Skip to main content
Privacy you can verify

Your email content is never stored in our database.

Most security tools store your email on their servers. We don't. Here is exactly how your data flows, what we retain (almost nothing), and the commitment we make to your privacy.

How your data flows

From inbox to protection in 5 steps

Step 1

Email arrives

In Gmail or Outlook, like normal.

Step 2

Picked up by Ṣọ

The Ṣọ extension or app on your device sees the new email and sends it for checking.

Step 3

Analyzed on Ṣọ servers

Checked on our servers over an encrypted connection. Deleted as soon as the check is done.

Step 4

Result shown to you

What we found, with a plain-language reason.

Step 5

Nothing retained

Not kept in our database, shared, or used for training.

What leaves your device

A complete list of what we send and what we retain. If it is not here, it is never stored.

  • The email being checked: sender, subject, body and links. Discarded after the check
  • Your email address (for login only)
  • Anonymized threat patterns (no personal content)
  • Breach scan requests (just the email, never passwords)
  • Email content stored or retained after analysisNEVER
  • Contact lists, calendar events, or filesNEVER
  • Meeting audio, video, or transcriptsNEVER

Verify it yourself

Email content is processed in memory on our secure servers and never written to persistent storage. You can verify what we retain in our data retention table — your email content does not appear there.

// What Ṣọ stores after analysis
Email body / subject: not kept in our database

Email threat analysis runs on our servers in the United States. Content is analysed in memory and not kept in our database; diagnostic logs can briefly hold parts of a request, then rotate out. Meeting security is not available yet.

Straight answers

What happens to your email

The questions people ask us most, answered without fine print.

Do you read my email?Yes, to check it. On our servers, then it is discarded.
Do you keep a copy afterwards?No. Email content is never saved to our database.
Do you share or sell it?No.
Do I need to change DNS or MX records?No.
Do I need an IT team to set it up?No. It takes about a minute.

Available everywhere

Feature availability by platform

Some features require browser-level access and are only available on the Chrome extension. Core protection works across all platforms.

Feature
Extension
Mobile
Desktop
Email threat scanning
Phishing and spoofing detection
Link and attachment analysis
Email categorization
Dark web breach monitoring
Breach alert emails
Suggested replies
Inline threat banners in Gmail/Outlook
Email tracker blocking
Audio deepfake detection (not yet available)---
Video deepfake detection (not yet available)---
Live meeting transcription (not yet available)---
VPN / datacenter detection in meetings (not yet available)---
Post-meeting recap (not yet available)---
Calendar integration-
Snooze and scheduled send-

Compliance

Standards we meet

Google CASA Verified

Passed Google's Cloud Application Security Assessment for Workspace API access.

GDPR Compliant

European privacy standards. Data minimization. Right to access, correct, and delete.

Zero-Retention Architecture

Email content is analysed in memory and is never stored in our database. Diagnostic logs can briefly hold parts of a request while it is processed, then rotate out.

Restricted Human Access

Nobody reads your mail to operate the product. Access to logs is limited to the few staff who need it, and every access is recorded.

Encrypted in Transit

All data transmitted between your device and our servers uses TLS encryption.

We do not yet hold SOC 2, ISO 27001, or HIPAA compliance. We are in an active SOC 2 Type I audit, with Type II to follow. If a certification matters for your purchase, ask us and we will tell you exactly where we stand.

What we retain and for how long

Email content (body, subject, attachments)Never stored on our servers
Meeting audio, video, and transcriptsNever leaves your device
Breach scan resultsUntil you delete your account
Account info (name, email)Until you delete your account
OAuth tokensAccess-controlled, duration of service use
Reported false positives (de-identified)90 days maximum
Billing and tax records7 years (legal requirement)

Try it yourself

The safest email data is the kind we never keep

Connect your inbox in about a minute. No DNS changes, no MX records, no IT ticket. Your email content stays out of our storage from the very first scan.

Reviewing Ṣọ for your organization? See what enterprises and MSPs get