats against their organization. |
| Authenticating administrators | Performance of our contract, and our legitimate interest in keeping accounts secure. |
| Diagnosing errors and abuse | Legitimate interest in operating the service reliably and safely. |
We do not sell personal data, we do not share it with advertisers, and we do not use it to train any AI model. See section 05 for what our providers commit to on that last point.
Baitwall relies on the following sub-processors. Which AI provider applies depends on how your deployment is configured; your administrator can confirm which one is active.
| Provider | What it receives, and why |
|---|---|
| Anthropic | When configured as the AI provider: the sender, subject, reply-to, and body of a message being analyzed. Anthropic states that API inputs are not used to train its models. |
| DeepSeek | When configured as the AI provider: the same fields. Review DeepSeek’s current terms and data-residency position before selecting it, particularly if your organization has restrictions on where data may be processed. |
| Resend | The security team email address and the alert message — which includes the sender, subject, score, indicators, and summary. Used to deliver the alert. |
| Google Workspace | The add-on runs inside Gmail and reads the open message using Google’s APIs. Google processes this as your organization’s existing Workspace provider. |
| Hosting and database | Hetzner (application server) and Neon (Postgres database), both in the European Union. |
Because these providers may operate outside your country, personal data may be transferred internationally. Where that involves transfers out of the EEA or the UK, they are made under Standard Contractual Clauses or an equivalent approved mechanism.
The Gmail add-on requests the following OAuth scopes. Each one is used solely for the purpose stated:
| Scope | Used for |
|---|---|
gmail.addons.execute | Running the add-on inside the Gmail interface. |
gmail.addons.current.message.readonly | Reading the message the employee currently has open, so it can be scored. This is the narrower, add-on-scoped version of Gmail read access — it grants nothing beyond the open message, unlike the broader gmail.readonly scope. |
script.external_request | Sending the analysis request to the Baitwall API. |
userinfo.email | Identifying which employee ran the scan or filed the report, so the result can be attributed to them on your security team’s dashboard. Not used to read, list, or store anyone else’s email address. |
Baitwall’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data except as necessary to provide the service, we do not use it for advertising, and we do not allow humans to read it except with your explicit consent, where required for security or legal reasons, or where the data has been aggregated and de-identified.
Current limitation. Automatic time-based deletion is not yet implemented. Reports stay until a workspace is deleted, at which point database cascade rules remove every associated row. If you need a specific retention window enforced today, contact us and we will action it manually.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to security@baitwall.com rather than disclosing it publicly, and we will respond promptly.
Depending on where you live, you may have the right to access, correct, delete, export, or restrict processing of your personal data, and to object to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time.
Administrators can exercise most of these directly: organization details and the security contact are editable in Settings, and reports can be dismissed or the workspace deleted. For anything else, write to privacy@baitwall.com and we will respond within 30 days.
If you are an employee rather than an administrator, your employer controls your reports; we will forward your request to them. You also have the right to lodge a complaint with your local supervisory authority — in the EEA or UK, your national data protection authority.
Baitwall is a workplace tool sold to organizations. It is not directed at anyone under 16, and we do not knowingly collect their data. If you believe a child’s data has reached us, contact us and we will delete it.
We will update this page when our practices change, and revise the date at the top. For changes that materially affect how we handle your data — a new sub-processor, a new category of stored data — we will notify workspace administrators by email before the change takes effect.
Questions about any of this go to privacy@baitwall.com. Our Terms & Conditions cover the commercial relationship.