1. Who runs this service
Fred's Privacy ("the Service," "we," "us") is a personal, non-commercial project operated by an individual developer. It provides an automated tool that analyzes emails for phishing and scam indicators. It is not a company, and it is offered without charge. Questions about this policy can be sent to pordfred3@gmail.com.
2. What you submit
You can submit an email for analysis in two ways, and they are handled differently:
-
Through the website: when you drop in or paste an email at
www.fredsprivacy.com, the raw email is sent to our analysis function, processed in memory, and returned to you as a verdict. The website submission is not written to long-term storage. - By email: when you forward an email to our analysis address, the incoming message is received by Amazon SES and stored temporarily in an Amazon S3 bucket so our function can read it. These stored emails are automatically deleted after 7 days.
In both cases, "the email" includes its headers, body text, and any links it contains, because those are exactly what the analysis inspects.
3. Third parties that process your email
Analyzing an email requires sending parts of it to external services. By using the Service, you understand that the following third parties may receive email content:
- Anthropic (Claude API): the email's headers and body (truncated) are sent to Anthropic's Claude models to assess social-engineering patterns. Anthropic processes this data under its own API terms and data-handling policies.
- Threat-intelligence providers: up to three links found in the email are checked against VirusTotal, urlscan.io, and PhishTank. This means those URLs (and the domains within them) are shared with those services, each of which has its own privacy policy.
We do not control how these third parties use data submitted to them. Review their respective privacy policies if that matters to you.
4. What we log and keep
For each analysis we record a small metadata log entry to help us monitor and debug the Service. This log does not contain the email body or the sender's full address. It records items such as: the sender's domain, the return-path domain, SPF/DKIM/DMARC authentication results, the number of links found, the verdict, and the confidence score. These logs are retained for 30 days and then automatically deleted.
We also temporarily store, in a database with automatic expiration: short-lived counters used for rate limiting (keyed to a sender email address or IP address), and cached URL-reputation results (keyed to a hashed version of the URL). These entries expire automatically and are not used to build any profile of you.
5. What we do not do
- We do not sell or rent your data.
- We do not use your submitted emails to build advertising profiles.
- We do not require you to create an account or provide personal information to use the Service.
- We do not intentionally retain the content of analyzed emails beyond the windows described above.
6. Please don't submit sensitive information
Because your email is processed by automated cloud services and third parties, you should not submit emails that contain passwords, financial account details, government identifiers, health information, or other sensitive personal data. If an email you want checked contains such information, redact it first, or simply don't submit it. You are responsible for what you choose to send to the Service.
7. Children
The Service is not directed at children and is not intended for use by anyone under 13. We do not knowingly collect information from children.
8. Security
The Service uses reasonable technical measures (transport encryption, short retention windows, rate limiting), but no method of transmission or storage is perfectly secure. This is a personal project provided without warranty, and you use it at your own risk.
9. Changes to this policy
This policy may be updated from time to time. The "last updated" date at the top reflects the most recent change. Continued use of the Service after a change means you accept the updated policy.
10. Contact
Questions or requests regarding this policy or your data can be directed to pordfred3@gmail.com.
This document is provided for transparency about how the Service handles data. It is not legal advice, and it has not been reviewed by an attorney.