Coming soon: the Gmail add-on is finishing Google Workspace Marketplace review for one-click install.

Security

Security & data

What's sent, when, to which AI provider, what we keep, and how to get it deleted — answered directly, before you have to ask.

Last updated · 17 September 2026

01

What we send, and when

Nothing is sent automatically when an employee opens an email. The add-on only reads and transmits a message when the employee presses Analyze or Report to security — opening a message shows an idle card with no network call.

On that click, the sender address and display name, subject, reply-to address, and plain-text body of the one message currently open are sent over HTTPS to our API, held in memory for the duration of the request, and forwarded to the configured AI provider for scoring. Nothing else in the mailbox is read.

02

Which AI provider, and its retention terms

Scoring is performed by either Anthropic or DeepSeek, depending on how a deployment is configured — never both, and never chosen per request.

ProviderRetention position
AnthropicStates that API inputs are not used to train its models. Refer to Anthropic’s own data usage policy for their retention window on API traffic.
DeepSeekReview DeepSeek’s current terms and data-residency position directly before selecting it as provider, particularly if your organization restricts where data may be processed — its policies differ from Anthropic’s.

Either way: we do not use your email content to train any model ourselves, and the body is discarded on our side the moment the request completes — see the next section for exactly what does get kept.

03

What we store, and for how long

StoredNot stored
Sender address/name, subject, reply-to, phishing score, category, AI-written indicators and summary, workflow status, reporter address, timestamps.The email body, HTML, attachments, or any header beyond sender/reply-to/message-id.

Stored metadata is retained for as long as the workspace is active, so trend data stays meaningful. It is deleted immediately when a workspace is closed — see deletion requests below for closing early.

Honest caveat. The AI-written summary and indicators fields can paraphrase or quote a short fragment of the message (e.g. the specific urgency phrasing that triggered the score). If your threat model requires that literally nothing derived from message content is retained, say so before piloting — this is the one exception worth flagging up front.

04

Workspace permissions the add-on requests

Four OAuth scopes, all narrowly used:

ScopeUsed for
gmail.addons.executeRunning the add-on inside Gmail.
gmail.addons.current.message.readonlyReading only the message currently open when Analyze/Report is pressed — not the mailbox, not other messages.
script.external_requestSending the analysis request to our API.
userinfo.emailAttributing a scan or report to the employee who ran it, for your dashboard. Nothing else about that identity is read.

No domain-wide Gmail read access, no ability to send mail, no access to Drive, Calendar, or Contacts.

05

Where the servers are

  • Application server: Hetzner, European Union.
  • Database: Neon (Postgres), European Union.
  • Email delivery:Resend, used only to relay the alert containing a report’s metadata to your security inbox.
06

Requesting data deletion

Email privacy@baitwall.com from an admin address on the workspace. Closing a workspace deletes every associated row — tenant, users, reports, and analysis logs — immediately via database cascade, not on a delay.

For a specific subset of reports rather than the whole workspace, tell us which ones and we will action it manually within a few business days.

07

Full legal detail

This page is the fast version. For the complete, legally precise account — data controller/processor roles, legal basis for processing, sub-processor list, and your rights — read the Privacy Policy. Commercial terms are in the Terms & Conditions.