Book a demo →

Aegis AI "Report Phishing" Add-on Privacy Policy

Effective date: January 12, 2026

This Privacy Policy describes how Aegis AI Security, Inc. ("Aegis AI," "we," "us," or "our") collects, uses, and protects information when you use the Aegis AI Workspace Add-on (the "Add-on"). This policy applies specifically to our Google Workspace integration and the Google user data accessed through it. For information about our other services and website, please see our general Privacy Policy.

1. About the Aegis AI Workspace Add-on

The Aegis AI "Report Phishing" Add-on is an enterprise security solution that helps organizations detect and prevent phishing, business email compromise (BEC), and other email-based threats. The Add-on is deployed by Google Workspace administrators via domain-wide installation for use within their organization.

2. Google User Data We Access

  • Email metadata: Sender, recipient, subject line, timestamps — analyzed to identify suspicious patterns
  • Email content: Message body and headers — scanned for phishing indicators and malicious content
  • Attachments: File names and attachment data — analyzed for malware and suspicious payloads
  • User profile information: Email address — used to authenticate the reporter and send status notifications

3. How We Use Google User Data

We use Google user data exclusively to provide and improve the Add-on's security functionality:

  • Threat Detection: Analyzing emails in real-time to identify phishing, BEC, impersonation, and other threats
  • Alerting: Notifying users and administrators of detected threats
  • Reporting: Providing security dashboards and reports to organization administrators
  • Service Improvement: Enhancing our threat detection models and user-facing features within the Add-on

We Do NOT Use Google User Data For:

  • Advertising, marketing, or promotional purposes
  • Serving ads, including retargeting or interest-based advertising
  • Sale or transfer to third parties for purposes unrelated to providing the Add-on
  • Building user profiles for non-security purposes
  • Training generalized AI/ML models unrelated to the Add-on's security features
  • Credit determinations or lending purposes

4. Google API Services User Data Policy — Limited Use Disclosure

Aegis AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we confirm that:

Limited Use: We only use Google user data to provide or improve the user-facing security features of the Aegis AI Add-on that are visible and prominent in the application's interface.

No Prohibited Transfers: We do not transfer Google user data to third parties except:

  • To provide or improve the Add-on's security functionality, with user consent
  • For security purposes (e.g., investigating abuse or security incidents)
  • To comply with applicable laws or legal process

No Human Access to User Data: We do not allow humans to read Google user data unless:

  • The user or administrator has provided affirmative consent to view specific data (e.g., for support purposes)
  • It is necessary for security purposes (e.g., investigating a bug or abuse)
  • It is required to comply with applicable law
  • The data is aggregated and anonymized for internal operations in compliance with applicable privacy laws

No Advertising Use: We do not use Google user data for serving ads or any advertising-related purpose.

5. Data Sharing

Infrastructure providers

Purpose: Hosting and processing data to operate the Add-on
Safeguards: Bound by data processing agreements; data encrypted in transit and at rest

Your organization's administrators

Purpose: Providing security reports and alerts
Safeguards: Data limited to their organization only

Legal authorities

Purpose: When required by law, subpoena, or court order
Safeguards: We notify customers where legally permitted

We Do NOT Share Google User Data With:

  • Advertising platforms or ad networks
  • Data brokers or information resellers
  • Marketing service providers
  • Any third party for purposes unrelated to providing the Add-on's security services

6. Data Security

We implement enterprise-grade security measures to protect Google user data:

  • Encryption: All data encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Access Controls: Role-based access with least-privilege principles; access logged and audited
  • Infrastructure: Hosted on SOC 2 Type II certified cloud infrastructure
  • Monitoring: Continuous security monitoring and incident response procedures
  • Assessments: Regular security assessments and penetration testing

7. Data Retention and Deletion

  • Threat detection logs — 30 days (or as configured by your administrator).
  • Email analysis data — Processed in real-time; raw content not stored beyond analysis.
  • Account/authentication data — Duration of service; deleted upon offboarding.

Deletion: When your organization uninstalls the Add-on or terminates service, we delete all associated Google user data within 30 days, except where retention is required by law.

Organization administrators may request data deletion at any time by contacting support@aegisai.ai.

8. Your Organization's Control

Because the Add-on is deployed via domain-wide installation:

  • Administrators control access: Your Workspace admin decides whether to install, configure, or remove the Add-on
  • Administrators can revoke access: The Add-on can be removed at any time via the Google Admin Console

Individual users within the organization can contact their administrator regarding data access or concerns.

9. Data Processing Location

Google user data is processed and stored in the United States. For customers requiring specific data residency, please contact us to discuss available options.

10. Children's Privacy

The Aegis AI Add-on is an enterprise security product intended for use by organizations and their employees. It is not directed at children under 18, and we do not knowingly collect data from children.

11. Changes to This Policy

We may update this Privacy Policy periodically. If we make material changes to how we handle Google user data, we will:

  • Post the updated policy at this URL with a new effective date

Continued use of the Add-on after changes become effective constitutes acceptance of the revised policy.

Contact Information:

For questions about this Privacy Policy, our data practices, or to exercise data rights:

Last Updated: January 12, 2026

See what AI-native security feels like

Thirty minutes. Real attacks pulled from environments like yours (BEC, vendor fraud, credential phishing) with the reasoning behind each verdict. No setup required.

Five-minute connect · monitoring mode · disconnect any time without touching mail routing