Back to Home
Oversight

Privacy Policy

How Oversight handles your data across the Chrome & Edge extension, the iOS app, the Android app, and our web service — together, as one product.

Effective date: June 14, 2026 · Last updated: September 13, 2026

Oversight is operated by Renderwise ("Renderwise", "we", "us"). Contact: admin@renderwise.net · Website: oversightscan.com

Privacy at a glance

  • Quick Scans run entirely on your device — nothing leaves it.
  • AI Deep Scans send only the screenshot or text you chose to scan; images are processed, then discarded, never stored.
  • We store scan results (scores and short explanations), not the email messages or images you scan.
  • If you submit a support request, its text, diagnostics, and any file you intentionally attach are stored with the ticket until you delete your account.
  • You can delete your account and all associated data in-app at any time, or follow the steps at https://oversightscan.com/data-deletion.
  • We don't sell your data or use it for third-party advertising.
  • Approximate IP location at first launch/install event can estimate country, state/region, and sometimes city one time, when the first install or first-launch event reaches Oversight. No device location permission is requested, and it never uses GPS or device Location Services.
  • Optional notifications can include reminders, scam-checking tips, product updates, and promotional offers only after an in-app choice and the device's permission. You can turn them off in the app.
  • Our marketing website runs no analytics or ad trackers. The Oversight sign-in service uses only short-lived, essential security cookies during social sign-in.

1. Information we collect

We collect only what we need to detect scams and run the service. "Transient" means it is processed and then discarded; retention of stored data is described below (see Retention & Deletion).

CategoryWhat it isHandling
Account dataYour email address, optional name, subscription tier, and login methods. If you use a password, it is kept only as a scrypt hash — never in plain text. If you use Google or Apple, we store the provider's stable account identifier and verified email/profile fields needed to identify your Oversight account; we never receive your Google or Apple password.Stored
Social sign-in security dataShort-lived, one-time state, nonce, code-verifier, handoff, and reauthentication records used to prevent login forgery and replay. For Sign in with Apple, a revocation credential is encrypted at rest so we can disconnect Apple when you delete your account; failed revocations may be retried using a minimal queued job. A keyed, pseudonymous provider-subject claim may be retained to prevent repeated introductory-trial abuse and cannot be used to sign in.Security records expire quickly; identity/revocation data until unlink or deletion; anti-abuse claim retained as needed
Scan contentThe screenshot or text you submit for an AI Deep Scan. It is analyzed in memory to produce a result and is never written to disk.Transient
Scan metadataRisk score, verdict, detection engine, a short summary (≤200 characters), the top reasons, the risk factors, and a message fingerprint. Only stored when result storage is enabled (storeRiskMetadata, on by default for your own history). Sender and subject signals — a one-way hashed sender address, the sender domain, and an 80-character subject snippet — are stored only when you turn on the matching sharing options (shareSenderMetadata / shareSubjectSnippet), which are off by default.Stored
Support requestsThe category, subject, message, status, and any screenshot or file you intentionally attach, plus limited troubleshooting details such as app version, platform, operating-system version, device or browser type, and locale. Oversight does not automatically include scanned messages, passwords, or authentication tokens.Stored until account deletion
Waitlist sign-up (website)If you join the waitlist on our marketing website, we store the email address you submit (and an optional company name) so we can notify you about availability. The marketing website runs no analytics or ad trackers.Stored until launch / opt-out
Payment dataHandled entirely by Stripe (web) or Apple / Google (in-app purchases). We never receive or store full card numbers.Stored by processor
Family / guardian dataRelationship links between a guardian and a protected person, and alerts shared according to the protected person's privacy settings (off by default).Stored
Phone numbersCrowd-reported scam numbers used by Call Shield / Call Directory to warn you about known scam callers. On Android, when the call shield screens a call the incoming number is sent to our servers to check its reputation; we don't store these lookups. On iOS, labeling happens entirely on-device from a downloaded list — no number is sent per call. When you report a number, we record that you reported it (linked to your account); the aggregate scam list itself is not tied to your identity.Stored (aggregate); lookups transient
SMS content (iOS)Filtered on your device. Only messages the on-device filter is unsure about are sent for a check, with no account identity attached.Transient
Photos / screenshotsImages you actively scan, or ones the opt-in screenshot watcher captures, are transient. A screenshot is stored only when you intentionally attach it to a support request. The watcher is off by default.Scans transient; support attachments stored until account deletion
IP addressProcessed to rate-limit requests and prevent abuse. The IP address on the first eligible install or first-launch event may also be used once to estimate country, state/region, and sometimes city. We do not store the raw IP address with the location estimate; a coarse network prefix may be stored separately for abuse prevention. Raw IP addresses may appear in operational infrastructure logs, including Cloud Run request logs.Raw IP transient in app; prefix stored; logs ~30 days
Install and activation eventsApp/extension platform, version, onboarding events, timestamps, and a hash of a randomly generated installation identifier kept in normal app or extension storage. The first-event location estimate is grouped by that pseudonymous identifier and platform. After sign-in, that exact anchor may be linked to your account only so privacy withdrawal and account deletion can find and suppress it; administrators still receive only aggregate location counts. A first-open/install event is not a verified app-store download or historical physical-install position.Stored with onboarding events
Approximate first-event locationOne time, when the first install or first-launch event reaches Oversight, we may estimate country, state/region, and sometimes city from that connection's IP address. This is not GPS, precise location, residence, or live location. VPNs, relays, mobile networks, and corporate networks can make it inaccurate or unavailable. If that first event cannot be resolved, it remains Unknown; later sign-in, travel, retry, or app use does not replace it with a later location. No device location permission is requested.Detailed estimate retained for up to 90 days; non-identifying country/day/platform totals may remain
Optional notification dataFor iOS and Android devices that choose notifications, we store an encrypted push token, app/device delivery details, the current in-app notification-choice version, and delivery status. This supports reminders, scam-checking tips, product updates, and promotional offers. Existing operating-system permission alone does not opt you in, and turning the in-app choice off stops these campaigns.Until opt-out, installation replacement, or account deletion
DiagnosticsServer logs and extension heartbeats used for reliability, security, and abuse prevention.~30 days

