Most "free" security tools pay for themselves by harvesting your data. We don't. SafeToOpen never collects, stores, or sells your browsing — and this page explains exactly how that works.
Plain, specific, and the same for everyone — individuals, families and organizations alike.
Not to advertisers, not to data brokers, not to anyone. Our products are funded by subscriptions — not by monetising you.
Analysis happens at the moment of risk to return a verdict, then logs are deleted. There's no browsing history to store or leak.
We actively stop known trackers from collecting your data and strip tracking parameters from your searches.
We process the least we can to keep you safe — data minimisation isn't a setting, it's how the product is built.
It's a fair question: how does a tool scan risky pages without building a profile of you? The answer is in when and why analysis happens — and what happens to it afterwards.
A page is analysed only when it looks risky, only to decide if it's safe, and the analysis log is deleted after the check. The verdict stays with you. Nothing is assembled into a history, and nothing is sold.
The same restraint applies to Scam Check, where you are testing your own people rather than being protected: the questions are fictional examples we wrote, so no real message of yours is ever read, and you can run a whole campaign in anonymous mode where no address is stored at all.
Strong privacy needs strong security behind it. Here's our posture.
Data minimisation by design, no sale of personal data, and a Data Processing Agreement for business customers.
READ THE DPA →Independently certified against the international standard for information security management.
ABOUT THE CERTIFICATION →Communication between the product and our services is encrypted, and access is least-privilege by default.
SECURITY OVERVIEW →Found a security issue? We welcome responsible disclosure and respond quickly.
CONTACT SECURITY →The full legal detail behind the promise — always linked in the footer too.
What we process, why, for how long, and your rights.
READ →The terms that govern use of SafeToOpen products.
READ →For organizations that need a DPA in place.
READ →The minimal cookies our sites and products use.
READ →No. SafeToOpen never sells your data — not to advertisers, data brokers, or anyone else. Our products are paid for by subscriptions, not by monetising your browsing.
Analysis happens at the moment of risk and is used only to return a safe-or-unsafe verdict. Analysis logs are deleted after each check, so there's no browsing history to store or sell.
As little as the campaign needs, and you choose how much that is. In named mode we store the address so you can see results per person. In pseudonymous mode the address generates the link and is never written to our database. In anonymous mode no address exists at all — people enter a code, and nobody can be identified from the results. In every mode we store the answers, the score and how long each question took; we never record a recipient’s IP address, device or location, and we never email your people — you send the links yourself. You are the controller and we are your processor. The detail is in the Privacy Policy.
SafeToOpen is built to be GDPR-ready: data minimisation by design, no sale of personal data, and a Data Processing Agreement available for business customers.
The full privacy policy, terms, cookie policy and Data Processing Agreement are linked from the footer of every page and from the documents section above.
No. Email content is analysed in transit and never stored, and scan metadata is anonymised. Our products are independently assessed, too: ISO/IEC 27001:2022 certified, verified under Google’s CASA security assessment, a Microsoft 365 certified add-in listed on the Google Workspace Marketplace — with annual third-party penetration testing and a 99.9% uptime SLA.
Get real-time protection that respects your privacy by design — free to start, no data sold, ever.
Security reviewer or procurement team? Certifications, whitepapers and policies live in the SafeToOpen Trust Center →