Coming soon: the Gmail add-on is finishing Google Workspace Marketplace review for one-click install.
Security
What's sent, when, to which AI provider, what we keep, and how to get it deleted — answered directly, before you have to ask.
Last updated · 17 September 2026
Nothing is sent automatically when an employee opens an email. The add-on only reads and transmits a message when the employee presses Analyze or Report to security — opening a message shows an idle card with no network call.
On that click, the sender address and display name, subject, reply-to address, and plain-text body of the one message currently open are sent over HTTPS to our API, held in memory for the duration of the request, and forwarded to the configured AI provider for scoring. Nothing else in the mailbox is read.
Scoring is performed by either Anthropic or DeepSeek, depending on how a deployment is configured — never both, and never chosen per request.
| Provider | Retention position |
|---|---|
| Anthropic | States that API inputs are not used to train its models. Refer to Anthropic’s own data usage policy for their retention window on API traffic. |
| DeepSeek | Review DeepSeek’s current terms and data-residency position directly before selecting it as provider, particularly if your organization restricts where data may be processed — its policies differ from Anthropic’s. |
Either way: we do not use your email content to train any model ourselves, and the body is discarded on our side the moment the request completes — see the next section for exactly what does get kept.
| Stored | Not stored |
|---|---|
| Sender address/name, subject, reply-to, phishing score, category, AI-written indicators and summary, workflow status, reporter address, timestamps. | The email body, HTML, attachments, or any header beyond sender/reply-to/message-id. |
Stored metadata is retained for as long as the workspace is active, so trend data stays meaningful. It is deleted immediately when a workspace is closed — see deletion requests below for closing early.
Honest caveat. The AI-written summary and indicators fields can paraphrase or quote a short fragment of the message (e.g. the specific urgency phrasing that triggered the score). If your threat model requires that literally nothing derived from message content is retained, say so before piloting — this is the one exception worth flagging up front.
Four OAuth scopes, all narrowly used:
| Scope | Used for |
|---|---|
gmail.addons.execute | Running the add-on inside Gmail. |
gmail.addons.current.message.readonly | Reading only the message currently open when Analyze/Report is pressed — not the mailbox, not other messages. |
script.external_request | Sending the analysis request to our API. |
userinfo.email | Attributing a scan or report to the employee who ran it, for your dashboard. Nothing else about that identity is read. |
No domain-wide Gmail read access, no ability to send mail, no access to Drive, Calendar, or Contacts.
Email privacy@baitwall.com from an admin address on the workspace. Closing a workspace deletes every associated row — tenant, users, reports, and analysis logs — immediately via database cascade, not on a delay.
For a specific subset of reports rather than the whole workspace, tell us which ones and we will action it manually within a few business days.
This page is the fast version. For the complete, legally precise account — data controller/processor roles, legal basis for processing, sub-processor list, and your rights — read the Privacy Policy. Commercial terms are in the Terms & Conditions.