Privacy Policy

Sentinel - AI-Powered Phishing Detection

🔒 GDPR Compliant

Last updated: February 3, 2026

1. Introduction

Welcome to Sentinel ("we", "our", "us"). We are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, and protect your information when you use our browser extension for AI-powered phishing detection.

Sentinel is operated by Explore Nebula. As the data controller, we determine the purposes and means of processing your personal data in compliance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and other applicable data protection laws.

🔒 Our Core Privacy Principle: Your email content is NEVER stored. We process emails in memory only for real-time phishing analysis, and all content is immediately discarded after the scan is complete.

2. What Data We Collect

2.1 Account Information (Optional)

When you create an account, we collect:

2.2 Anonymous Usage (For Non-Registered Users)

If you use Sentinel without an account, we collect:

This fingerprint does not identify you personally and is used only to enforce the anonymous limit of 3 one-time scans. Registered users receive 10 scans per month.

2.3 Email Content (Temporary Processing with PII Masking)

When you scan an email, we temporarily process:

🔒 Enhanced Privacy Protection: Before sending data to AI for analysis, we automatically mask all personally identifiable information (PII):

  • Email addresses → Replaced with [EMAIL_MASKED]
  • Names in signatures → Replaced with [NAME_MASKED]
  • Phone numbers → Replaced with [PHONE_MASKED]
  • Email signatures → Automatically removed

â„šī¸ Important: After PII masking, data is processed in memory only and is immediately discarded after the AI analysis is complete. We do NOT:

  • Store email content in any database
  • Log email content in server logs
  • Use email content for any purpose other than phishing detection
  • Send unmasked personal data to AI services

2.4 Subscription Data

When you subscribe to Premium, we store:

We do NOT store your payment card details. All payments are processed securely by Stripe.

3. How We Use Your Data

Purpose Data Used Legal Basis
User authentication Email, password Contract performance
Phishing detection Email content (temporary) Explicit consent
Scan limit enforcement Browser fingerprint, scan count Legitimate interest
Subscription management User ID, subscription data Contract performance
Payment processing Transaction data Contract performance

4. Data Processors (Sub-processors)

We use the following third-party services to provide our service:

4.1 Microsoft Azure OpenAI (AI Analysis - EU Region)

✅ GDPR-Compliant AI Processing:

  • PII Masking: All personal data is masked BEFORE being sent to AI
  • EU Processing: Data is processed exclusively in European Union data centers
  • No Storage: Azure OpenAI does not store your data after analysis
  • Classification Only: AI is used solely for phishing classification, not profiling or other purposes
  • Transfer Impact Assessment (TIA): We have conducted a full TIA documenting GDPR compliance

4.2 Supabase (Authentication & Database)

4.3 Stripe (Payment Processing)

5. Data Minimization & Privacy by Design

We follow the principle of data minimization as required by GDPR Article 5(1)(c) and Privacy by Design (Article 25):

5.1 Pre-Processing (Before AI Analysis)

5.2 Additional Protections

6. Data Retention

Data Type Retention Period
Email content 0 seconds - Immediately discarded after analysis
Account information Until account deletion or 3 years of inactivity
Browser fingerprint Reset monthly, deleted after 6 months of inactivity
Subscription records Duration of subscription + 7 years (legal requirement)
GDPR consent records Duration of account + 3 years

7. Your Rights Under GDPR

As a data subject, you have the following rights:

7.1 Right of Access (Article 15)

You can request a copy of all personal data we hold about you.

7.2 Right to Rectification (Article 16)

You can request correction of inaccurate personal data.

7.3 Right to Erasure / "Right to be Forgotten" (Article 17)

You can request deletion of your account and all associated data. This can be done directly through the extension or by contacting us.

7.4 Right to Data Portability (Article 20)

You can request your data in a machine-readable format.

7.5 Right to Object (Article 21)

You can object to processing based on legitimate interest.

7.6 Right to Withdraw Consent (Article 7)

You can withdraw your consent at any time. This does not affect the lawfulness of processing based on consent before withdrawal.

📧 To exercise any of these rights: Contact us at info@explorenebula.com. We will respond within 30 days as required by GDPR.

8. International Data Transfers

EU Data Processing: We use Microsoft Azure OpenAI with data centers located in the European Union (Sweden Central or France Central). This ensures that your email data (already masked) is processed within the EU and benefits from GDPR protections.

8.1 Safeguards for International Transfers

For any data that may be transferred outside the EEA (such as account data to US-based services), we ensure appropriate safeguards:

8.2 Schrems II Compliance

Following the Schrems II ruling (CJEU Case C-311/18), we have:

9. Security Measures

We implement appropriate technical and organizational measures to protect your data:

10. Refund Policy (Digital Services)

Sentinel provides digital content and services that are delivered immediately upon subscription. In accordance with EU Consumer Rights Directive 2011/83/EU and Italian Legislative Decree 206/2005 (Consumer Code), the following refund policy applies:

10.1 No Refunds for Digital Services

By subscribing to Sentinel Premium, you explicitly agree to the following:

10.2 Legal Basis (EU & Italian Law)

Under Article 16(m) of the EU Consumer Rights Directive 2011/83/EU and Article 59, paragraph 1, letter o) of the Italian Consumer Code (Legislative Decree 206/2005), the right of withdrawal does NOT apply to:

"The supply of digital content which is not supplied on a tangible medium if the performance has begun with the consumer's prior express consent and his acknowledgment that he thereby loses his right of withdrawal."

By completing your subscription purchase, you provide this explicit consent and acknowledgment.

10.3 Cancellation Policy

While we do not offer refunds, you may cancel your subscription at any time:

10.4 Service Issues

If you experience technical issues preventing service use:

10.5 Exceptions

Refunds may be issued only in the following cases:

Claims must be submitted within 30 days of the charge with supporting documentation.

10.6 Free Trial Policy

We encourage users to:

âš ī¸ Important: By clicking "Subscribe" or "Unlock Premium", you confirm that:

  • You have read and understood this Refund Policy
  • You agree to immediate access to the digital service
  • You waive your 14-day right of withdrawal
  • You accept that no refunds will be provided

11. Children's Privacy

Sentinel is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

13. Supervisory Authority

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection supervisory authority. For users in Italy, this is the Garante per la protezione dei dati personali (garanteprivacy.it).

14. Dispute Resolution

For users in the European Union and Italy:

đŸ“Ŧ Contact Us

For any questions, concerns, or requests regarding your privacy or this policy:

info@explorenebula.com

We typically respond within 48 hours for general inquiries
and within 30 days for GDPR-related requests.