Privacy Policy
Last updated: September 27, 2026
This Privacy Policy explains how Phishing Investigation Assistant handles information when you use the application and its supported email integrations.
1. Purpose of the Application
Phishing Investigation Assistant is a cybersecurity application designed to help users investigate potentially suspicious email messages. The application analyzes security indicators such as suspicious links, domain mismatches, impersonation indicators, credential requests, urgency indicators, and other characteristics associated with phishing and social engineering.
2. Email Provider Access
When a user chooses to connect a supported email account, the application uses the authorization mechanisms provided by that email provider.
For Gmail, Phishing Investigation Assistant requests read-only Gmail access. This permission allows the application to retrieve email information needed to perform phishing investigations. The application does not request permission to send email through Gmail or modify Gmail messages as part of this read-only access.
Users choose whether to authorize an email account and may disconnect an integration when they no longer wish to use it.
3. Information Processed
Depending on the email and the functionality being used, information processed for an investigation may include:
- Email sender information
- Email subject
- Email message content
- Message and thread identifiers
- Email headers and related metadata
- Links contained in email messages
- Attachment-related information used by supported analysis features
- Investigation findings and risk-assessment results
4. How Information Is Used
Email information accessed through a connected account is used to provide the application's email investigation and security-analysis functionality.
The application may use email content and related information to perform local security checks, machine-learning classification, risk scoring, domain and URL analysis, and generation of investigation findings.
5. Local Processing and Storage
The current desktop application performs its phishing investigation and machine-learning analysis locally on the user's computer. Investigation information and results may be stored in the application's local database on that computer so that users can view investigation history and related results.
OAuth authorization information used by supported integrations is stored locally by the application using the security mechanisms implemented for the applicable integration.
6. Sharing of Email Data
Phishing Investigation Assistant does not sell email content obtained through connected email-provider accounts.
Based on the current desktop architecture, email investigation content is processed by the locally installed application rather than being uploaded to an application-operated cloud server for phishing analysis. The application communicates with the applicable email provider as necessary to authenticate the user and retrieve authorized email information.
7. Google API Data
Phishing Investigation Assistant's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including applicable Limited Use requirements.
Google user data accessed through Gmail authorization is used only to provide user-facing email investigation functionality authorized by the user.
8. Data Retention
Investigation records may remain in the application's local database on the user's computer. Local application data may therefore remain available until it is removed through supported application or system data-management procedures.
Disconnecting an email account prevents continued authorized access through that connection but does not necessarily remove investigation records that were previously stored locally.
9. Security
The application is designed to limit email-provider permissions to those required for supported functionality and to protect locally stored authorization information using the security mechanisms implemented for each integration.
No software system can guarantee absolute security. Users should maintain appropriate operating-system, account, and device security practices.
10. User Choices
Users control whether they connect supported email accounts to Phishing Investigation Assistant. Users may disconnect an email integration if they no longer want the application to access that account through the granted authorization.
11. Changes to This Privacy Policy
This Privacy Policy may be updated as the application, its features, or applicable requirements change. The date at the top of this page identifies the most recent revision.
12. Contact
Questions regarding this Privacy Policy may be submitted through the official support contact information published on the Phishing Investigation Assistant website.