← Jack Knife SecurityJack Knife — Privacy Policy
Last updated: [DATE] · Effective date: [DATE]
⚠️ ATTORNEY REVIEW REQUIRED BEFORE PUBLICATION. This is a technically-accurate first draft, written directly from Jack Knife's actual code and data-handling behavior — not a generic template. It is not a substitute for review by a licensed attorney, particularly regarding: California authorized-agent obligations (Delete Act), CCPA/CPRA specifics, Google API Services User Data Policy compliance language, breach-notification law by state, and enforceability of the liability/dispute terms in the companion Terms of Service. Do not publish or submit for Google OAuth verification until counsel has reviewed and approved this document.
1. Who we are and what this policy covers
Jack Knife ("Jack Knife," "we," "us") provides an email security service that connects to your email account (currently Gmail, with Microsoft/Outlook support planned) to detect phishing and scam emails, identify unwanted marketing ("clutter"), and — only with your explicit, per-instance confirmation — help you unsubscribe from or remove your information from senders and data brokers.
This policy explains what data we access, what we store, what we never store, who we share data with, and the choices and rights you have. It applies to our web application, API, and any connected-mailbox integration.
2. The core promise: most of your email leaves no trace with us
Jack Knife is built on a principle we call notify-and-defer: we detect and show you what we found; you decide what happens. This has a direct, technical consequence for your privacy:
- A safe email is never stored. When we scan a message and determine it poses no threat and isn't unwanted marketing, nothing about that email — not its content, not even a record that it existed — is written to our systems. It is processed in memory during the scan and then discarded.
- Only flagged emails create a record, and even then, only a minimized one (see Section 4).
- We never move, delete, or alter your email without your explicit action, except for the specific, reversible, disclosed automated behaviors described in Section 6 (which you can review and correct at any time, and which never delete anything).
3. What we access
When you connect an email account to Jack Knife via OAuth (Google or Microsoft sign-in), we request permission to read your mail. We use this access only to:
- Scan incoming and existing messages for phishing, scam, and malware indicators;
- Identify unwanted marketing/promotional mail;
- Read label and folder changes you make (e.g., marking something as spam, or relabeling a message) so we can learn your preferences;
- Apply labels (e.g., a colored "Marketing" or "Threat" tag) and, only when you've enabled it and a sender is already known to us as unwanted, move mail to your Spam or Clutter folder — never delete;
- With your separate, explicit confirmation, send an unsubscribe request to a sender on your behalf.
We do not read your email for any purpose other than these. We do not sell, rent, or use your email content for advertising. We do not use your email content to train models that are shared outside of the limited, human-reviewed process described in Section 5.
We never ask for or store your email password. Access is granted entirely through your provider's OAuth consent screen — we receive a limited-scope authorization token, not your credentials, and you can revoke it at any time directly from your Google or Microsoft account settings, or by disconnecting within Jack Knife.
4. What we store, and how it's minimized
4.1 Threat records ("incidents")
When a message is flagged as suspicious or dangerous, we store a minimized incident record: the verdict, a numeric risk score, the sender's domain (not your or their full address), plain-language descriptions of why it was flagged (e.g., "failed DMARC check," "requests a gift card"), and a non-content pointer (a message ID) so you can locate it in your own inbox. We do not store the subject line or body of the email. Incident records are automatically deleted after 90 days.
4.2 Sender behavior profiles
To recognize patterns like a sender suddenly changing its usual link domains (a sign of a hijacked account), we keep a lightweight profile per sender domain you've received mail from: how many messages we've seen, which link/signing domains they've historically used, and whether you've approved, blocked, or flagged them as marketing. This never includes message content. Profiles for senders you haven't heard from in over a year are automatically deleted.
4.3 Raw email content — only in two narrow, disclosed cases
- Short-term cache for correcting a threat flag. If a message is flagged as a threat, we may hold its raw content for up to 7 days, solely so that if you later tell us we got it wrong (or confirm we got it right), we can optionally save that exact example to improve detection. This cache is never created for messages we judged safe, is deleted automatically after 7 days regardless of whether you act on it, and is used at most once.
- Explicit, per-message consent. If you check a box to "help improve detection" when correcting a flag, or you use the "report a missed phishing email" feature, we save that specific email's content to a separate, access-restricted store. Every submission here is reviewed by a human before it is ever used to improve our detection models — nothing is auto-trained on unverified data, which also protects against someone trying to poison our detection by submitting fake reports.
4.4 Account and connection data
Your account email, an internal opaque account ID, which mailbox(es) you've connected, and encrypted OAuth tokens. Your real email address is never stored alongside threat or sender-profile data — they're linked only through the internal ID, so a compromise of one store doesn't expose the other.
If you use the exposure-check feature, we query a third-party breach database (Have I Been Pwned) with your email address to tell you how many known data breaches it appears in. We also independently identify, from your own inbox, which companies are actively sending you marketing — this is derived locally and never shared with a third party.
5. Google user data — Limited Use compliance
Where Jack Knife accesses your Gmail data via Google's APIs, our use of that data is governed by the Google API Services User Data Policy, including its Limited Use requirements, in addition to everything else in this policy. Specifically:
- We use Gmail data only to provide the detection, decluttering, and scrub features that are prominent in the Jack Knife interface — never for any undisclosed purpose.
