Privacy Policy

How SavvyShield handles your information

Last updated: October 2, 2026

The short version

  • We don’t sell personal information, and we don’t share it for targeted advertising.
  • We don’t use data from the SavvyShield service for advertising or marketing.
  • The browser extension checks links you click to other websites. It sends the link address, the address of the page you’re on, and the link’s text. It never sends what you type into forms, your passwords or your cookies.
  • Administrators can turn on link-only mode, which sends even less: just the link and a masked page address.
  • Scans are analyzed by an AI provider. We keep only a redacted copy, and we delete it after 90 days.
  • The AI providers we use aren’t allowed to train their models on your data.
  • If you use SavvyShield through your employer, your employer controls your data and decides how it’s used.

1. Who we are and what this policy covers

SavvyShield Inc. (“SavvyShield,” “we,” “us”) is a Delaware corporation. This policy explains how we handle personal information in:

  • our website, savvyshield.com;
  • the SavvyShield browser extension for Chrome, Edge and Firefox;
  • the user portal (portal.savvyshield.com) and admin portal (admin.savvyshield.com);
  • the SavvyShield Outlook add-in; and
  • the emails we send, including simulated phishing emails.

We call the extension, portals, add-in and related emails “the Service.” Sections 3 to 9 describe the Service. Section 10 describes the website. The rest applies to both.

2. Business accounts and personal accounts

Business accounts

When an organization buys SavvyShield for its people, the organization controls the personal information in its account. We process that information on the organization’s behalf, following its instructions and our agreement with it. (Under privacy laws such as the GDPR, the organization is the “controller” and we are its “processor” or “service provider.”)

The organization’s administrators decide which features are on (automatic link checks, simulations, training, research), which settings apply, and what they do with the results. If you use SavvyShield through your employer, your employer’s own privacy notice also applies, and you should send privacy requests to your employer. If you contact us instead, we’ll pass your request to your organization and help it respond.

Personal accounts

When you buy SavvyShield for yourself or your household, we are responsible for your personal information as its controller.

Our website and customer relationships

We are also the controller for information about website visitors, people who contact us, and the billing and administrative contacts of our customers.

Part A: The SavvyShield Service

3. Account information

  • Profile: your name, email address, preferred language, role (user, admin or owner) and the labels or groups you belong to.
  • Directory details: your job title, department and any other attributes your administrator enters or syncs from your organization’s identity provider (for example Okta or Microsoft Entra ID) through single sign-on (SAML) or SCIM provisioning.
  • Sign-in: sign-in is handled by Google Firebase Authentication and Google Identity Platform. If you use a password, Google stores it in hashed form and we never see it. If you use single sign-on, we receive the identity details your identity provider sends.
  • Billing: payments are handled by Stripe. We never receive your full card number. We keep the plan, seat count, billing status, Stripe customer ID and billing contact email.
  • Support: what you tell us when you contact support.

4. What the browser extension sends

4.1 Automatic link checks

The extension checks a link before it opens when:

  • you click a link that goes to a different website from the one you’re on; or
  • a link opens in a new tab from outside the browser, for example from an email app, chat app or document.

For each check, the extension sends:

  • the address (URL) of the link;
  • the address of the page you’re on, and of the frame inside the page if the link is in one;
  • the text of the link; and
  • your language, so the result is written in it.

It does not send the content of the page, anything you type into forms, passwords, cookies or your browsing history. Links within the same website aren’t checked, and neither are file downloads. The extension never checks SavvyShield’s own sites or sites your organization has excluded, and it doesn’t run in incognito or private windows unless you allow that in your browser settings. Your organization’s administrators can turn automatic link checks off.

4.2 Scans you ask for

When you right-click and choose Scan, the extension sends what you chose, along with the address of the page you’re on:

  • for a link, the link address;
  • for selected text, that text;
  • for an image, the image and its address;
  • for anything else on the page, the HTML markup of the element you clicked. Anything typed into form fields is removed first, and the markup is limited in size. If you right-click inside an email open in your browser, this can include part of that email.

