Your email content is never stored in our database.
Most security tools store your email on their servers. We don't. Here is exactly how your data flows, what we retain (almost nothing), and the commitment we make to your privacy.
How your data flows
From inbox to protection in 5 steps
Email arrives
In Gmail or Outlook, like normal.
Picked up by Ṣọ
The Ṣọ extension or app on your device sees the new email and sends it for checking.
Analyzed on Ṣọ servers
Checked on our servers over an encrypted connection. Deleted as soon as the check is done.
Result shown to you
What we found, with a plain-language reason.
Nothing retained
Not kept in our database, shared, or used for training.
What leaves your device
A complete list of what we send and what we retain. If it is not here, it is never stored.
- The email being checked: sender, subject, body and links. Discarded after the check
- Your email address (for login only)
- Anonymized threat patterns (no personal content)
- Breach scan requests (just the email, never passwords)
- Email content stored or retained after analysisNEVER
- Contact lists, calendar events, or filesNEVER
- Meeting audio, video, or transcriptsNEVER
Verify it yourself
Email content is processed in memory on our secure servers and never written to persistent storage. You can verify what we retain in our data retention table — your email content does not appear there.
Email threat analysis runs on our servers in the United States. Content is analysed in memory and not kept in our database; diagnostic logs can briefly hold parts of a request, then rotate out. Meeting security is not available yet.
Straight answers
What happens to your email
The questions people ask us most, answered without fine print.
Available everywhere
Feature availability by platform
Some features require browser-level access and are only available on the Chrome extension. Core protection works across all platforms.
| Feature | Extension | Mobile | Desktop |
|---|---|---|---|
| Email threat scanning | |||
| Phishing and spoofing detection | |||
| Link and attachment analysis | |||
| Email categorization | |||
| Dark web breach monitoring | |||
| Breach alert emails | |||
| Suggested replies | |||
| Inline threat banners in Gmail/Outlook | |||
| Email tracker blocking | |||
| Audio deepfake detection (not yet available) | - | - | - |
| Video deepfake detection (not yet available) | - | - | - |
| Live meeting transcription (not yet available) | - | - | - |
| VPN / datacenter detection in meetings (not yet available) | - | - | - |
| Post-meeting recap (not yet available) | - | - | - |
| Calendar integration | - | ||
| Snooze and scheduled send | - |
Compliance
Standards we meet
Google CASA Verified
Passed Google's Cloud Application Security Assessment for Workspace API access.
GDPR Compliant
European privacy standards. Data minimization. Right to access, correct, and delete.
Zero-Retention Architecture
Email content is analysed in memory and is never stored in our database. Diagnostic logs can briefly hold parts of a request while it is processed, then rotate out.
Restricted Human Access
Nobody reads your mail to operate the product. Access to logs is limited to the few staff who need it, and every access is recorded.
Encrypted in Transit
All data transmitted between your device and our servers uses TLS encryption.
We do not yet hold SOC 2, ISO 27001, or HIPAA compliance. We are in an active SOC 2 Type I audit, with Type II to follow. If a certification matters for your purchase, ask us and we will tell you exactly where we stand.
What we retain and for how long
Try it yourself
The safest email data is the kind we never keep
Connect your inbox in about a minute. No DNS changes, no MX records, no IT ticket. Your email content stays out of our storage from the very first scan.
Reviewing Ṣọ for your organization? See what enterprises and MSPs get