Privacy Policy
Version 2.0 Effective Date: September 5, 2026. Replaces all previous versions.
Legal Entity and Service Scope
This Privacy Policy (the “Policy”) applies to services provided by Vigilcode, Inc., a Delaware corporation (“Vigilcode,” “we,” “us,” or “our”), including:
- Our website at vigilcode.com and all subdomains
- The Vigil mobile application for iOS and Android
- Our API services at api.vigilcode.com
- All related online services and features
This Policy does not apply to third-party websites, services, or applications, even if accessed through our Services.
Overview
Vigil provides AI-powered threat detection and security analysis services to help users identify potential digital security risks. This Privacy Policy explains how we collect, use, and protect your information when you use our services.
On-Device Processing
Vigil’s core threat detection engine (Sentinel) runs entirely on your device using on-device machine learning models. This means:
- Your messages stay on your device: the text of the messages and emails you scan is analyzed locally and is never transmitted to our servers
- Core threat analysis runs locally: Sentinel performs threat detection computation on your device; our servers are not involved in analyzing your message content
- Privacy by design: On-device processing ensures your sensitive content remains under your control at all times
Cloud-Assisted Features (Scout and Sage)
Scout and Sage are optional paid features that do their reasoning in our cloud rather than on your device. The text of your message still does not leave your device when they run. They work from Sentinel’s analysis, plus a short list of specific items pulled out of the message, such as the link it points at. That list is written out in full under What Scout and Sage Send below, and it is worth reading rather than taking our word for it.
Scout and Sage never run on their own. Each runs only when you choose to start it on a given analysis, so declining to run them keeps that analysis entirely on your device with Sentinel’s output alone.
What We Collect
One list, so there is no doubt about what is on it. The short version: we collect what is needed to run your account, and we do not collect the text of the messages you scan.
Account and Service Data
- Email address, for magic-link sign-in and service communications
- First and last name, optional, if you choose to add them
- A Vigil account identifier we generate for you
- A one-way hash of your device identifier, used to bind sessions to a device. The underlying identifier itself is never transmitted
- Session tokens, settings and preferences you configure
- Authentication logs, for security monitoring
- Scan counts per period, to apply your plan’s limits
What Stays On Your Device
These never reach our servers at all. This is not a retention promise, which would mean we hold them briefly; we do not receive them:
- The text of the messages and emails you scan. Sentinel, our threat-detection engine, runs on your device. Analysis happens locally and the content is discarded from memory when it finishes. If you choose to run Scout or Sage, a short list of specific items extracted from the message does leave your device, and that list is written out in full below
- Your email account credentials. When you connect Gmail, the access and refresh tokens are stored in your device’s secure hardware-backed keychain and are used from your device only. Our backend never receives or stores them
- Your inbox. Message senders, subjects and dates are cached on your device so the app can show a list. That cache is local, and expires on its own
What Scout and Sage Send (Optional, Paid)
Scout and Sage are optional paid features that reason about a message you have already scanned. They never receive the text of your message. They receive Sentinel’s analysis of it, plus a small set of specific items pulled out of the message, because neither feature can ask a useful question or give useful advice without knowing what the message is pointing you at.
Here is the complete list of what leaves your device when you run Scout or Sage.
Sentinel’s analysis. No part of this is content:
- The risk score, its risk band, and the malicious or legitimate prediction
- The dominant manipulation pattern, and the full distribution of pattern probabilities behind it
- The derived risk signals Sentinel computes
- The pretext topic and its probability distribution, chosen from a fixed list
Items extracted from the message. Two of these are taken from the message word for word:
- The target: the link, phone number, email address, or code the message points you at, exactly as it appears. If a message contains a phishing link, that link is sent. If a message has no link or number in it but asks you to write back, the address it wants you to write to is the target, and that is usually the sender’s own reply-to address.
- The names of organizations the message mentions, both normalized and as they literally appear in the message. We send the literal form because character substitution in a brand name is itself a scam signal, and normalizing it away would destroy the evidence.
- The channel it arrived on and the action it asks for, each chosen from a fixed list
- The names of people mentioned. This is always empty today, because Vigil does not currently extract personal names. If that changes, this policy changes first.
What is never sent: the body of the message or its subject line.
Your answers to Scout’s questions, which are yes, no, or unsure.
This goes to our backend and on to Amazon Bedrock, AWS’s managed foundation model service. Under AWS’s terms Bedrock does not retain these inputs, use them for training, or share them with the providers of the underlying models.
What We Keep So Your Devices Agree
When you run Scout or Sage on an email, we save the analysis described above, together with Scout’s questions, your answers, and Sage’s recommendation, to your account. This is so that opening the same email on your phone and your tablet shows you the same result instead of re-running and possibly disagreeing with itself.
That saved record contains the extracted items listed above, including the target and the organization names. It still does not contain the message. We keep it while your account is active, and deleting your account deletes it.
Scans of text you paste are not saved this way.
