MailBond MailBond™
Home Features Pricing Security Request Demo

Privacy Policy

Last updated: September 10, 2026

MailBond LLC, a California limited liability company ("MailBond", "we", "us", "our"), operates the MailBond™ email security add-in for Microsoft Outlook and the website at mailbond.us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.

1. Information We Collect

Account Information: When you sign up or request a demo, we collect your name, work email address, company name, and number of users.

Email Analysis Data: When you use the MailBond add-in to scan an email, we process the currently selected email's headers, sender information, recipient address, subject line, URLs, attachment metadata, supported attachment content, screenshots, OCR text, and decoded QR/barcode payloads to perform security analysis. This request content is ephemeral: it is validated, analyzed, returned as a verdict, and destroyed. By default, production scan logs retain minimized metadata — timestamp, tier, risk score, primary risk reason, attachment count, sender and recipient domains, and available public sender mail-relay IP — for up to 90 days. An authorized tenant administrator may explicitly enable encrypted retention of full sender and recipient addresses for 7 or 30 days, extend unexpired records in 30-day increments, select one automatic extension, or select continuous retention capped at one year with annual reconfirmation. Subjects, URLs, attachment names and content, headers, screenshots, OCR text, and decoded QR/barcode payloads are never persisted in production scan logs.

Account and Seat Information: Customer and billing records, customer administrator contacts, and verified Microsoft identity information used for customer-scoped seat management are stored separately from scan content.

Usage Data: We collect scan counts, feature usage, and error logs to improve our service.

Payment Information: Billing is handled by Stripe. We do not store credit card numbers. Stripe's privacy policy governs payment data processing.

2. How We Use Your Information

  • To provide and maintain our email security analysis service
  • To detect and report phishing, BEC, QR-code phishing, image-only lures, look-alike domains, and other email-borne threats
  • To process your subscription and billing
  • To respond to your demo requests and support inquiries
  • To improve our threat detection algorithms and service reliability
  • To send service-related communications (e.g., billing confirmations, security alerts)

3. Data Retention

  • Request content: email bodies, supported attachment content, screenshots, OCR text, and decoded QR/barcode payloads are not persisted. They are processed for the scan and destroyed after analysis.
  • Minimized scan metadata: timestamp, tier, risk score, primary risk reason, attachment count, sender and recipient domains, and available public sender mail-relay IP are retained for up to 90 days to power dashboard, audit-log, scan-history, and customer-export features.
  • Optional full addresses: an authorized tenant administrator may enable encrypted sender and recipient address retention for 7 or 30 days. Unexpired records may be extended manually by 30 days, once automatically, or continuously up to one year with annual reconfirmation. Expired addresses are permanently removed from the database. Disabling full-address retention immediately scrubs retained full addresses while domain metadata may remain for the standard event-retention period.
  • Message-specific details: subjects, URLs, attachment names and content, headers, screenshots, OCR text, and decoded QR/barcode payloads are not persisted in production scan logs.
  • Customer exports: authorized customer administrators can export scan history before the 90-day retention window expires.
  • Customer and seat records: verified Microsoft identity information used for customer-scoped licensing is retained while the customer account or seat remains active and can be removed by an authorized administrator.
  • Account & billing records: retained while your account is active and for up to 30 days after cancellation, after which personal data is deleted. Billing records required by law (e.g., tax records) are retained by Stripe per their policies.

You can request earlier deletion of your scan history at any time by contacting admin@mailbond.us.

4. Data Sharing

We do not sell your personal information. We share data only with:

  • Google Web Risk: URLs extracted from emails, discovered by OCR, or decoded from QR/barcodes are checked against Google's threat databases. We do not send email bodies, attachments, screenshots, or customer identifiers to Google Web Risk.
  • PhishTank: URLs extracted from emails, discovered by OCR, or decoded from QR/barcodes may be checked against PhishTank's crowdsourced phishing database. We do not send email bodies, attachments, screenshots, or customer identifiers to PhishTank.
  • IPWho: When an authorized tenant administrator loads approximate sender location in the dashboard, MailBond sends only the validated public sender mail-relay IP for approximate city, region, country, and network lookup. VPNs, proxies, forwarding, and mail relays can obscure the original source.
  • Stripe: For payment processing
  • Microsoft Entra ID / Microsoft identity services: For required Office SSO on Outlook browser requests and Microsoft sign-in to the customer dashboard. We do not maintain separate MailBond user or dashboard passwords.
  • Microsoft Azure: Our infrastructure provider, bound by their data processing agreements

5. Data Security

We use industry-standard security measures including TLS 1.2+ encryption in transit, encrypted storage at rest, validated Microsoft Office SSO for browser requests, hash-only credentials for explicitly authorized machine integrations, private Key Vault and backup-storage endpoints, managed-identity backup access, isolated non-root rendering, and role-based administrative access controls. MailBond is currently undergoing a SOC 2 audit. MailBond is hosted on Microsoft Azure, whose independent compliance reports and certifications cover the infrastructure and platform services we use.

6. Microsoft Outlook Add-in Permissions

MailBond requests ReadItem permission only — the minimum permission required to analyze the currently open email. We cannot modify, delete, or send emails on your behalf, and we cannot browse other mailbox items.

7. Cookies

Our website uses minimal cookies:

  • Essential cookies: Required for basic website functionality
  • Analytics cookies: We may use privacy-respecting analytics to understand website traffic. No personal data is shared with third-party advertisers.

You can control cookies through your browser settings. Disabling cookies may affect website functionality.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing
  • Data portability

To exercise these rights, contact us at admin@mailbond.us.

9. Children's Privacy

MailBond is a business product not directed at individuals under 16. We do not knowingly collect data from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of our services after changes constitutes acceptance.

11. Contact Us

If you have questions about this Privacy Policy, please contact:

MailBond LLC
100 W High St, PO Box 1153
Moorpark, CA 93020
Privacy: privacy@mailbond.us
General: admin@mailbond.us
Website: mailbond.us

© 2026 MailBond LLC. MailBond™ is a trademark of MailBond LLC. USPTO Serial No. 99836871. All rights reserved. · EULA / Terms · Privacy Policy · Security