Note the difference between processed and retained: we always read the sender and subject of a message to compute its risk score, but we only keep them afterward if you've turned on the sharing options above. The message body and the screenshot are never retained.

2. How we use your data

  • Detect scams and phishing in the messages you choose to scan.
  • Show you your results and scan history.
  • Send family / guardian alerts when enabled by the protected person.
  • Process and manage your subscription and billing.
  • Prevent abuse and enforce rate limits.
  • Authenticate you, link login methods only with fresh proof, revoke sessions after sensitive account changes, and prevent repeated introductory-trial abuse.
  • Respond to support requests, investigate technical issues, and track request status.
  • Understand acquisition and activation by platform and report aggregate approximate country counts from first install/first-launch events. Authorized administrators see aggregate map and table counts, including an Unknown bucket, rather than user-level location pins.
  • Send optional reminders, scam-checking tips, product updates, and promotional offers to mobile accounts that make the current in-app notification choice and also allow device notifications.
  • Improve our detection (using results and your feedback — never your stored emails or images).

We never sell your data or use it for third-party advertising. Optional promotional notifications concern Oversight's own products and are sent only after the current in-app opt-in and device permission.

3. Third-party processors

We share data with the service providers below only as needed to run Oversight. Each processes data under its own privacy policy.

ProcessorWhat they do
OpenAIAI vision/text analysis of the content you submit for a Deep Scan. Content sent via OpenAI's API is not used to train their models.
StripePayment processing for web subscriptions
AppleSign in with Apple, iOS in-app purchases, and APNs delivery for opted-in iOS notifications
GoogleGoogle sign-in and Google Play in-app purchases
Google Cloud PlatformHosting — Cloud Run + Cloud SQL (us-central1 region), network ingress, and Firebase Cloud Messaging delivery for opted-in Android notifications
MaxMindSource of a locally operated database used for the one-time first-event IP-location estimate; Oversight does not send individual lookup IP addresses to MaxMind
ResendTransactional and guardian-alert emails
UpstashRate limiting (listed for completeness; activated only if/when enabled)

4. Data sharing

  • With guardians: consent-based and controlled by the protected person, who decides what (if anything) is shared.
  • Within teams / organizations: admins can see alerts for the members they manage.
  • With the processors listed above.

We do not sell your data or share it for third-party advertising.

5. Data retention & deletion

  • Scan screenshots & images: discarded immediately after analysis — never stored. A file you intentionally attach to a support request is stored with that ticket until you delete your account.
  • Scan metadata: retained until you delete your account (or for the retention window your organization sets, if any).
  • Support requests: ticket text, limited diagnostics, status, and optional attachments are retained until you delete your account.
  • Install and activation events: retained for product analytics and onboarding diagnosis. Account-linked events are removed on account deletion. Events not linked to an account are not automatically removed by account deletion; contact us about these records using the data deletion page below.
  • Approximate first-event location: the detailed country/state-or-region/estimated-city result is retained for up to 90 days and then removed. Non-identifying country/day/platform totals may remain for the historical globe; they contain no account, installation identifier, IP, region/city, timestamp, or user coordinates. A previously recorded privacy withdrawal or deletion suppression remains blocked so delayed traffic cannot restore that installation's estimate. Because this record may remain unlinked until sign-in, use our data deletion page if you need help identifying and deleting an unlinked installation record. The service stores no raw IP with the estimate.
  • Optional notifications: turning the in-app Notifications choice off revokes campaign eligibility. Push-installation data is also removed or replaced when the installation is disconnected, transferred, or the account is deleted.
  • Server logs: retained for about 30 days.
  • Social sign-in: one-time security records expire automatically. Linked Google/Apple identities are removed when you unlink them or delete your account. Apple revocation credentials are encrypted and deleted after revocation; minimal retry metadata may remain briefly if Apple is temporarily unavailable. A keyed, pseudonymous trial claim may be retained after deletion only to prevent repeated introductory-trial abuse.
  • Account deletion: delete your account in-app (Settings → Delete account) at any time. This permanently removes your account and cascades deletion of your scans, support tickets and attachments, alerts, team memberships, and guardian links. You can also email admin@renderwise.net or use our data deletion page (https://oversightscan.com/data-deletion).