- We do not use Gmail data, or anything derived or aggregated from it, for advertising of any kind (including retargeting or interest-based advertising), for transfer to or use by advertising platforms, data brokers, or information resellers as a product or business arrangement, or for credit, lending, or insurance underwriting decisions. (This is distinct from our optional Tier 2 feature, described below, where — only at your explicit direction — we send removal requests to data brokers on your behalf; we never send your Gmail content to a broker, and we never sell or hand over your data as part of a business relationship with any broker or reseller.)
- Human access to your Gmail data is restricted. No one at Jack Knife reviews your email content except: (a) the narrow, disclosed cases in Section 4.3 where you've given specific, per-message consent; (b) as necessary for security investigations, to comply with the law, or to enforce our terms; or (c) in aggregated or anonymized form for internal operations that do not involve reading your specific messages.
- We do not transfer Gmail data except as necessary to provide the Service, as you direct, to comply with the law, or as part of a merger, acquisition, or asset sale (in which case any successor remains bound by these same Limited Use restrictions).
6. Who we share data with
We do not sell your data. We share data only as follows:
- Your email provider (Google/Microsoft): to read and act on your mailbox, as authorized by you.
- Have I Been Pwned: your email address only, when you use the exposure-check feature, to look up breach history.
- Senders you ask us to unsubscribe from: when you explicitly confirm an unsubscribe action, we send that sender's own published unsubscribe request — this is the same request your browser would send if you clicked "unsubscribe" yourself.
- Data brokers (planned, not yet active): if and when our data-broker removal feature ("Tier 2") is enabled, we will submit removal requests to data brokers or state-run removal platforms (e.g., California's DROP) on your behalf. Where we act as your legal "authorized agent" (e.g., under California's CCPA/Delete Act), we will collect a written, signed authorization from you meeting the applicable legal requirements — not merely a checkbox — before submitting any request on your behalf. This feature is currently disabled and will have its own dedicated authorization flow before activation.
- Service providers who help us operate (e.g., cloud hosting), under contracts that prohibit them from using your data for any other purpose.
- Legal requirements: if required by valid legal process, or to protect the rights, property, or safety of Jack Knife, our users, or the public.
We do not use your data for advertising, and we do not share it with data brokers about you — only, at your explicit direction, to remove you from them.
7. Automated actions — what we do on our own, and what we don't
- We never auto-execute an action that leaves our system (like sending an unsubscribe request) based solely on you flagging one email. A single designation only creates a proposal describing what we could do; nothing is sent to a third party until you separately, explicitly confirm that specific proposal.
- We do automatically apply your correction to the rest of a sender's mail within your inbox — for example, if you mark one email from a sender as "not a threat," we'll relabel other existing messages from that same sender to match, and remember your decision for their future mail. This stays entirely within your own inbox (a label or folder change), is fully reversible, and never involves a third party.
- Moving mail to Spam or a Clutter folder only happens for senders already established as unwanted through your own prior decisions, is disabled by default until you enable it, and never deletes anything — every action is reversible from within your email client.
8. Data retention
| Data |
Retention |
| Safe email content |
Never stored |
| Threat incident records |
90 days, then automatically deleted |
| Sender behavior profiles |
Deleted after 12 months of inactivity |
| Raw email cache (post-flag correction window) |
7 days maximum, single-use |
| User-consented training examples |
Retained until reviewed; you may request deletion at any time |
| Account and connection data |
Retained until you delete your account |
9. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your data, and to opt out of certain data practices. Regardless of location, you can, at any time:
- Disconnect any mailbox from Jack Knife (revokes our access immediately);
- Request deletion of your account and all associated data;
- Decline any scrub/unsubscribe proposal — nothing acts without your confirmation;
- Withdraw consent for any previously-submitted training example.
California residents: you have rights under the CCPA/CPRA, including the right to know, delete, and opt out of the sale or sharing of personal information. We do not sell or share your personal information as those terms are defined by California law. If you're a California resident and you enable our data-broker removal feature (Tier 2, not yet active), we act as your authorized agent for the purpose of submitting deletion requests to registered data brokers, consistent with the Delete Act — which requires us to obtain a written, signed authorization from you (see Section 6) before acting.
To exercise any of these rights, contact us at [PRIVACY CONTACT EMAIL].
10. Security
We apply the following safeguards: OAuth-only authentication (no password handling), encryption of stored tokens, strict ownership checks so one account can never access another's data, minimized data collection by design (see Section 4), and rate limiting against abuse. No system is perfectly secure, and we will notify affected users and relevant authorities in the event of a breach as required by applicable law.
11. Children's privacy
Jack Knife is not directed to, and we do not knowingly collect information from, children under 13 (or the relevant minimum age in your jurisdiction). If we learn we have inadvertently collected such information, we will delete it.
12. International users
Jack Knife's infrastructure currently operates in the United States. If you use our service from outside the United States, your information will be transferred to and processed in the United States.
13. Changes to this policy
We'll post any material changes here with an updated "Last updated" date, and where required by law, provide additional notice before the change takes effect.
[COMPANY LEGAL NAME]
[ADDRESS]
[PRIVACY CONTACT EMAIL]