We read the threat. Never your life.
- Block scams, phishing & malware on your devices
- Scan new incoming email for threats (if you connect it)
- Explain every block in plain language
- Keep only sender / subject / verdict on flagged mail
- Encrypt everything, twice where it counts
- Sell your data — to anyone, ever
- Use your data for advertising
- Let humans read your email
- Train AI models on your content
- Scan your old email history
- Send email as you
1. Who we are & what this covers
Raptix AI (“Raptix,” “we,” “us”) is a veteran-built cybersecurity company. This policy covers our website, the Raptix console, the on-device protection agents, the browser extension, and the optional email connectors for Gmail and Outlook. It explains what we collect, why, where it goes, how long it lives, and the controls you have. If we change it, we update the date above and tell you in the app about anything material.
2. What we collect
- Account basics — your email address and, from your sign-in provider, your name and profile photo.
- Protection data — the links, domains, message text, or phone numbers you ask us to check (or that your device checks automatically), and the resulting threat verdicts.
- Device security posture — for enrolled devices: OS version, whether disk encryption and the firewall are on, and a protection score. We do not collect browsing history, files, keystrokes, or screen contents.
- Connected email (optional) — covered in detail in section 3.
- Waitlist / support — an email address you give us, used only to contact you about Raptix.
3. Google & Microsoft email data (Inbox Protection)
Connecting a mailbox is optional and off by default. If you connect Gmail or Outlook, here is exactly what happens — no more, no less:
- Minimum scope. We request only what the protection needs: Google's gmail.modify scope and Microsoft Graph Mail.ReadWrite — enough to read a new message and label, move, or quarantine it. We cannot send mail as you, and we never ask for broader access.
- Only new mail. Scanning starts at the moment you connect. We do not scan, import, or index the existing contents of your mailbox.
- Recognizing your contacts. To avoid over-flagging people you know, we read the recipient addresses of the mail you have sent (addresses only — never the contents of your sent mail) to build a private trusted-contacts list, used solely to reduce false alarms and never sold or used for advertising.
- What a scan looks at. The sender, the links, and the wording of each new message — to decide whether it is a scam, phishing, or safe.
- What we do about a threat. Dangerous mail is moved to a “Raptix Quarantine” folder/label so no one clicks it (only the account owner can release it); suspicious mail is labeled in place. If you accept a tidy-inbox suggestion, we create a folder and a native mail rule for a sender you choose.
- What we store. For a message we flag: the sender, subject, and verdict (with the plain-language reason). We do not persistently store message bodies or attachments. For volume statistics (the tidy-inbox feature), we store per-sender counts — never content.
- Revocation. Disconnect anytime in the Raptix console — we stop scanning, delete the stored connection, and revoke our own access. You can also revoke from your Google Account or Microsoft account settings.
What we access and the actions we take on your behalf: with your consent, Raptix accesses new incoming message content, headers, metadata, and labels/folders in the connected mailbox, and — solely to protect you — applies labels, moves messages (including to quarantine), and creates the mail filters/folders you approve. That is the complete list.
4. How our AI uses data
Raptix is AI-native: when something has never been seen before, our AI rules on it in milliseconds. Here is the fine print that makes that safe:
- Transient processing. To produce a verdict, content (a URL, message text, or email) is sent to our security models. Inference is performed by Anthropic (the Claude API), with Amazon Web Services (Amazon Bedrock) as a fallback provider. It is processed to answer one question — “is this dangerous?” — and is not retained by the model provider for training.
- No model training. Google user data (and all connected-mailbox data) is never used to create, train, or improve any AI or machine-learning model — including foundational or generalized models — and is never stored in conjunction with such models. The same is true for every other kind of data we process: your content trains nothing.
- What survives. The verdict (e.g., “this domain is a phishing site”) joins our threat database so every Raptix user is protected. The verdict contains the threat indicator (like a domain name) — not your identity, and not your content.
- No human review. No employee or contractor reads your messages, subject to only the four Limited Use exceptions listed above.
5. Sharing
We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising. We share data only with the service providers that run our platform under contract — principally Amazon Web Services (hosting, storage, and fallback AI inference) andAnthropic (the Claude API used for threat verdicts) — and when required by law (we review every demand and narrow it where we can). Threat indicators we compile (e.g., a malicious domain) are shared across the Raptix protection network without any tie to who encountered them.
6. Retention & deletion
| Data | Kept | Then |
|---|---|---|
| Email flag records (sender / subject / verdict) | 90 days | Auto-deleted |
| Mailbox connection (encrypted tokens) | Until you disconnect | Deleted immediately on disconnect |
| Per-sender volume counts (tidy inbox) | 60 days | Auto-deleted; removed on disconnect |
| Trusted-contacts list (addresses you have emailed, to cut false alarms) | ~13 months | Auto-deleted; removed on disconnect |
| Threat verdicts (indicators, no identity) | ~6 months if not re-seen | Auto-expired |
| Account data | Life of the account | Deleted on account deletion request |
To delete your account and its data, use the console or email privacy@raptix.ai. We honor verified requests within 30 days, subject to legal retention duties.
7. Security
- Encryption in transit (TLS 1.2+) and at rest, everywhere.
- Email access tokens are additionally envelope-encrypted (AES-256-GCM) on top of database encryption — a database copy alone can never yield a usable token.
- Least-privilege access: each system component can touch only what it needs; production access is gated by SSO with MFA.
- Rate limiting, monitoring, and annual third-party security assessment (CASA) for our Google integration.
8. Your rights & choices
Wherever you live, we extend the same rights: access a copy of your data, correct it, delete it, and take it with you. We do not sell or share personal information as defined by the California Consumer Privacy Act (as amended), so there is nothing to opt out of — but if that ever changed, we would give you the opt-out first. We honor Global Privacy Control signals. We will never discriminate against you for exercising any right. To exercise one, email privacy@raptix.ai — we verify, then act within 30 days.
9. Children & families
Raptix protects households, and that can include kids. Accounts are created and managed by an adult account owner; where a household member is a minor, the owner (a parent or guardian) consents to protection on their behalf and controls their settings. We collect from protected members only what the protection requires (threat checks and device posture — never browsing content), we tailor coaching by audience rather than profiling children, and we never sell or advertise with any family member's data. If you believe a child's data reached us outside these rules, contact us and we will delete it.
10. Contact
Raptix AI · Veteran-owned · Service-disabled veteran founded
Privacy: privacy@raptix.ai · Support: support@raptix.ai
Raptix AI, LLC · c/o Industrious, 1001 Liberty Ave, Floor 5, Pittsburgh, PA 15222