1. Overview
TruSender provides AI-assisted email security, analysis, and administrative review tools. This Privacy Policy applies to the TruSender website, dashboard, private beta, connected email integrations, and related services (collectively, the “Service”).
TruSender is currently offered as a private beta. Features, integrations, and data practices may evolve as the Service is prepared for broader release. We will update this policy when material changes are made.
2. Information we collect
Account and organization information
We may collect names, email addresses, organization details, account roles, authentication settings, support communications, and early-access requests.
Email security data
When an authorized administrator connects an email environment, TruSender may process message headers, sender and recipient information, subject lines, message text or HTML, links, attachment information or content, authentication results, delivery metadata, folder or label information, and other security signals needed to evaluate a message.
Analysis and review data
We create and store security decisions, confidence scores, indicators, analysis explanations, administrator actions, review labels, evaluation categories, and related feedback. This information helps display results, measure accuracy, reduce false positives, and improve decisions for the applicable customer environment.
Technical and usage information
We may collect IP addresses, browser and device information, login and security events, feature usage, error logs, system health data, and audit history needed to operate and protect the Service.
3. How we use information
We use information to:
- authenticate users and administer customer accounts;
- retrieve and analyze messages an authorized user has connected or imported;
- identify phishing, scams, impersonation, malware, and other malicious activity;
- present findings, support human review, and carry out administrator-selected actions;
- maintain customer-specific trusted context and improve detection accuracy;
- troubleshoot failures, monitor system health, prevent abuse, and secure the Service;
- communicate about access, support, security, and material Service changes; and
- meet legal obligations and enforce our Terms of Service.
4. Google and Gmail data
Gmail is an optional integration that may be provided for testing, evaluation, or supported deployments. Connecting a Google account is not required to browse our public website. TruSender accesses Google account data only after the account holder or an authorized administrator grants permission through Google OAuth.
Depending on the permissions approved, TruSender may read messages and metadata for security analysis and may apply labels or perform a user-requested mailbox action. We use Google data only to provide and improve the visible email-security features requested by the connected user or organization.
- We do not sell Google user data or use it for advertising.
- We do not use Google Workspace API data to train generalized AI or machine-learning models shared across customers.
- We do not allow humans to read Google user data except with the user’s affirmative agreement for support or review, when required for security or abuse investigation, or when required by law.
- Our handling of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
A user can revoke TruSender’s Google access through their Google Account security settings. Revocation stops future API access but does not automatically remove information already retained under the customer’s settings; deletion options are described below.
5. Microsoft 365 and other integrations
When Microsoft 365 or another supported service is connected, TruSender receives only the access authorized through that provider and uses the resulting data to deliver the requested email-security features. Third-party providers maintain their own privacy policies and account controls.
6. AI analysis and customer feedback
TruSender uses automated systems, security rules, threat intelligence, and AI models to evaluate email. An AI decision may be incorrect and should not be treated as a guarantee that a message is safe or malicious. The Service includes human-review workflows so authorized users can confirm or correct decisions.
Review feedback and evaluation imports may be used to tune policies, benchmarks, and organization-specific trusted context. Unless we enter a separate written agreement or obtain clear permission, we do not use private mailbox content to train a generalized model shared with other customers.
8. Retention and deletion
We retain information only as long as reasonably needed to provide and secure the Service, meet customer-configured retention settings, resolve disputes, maintain required audit records, and satisfy legal obligations. Different records may have different retention periods.
Authorized administrators can use available retention and deletion controls or contact us to request deletion of connected account data. We may retain limited records in backups, security logs, or legally required archives for a reasonable period. Disconnecting an integration prevents future access but may not by itself delete previously processed records.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, authentication protections, encrypted transport, security logging, and restricted administrative access. No system can guarantee absolute security, and customers remain responsible for securing their own accounts, devices, and administrator access.
10. Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection concerning your personal information. Customer end users should generally contact their organization’s administrator first because the customer controls its connected email environment. You may also contact us directly, and we will respond as required by applicable law.
11. Children’s privacy
The Service is designed for businesses and administrators and is not directed to children under 18. We do not knowingly collect personal information directly from children through the public website.
12. Changes to this policy
We may update this Privacy Policy as the Service changes. The effective date at the top of this page shows when the current version took effect. We will provide additional notice when required by law or when a change materially affects how we handle information.
13. Contact us
Questions, privacy requests, and deletion requests can be sent to hello@trusender.com.