Instant transparency

How Mailqor processes an email

Badges render entirely inside your browser. Only the technical identifiers required to score a sender ever leave your inbox, and that data is minimized and encrypted.

Local only

The extension renders inside Gmail or Outlook

Mailqor attaches to the DOM and never streams message bodies to our servers.

  • We read the From, Reply-To and authentication headers only.
  • No background sync: messages are processed one by one as you open them.
Headers only

We extract sender & security signals

The extension parses SPF/DKIM/DMARC, MX information and TLS fingerprints locally.

  • The raw body stays in the DOM; we only compute hashes of the indicators we need.
  • Missing headers result in a ā€œNot checkedā€ badge instead of uploading content.
Encrypted in transit

Domain lookup hits the Mailqor API

Only the domain, hashed sender identifier and badge metadata leave your device.

  • Traffic is HTTPS-only and cached for 24 hours to avoid repetitive calls.
  • The API responds with the badge + explanation then discards the payload immediately.
Opt-in

Manual AI analysis

If you click Analyze with AI we snapshot that email, encrypt it and send it for AI-only processing.

  • Snapshots are deleted when you remove the conversation or after 30 days.
  • No attachment or body content is shared with models unless you push the button.

What we store and how long we keep it

Here is the complete list of objects that can leave your browser when using Mailqor.

Domain verdict cache

Auto-delete Ā· 24h

Prevents us from reprocessing the exact same sender hundreds of times per day.

  • Data: sender domain, hashed sender id, verdict label, timestamp.
  • Retention: deleted automatically after 24 hours.

Trusted sender list

Delete any time

Entries you explicitly approve so we can show Verified instantly next time.

  • Data: hashed local-part + domain, badge label, account id.
  • Retention: stored until you remove the entry or delete your account.

Security & reliability logs

30 days

Used to detect abuse, rate-limit bots, and debug extension crashes.

  • Data: random request id, browser version, error codes, reduced IP metadata.
  • Retention: purged automatically after 30 days and stored in EU infrastructure.

Manual AI snapshots

Up to 30 days

Only exists if you click Analyze with AI on a message.

  • Data: encrypted body, attachment metadata, AI response.
  • Retention: deleted when you delete the conversation or after 30 days.

Key facts

  • We never read or store email content unless you explicitly ask for an AI review.
  • Badges rely on headers, domains and the trusted sender catalog—not message bodies.
  • Every call to our API is HTTPS-only and scoped to the identifiers listed above.
  • You can disable the extension or delete your Mailqor account at any time—no Gmail/Outlook tokens are stored.

Privacy Policy

Last updated: November 14, 2025

Data controller

Mailqor is operated by Mathis Zeghouani, Auch, France.

  • Jurisdiction: France
  • Contact: support@mailqor.com

Data we collect

We divide the information we process into the following categories to stay transparent with Google and Microsoft policies:

User account

  • Login email address
  • Interface preferences such as language, theme, and badge display options

Usage and sender data

  • Sender email address (From) only
  • Sender domain extracted from the From field
  • Badge decision (Verified / Not checked / Suspicious)
  • History of previously trusted senders added by the user

AI analysis data (manual only)

  • Email ID captured only when the user explicitly clicks Analyze with AI
  • No automatic scanning of emails takes place

Technical signals

  • Error and performance logs
  • Browser name and version
  • Extension or app version
  • Date and time of the verification event

What we do not collect

  • We never automatically read the content of your emails.
  • Content is only processed when you manually trigger the AI analysis.
  • We minimize data (links, domains, technical indicators only) and do not keep the raw body after the analysis finishes.

Browser permissions inside Gmail / Outlook

  • Read the sender address directly from the email you have opened to render the badge (no mailbox connection required).
  • Parse on-screen headers to check SPF, DKIM, and DMARC locally—no Gmail or Outlook API scopes are used.
  • Capture the body only if you manually start the AI analysis; otherwise the content never leaves your browser.
  • Disable or remove the extension at any time from your browser; Mailqor stores zero Google/Microsoft tokens.

Manual AI analysis storage & encryption

  • Email snapshots from manual AI reviews stay with the conversation history (still encrypted) until you delete that conversation or account.
  • Only the email content is encrypted with AES-256-GCM at rest and it is never stored in plaintext.

Gmail compliance (DOM-only, no API tokens)

Mailqor no longer connects to Gmail via OAuth. The browser extension simply reads the Gmail tab you already opened and keeps processing local.

This means:

• No Gmail API scopes or refresh tokens are stored—removing the extension instantly removes access.

• Gmail data never leaves the browser unless you click a badge that triggers an analysis.

