Privacy Policy
How Oversight handles your data across the Chrome & Edge extension, the iOS app, the Android app, and our web service — together, as one product.
Effective date: June 14, 2026 · Last updated: September 13, 2026
Oversight is operated by Renderwise ("Renderwise", "we", "us"). Contact: admin@renderwise.net · Website: oversightscan.com
Privacy at a glance
- Quick Scans run entirely on your device — nothing leaves it.
- AI Deep Scans send only the screenshot or text you chose to scan; images are processed, then discarded, never stored.
- We store scan results (scores and short explanations), not the email messages or images you scan.
- If you submit a support request, its text, diagnostics, and any file you intentionally attach are stored with the ticket until you delete your account.
- You can delete your account and all associated data in-app at any time, or follow the steps at https://oversightscan.com/data-deletion.
- We don't sell your data or use it for third-party advertising.
- Approximate IP location at first launch/install event can estimate country, state/region, and sometimes city one time, when the first install or first-launch event reaches Oversight. No device location permission is requested, and it never uses GPS or device Location Services.
- Optional notifications can include reminders, scam-checking tips, product updates, and promotional offers only after an in-app choice and the device's permission. You can turn them off in the app.
- Our marketing website runs no analytics or ad trackers. The Oversight sign-in service uses only short-lived, essential security cookies during social sign-in.
1. Information we collect
We collect only what we need to detect scams and run the service. "Transient" means it is processed and then discarded; retention of stored data is described below (see Retention & Deletion).
| Category | What it is | Handling |
|---|---|---|
| Account data | Your email address, optional name, subscription tier, and login methods. If you use a password, it is kept only as a scrypt hash — never in plain text. If you use Google or Apple, we store the provider's stable account identifier and verified email/profile fields needed to identify your Oversight account; we never receive your Google or Apple password. | Stored |
| Social sign-in security data | Short-lived, one-time state, nonce, code-verifier, handoff, and reauthentication records used to prevent login forgery and replay. For Sign in with Apple, a revocation credential is encrypted at rest so we can disconnect Apple when you delete your account; failed revocations may be retried using a minimal queued job. A keyed, pseudonymous provider-subject claim may be retained to prevent repeated introductory-trial abuse and cannot be used to sign in. | Security records expire quickly; identity/revocation data until unlink or deletion; anti-abuse claim retained as needed |
| Scan content | The screenshot or text you submit for an AI Deep Scan. It is analyzed in memory to produce a result and is never written to disk. | Transient |
| Scan metadata | Risk score, verdict, detection engine, a short summary (≤200 characters), the top reasons, the risk factors, and a message fingerprint. Only stored when result storage is enabled (storeRiskMetadata, on by default for your own history). Sender and subject signals — a one-way hashed sender address, the sender domain, and an 80-character subject snippet — are stored only when you turn on the matching sharing options (shareSenderMetadata / shareSubjectSnippet), which are off by default. | Stored |
| Support requests | The category, subject, message, status, and any screenshot or file you intentionally attach, plus limited troubleshooting details such as app version, platform, operating-system version, device or browser type, and locale. Oversight does not automatically include scanned messages, passwords, or authentication tokens. | Stored until account deletion |
| Waitlist sign-up (website) | If you join the waitlist on our marketing website, we store the email address you submit (and an optional company name) so we can notify you about availability. The marketing website runs no analytics or ad trackers. | Stored until launch / opt-out |
| Payment data | Handled entirely by Stripe (web) or Apple / Google (in-app purchases). We never receive or store full card numbers. | Stored by processor |
| Family / guardian data | Relationship links between a guardian and a protected person, and alerts shared according to the protected person's privacy settings (off by default). | Stored |
| Phone numbers | Crowd-reported scam numbers used by Call Shield / Call Directory to warn you about known scam callers. On Android, when the call shield screens a call the incoming number is sent to our servers to check its reputation; we don't store these lookups. On iOS, labeling happens entirely on-device from a downloaded list — no number is sent per call. When you report a number, we record that you reported it (linked to your account); the aggregate scam list itself is not tied to your identity. | Stored (aggregate); lookups transient |
| SMS content (iOS) | Filtered on your device. Only messages the on-device filter is unsure about are sent for a check, with no account identity attached. | Transient |
| Photos / screenshots | Images you actively scan, or ones the opt-in screenshot watcher captures, are transient. A screenshot is stored only when you intentionally attach it to a support request. The watcher is off by default. | Scans transient; support attachments stored until account deletion |
| IP address | Processed to rate-limit requests and prevent abuse. The IP address on the first eligible install or first-launch event may also be used once to estimate country, state/region, and sometimes city. We do not store the raw IP address with the location estimate; a coarse network prefix may be stored separately for abuse prevention. Raw IP addresses may appear in operational infrastructure logs, including Cloud Run request logs. | Raw IP transient in app; prefix stored; logs ~30 days |
