π‘οΈ
Orunmila Privacy Policy
Last Updated July 27, 2026
Your privacy matters to us. This Privacy Policy explains how Orunmila BEC Shield ("we", "our", or "us") collects, uses, and protects your information when you use our Chrome extension and associated services.
1. Information We Collect
To provide you with accurate BEC (Business Email Compromise) and phishing detection, we process the following data:
- Email Metadata & Content: Sender address, subject line, email body text, and embedded links. (We only process this data locally on your device and via our secure API for AI analysis.)
- Device Identifier: A unique device ID generated locally to manage your trial/scans and license binding.
- Email Address (for registration): Used to send you OTP verification codes, trial alerts, and license updates. We never sell or share your email.
- Usage Analytics: Aggregated threat scores, buckets (SAFE/CAUTION/SUSPICIOUS/HIGH), and anonymized domain statistics to improve our detection models.
2. How We Use Your Data
- Threat Detection: To analyze emails in real-time and display safety ratings (Local Scorer or Oracle AI).
- Service Improvement: To refine our AI models and local scoring algorithms.
- Communication: To send you important service updates, trial expiry warnings, and verification codes.
- License Management: To enforce usage limits (e.g., 20 free scans) and manage premium tiers (Oracle/Pro).
3. Data Storage & Security
- Local Storage (Extension): Your scan history, preferences, and license status are stored locally in your browser using
chrome.storage.local.
- Cloud Storage (Redis/Upstash): Email text is temporarily hashed and cached for 1 hour to avoid re-processing identical emails. Aggregated scan events are stored to show you your history.
- Encryption: All data transmitted between your extension and our API is encrypted via HTTPS/TLS.
- No Human Review: We do not manually read your emails. All analysis is performed by automated AI/ML models.
4. Third-Party Services
We rely on trusted third-party infrastructure to operate:
- Vercel: Hosts our API and backend logic.
- Upstash (Redis): Manages caching, rate limiting, and temporary scan event storage.
- Resend: Sends OTP verification and transactional emails to you.
These providers are GDPR and CCPA compliant. We do not share your actual email body text with themβonly aggregated metadata.
5. Your Rights
- Access & Deletion: You can request a copy of your stored scan data or ask us to delete it by contacting hello@becshield.company.
- Opt-out of Emails: Click the "Unsubscribe" link in any promotional email, or adjust your settings in the extension popup.
- Disable Extension: Uninstalling the extension will remove all locally stored data from your browser.
6. Data Retention
- Scan Events: Stored for up to 30 days to provide you with a threat history dashboard.
- OTP Codes: Expire after 10 minutes and are immediately deleted after successful verification.
- Cache: Email score caches expire after 1 hour automatically.
7. Children's Privacy
Our service is not directed at individuals under the age of 16. We do not knowingly collect personal information from children.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the extension popup or email. The "Last Updated" date at the top of this page will reflect the latest revision.
9. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please reach out to us:
π Built with trust and transparency.