MailSleuth.AI
Header Forensics
Back to analyzer
Legal

Privacy Policy

Last updated: August 22, 2026

MailSleuth.AI (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information when you use our email header forensics platform.

What we collect

We collect only what is needed to run the service: • **Email headers you paste or upload** — processed in real time to generate the security analysis. We do not read the message body. • **Account information** — when you sign in with Google OAuth, we receive your email address and a unique user ID from our authentication provider. • **Usage data** — anonymized analytics (page views, feature usage) via Google Analytics to help us improve the product. • **Technical logs** — basic request metadata such as IP address, user-agent, and timestamps, retained for security and debugging purposes.

How we use your data

We use your data solely to operate and improve MailSleuth: • To perform email header analysis and return forensic results. • To save scan history for authenticated users who opt in. • To monitor service health, prevent abuse, and fix bugs. • We do **not** sell, rent, or trade your data. We do not use email headers to train AI models.

Data storage & retention

Authenticated users may optionally save analyses to their history. Saved headers are stored in our backend database and are subject to row-level security, meaning only the owning account can access them. You can delete individual history items at any time from the History page. If you delete your account, all associated saved analyses are removed. Email headers submitted without signing in are processed transiently and are not retained after the analysis completes.

Cookies & tracking

We use essential cookies to maintain authentication sessions and optional analytics cookies via Google Analytics. You can disable analytics tracking through your browser or ad-blocker settings. We do not use third-party advertising cookies or trackers.

Third-party services

MailSleuth relies on a small number of trusted providers: • **Lovable Cloud / Supabase** — authentication, database, and edge-function hosting. • **Google Analytics** — anonymized usage analytics. • **Sanity** — content management for the blog. • **APIVoid / public DNS services** — threat intelligence and DNS lookups for diagnostic tools. Each provider is contractually bound to process data only as instructed and in compliance with applicable law.

Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. To exercise these rights, or to ask questions about this policy, contact us at privacy@mailsleuth.ai. We will respond to verifiable requests within 30 days.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of the page. Continued use of MailSleuth after changes constitutes acceptance of the revised policy.