4.3 Link-only mode

Administrators can turn on Limit scan context to link only. It’s off by default because it can make detection less accurate. With it on:

  • automatic link checks send only the link address and the page address, and the page address has its query values masked (for example, ?id=12345 becomes ?id=[redacted]);
  • right-click scans send only the item you chose: the link, the selected text, the image or the page address; and
  • element markup, link text and frame addresses are never sent.

4.4 Stored on your device

The extension stores your settings, your organization’s policy, your sign-in session and the results of your last 50 scans (so the same link isn’t sent twice) in your browser. This is removed when you uninstall the extension.

4.5 Simulations in the browser

If your organization uses browser simulations, the extension may show you a simulated threat, such as a fake sign-in prompt. It records whether you reported it, interacted with it or ignored it, and when. Anything you type into a simulation is never recorded or sent.

5. How scans are analyzed and stored

  • Analysis: each scan goes to our scan servers and then to Google’s Gemini API, which analyzes it for signs of phishing and social engineering. The AI receives the information described in section 4. Requests go to the scan server nearest you: in the United States, Poland or Singapore, chosen from your device’s time zone.
  • What we keep: we store a redacted copy of each scan with its result. Query values and anything that looks like a token are masked, typed values are removed, text and markup are shortened, and images are dropped. Results are also cached for your organization so the same link isn’t analyzed twice. Both are deleted after 90 days.
  • Detections: when a scan is flagged, we record the threat type, when it happened, whether you went ahead or turned back, and any feedback you give. This record contains no page content. It appears in your detection history and your organization’s reports, and we keep it for as long as the account is active.
  • Alerts: if your organization turns on security alerts, the people it chooses get an email with your name, your email address, the threat type and the time. The alert doesn’t include the link.

6. Simulations, training and the Savvy Score

  • Email simulations: we send simulated phishing emails to your work email address through Twilio SendGrid. Each link carries a unique code, and we record when the email was sent and whether and when you clicked or reported it. Simulated emails don’t contain tracking pixels, and we never collect passwords or anything typed on a simulation page.
  • Outlook add-in: when you report an email, the add-in sends its sender, subject, received time and message IDs, not the body. Reports of real (non-simulated) emails are kept for your security team to review.
  • Training: we record which trainings you’re assigned, your progress, your answers and when you finish. Training videos are streamed from our video host, bunny.net, which receives your IP address and browser details when a video plays.
  • Savvy Score: we calculate a score from your simulation results, training and how you respond to detected threats. Your administrators can see your score and results. People in your organization can see your name and points on the leaderboard. SavvyShield doesn’t make employment decisions; your organization decides how it uses scores.
  • Reports: administrators can have weekly or monthly reports emailed to people they choose. Reports can include users’ names, scores and results.
  • Industry benchmarks: we combine scores across organizations into anonymized averages so customers can compare themselves with their industry. No person or organization can be identified from them.

7. AI-generated content and research

SavvyShield uses AI to write trainings, simulations and simulated emails that fit your organization.

Organization and department research

Administrators can ask SavvyShield to research their organization or its departments. We send the company name, website domains, industry, location, department details and the administrator’s notes to Anthropic, whose AI searches the public web and writes a summary used to make simulations realistic.

Research uses only publicly available information. We never access private accounts or non-public sources. Reports are stored in the organization’s account and are visible to its administrators. Simulations built from them may use the real names of the organization’s executives or employees as the apparent sender. A report is deleted when an administrator deletes it or when the account closes.

Training and simulation content

To write a training about a specific detection or simulation, we send OpenAI the threat type and the redacted details of that event. To write simulations and simulated emails, we send Anthropic the organization and department research and the settings administrators chose.

8. AI providers and automated decisions

  • Google (Gemini API): analyzing scans.
  • OpenAI: writing training content.
  • Anthropic: writing simulations and simulated emails, and doing research with web search.

We use each provider’s business API. Under our agreements, these providers can’t use your data to train their models. They may keep requests for a limited time to detect abuse, as their terms allow, and then delete them.

