Email assessments
The official scanner processes the subject, sender address, and normalized message text only to produce the requested assessment.
- Maillume does not save email text, sender details, screenshots, .eml files, detected links, or completed results to scan history or application storage.
- Screenshot OCR and .eml parsing run in the browser before normalized text is submitted.
- For .eml scans the browser also reads the sender-authentication headers your mail provider added and sends only their outcomes, such as whether SPF, DKIM, or DMARC passed and whether replies would go to a different domain. The header text itself is never sent.
- Analysis and feedback routes send Cache-Control: no-store responses, and application code does not log request bodies.
- The public beta uses Maillume's built-in heuristic checks and does not send scan text to an AI model provider. Normalized scan text is sent to Maillume only for the requested assessment.
- Hosting, network, and security infrastructure still process request data transiently to deliver and protect the service. Their operational processing is separate from Maillume saving scan content or results in application storage.
Purposes and legal bases
Where the GDPR applies, Maillume processes ordinary scan content to take the assessment you request and, where applicable, to perform the service relationship. It processes account, credential, and connection metadata to provide the optional account and browser-connection features.
We rely on legitimate interests for service security, abuse prevention, troubleshooting without payloads, and the non-identifying daily usage counts, after considering the privacy impact. We process optional feedback only when you choose to submit it; where consent is required, we rely on that consent and you may withdraw it by contacting us. We may also process limited data where needed to meet a legal obligation. The precise basis depends on the context and applicable law.
Data categories and recipients
The categories described in this notice are: the scan fields you submit (subject, sender, normalized text, detected links, and limited technical indicators); optional feedback labels; account and authentication data; browser or developer credential metadata; contact messages; and limited operational or security metadata. The original screenshot and .eml file stay in the browser and are not uploaded as source files.
Recipients are limited to the service providers named below when their role is enabled, and to authorities or advisers where law requires it. Maillume does not sell scan data, use it for advertising or credit decisions, or disclose it for unrelated purposes.
Usage counts
Maillume counts how many assessments are completed each day, split only by input mode: pasted text, screenshot, .eml file, or Chrome extension. This is how the project can tell whether the scanner is used at all.
A count is a single number for one day and one input mode. It records nothing about the message, the assessment, or you. No account, session, IP address, request identifier, score, result, or time of day is stored, so a count cannot be traced back to a person or to a specific scan. Maillume uses no third-party analytics, advertising, or tracking service.
Optional feedback
If feedback is enabled and you choose to submit it, Maillume receives only your selected accuracy label, expected classification, high-level signal categories, language, input mode, analyzer version, and score band.
Feedback excludes email text, sender, subject, links, attachments, screenshots, and .eml files. Detailed feedback records are configured to expire after no more than 90 days.
Optional accounts
Email-and-password sign-in and Google sign-in are optional and are provided through Supabase when enabled. The account may include your email address, display name, provider identifier, session cookies, and basic authentication metadata.
If you enable authenticator-app two-factor authentication, Supabase processes the enrollment and verification data needed for TOTP. Maillume does not receive or store the authenticator app's private data outside the authentication service.
Signing in does not create scan history. Authentication cookies maintain the signed-in session. When production authentication is enabled, the account page provides confirmation-gated deletion of the Supabase identity.
For developer API keys and browser connections, Maillume stores the owner, name, short prefix, credential SHA-256 hash, type, quota, timestamps, UTC billing month, and aggregate request count. Browser connections also store only the SHA-256 hash of a random installation identifier and a rolling inactivity deadline. Plaintext credentials are returned once. API usage records exclude message content, results, links, IP addresses, and message identifiers.
Chrome browser extension
The Chrome extension captures text you explicitly select or, when supported and unambiguous, the visibly open webmail message after you start the action. For that assessment it sends the subject, sender, message text, and detected HTTP(S) link destinations (including displayed-link and destination pairs when available) to the Maillume deployment displayed in the extension.
The extension does not perform background mailbox scanning and does not persist message content or results. Its endpoint, dedicated browser credential, expiry metadata, and random installation identifier are stored in trusted extension-local storage across restarts and updates. The server receives only a hash of the installation identifier. Advanced manual setup can keep a developer API key locally or only for the browser session.
Chrome extension data is used only to provide and secure the email-risk assessment you request. Maillume does not sell extension data, use it for advertising or credit decisions, transfer it for unrelated purposes, or allow people to read message content except when you give specific support consent or when access is required for security or legal obligations.
Service providers and infrastructure
The official deployment uses Hostinger for application hosting, Cloudflare for DNS, protected ingress, and abuse prevention, Supabase for authentication and non-content feedback, Resend for transactional authentication email, Google Workspace for monitored contact mailboxes, GitHub for source development and releases, and UptimeRobot for content-free availability monitoring. These providers may process technical request, account, email-delivery, or operational data according to their role; that does not mean Maillume stores scan content or results in scan history or application storage.
If the hosted service enables an external AI provider in the future, normalized message text will be sent to that configured provider for the requested assessment. The provider and its processing terms must be disclosed before that mode is enabled.
Production monitoring must exclude scan and feedback payloads. A provider is active only when it has been configured for the deployed service.
Retention
Ordinary scan content and completed assessments are processed for the current request and response, then discarded. Maillume does not create application scan history. This does not prevent hosting, network, or security infrastructure from handling request data transiently while delivering or protecting the request.
Optional feedback expires within 90 days. Account data is kept while an account is active and removed through the deletion workflow, unless a lawful obligation requires a narrower record to be retained. Credential metadata is kept until expiry, revocation, or account deletion; aggregate monthly quota records are kept for up to 13 months. A browser connection has a one-year hard expiry and a rolling 90-day inactivity deadline.
Daily scan counts are non-identifying aggregates kept only while needed for product operations and erased or further aggregated when no longer needed. Official operational security records must exclude scan payloads; the service target for permitted request metadata is a maximum of 14 days. Contact correspondence is retained only as long as needed to handle the request, maintain required records, or resolve a dispute. Actual provider, log, and backup retention settings must be verified before launch and before production changes.
International transfers
The official service is operated from the Netherlands and is intended to use an EU-region authentication project. Some listed providers may process relevant personal data outside the European Economic Area, depending on their service configuration and support operations.
Before the official operator makes a restricted transfer, it must use an applicable transfer mechanism, such as an adequacy decision or Standard Contractual Clauses with any needed supplementary measures. Contact the privacy address for the current provider, country, and safeguard information relevant to your request.
Open source and self-hosting
Anyone can run a separate Maillume deployment. Those operators choose their own infrastructure, analytics, authentication, AI providers, and retention settings. Their privacy practices may differ from the official service.
Contact and your rights
You may ask to access, correct, erase, restrict, or receive portable copies of applicable personal data, object to processing based on legitimate interests, and withdraw consent where it is the basis. We may need to verify your identity and may explain any lawful limit on a request.
For the official public beta, the controller is Maillume. Dutch Chamber of Commerce 99723239; VAT ID NL005406760B59.
Privacy contact: privacy@maillume.io.
You may also complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens. Contact Maillume to exercise rights or request clarification about this public beta. This notice explains the service design and is not legal advice or legal certification.
Security issues should be reported through the process on the security page, never through a public issue containing private email data.