| Install and activation events | App/extension platform, version, onboarding events, timestamps, and a hash of a randomly generated installation identifier kept in normal app or extension storage. The first-event location estimate is grouped by that pseudonymous identifier and platform. After sign-in, that exact anchor may be linked to your account only so privacy withdrawal and account deletion can find and suppress it; administrators still receive only aggregate location counts. A first-open/install event is not a verified app-store download or historical physical-install position. | Stored with onboarding events |
| Approximate first-event location | One time, when the first install or first-launch event reaches Oversight, we may estimate country, state/region, and sometimes city from that connection's IP address. This is not GPS, precise location, residence, or live location. VPNs, relays, mobile networks, and corporate networks can make it inaccurate or unavailable. If that first event cannot be resolved, it remains Unknown; later sign-in, travel, retry, or app use does not replace it with a later location. No device location permission is requested. | Detailed estimate retained for up to 90 days; non-identifying country/day/platform totals may remain |
| Optional notification data | For iOS and Android devices that choose notifications, we store an encrypted push token, app/device delivery details, the current in-app notification-choice version, and delivery status. This supports reminders, scam-checking tips, product updates, and promotional offers. Existing operating-system permission alone does not opt you in, and turning the in-app choice off stops these campaigns. | Until opt-out, installation replacement, or account deletion |
| Diagnostics | Server logs and extension heartbeats used for reliability, security, and abuse prevention. | ~30 days |
Note the difference between processed and retained: we always read the sender and subject of a message to compute its risk score, but we only keep them afterward if you've turned on the sharing options above. The message body and the screenshot are never retained.
2. How we use your data
- Detect scams and phishing in the messages you choose to scan.
- Show you your results and scan history.
- Send family / guardian alerts when enabled by the protected person.
- Process and manage your subscription and billing.
- Prevent abuse and enforce rate limits.
- Authenticate you, link login methods only with fresh proof, revoke sessions after sensitive account changes, and prevent repeated introductory-trial abuse.
- Respond to support requests, investigate technical issues, and track request status.
- Understand acquisition and activation by platform and report aggregate approximate country counts from first install/first-launch events. Authorized administrators see aggregate map and table counts, including an Unknown bucket, rather than user-level location pins.
- Send optional reminders, scam-checking tips, product updates, and promotional offers to mobile accounts that make the current in-app notification choice and also allow device notifications.
- Improve our detection (using results and your feedback — never your stored emails or images).
We never sell your data or use it for third-party advertising. Optional promotional notifications concern Oversight's own products and are sent only after the current in-app opt-in and device permission.
3. Third-party processors
We share data with the service providers below only as needed to run Oversight. Each processes data under its own privacy policy.
| Processor | What they do |
|---|---|
| OpenAI | AI vision/text analysis of the content you submit for a Deep Scan. Content sent via OpenAI's API is not used to train their models. |
| Stripe | Payment processing for web subscriptions |
| Apple | Sign in with Apple, iOS in-app purchases, and APNs delivery for opted-in iOS notifications |
| Google sign-in and Google Play in-app purchases | |
| Google Cloud Platform | Hosting — Cloud Run + Cloud SQL (us-central1 region), network ingress, and Firebase Cloud Messaging delivery for opted-in Android notifications |
| MaxMind | Source of a locally operated database used for the one-time first-event IP-location estimate; Oversight does not send individual lookup IP addresses to MaxMind |
| Resend | Transactional and guardian-alert emails |
| Upstash | Rate limiting (listed for completeness; activated only if/when enabled) |
4. Data sharing
- With guardians: consent-based and controlled by the protected person, who decides what (if anything) is shared.
- Within teams / organizations: admins can see alerts for the members they manage.
- With the processors listed above.
We do not sell your data or share it for third-party advertising.
5. Data retention & deletion
- Scan screenshots & images: discarded immediately after analysis — never stored. A file you intentionally attach to a support request is stored with that ticket until you delete your account.
- Scan metadata: retained until you delete your account (or for the retention window your organization sets, if any).
- Support requests: ticket text, limited diagnostics, status, and optional attachments are retained until you delete your account.
- Install and activation events: retained for product analytics and onboarding diagnosis. Account-linked events are removed on account deletion. Events not linked to an account are not automatically removed by account deletion; contact us about these records using the data deletion page below.
- Approximate first-event location: the detailed country/state-or-region/estimated-city result is retained for up to 90 days and then removed. Non-identifying country/day/platform totals may remain for the historical globe; they contain no account, installation identifier, IP, region/city, timestamp, or user coordinates. A previously recorded privacy withdrawal or deletion suppression remains blocked so delayed traffic cannot restore that installation's estimate. Because this record may remain unlinked until sign-in, use our data deletion page if you need help identifying and deleting an unlinked installation record. The service stores no raw IP with the estimate.