Scan results are automated: the AI decides whether a link looks dangerous. A flagged result only warns you, and you can always choose to continue. SavvyShield doesn’t make decisions that have legal or similarly significant effects on you.

9. How we use information from the Service

We use it to:

  • protect you, and run the simulations, training, scores and reports your account uses;
  • manage accounts, billing and support;
  • keep the Service secure and prevent abuse and fraud;
  • find and fix problems and improve detection accuracy, using redacted scan records and the feedback you give us;
  • send emails about the Service: invitations, password resets, alerts, reminders, reports and, for account owners and administrators, product updates (each product update email has an unsubscribe link); and
  • meet legal obligations.

We don’t:

  • sell personal information or share it for targeted (cross-context behavioral) advertising;
  • use data from the Service for advertising, or to market to the users of business accounts;
  • train AI models on your data, or let our AI providers do so;
  • use data from the Service to decide creditworthiness or for lending; or
  • let our staff read your scan data except when you or your organization ask for help, when we need to for security, or when the law requires it.

Part B: Our website

10. Our website

Information you give us

  • Contact form: name, email address and message.
  • Newsletter: email address.
  • Webinar registrations and recording requests: first and last name, email address, company and job title. We use Twilio SendGrid to send calendar invitations and webinar links.
  • Risk assessment requests: name, email address, company, team size and any notes.
  • Cyber Savviness quiz: your answers stay in your browser. If you create a comparison challenge, we store your email address, the challenge title, your score, which questions you got right, and whether you agreed to hear from us. People who take your challenge are anonymous: we store only their score and which questions they got right.

Form submissions are emailed to our team through Google Workspace. To block spam, forms include a hidden field and measure how fast they’re filled in. Submissions that look automated are kept so we can recover any real ones that were blocked by mistake.

Analytics and cookies

We use Microsoft Clarity to understand how visitors use the website. Clarity records clicks, scrolling, mouse movement, the pages you view, your device and browser, and your approximate location, and makes session recordings with form fields and page text masked. It uses cookies (such as _clck and _clsk). Where the law requires consent (for example in the EEA, the UK and Switzerland), we load Clarity only after you accept analytics cookies. Anyone can change their choice with Cookie settings at the bottom of the page. See Microsoft’s privacy statement for how Microsoft handles this data.

Videos on the website are streamed from bunny.net, which receives your IP address and browser details when a video plays. We also count quiz and demo events in anonymous daily totals that contain no identifiers, and the site uses your browser’s session storage to remember quiz progress. We don’t use advertising pixels or retargeting.

How we use website information

We use it to answer you, run webinars, send the newsletters and webinar recordings you asked for (you can unsubscribe from any of them with the link in the email) and understand how the website is used. Calendar invitations, updates and join links for a webinar you registered for are part of that registration.

Part C: For everyone

11. Who we share information with

  • Service providers that host, run or support SavvyShield for us, under contracts that limit their use of the data to providing those services. They’re listed on our Subprocessors page.
  • Your organization, for business accounts, as described in this policy.
  • Legal reasons: when the law requires it, or to protect the rights, property or safety of our customers, our users, the public or SavvyShield.
  • Business transfers: if SavvyShield is involved in a merger, acquisition or sale of assets, under terms that keep this policy’s protections in place.
  • With your permission, for any other purpose.

We have not sold personal information or shared it for targeted advertising, and we don’t.

12. Where information is stored and processed

Our database is Google Cloud Firestore in the United States. Scan requests are handled by servers in the United States, Poland or Singapore, depending on your time zone, and our AI and email providers process data mainly in the United States. Videos are streamed from bunny.net’s worldwide network. When personal information from the EEA, the UK or Switzerland is transferred to the United States, it’s protected by the Standard Contractual Clauses (and the UK Addendum) in our agreements with these providers.