Threat Scores
When a scan of an email finishes, the result is saved to your account so the same message shows the same verdict on your other devices. That record holds:
- The identifier your email provider assigned to that message. For Gmail, this is the Gmail message ID. It is a pointer, not a copy: it means nothing without access to your mailbox, which we do not have. It is not a hash of the message
- Which account it came from
- The numeric score, its color and its risk band
- The short band description shown in the app
- When it was analyzed
It does not include the message.
Feedback
If you use the in-app feedback form, we receive your ratings and any comment you write. The feedback record carries no account identifier, so what you send cannot be traced back to you from the stored record.
Diagnostic Data
App performance metrics, error reports and usage analytics are collected automatically to help us improve Vigil. This data is:
- Not linked to your Vigil account identity in our analytics provider’s systems: we deliberately do not send your Vigil user ID to Firebase Analytics or Firebase Crashlytics
- Limited in content: crash reports contain exception types and stack traces only, with personally identifiable information filtered before transmission
- Used only to improve Vigil: we do not sell it, share it with advertisers, or use it for marketing to you
- Tagged with an anonymous device-level identifier so we can distinguish one device’s usage pattern from another’s, but contains no information that would identify the person using the device
Automatically Collected
- IP addresses, for security and fraud prevention
- Error logs, for technical support and debugging
Optional Account Connections
You may choose to connect a third-party account, such as Google Gmail, to scan that inbox. When you do:
- We use industry-standard OAuth 2.0 to authenticate with the provider
- We never see or store your third-party account passwords
- The resulting access tokens stay on your device, in secure storage, and are used from your device. They are not sent to us
- Your mail is fetched by the app, on your device, and analysed there
- You can revoke access at any time, in the app or with the provider
Google API Services Limited Use Disclosure
Vigil’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, and specific to Vigil:
- We use Gmail data only to analyze your messages for scam and phishing indicators, which is the feature you connected the account for
- We do not transfer Gmail data to anyone except as needed to provide that feature, and only with your action, as described under What Scout and Sage Send
- We do not use Gmail data for advertising of any kind
- No human at Vigilcode reads your Gmail data
- We do not use Gmail data to create, train, or improve any machine learning or artificial intelligence model. Google’s policy prohibits this and we do not do it. See We Do Not Train On Your Messages below
How We Use Your Information
Primary Service Functions
- Authentication: Provide secure, password-less login via magic links
- Service Delivery: Return the verdict Sentinel produced on your device, and, if you use Scout or Sage, reason about its derived signals
- Account Management: Maintain your account and service preferences
- Quota Management: Track usage to enforce service tier limits
Service Improvement
- Product Development: Improve threat detection and the app, using the diagnostic and usage data described above
- Research: Understand emerging security threats and develop better protections
We Do Not Train On Your Messages
We do not use your messages or emails to train our models. We cannot: the content never reaches us. Sentinel’s models are trained on security data we generate and curate ourselves, not on anything you scan.
There is no opt-in for this, because there is nothing to opt into. If that ever changes, it will require a new version of this policy and your explicit, separate consent. It will never be a default, and it will never be buried in an update.
Your Data
You own your content, and the strongest form of that is not a promise about how we handle it. It is that we do not have it.
What This Means
- Your messages are yours and stay yours. They are analysed on your device and are not transmitted to us, so there is nothing for us to claim, sell, retain or lose
- Limited processing rights: we process the account data described above only to deliver the service you asked for
- No permanent claims: our processing rights end when you delete your account or withdraw consent
- Exportable data: you can request a copy of the data we hold about you at any time
Our Commitment
For the account data we hold, we are the controller: we decide what is collected and why, and we are accountable for it. We hold it to run your account and deliver the service you asked for, and for nothing else. For the text of the messages you scan, the question does not arise, because we do not have it.
Information Sharing and Disclosure
We Do Not Sell Your Data
We do not and will not:
- Sell your personal data to advertisers, data brokers, or marketing companies
- Share data with third parties for their own commercial purposes
- Use your data for advertising to third parties
- Create marketing profiles from your messages or your activity in the app
- Monetize your information beyond providing you our security services
This is a core commitment. If it ever changes, it will require a new version of this policy, and we will tell you before it takes effect.
If Vigilcode Is Ever Sold
If Vigilcode is acquired, merges, or sells the part of its business that runs Vigil, your account data would transfer to the buyer as part of that transaction. We will notify you, and the commitments in this section travel with the data: a buyer takes it subject to this policy, and cannot start selling it or using it for advertising without giving you notice and a new version of this policy.