• We never sell Gmail data or use it for advertising.

• When you start the AI analysis we encrypt only that specific snapshot.

- No human can access Gmail data unless you explicitly share a snapshot for support,

- or we are legally required to investigate abuse.

The DOM-only model keeps Mailqor compliant with Google API Services rules while avoiding centralized storage.

Microsoft compliance (Outlook DOM-only)

Mailqor no longer requests Microsoft Graph scopes. The extension inspects the Outlook web interface you already use and parses headers inside the browser.

• Data leaves the tab only when you click a badge that needs verification.

• Outlook information is never sold or shared with third parties.

• The body is analyzed only if you trigger the manual AI review.

• Disable/uninstall the extension anytime—there are no tokens to revoke at https://account.live.com/consent/Manage.

Data transfers outside the European Union

Some technical services (CDN, edge runtime, optional AI processing) may temporarily transfer data outside the EU.

When this happens we apply:

• EU Standard Contractual Clauses (SCCs)

• encryption in transit and at rest

• data minimization for any transfer

No Gmail or Outlook data is permanently stored outside the EU.

Transfers occur only when strictly necessary to run Mailqor (execution, CDN delivery, or on-demand AI processing).

Sous-traitants (Processors)

Nous utilisons les fournisseurs suivants pour faire fonctionner Mailqor :

ProviderRolePrimary regionPolicy
VercelWeb hosting / CDNEU / UShttps://vercel.com/legal/privacy
Neon (PostgreSQL)DatabaseEU regionhttps://neon.com/privacy-policy
OpenRouterOn-demand AI analysis onlyRegion depends on configurationhttps://openrouter.ai/privacy

On-demand AI processing via OpenRouter may transit briefly through model providers (e.g., OpenAI, Anthropic, etc.). We request customer-data training opt-outs whenever available. No data is used for advertising.

Purpose of processing

Each type of data serves a different goal:

DataReason
From address and domainClassify the sender and assign the correct badge
Email body (manual AI)Provide an optional AI summary when you request it
Usage logs and diagnosticsImprove reliability, spot abuse, and fix bugs
Account email and preferencesAuthenticate you, send support responses, and remember your settings

Legal bases under GDPR

  • Article 6(1)(b) – processing necessary to deliver the Mailqor service you requested.
  • Explicit consent – granted when you approve Gmail/Outlook permissions for manual analysis.
  • Legitimate interest – protecting our infrastructure and detecting abuse.

The core badge still works even if you decline content analysis.

Data retention

  • Account data: retained until you delete the account.
  • Trusted senders you add manually: until you remove them.
  • Technical and access logs: 90 days.
  • AI-reviewed content: deleted right after processing; only the message ID and outcome are stored.

Data sharing and hosting

  • We never sell or rent your data to commercial third parties.
  • We use vetted processors such as Vercel strictly to run the platform.
  • Primary servers and databases are hosted within EU data centers to keep data close to French jurisdiction.

Cookies and analytics

  • We do not use advertising cookies.
  • For analytics we may rely on privacy-friendly tools without third-party trackers or ad profiling.

Manage your preferences in the site settings when available.

Security measures

  • All traffic uses HTTPS/TLS.
  • Sensitive tokens are hashed or encrypted at rest.
  • Internal access is restricted to authorized personnel.
  • We log IP address and timestamps for security/abuse prevention (kept 90 days).

Your GDPR rights

You can exercise these rights via settings or by emailing support@mailqor.com:

  • Access and portability.
  • Erasure of your account and personal data.
  • Withdrawal of Gmail/Outlook permissions from your Google/Microsoft account.
  • Right to object or lodge a complaint with the authority in your region.

We respond within 30 days and may request proof of identity when necessary.

You can also contact the competent supervisory authority (CNIL): https://www.cnil.fr/fr/plaintes

Minimum age

Mailqor is not intended for individuals under 16. We do not knowingly collect data about minors.

Security incident notice

If a breach poses a high risk to your rights, we will notify you and the competent authority within the applicable timeframe.

Account deletion

Deleting your account removes personally identifiable data from our systems. Aggregated or anonymized security logs may be retained to prevent future abuse.

Deletion timeline

Deleting the account removes personal data within 7 days. Aggregated or anonymized data may remain for statistics or abuse prevention. Connected permissions (Google/Microsoft) are revoked and caches are purged within the same window.

Updates to this policy

We may update this Privacy Policy when our product or legal obligations change. We will notify you of significant updates via email or in-app notice.

Contact

Questions about privacy? Contact support@mailqor.com.

Reference language

If translations differ, the French version prevails.

Privacy Policy | Mailqor | Mailqor