- Optional notifications: turning the in-app Notifications choice off revokes campaign eligibility. Push-installation data is also removed or replaced when the installation is disconnected, transferred, or the account is deleted.
- Server logs: retained for about 30 days.
- Social sign-in: one-time security records expire automatically. Linked Google/Apple identities are removed when you unlink them or delete your account. Apple revocation credentials are encrypted and deleted after revocation; minimal retry metadata may remain briefly if Apple is temporarily unavailable. A keyed, pseudonymous trial claim may be retained after deletion only to prevent repeated introductory-trial abuse.
- Account deletion: delete your account in-app (Settings → Delete account) at any time. This permanently removes your account and cascades deletion of your scans, support tickets and attachments, alerts, team memberships, and guardian links. You can also email admin@renderwise.net or use our data deletion page (https://oversightscan.com/data-deletion).
6. Your rights
Depending on where you live, you have rights over your data, including the right to access, correct, delete, and port it. Under the GDPR (EEA/UK) and the CCPA/CPRA (California), you also have the right to know what we collect, to request deletion, and to opt out of the sale of personal information — and we do not sell personal information. We will not discriminate against you for exercising these rights.
To exercise any of these, delete your account in-app, visit our data deletion page, or email admin@renderwise.net.
7. Security
- All data is encrypted in transit with HTTPS/TLS.
- Passwords are hashed with scrypt; sessions use signed JWTs.
- Sender email addresses are stored only as HMAC (one-way) hashes.
- Authentication tokens are stored securely on each platform — the iOS Keychain, Android EncryptedSharedPreferences, and chrome.storage.local in the extension.
- Internal access is limited to authorized staff, who may view account and scan metadata, and the contents of support requests you choose to submit, only as needed to operate, support, and secure the service. We never access the message bodies or screenshots you scan — they are never stored.
8. Children's privacy
Oversight is not directed to children under 13 (or under 16 in the EEA/UK), and we do not knowingly collect their personal data. Family Overwatch is a tool for guardians to help protect family members from scams — it is not a service that targets or profiles children.
9. Per-platform permissions
Why each sensitive permission is requested on each platform.
iOS & iPadOS
| Permission | Why we need it |
|---|---|
| Photo Library | So you can choose a screenshot for a Deep Scan or intentionally attach one to a support request. |
| Messages / SMS Filter | To filter scam texts on-device; uncertain messages are checked without your identity attached. |
| Call Directory | To label known scam numbers before you answer. |
| Screenshot watcher (opt-in) | Background screenshot scanning. Off by default; turned on only after an explicit consent screen. |
| Notifications | To deliver protection alerts and, only after the separate current in-app choice, optional reminders, scam-checking tips, product updates, and promotional offers. You can turn optional notifications off in the app. |
Android
| Permission | Why we need it |
|---|---|
| Photos & media (READ_MEDIA_IMAGES) | So you can select a screenshot to scan. |
| Call screening (CallScreeningService) | To flag or silence known scam callers. |
| Screen capture (MediaProjection) | Powers the Quick Settings "scan screen" tile — captures the current screen only when you tap to scan. |
| Screenshot watcher (opt-in) | Background photo access for the optional watcher. Off by default, with a prominent in-app consent screen. |
| Notifications | To deliver protection alerts and, only after the separate current in-app choice, optional reminders, scam-checking tips, product updates, and promotional offers. You can turn optional notifications off in the app. |
Chrome & Edge extension
| Permission | Why we need it |
|---|---|
| activeTab / tabs | To capture a screenshot of the visible tab when you run a scan. |
| scripting | To display the risk-score panel inside the page (Gmail / Outlook). |
| Host access (Gmail, Outlook, and <all_urls>) | Needed to read the message you choose to scan and to use captureVisibleTab for in-page Deep Scans. |
| storage | Keeps your settings and session locally (chrome.storage.local). |
| identity | Opens Google's secure sign-in page and returns a one-time result to the extension. Oversight does not receive your Google password or access to Gmail, Drive, contacts, or calendar. |
Chrome Web Store — single purpose & Limited Use
Oversight has a single purpose: detecting scams and phishing in the messages you choose to scan.
Oversight's use of information received from Google APIs and from your browser adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically: we use the data only to provide and improve this single scam-detection purpose; we do not sell this data; we do not use or transfer it for advertising, personalized ads, or creditworthiness/lending purposes; and we do not allow humans to read the data except (a) with your consent, (b) as necessary for security, abuse prevention, or legal reasons, or (c) where the data has been aggregated or anonymized for internal operations.
10. Changes to this policy
We may update this policy from time to time. When we do, we'll revise the "Last updated" date above, and for material changes we'll notify you by email or in-app.
11. Contact
Questions about this policy or your data? Contact Renderwise at admin@renderwise.net.