13. How long we keep information

  • Redacted scan records and cached results: 90 days.
  • Detections, simulation results, training records and Savvy Score history: for as long as the account is active.
  • Organization and department research reports: until an administrator deletes them or the account closes.
  • Removed users: when an administrator removes a user, or the identity provider deprovisions them through SCIM, we delete that user’s personal information within 30 days. We keep a de-identified record of their activity, for example that a former member failed a simulation on a given date, so the organization’s trends stay accurate. It has no name, email address, department or content, and isn’t linked to the person’s account. We keep it until the organization asks us to delete it.
  • Closed accounts: when a subscription ends and isn’t renewed, we delete the account’s data within 90 days. We keep only organization-level monthly totals, such as how many simulations were reported, which contain no information about individuals, until the organization asks us to delete them.
  • Billing records: as long as tax and accounting law requires.
  • Server logs, which include IP addresses: up to 30 days.
  • Website form submissions: until you ask us to delete them, or we no longer need them to respond to you or send what you signed up for.
  • Data in the extension: until you uninstall it.

14. Security

  • Data is encrypted in transit (TLS) and at rest on Google Cloud.
  • Access is limited by role, for customers and for our staff.
  • Business accounts can use single sign-on (SAML) and SCIM provisioning; multi-factor authentication is available.
  • Scan content is redacted before it’s stored and deleted after 90 days.
  • Administrative actions are recorded in an audit log.

No system is perfectly secure. If a breach affects your personal information, we’ll notify the affected customers and individuals as the law requires.

15. Your rights and choices

If you use SavvyShield through your employer, contact your organization’s administrator first; it controls your data. We’ll help it respond. After you’re removed from an organization, your activity is kept only in de-identified form (see section 13), which we can no longer connect to you.

Everyone else, and anyone with a question about how we handle data, can email privacy@savvyshield.com. Depending on where you live, you may have the right to:

  • see the personal information we hold about you and get a copy of it;
  • correct it;
  • have it deleted;
  • object to or limit how we use it;
  • withdraw consent you gave us; and
  • stop marketing emails at any time, using the unsubscribe link or by emailing us.

We’ll confirm your identity, usually by writing to the email address on your account, and respond within 30 days (or within the time your law allows, letting you know if we need longer). You can use an authorized agent. We won’t treat you differently for using your rights. If we turn down your request, you can appeal by replying to our decision.

EEA, UK and Switzerland

We rely on these legal bases:

  • Contract: to provide the Service and manage your account;
  • Legitimate interests: to keep the Service secure, prevent fraud, improve the Service and communicate with business contacts;
  • Consent: for website analytics and newsletters where the law requires it; and
  • Legal obligation: for tax, accounting and legal requests.

For business accounts, your organization decides the legal basis for its use of the Service. You can complain to your local data protection authority.

California and other US states

In the last 12 months we have collected these categories of personal information:

  • Identifiers: name, email address and account IDs.
  • Customer records: billing contact and plan details.
  • Commercial information: plans and seats purchased.
  • Internet activity: link and page addresses and the other scan content described in section 4, and how you use our website.
  • Professional information: job title and department.
  • Inferences: the Savvy Score and risk groupings.
  • Sensitive information: account sign-in details, used only to sign you in.

We get this information from you, from your organization and its identity provider, from your device, and, for organization research, from public web sources. We use it for the purposes in sections 9 and 10, and we disclose it only to the service providers and others listed in section 11. We have not sold or shared personal information, including that of anyone under 16.

16. Children

SavvyShield is built for workplaces and adults. You must be 18 or older to hold a personal account. The Service isn’t directed to children under 13, and we don’t knowingly collect their personal information. Please don’t install the extension on a device used by a child under 13. If you think we have information about a child under 13, email privacy@savvyshield.com and we’ll delete it.

17. Browser extension stores

The extension uses the data described in this policy only to provide its single purpose: protecting you from phishing and online threats, and delivering your organization’s simulations and training. The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

18. Changes to this policy

When we update this policy, we’ll change the date at the top. If a change is significant, we’ll email account owners before it takes effect.

19. Contact us

SavvyShield Inc.
Attn: Privacy
501 Hunter Ln Exd
Santa Rosa, CA 95404
United States
privacy@savvyshield.com
(707) 481-2437