Privacy Policy

Version 2.0 Effective Date: September 5, 2026. Replaces all previous versions.

This Privacy Policy (the “Policy”) applies to services provided by Vigilcode, Inc., a Delaware corporation (“Vigilcode,” “we,” “us,” or “our”), including:

This Policy does not apply to third-party websites, services, or applications, even if accessed through our Services.

Overview

Vigil provides AI-powered threat detection and security analysis services to help users identify potential digital security risks. This Privacy Policy explains how we collect, use, and protect your information when you use our services.

On-Device Processing

Vigil’s core threat detection engine (Sentinel) runs entirely on your device using on-device machine learning models. This means:

Cloud-Assisted Features (Scout and Sage)

Scout and Sage are optional paid features that do their reasoning in our cloud rather than on your device. The text of your message still does not leave your device when they run. They work from Sentinel’s analysis, plus a short list of specific items pulled out of the message, such as the link it points at. That list is written out in full under What Scout and Sage Send below, and it is worth reading rather than taking our word for it.

Scout and Sage never run on their own. Each runs only when you choose to start it on a given analysis, so declining to run them keeps that analysis entirely on your device with Sentinel’s output alone.

What We Collect

One list, so there is no doubt about what is on it. The short version: we collect what is needed to run your account, and we do not collect the text of the messages you scan.

Account and Service Data

What Stays On Your Device

These never reach our servers at all. This is not a retention promise, which would mean we hold them briefly; we do not receive them:

What Scout and Sage Send (Optional, Paid)

Scout and Sage are optional paid features that reason about a message you have already scanned. They never receive the text of your message. They receive Sentinel’s analysis of it, plus a small set of specific items pulled out of the message, because neither feature can ask a useful question or give useful advice without knowing what the message is pointing you at.

Here is the complete list of what leaves your device when you run Scout or Sage.

Sentinel’s analysis. No part of this is content:

Items extracted from the message. Two of these are taken from the message word for word:

What is never sent: the body of the message or its subject line.

Your answers to Scout’s questions, which are yes, no, or unsure.

This goes to our backend and on to Amazon Bedrock, AWS’s managed foundation model service. Under AWS’s terms Bedrock does not retain these inputs, use them for training, or share them with the providers of the underlying models.

What We Keep So Your Devices Agree

When you run Scout or Sage on an email, we save the analysis described above, together with Scout’s questions, your answers, and Sage’s recommendation, to your account. This is so that opening the same email on your phone and your tablet shows you the same result instead of re-running and possibly disagreeing with itself.

That saved record contains the extracted items listed above, including the target and the organization names. It still does not contain the message. We keep it while your account is active, and deleting your account deletes it.

Scans of text you paste are not saved this way.

Threat Scores

When a scan of an email finishes, the result is saved to your account so the same message shows the same verdict on your other devices. That record holds:

It does not include the message.

Feedback

If you use the in-app feedback form, we receive your ratings and any comment you write. The feedback record carries no account identifier, so what you send cannot be traced back to you from the stored record.

Diagnostic Data

App performance metrics, error reports and usage analytics are collected automatically to help us improve Vigil. This data is:

Automatically Collected

Optional Account Connections

You may choose to connect a third-party account, such as Google Gmail, to scan that inbox. When you do:

Google API Services Limited Use Disclosure

Vigil’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain terms, and specific to Vigil:

How We Use Your Information

Primary Service Functions

Service Improvement

We Do Not Train On Your Messages

We do not use your messages or emails to train our models. We cannot: the content never reaches us. Sentinel’s models are trained on security data we generate and curate ourselves, not on anything you scan.

There is no opt-in for this, because there is nothing to opt into. If that ever changes, it will require a new version of this policy and your explicit, separate consent. It will never be a default, and it will never be buried in an update.

Your Data

You own your content, and the strongest form of that is not a promise about how we handle it. It is that we do not have it.

What This Means

Our Commitment

For the account data we hold, we are the controller: we decide what is collected and why, and we are accountable for it. We hold it to run your account and deliver the service you asked for, and for nothing else. For the text of the messages you scan, the question does not arise, because we do not have it.

Information Sharing and Disclosure

We Do Not Sell Your Data

We do not and will not:

This is a core commitment. If it ever changes, it will require a new version of this policy, and we will tell you before it takes effect.

If Vigilcode Is Ever Sold

If Vigilcode is acquired, merges, or sells the part of its business that runs Vigil, your account data would transfer to the buyer as part of that transaction. We will notify you, and the commitments in this section travel with the data: a buyer takes it subject to this policy, and cannot start selling it or using it for advertising without giving you notice and a new version of this policy.

What We Don’t Do

Limited Disclosure Scenarios

We may disclose information only when:

Service Providers

We use the following categories of trusted service providers to deliver our services. Each provider is contractually bound to protect your information and may not use your data for their own purposes:

Data Security

Protection Measures

Data Retention

Deleting your account deletes your threat scores and your Scout and Sage records along with it.

Your Rights and Choices

Account Control

Communication Preferences

Data Processing Rights

Children’s Privacy

You must be at least 18 to create a Vigil account. A person aged 13 to 17 may use Vigil only if their parent or legal guardian agrees to our Terms of Use on their behalf and supervises their use.

Vigil is not intended for and may not be used by anyone under 13. We do not knowingly collect personal information from children under 13. If we learn that we have, we will delete the account and the associated data promptly. If you believe a child under 13 has given us information, contact privacy@vigilcode.com.

International Data Transfers

Your information may be processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data when transferred internationally, including:

California Privacy Rights

California residents have additional rights under the California Consumer Privacy Act (CCPA):

Changes to This Policy

Vigilcode reserves the right to modify this Privacy Policy at any time. When we make changes:

Third-Party Services and Websites

This Policy does not cover third parties or their products, actions, or services. Vigilcode is not responsible for:

For information about third-party privacy practices, please consult their respective privacy policies.

Contact Information

For privacy-related questions, concerns, or requests:

Email: privacy@vigilcode.com

By using Vigil services, you acknowledge that you have read and understood this Privacy Policy and agree to our data practices as described herein.