Email Scam Checker Email Scam Checker

Privacy Policy

Last updated: 2026-09-14

Email Scam Checker is a Chrome extension that detects scam and phishing emails in Gmail, Outlook, Yahoo Mail, Proton Mail, iCloud Mail, and Zoho Mail. This page explains what data the extension processes, what it stores, and what it never collects.

Email analysis happens on your device, with a few narrow lookups

When you open an email, the extension extracts the sender, subject, body, and links directly from the page and runs its checks locally in your browser. No email content — subject, body, or attachments — is ever sent to any external server for analysis. This applies both to the automatic heuristic checks and to the optional on-device AI Deep Scan, which downloads a small phishing-detection model once (about 67 MB) and then runs completely offline.

Four lookups do reach the network, and each sends only what it needs. First, to check whether a link's domain was recently registered, the extension sends only the bare domain name (for example, paypal.com) to the public RDAP domain registry (rdap.org) to read its registration date — never your email body, subject, sender, the full link, or the URL path. Second, when an email contains a shortened link (bit.ly, tinyurl.com, t.co, and similar), the extension sends that shortened URL to the shortener to learn where it points; it reads the single redirect the shortener returns and never follows the link through to its destination. Third, to decode a QR code hidden in an image, the extension fetches that image and decodes it locally. Often it is an attachment on your mail provider's own host — for Gmail, that is Google's mail-attachment.googleusercontent.com. It can also be an image hosted anywhere else that appears in the email body or is linked from it, because a QR code can be hidden in any image a message carries; that request carries whatever cookies your browser sends for the host, and the extension does not follow redirects away from it. The image is only read and decoded on your device — nothing is uploaded.

The fourth is a read of your own scan history: to see whether you have received mail from a sender's domain before, the extension asks the private backup described below how many times that domain has been scanned. That query is scoped to your installation, returns a count rather than any message, and no other installation can read it.

Permissions we request, and why

  • mail.google.com (Gmail), outlook.live.com / outlook.office.com / outlook.cloud.microsoft (Outlook), mail.yahoo.com (Yahoo Mail), mail.proton.me (Proton Mail), www.icloud.com / www-mail.icloud-sandbox.com (iCloud Mail), mail.zoho.com and Zoho's regional Mail domains such as mail.zoho.eu (Zoho Mail) — needed so the content script can read the currently open email's sender, subject, body, and links from the page and display the scam-risk badge directly in your inbox.
  • mail-attachment.googleusercontent.com — needed to fetch a PDF attachment from Gmail's own attachment host so the extension can decode any QR code hidden inside it locally. The PDF is read on your device and never uploaded anywhere.
  • huggingface.co and cdn.jsdelivr.net — used once to download the on-device AI Deep Scan model files. No email data is sent to these hosts; they only serve the static model.
  • Shortener hosts — bit.ly, t.co, tinyurl.com and similar services — needed to resolve a shortened link in an email to the destination it points at. Only the shortened URL is sent; the extension reads the single redirect and never follows the link through to its destination.
  • activeTab — lets the extension identify the mail tab you're actively viewing.
  • storage — needed to save your settings, anti-phishing codes, and marked-sender lists locally in your browser.

Beyond the mail domains, attachment hosts, model hosts, and shortener services listed above, the extension does not request access to any other website, your browsing history, or any Gmail/Outlook/ Yahoo/Proton/iCloud/Zoho account API — it only reads what's already rendered on the page you have open.

What we store, and why

To keep your stats and recent-scams list available even if you switch computers or clear your browser data, a short summary of each scam email is backed up to a private store tied to your installation:

  • Sender — the email address and display name of the message that was flagged (i.e. the suspected scammer's address, not your own)
  • Subject line of the flagged message
  • Verdict and score — the risk classification the extension assigned, and its numeric score
  • Quoted fragments — the short piece of text behind each finding, so your recent-scams list can show you why an email was flagged. Where the finding concerns a link, that fragment is the address of that link.
  • Anti-phishing phrases — when an email displays a labelled anti-phishing code, the phrases you have configured are included, so the result can be explained to you: every phrase you have configured, for every service, when the code does not match, and the matched phrase when it does.
  • Reassurance checks — which positive signals fired (for example, an unsubscribe link), so a verdict can be explained in both directions

The full email body and any attachments are never included, and neither is the complete list of links in a message — what is stored is the short fragment described above for each finding, which for a link finding is the address of that one link. This backup is scoped to an anonymous identifier created for this installation — it is not linked to your name, your own email address, or any account, and no other installation of the extension — including other users — can read it.

Data retention and deletion

The backup keeps your most recent scam records (up to the last 20) plus your aggregated stats for as long as the extension remains installed. Uninstalling the extension does not automatically delete this backup, since it's keyed to an anonymous installation identifier rather than an account. To request deletion of your backed-up data, email us at the address below with the approximate date you installed or uninstalled the extension, and we will erase the matching record.

What is stored in your browser

The following are stored locally in your browser and are never sent anywhere:

  • Your list of senders marked "safe" or "reported as scam"
  • The local cache of recently scanned emails, used to avoid re-scanning the same message — the cache itself is local to this browser; the backed-up summary described above is a separate copy of the same scan

Your on/off setting and your light/dark theme choice work differently. The extension stores them in your browser and does not send them anywhere itself, but they use the browser's synced storage, so if you have browser sync turned on (Chrome Sync, your Microsoft account, or Firefox Sync), your browser may copy those two values to your other signed-in devices. What travels is a yes/no and a theme name — nothing about your email.

Your anti-phishing codes (personal secret phrases you configure for services like Proton Mail, Coinbase, Gate, or Binance) are stored locally in your browser too, with one exception you should know about. When a scanned email displays a labelled anti-phishing code, the phrases you have configured are written into the backed-up summary described in "What we store, and why". A mismatch writes every phrase you have configured, for every service, and is treated as a finding, so it can be explained to you. A match writes the matched phrase, so it can be explained to you. Those backed-up phrases are covered by the deletion request described in "Data retention and deletion".

What we never collect

In the course of checking your email, we do not collect your name, your own email address or account identity, browsing history, or the full content of any email (body, links, or attachments). We do not sell or share data with advertisers, and we do not use any data for advertising or purposes unrelated to detecting scam emails. The extension does not require an account or sign-in.

Third-party infrastructure

The anonymized scan-summary backup described above is stored using Google Firebase (Cloud Firestore), with an anonymous Firebase Authentication identity generated per installation. Firebase only ever receives the anonymized summary data described in "What we store, and why" — it never receives raw email content, and server-side security rules restrict access to each installation's records to that installation alone. See Google's Firebase privacy and security policy for how Google handles this infrastructure.

This website

This landing page (emailscamcheck.com) uses Google Analytics to measure aggregate, anonymous visitor statistics (page views and approximate region). Google Analytics sets cookies for this; it never receives email content or anything that identifies you personally. See Google's privacy policy and how Google uses information from sites.

The contact form

This is separate from the extension and is the one place on this site where you send us something about yourself. If you use the contact form, the name, email address and message you type are sent to us so that we can reply. The message is delivered to us through Telegram, which processes it as the delivery channel. It is not stored anywhere else, not added to a mailing list, and not used for anything other than answering you. The form asks for nothing else, and using it does not require or reveal whether you have the extension installed.

Your message stays in our Telegram chat until we delete it. Ask us to remove it — through the form or by email — and we will.

Children's privacy

Email Scam Checker is not directed at children and does not knowingly collect information from children under 13.

Changes to this policy

If this policy changes, we will update this page and revise the "Last updated" date above.

Contact

Questions about this policy or your data? Email dubstr1@gmail.com.