How we handle data — and our commitment not to sell your browsing. This policy explains what we collect, why, and the choices you have.
At SafeToOpen, we respect your privacy and are committed to protecting your personal and business information. This Privacy Policy explains how we collect, use, disclose, and safeguard information across our products and services, including our website and dashboard, the SafeToOpen browser extension (Browser Security & Privacy), our email security add-ins for Outlook and Gmail, our brand protection service, Scam Check, and our developer API.
This Policy applies to all personal and business information we collect through SafeToOpen’s websites and dashboard, the browser extension (managed and unmanaged versions), our email security add-ins, our brand protection service, our developer API, and any backend components you deploy in your own cloud environment.
We collect only the information necessary to provide, improve, and support our products. The types vary by product.
Depending on version, we may process your email address, IP address and country, and a SHA-2 hash of fully-qualified domain names (FQDNs) from links in analysed emails. We design our email analysis to minimise data and, where used, emails analysed for verification are deleted from our processing servers once analysis is complete.
For the unmanaged/free version we may process your IP address, a SHA-2 hash of the FQDNs and domain names you visit, the extension version, and the reasons a URL was flagged. Payment-card (PCI) detection and redaction performed by Paste Guard happens locally on your device and is not transmitted to us. Managed/business deployments may be configured to send detection events to your own administrators and security tools.
Paste Guard helps detect when sensitive information is about to be pasted, uploaded, typed, or submitted into a website. Card-data detection runs locally. For optional PII detection, content may be analysed in real time to perform detection, but is not stored or sold; for organisations, this analysis can be configured to run within your own private network.
If you deploy a SafeToOpen component in your own cloud environment, credentials and configuration may reside on your infrastructure, under your control. We collect only what is described in your applicable agreement.
Scam Check lets a business account send its own staff or customers a short, timed test made up of example scam and genuine messages. Where a business runs a campaign, that business is the data controller and SafeToOpen acts as its processor: the business decides who is tested and supplies the recipient list, and we process that list only to run the campaign and report the results back to them. Our Data Processing Agreement governs that relationship.
What is processed depends on the identity mode the business chooses for each campaign:
In every mode we store, per recipient: a random access token, the timestamps for the invitation being opened, started and completed, the number of reminders the business recorded, an expiry date for the link, and the final score. Per question we store the answer given, whether it was correct, how long it took, and whether it exceeded the campaign’s time budget — timing is used to distinguish reading from guessing.
We do not record recipients’ IP addresses, device or browser identifiers, or location when they take a test, and Scam Check does not place advertising or analytics cookies on the test screens. The questions are fictional examples written by us; no real message from the business or its recipients is read, uploaded or analysed at any point.
We do not email recipients. SafeToOpen sends nothing to the people being tested. The business exports the personal links and distributes them itself, from its own systems and its own address.
Scam Check results are visible only to administrators of the business account that ran the campaign. They are not used to train detection models, are never combined with data from our browser extension or email add-ins, and are never sold or shared with advertisers or data brokers.
Separately, our free public quiz at safetoopen.com/phishing-quiz is anonymous: we record only the final score and the country the attempt came from, with no account, name or email, and we publish those figures only as aggregates.
We do not sell, rent, or lease your personal information. We disclose information only to trusted service providers who process it on our behalf under contract (for example, payment processors and cloud hosting), where required by law or to protect our legal rights, or in connection with a corporate transaction, subject to this Policy.
We are committed to compliance with the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA) where they apply to you.
You may have rights of access, rectification, erasure, restriction, objection, and portability, and the right to withdraw consent and to lodge a complaint with a supervisory authority.
You may have rights to know, delete, correct, and opt out of the “sale” or “sharing” of personal information (we do not sell or share it), and the right not to be discriminated against for exercising these rights.
Contact us at [email protected]. We may request information to verify your identity before acting on a request.
We implement appropriate physical, technical, and organisational safeguards designed to protect information from unauthorised access, alteration, disclosure, or destruction — including encrypted transmission (TLS/SSL), access controls, and an information-security programme aligned to ISO/IEC 27001:2022.
We retain information only as long as necessary to provide the services, meet legal obligations, resolve disputes, and enforce our agreements. For example, emails analysed for verification are deleted from our processing servers once analysis is complete. We then delete or anonymise information unless a longer retention period is required by law.
Scam Check campaign data — recipient records, answers and scores — is retained for as long as the business account that created the campaign keeps it. An unpaid draft campaign can be deleted by the business at any time from its dashboard, which removes it and its question selection. A campaign that has been paid for cannot be deleted from the dashboard, to protect the record a customer has bought; a business that wants such a campaign and its recipient data erased can ask us to erase it and we will do so. Personal links expire on the date the business sets, up to 120 days.
Our services are not directed to children under 13, and we do not knowingly collect their information. If we learn we have collected information from a child under 13, we will delete it promptly.
As a global company, we may process and store information in multiple regions, with appropriate safeguards such as Standard Contractual Clauses where required. If you have specific data-residency requirements, contact us at [email protected].
We may update this Privacy Policy from time to time. Changes will be posted here with a revised “Last updated” date; significant changes may also be communicated by email or in-product notice.
Questions about this Privacy Policy or your rights? Email [email protected].
© 2026 SafeToOpen Limited and its subsidiaries. All rights reserved. SafeToOpen is ISO/IEC 27001:2022 certified.