← Jack Knife Security

Jack Knife — Privacy Policy

Last updated: [DATE] · Effective date: [DATE]

⚠️ ATTORNEY REVIEW REQUIRED BEFORE PUBLICATION. This is a technically-accurate first draft, written directly from Jack Knife's actual code and data-handling behavior — not a generic template. It is not a substitute for review by a licensed attorney, particularly regarding: California authorized-agent obligations (Delete Act), CCPA/CPRA specifics, Google API Services User Data Policy compliance language, breach-notification law by state, and enforceability of the liability/dispute terms in the companion Terms of Service. Do not publish or submit for Google OAuth verification until counsel has reviewed and approved this document.


1. Who we are and what this policy covers

Jack Knife ("Jack Knife," "we," "us") provides an email security service that connects to your email account (currently Gmail, with Microsoft/Outlook support planned) to detect phishing and scam emails, identify unwanted marketing ("clutter"), and — only with your explicit, per-instance confirmation — help you unsubscribe from or remove your information from senders and data brokers.

This policy explains what data we access, what we store, what we never store, who we share data with, and the choices and rights you have. It applies to our web application, API, and any connected-mailbox integration.

2. The core promise: most of your email leaves no trace with us

Jack Knife is built on a principle we call notify-and-defer: we detect and show you what we found; you decide what happens. This has a direct, technical consequence for your privacy:

3. What we access

When you connect an email account to Jack Knife via OAuth (Google or Microsoft sign-in), we request permission to read your mail. We use this access only to:

We do not read your email for any purpose other than these. We do not sell, rent, or use your email content for advertising. We do not use your email content to train models that are shared outside of the limited, human-reviewed process described in Section 5.

We never ask for or store your email password. Access is granted entirely through your provider's OAuth consent screen — we receive a limited-scope authorization token, not your credentials, and you can revoke it at any time directly from your Google or Microsoft account settings, or by disconnecting within Jack Knife.

4. What we store, and how it's minimized

4.1 Threat records ("incidents")

When a message is flagged as suspicious or dangerous, we store a minimized incident record: the verdict, a numeric risk score, the sender's domain (not your or their full address), plain-language descriptions of why it was flagged (e.g., "failed DMARC check," "requests a gift card"), and a non-content pointer (a message ID) so you can locate it in your own inbox. We do not store the subject line or body of the email. Incident records are automatically deleted after 90 days.

4.2 Sender behavior profiles

To recognize patterns like a sender suddenly changing its usual link domains (a sign of a hijacked account), we keep a lightweight profile per sender domain you've received mail from: how many messages we've seen, which link/signing domains they've historically used, and whether you've approved, blocked, or flagged them as marketing. This never includes message content. Profiles for senders you haven't heard from in over a year are automatically deleted.

4.3 Raw email content — only in two narrow, disclosed cases

  1. Short-term cache for correcting a threat flag. If a message is flagged as a threat, we may hold its raw content for up to 7 days, solely so that if you later tell us we got it wrong (or confirm we got it right), we can optionally save that exact example to improve detection. This cache is never created for messages we judged safe, is deleted automatically after 7 days regardless of whether you act on it, and is used at most once.
  2. Explicit, per-message consent. If you check a box to "help improve detection" when correcting a flag, or you use the "report a missed phishing email" feature, we save that specific email's content to a separate, access-restricted store. Every submission here is reviewed by a human before it is ever used to improve our detection models — nothing is auto-trained on unverified data, which also protects against someone trying to poison our detection by submitting fake reports.

4.4 Account and connection data

Your account email, an internal opaque account ID, which mailbox(es) you've connected, and encrypted OAuth tokens. Your real email address is never stored alongside threat or sender-profile data — they're linked only through the internal ID, so a compromise of one store doesn't expose the other.

4.5 Exposure and breach information

If you use the exposure-check feature, we query a third-party breach database (Have I Been Pwned) with your email address to tell you how many known data breaches it appears in. We also independently identify, from your own inbox, which companies are actively sending you marketing — this is derived locally and never shared with a third party.

5. Google user data — Limited Use compliance

Where Jack Knife accesses your Gmail data via Google's APIs, our use of that data is governed by the Google API Services User Data Policy, including its Limited Use requirements, in addition to everything else in this policy. Specifically:

6. Who we share data with

We do not sell your data. We share data only as follows:

We do not use your data for advertising, and we do not share it with data brokers about you — only, at your explicit direction, to remove you from them.

7. Automated actions — what we do on our own, and what we don't

8. Data retention

Data Retention
Safe email content Never stored
Threat incident records 90 days, then automatically deleted
Sender behavior profiles Deleted after 12 months of inactivity
Raw email cache (post-flag correction window) 7 days maximum, single-use
User-consented training examples Retained until reviewed; you may request deletion at any time
Account and connection data Retained until you delete your account

9. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your data, and to opt out of certain data practices. Regardless of location, you can, at any time:

California residents: you have rights under the CCPA/CPRA, including the right to know, delete, and opt out of the sale or sharing of personal information. We do not sell or share your personal information as those terms are defined by California law. If you're a California resident and you enable our data-broker removal feature (Tier 2, not yet active), we act as your authorized agent for the purpose of submitting deletion requests to registered data brokers, consistent with the Delete Act — which requires us to obtain a written, signed authorization from you (see Section 6) before acting.

To exercise any of these rights, contact us at [PRIVACY CONTACT EMAIL].

10. Security

We apply the following safeguards: OAuth-only authentication (no password handling), encryption of stored tokens, strict ownership checks so one account can never access another's data, minimized data collection by design (see Section 4), and rate limiting against abuse. No system is perfectly secure, and we will notify affected users and relevant authorities in the event of a breach as required by applicable law.

11. Children's privacy

Jack Knife is not directed to, and we do not knowingly collect information from, children under 13 (or the relevant minimum age in your jurisdiction). If we learn we have inadvertently collected such information, we will delete it.

12. International users

Jack Knife's infrastructure currently operates in the United States. If you use our service from outside the United States, your information will be transferred to and processed in the United States.

13. Changes to this policy

We'll post any material changes here with an updated "Last updated" date, and where required by law, provide additional notice before the change takes effect.

14. Contact us

[COMPANY LEGAL NAME] [ADDRESS] [PRIVACY CONTACT EMAIL]