6. Your rights

Depending on where you live, you have rights over your data, including the right to access, correct, delete, and port it. Under the GDPR (EEA/UK) and the CCPA/CPRA (California), you also have the right to know what we collect, to request deletion, and to opt out of the sale of personal information — and we do not sell personal information. We will not discriminate against you for exercising these rights.

To exercise any of these, delete your account in-app, visit our data deletion page, or email admin@renderwise.net.

7. Security

  • All data is encrypted in transit with HTTPS/TLS.
  • Passwords are hashed with scrypt; sessions use signed JWTs.
  • Sender email addresses are stored only as HMAC (one-way) hashes.
  • Authentication tokens are stored securely on each platform — the iOS Keychain, Android EncryptedSharedPreferences, and chrome.storage.local in the extension.
  • Internal access is limited to authorized staff, who may view account and scan metadata, and the contents of support requests you choose to submit, only as needed to operate, support, and secure the service. We never access the message bodies or screenshots you scan — they are never stored.

8. Children's privacy

Oversight is not directed to children under 13 (or under 16 in the EEA/UK), and we do not knowingly collect their personal data. Family Overwatch is a tool for guardians to help protect family members from scams — it is not a service that targets or profiles children.

9. Per-platform permissions

Why each sensitive permission is requested on each platform.

iOS & iPadOS

PermissionWhy we need it
Photo LibrarySo you can choose a screenshot for a Deep Scan or intentionally attach one to a support request.
Messages / SMS FilterTo filter scam texts on-device; uncertain messages are checked without your identity attached.
Call DirectoryTo label known scam numbers before you answer.
Screenshot watcher (opt-in)Background screenshot scanning. Off by default; turned on only after an explicit consent screen.
NotificationsTo deliver protection alerts and, only after the separate current in-app choice, optional reminders, scam-checking tips, product updates, and promotional offers. You can turn optional notifications off in the app.

Android

PermissionWhy we need it
Photos & media (READ_MEDIA_IMAGES)So you can select a screenshot to scan.
Call screening (CallScreeningService)To flag or silence known scam callers.
Screen capture (MediaProjection)Powers the Quick Settings "scan screen" tile — captures the current screen only when you tap to scan.
Screenshot watcher (opt-in)Background photo access for the optional watcher. Off by default, with a prominent in-app consent screen.
NotificationsTo deliver protection alerts and, only after the separate current in-app choice, optional reminders, scam-checking tips, product updates, and promotional offers. You can turn optional notifications off in the app.

Chrome & Edge extension

PermissionWhy we need it
activeTab / tabsTo capture a screenshot of the visible tab when you run a scan.
scriptingTo display the risk-score panel inside the page (Gmail / Outlook).
Host access (Gmail, Outlook, and <all_urls>)Needed to read the message you choose to scan and to use captureVisibleTab for in-page Deep Scans.
storageKeeps your settings and session locally (chrome.storage.local).
identityOpens Google's secure sign-in page and returns a one-time result to the extension. Oversight does not receive your Google password or access to Gmail, Drive, contacts, or calendar.

Chrome Web Store — single purpose & Limited Use

Oversight has a single purpose: detecting scams and phishing in the messages you choose to scan.

Oversight's use of information received from Google APIs and from your browser adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically: we use the data only to provide and improve this single scam-detection purpose; we do not sell this data; we do not use or transfer it for advertising, personalized ads, or creditworthiness/lending purposes; and we do not allow humans to read the data except (a) with your consent, (b) as necessary for security, abuse prevention, or legal reasons, or (c) where the data has been aggregated or anonymized for internal operations.

10. Changes to this policy

We may update this policy from time to time. When we do, we'll revise the "Last updated" date above, and for material changes we'll notify you by email or in-app.

11. Contact

Questions about this policy or your data? Contact Renderwise at admin@renderwise.net.