Privacy Policy
1. Overview and our approach
This Privacy Policy explains how LureSight LLC (“we,” “us,” “our”) handles information in connection with the LureSight software — the Outlook add-in, the web-based email scanner, and the community service and public dashboard (together, the “Software”). It applies to information processed through the Software and should be read with the End User License Agreement.
LureSight is designed to be privacy-protective by default. It analyzes email where you already read it, keeps message content on your device wherever possible, collects no account or identity information to operate, and shares data with us only when you actively choose to submit a community report.
2. The short version
What we collect
To run the scan: nothing is sent to us. Analysis happens on your device.
Only if you choose to submit a community report: a scrubbed, non-identifying record of a suspected phishing message (details in Section 4).
Basic, non-identifying operational data our servers may log to keep the community service running and secure (Section 6).
What we never collect
Your name, email address, or account credentials
Who received the email (you, colleagues, or CC lists)
Attachments or embedded files from your messages
Email addresses, phone numbers, or personal names left intact in
message text
Your organization's identity
Any identifier that links a community submission back to
you
3. Information processed on your device (not sent to us)
When you scan a message — in the Outlook add-in or the web scanner — the Software reads the message's content and headers and, for image-only messages, may run optical character recognition (OCR) to read text inside an image. This processing happens locally, in the add-in or in your browser. The message and any file you scan are not transmitted to us as part of the scan. Results are shown to you and are not retained by us.
Report to security. If you use the “Report to security” feature, the Software helps you send the message to a reporting address that you or your organization configure. That message goes to the address you choose — typically your own security team — and is not sent to us.
4. Information you choose to submit to the community service
Community submission is optional and off by default. It requires a one-time consent, and each submission asks you to label the message (“phishing” or “false alarm”). When you submit, the Software first removes personal information on your device, and our server removes it again on receipt (“scrub twice”). A submission includes:
the suspected sender's domain (for example, “paypa1-secure.com”);
the destination web addresses (URLs) of links in the message, including the true destination behind any security-gateway rewrapping, with any email address embedded in a link replaced by “[email]”;
the detection findings — the categories, severities, and plain-language reasons the Software generated;
the message subject and a short body excerpt, with email addresses replaced by “[email]”, phone numbers by “[number]”, and personal names by “[name]”;
the authentication results (SPF, DKIM, DMARC outcomes); and
the risk score, verdict, and the label you selected.
A submission does not include your name or email address, the recipients, attachments, embedded files, your organization's identity, or any identifier that could link the submission to you.
What scrubbing can and cannot promise. Removal is automatic and runs twice — once on your device and again on our server — and it reliably catches email addresses, telephone numbers, and personal names in greetings and sign-offs. It is pattern-based, so we cannot guarantee that every personal detail buried in a message body is caught. We therefore describe submissions as scrubbed and non-identifying rather than anonymous: we hold no identifier linking a report to you, but residual personal data may survive in message text. Please do not submit a message whose contents are especially sensitive.
Information about other people. A reported phishing message may contain personal data about people other than you — typically the sender, or someone named in the message. We keep this only to the extent it is part of the threat itself, apply the same scrubbing to it, never use it to contact or profile anyone, and delete it on the retention schedule in Section 8. Our lawful basis for this limited processing is described in Section 7.
Purpose. We use submissions to improve detection accuracy (including training the community model) and to produce aggregate threat statistics shown on the public dashboard.
5. Public dashboard
The public dashboard shows aggregate statistics only — counts and trends such as common attack methods, frequently reported sender and link domains, authentication-failure rates, and volumes over time. It does not publish message content, and the domains it lists are report counts, not accusations. Aggregated information cannot reasonably be used to identify you.
6. Operational data and security logging
To operate the community service reliably and protect it from abuse, our servers may process limited technical data such as timestamps and error logs. For rate-limiting we hold only a salted, irreversible hash of the network address, kept in memory and discarded when the service restarts; we do not write visitor IP addresses to disk. This data is used for security, abuse-prevention, and reliability, is kept to the minimum necessary, and is not used to build profiles of individuals. We apply reasonable technical and organizational measures to protect the information we hold; however, no method of transmission or storage is completely secure.
7. Legal bases for processing (EEA / UK)
Where the EU or UK General Data Protection Regulation applies, and to the extent any information we process is personal data, we rely on: your consent for community submissions, which you may decline; and our legitimate interests in operating, securing, and improving the Software and protecting users from phishing, balanced against your rights, for limited operational and security data and for any personal data of third parties contained in a reported message. Processing personal data to the extent strictly necessary for network and information security is expressly recognised as a legitimate interest (GDPR Recital 49), and a reported phishing message is precisely such a security record. Where we rely on consent, you may withdraw it at any time by ceasing to submit; because submissions carry no identifier linking them to you, withdrawal cannot retroactively single out reports you already sent.
8. Data retention
We retain community submissions for 24 months. Deletion is automatic rather than discretionary: the service removes expired submissions, and their associated findings and links, when it starts and once every day thereafter. Aggregate statistics and trained models are derived from submissions but contain no message content and do not identify individuals; these may be kept indefinitely, so deleting the underlying reports does not degrade detection. Encrypted backups are rotated weekly, so a deleted submission may persist in a backup copy for up to seven further days. Operational logs are kept only as long as needed for their purpose.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, to portability, and to lodge a complaint with a supervisory authority. To exercise rights, contact us at legal@luresight.com.
An honest limitation on access and deletion
Community submissions are unlinkable to you by construction — we deliberately collect no identifier that links a submission to you. As a result, we generally cannot locate or single out your particular submission to retrieve or delete it, because we have no way to tell which record came from you. This is a privacy feature, not an evasion: there is simply nothing tying the data to your identity. Where a controller cannot identify a data subject, the GDPR does not require it to collect extra information purely to enable identification (Article 11) — and collecting that information is exactly what we have chosen not to do. We remain able to act on operational data where it is linkable, and we honor rights requests to the extent technically possible.
10. Children
The Software is intended for use by adults in a workplace or personal email context and is not directed to children. We do not knowingly collect personal data from children under the age of 16 (or the age set by local law). If you believe a child has provided personal data, contact us and we will take appropriate steps.
11. International transfers
The community service is operated from the United States, so information you choose to submit is processed there. Where required, we use appropriate safeguards (such as standard contractual clauses) for cross-border transfers of personal data.
12. Third-party components and services
The Software uses third-party open-source components (for example, DOMPurify, Tesseract.js, and Chart.js). Some may be delivered to your browser from a content-delivery network when you use the web features; that request is handled by the delivery provider under its own terms. These components run in your browser and do not receive your message content from us. If you deploy the Software yourself, you are responsible for the components and infrastructure you choose.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new effective date and, where required, provide additional notice. Your continued use after an update takes effect constitutes acceptance to the extent permitted by law.
14. Contact us
For privacy questions or to exercise your rights: LureSight LLC, 502 W 7th St, Ste 100, Erie, PA 16502, legal@luresight.com, https://luresight.com. LureSight LLC is the data controller for information processed through the community service.
← Back to LureSight