What We Don’t Do
- No data sales: We do not and will never sell your personal data
- No advertising partnerships: We do not share data with advertisers or data brokers
- No marketing databases: We do not use your data for marketing to third parties
- No storage of your messages: we do not store the text you scan, encrypted or otherwise, because we never receive it
- No cross-selling: We do not share your information for others to market to you
Limited Disclosure Scenarios
We may disclose information only when:
- Required by law or legal process
- Protecting user safety in emergency situations
- Preventing fraud or security threats to our services
- With your explicit consent for specific purposes
Service Providers
We use the following categories of trusted service providers to deliver our services. Each provider is contractually bound to protect your information and may not use your data for their own purposes:
- Cloud Infrastructure (Amazon Web Services): Hosts our backend services, API endpoints, and securely stores account and quota data. Sign-in (magic-link email verification), session tokens, and all account management run on our AWS backend.
- Firebase Authentication (custom token bridge): Used only to issue a Firebase-scoped identity so the app can write to Cloud Firestore (for feedback and user statistics). After you sign in through our AWS backend, our backend mints a short-lived Firebase custom token containing your Vigil user ID; Firebase Authentication accepts it. Firebase Authentication does not receive your password, magic-link, or any credential material, and it does not manage your Vigil account.
- Cloud Firestore (Google Firebase): Stores in-app feedback, which carries no account identifier, and aggregated usage statistics (scan counts by risk level). Does not store message content.
- AI Analysis (Amazon Bedrock, part of AWS): Powers the optional Scout and Sage features. Receives the derived signals described above, never your message content. Under AWS’s terms Bedrock does not retain these inputs, use them for training, or share them with the providers of the underlying models. The specific model may change over time; AWS remains the sub-processor either way.
- Subscription Management (RevenueCat): Processes in-app purchase transactions and manages subscription entitlements. RevenueCat receives purchase receipts and anonymous user identifiers but not your personal content.
- OAuth Providers (Google): When you choose to connect an email account, Google handles authentication. The resulting access tokens are stored on your device and used from your device; we do not receive them, and our servers never hold credentials to your mailbox. Mail is fetched and analysed on your device.
- Analytics and Crash Reporting (Firebase Analytics, Firebase Crashlytics): Collects anonymized app performance data and crash reports to help us improve reliability. Not linked to your Vigil account identity in Firebase’s systems.
Data Security
Protection Measures
- Industry-standard encryption in transit, and encryption at rest for the account data we store
- Access controls limiting data access to authorized personnel only
- Regular security audits and vulnerability assessments
- Secure authentication using modern cryptographic methods
Data Retention
- Account data: retained while your account is active
- Message text: not retained, because it is never received
- Threat scores: retained while your account is active, so verdicts stay consistent across your devices
- Scout and Sage records, including the extracted items described above such as the target link and organization names: retained while your account is active, so your devices show you the same result
- Diagnostic and usage data: retained per our analytics provider’s policy, unlinked to your account identity
- Deletion requests: honoured in accordance with applicable law
Deleting your account deletes your threat scores and your Scout and Sage records along with it.
Your Rights and Choices
Account Control
- Access your data through account settings
- Update information including email preferences
- Delete your account and associated personal data
- Request a copy of your data in portable formats
Communication Preferences
- Opt out of non-essential communications
- Authentication emails cannot be disabled (required for service)
- Security alerts recommended but can be customized
Data Processing Rights
- Request data deletion (subject to legal and operational requirements)
- Correct inaccurate information in your account
- Object to processing for certain purposes
- Data portability for information you’ve provided
Children’s Privacy
You must be at least 18 to create a Vigil account. A person aged 13 to 17 may use Vigil only if their parent or legal guardian agrees to our Terms of Use on their behalf and supervises their use.
Vigil is not intended for and may not be used by anyone under 13. We do not knowingly collect personal information from children under 13. If we learn that we have, we will delete the account and the associated data promptly. If you believe a child under 13 has given us information, contact privacy@vigilcode.com.
International Data Transfers
Your information may be processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data when transferred internationally, including:
- Standard contractual clauses approved by regulatory authorities
- Adequacy decisions recognizing equivalent protection levels
- Additional security measures as required by applicable law
California Privacy Rights
California residents have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected and how it’s used
- Right to delete personal information (with certain exceptions)
- Right to opt-out of sale of personal information (we don’t sell data)
- Right to non-discrimination for exercising privacy rights
Changes to This Policy
Vigilcode reserves the right to modify this Privacy Policy at any time. When we make changes:
- We will update the “Last Updated” date at the top of this document
- For material changes, we will provide additional notice via email or prominent website notification
- Your continued use of our Services after changes constitutes acceptance of the updated Policy
- We encourage you to review this Policy periodically for updates
Third-Party Services and Websites
This Policy does not cover third parties or their products, actions, or services. Vigilcode is not responsible for:
- Third-party websites, applications, or services you may access through our Services
- Cookies, pixels, and tracking technologies used by third-party advertisers
- Social media platforms, email providers, or other external services you may connect to
- Privacy practices of companies that provide services to us
For information about third-party privacy practices, please consult their respective privacy policies.
Contact Information
For privacy-related questions, concerns, or requests:
Email: privacy@vigilcode.com
By using Vigil services, you acknowledge that you have read and understood this Privacy Policy and agree to our data practices as described herein.