Privacy Policy

Last Updated: July 30, 2026

Email Fraud Alert ("EFA", "we", "us", or "our") is operated by EFA LLC. This Privacy Policy explains what information our Outlook add-in and browser extension (the "Service") process, how that information is used, and the choices available to you.

Plain language summary: EFA performs fraud analysis locally on your device, and by default does not transmit any information derived from the emails it analyzes. We do not transmit or store your email content, subject lines, attachments, or recipients on EFA‑operated servers; that information is processed locally to perform fraud analysis. EFA has two optional network features, and both are off until you turn them on: a sender‑domain reputation check (transmits only a sender's domain — the part of the address after the @, e.g., example.com, which may include subdomains — over HTTPS to our reputation service; never your email content, addresses, subjects, or attachments) and anonymous usage statistics (which warning types appear and how serious they are, tied to a random install identifier that is never linked to you or to any message). The first time you use EFA, it asks you to choose, with both features switched off, and you can change your choice at any time in the add‑in's settings.

1. Who we are

Data Controller: EFA LLC, doing business as Email Fraud Alert.
Website: www.emailfraudalert.com
Contact: support@emailfraudalert.com

2. Information we process

2.1 First‑run choice

The first time you use EFA, it shows a short screen describing the two optional network features below, both switched off, and asks you to choose. EFA does not enable either feature unless you turn it on there, and you can change your choice at any time in the add‑in's settings. EFA's local, on‑device fraud analysis works the same whether or not you enable either optional feature.

2.2 Local email analysis

To detect potential fraud, EFA analyzes technical characteristics of the message within your mail client (for example: sender address, display name, reply‑to domain, header authentication results, URLs and attachments). This analysis happens locally on your device or within the Outlook runtime. We do not transmit email bodies, subjects, attachments, or recipients to our servers.

2.3 Domain reputation checks (optional — off by default)

This feature is off until you turn it on. When you enable it, EFA queries our reputation service to assess sender risk. In doing so, the client transmits only the sender's domain — the part of the email address after the @ (for example, example.com), which may include subdomains. We do not send the part of the address before the @, full URLs, paths, IP addresses, message headers, or any email content. If a message contains a QR code and this feature is enabled, EFA may also check the domain that the QR code links to. Requests are sent over encrypted HTTPS to our reputation service (hosted with Cloudflare). Standard connection metadata handled by our edge provider (such as IP address at the network layer) is used only to route and secure the request and is not used to identify you. You can turn reputation checks off again at any time in the add‑in's settings.

2.4 Anonymous usage statistics (optional — off by default)

This feature is off until you turn it on. When you enable it, EFA sends anonymous usage events to measure how often warnings appear. Each event contains only: the type(s) of warning shown (e.g., wire-fraud) and their severity, the app version, a timestamp, and a random install identifier. No email content, addresses, domains, subjects, bodies, attachments, or anything else derived from a message or a person is ever included. The install identifier is a random value (not derived from your account, device, or mail); it is generated only if you enable this feature, lets us count distinct installs without knowing who you are, is never linked to your identity or to any message, and is removed if you turn the feature off. You can turn usage statistics off again at any time in the add‑in's settings.

2.5 Access to your mailbox and contacts (Outlook add‑in)

To do its job inside Outlook, EFA requests read access to parts of your own mailbox through Microsoft. Microsoft handles authentication and issues the access credentials the add‑in uses to request permitted information from Microsoft Graph. EFA does not transmit those credentials to EFA LLC's servers or to unrelated third parties. EFA requests permission to:

EFA uses this access to analyze mail on your device. It does not copy your mailbox, contacts, or settings to our servers. Where information (such as domains learned from your Sent Items) is remembered between sessions, it is stored in your own Microsoft account's add‑in storage, not by EFA.

2.6 Account & billing (paid plans only)

If you subscribe to a paid plan, your payment is processed by our payment processor, Stripe. Stripe collects your payment details. EFA receives from Stripe only what is needed to manage your subscription, such as your email address and subscription status. EFA does not receive or store your full card number.

3. Information we do not transmit to or store on EFA‑operated servers

EFA reads and processes some of this information locally on your device to detect fraud, but it is not sent to or stored on our servers:

4. How we use information

5. Data processing locations

Email analysis runs on your device/Outlook environment. Reputation checks (which send only the sender's domain) are handled by our reputation service hosted with Cloudflare. All communications use HTTPS/TLS.

6. Third‑party services

7. Security

We implement administrative, technical, and organizational measures appropriate to the nature of the limited data we process. Reputation queries are transmitted via HTTPS. Sensitive operations like billing are handled by audited third parties (e.g., Stripe). As with any software, no system is 100% secure; report issues to the contact below.

8. Data retention

We do not retain email content or message metadata. Reputation results may be cached on the client briefly to improve performance and are not associated with a user or message. Account and billing records are retained while your subscription is active and as required by law. We do not sell personal data.

For the two optional features, when you enable them: anonymous usage events are stored to produce aggregate counts, and reputation queries are processed to return a risk signal. We retain this information only as long as necessary for those purposes.

9. Your rights & choices

10. Legal bases & regional disclosures

Where applicable (e.g., GDPR/UK GDPR): our on‑device fraud analysis and delivery of the Service rely on our legitimate interest in protecting users from fraud and on our contract with you (paid subscriptions). The two optional network features — domain reputation checks and anonymous usage statistics — rely on your consent, which you give by enabling a feature and can withdraw at any time by turning it off in the add‑in's settings. Mailbox and contact access relies on the permission you grant through Microsoft. For CCPA/CPRA, we do not "sell" or "share" personal information as defined by law.

11. Children's privacy

The Service is not directed to children under 13 (or the age of digital consent in your jurisdiction). We do not knowingly collect information from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Last Updated" date above and posting the revised policy at this URL. If we materially change how the optional network features handle data, EFA will also ask you to review and consent again before the changed behavior takes effect. Routine updates that do not change data handling will not re‑prompt you.

13. Contact

EFA LLC (Email Fraud Alert)
support@emailfraudalert.com
www.emailfraudalert.com