doorcheck
Why DoorcheckHow it worksWho it's forSign in
EN
🇺🇸English🇸🇦العربية🇪🇸Español🇫🇷Français🇩🇪Deutsch🇵🇹Português🇮🇹Italiano🇨🇳中文
Get early access →
Legal

Privacy Policy

Last updated: September 1, 2026

Doorcheck (“we”, “us”) provides email-security scanning for mailboxes that an administrator or mailbox owner explicitly connects. This policy explains what data we access, why, how we use it, and the controls you have. We act as a data processor on behalf of the organization that connects its mailboxes.

Information we access

When you connect a Microsoft 365, Google Workspace, Exchange on-premise, cPanel, or IMAP mailbox, you grant Doorcheck access to:

  • Message content and metadata — headers, sender/recipient, subject, body and attachments — which we read to compute a security verdict (phishing / spam / legitimate).
  • Mailbox and directory listing — the set of mailboxes in the organization — used only to build the protected-mailbox inventory.
  • Sign-in activity (where the provider exposes it) — used to detect account-takeover signals such as impossible-travel and password-spray.
  • Connected OAuth applications — the third-party apps with access to the tenant — used for the security-posture review.

How we use it

Message data is used solely to detect and act on email threats for the connecting organization: scoring messages, quarantining or filing suspicious mail (only in enforce mode, and only into a folder — we never send mail as you), producing the operator dashboards, and generating the protection reports your users receive. We do not use your data for advertising, and we do not sell it.

AI processing

Most mail is decided by our own rules and statistical models. Only the small fraction of borderline messages the free layers cannot classify is sent to a large-language-model provider for a verdict, and only the text needed for that decision. Operators may configure a self-hosted model so that no message content leaves their own infrastructure at all. When a cloud LLM is used, the provider processes the content transiently to return a verdict and is contractually barred from training on or retaining it.

Google API Services — Limited Use

Doorcheck’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the email-security features you connected; we do not transfer it to others except as necessary to provide those features, to comply with applicable law, or as part of a merger with your consent; we do not use it for advertising; and no humans read it except with your explicit consent, for security or to comply with law, or on data that has been aggregated and anonymized.

Data protection and security

We treat all mailbox content — including sensitive and restricted-scope data such as Gmail message bodies, attachments, and directory information — as confidential, and protect it with the following mechanisms:

  • Encryption in transit. All data moving between Doorcheck and mail providers (Google, Microsoft, IMAP), between Doorcheck and your browser, and between our internal services travels over TLS 1.2 or higher. We do not accept unencrypted connections.
  • Encryption at rest. OAuth refresh tokens and provider API keys — the credentials that could access your mailboxes — are encrypted with AES-256-GCM; the encryption key is held separately from the data it protects and is never stored alongside the ciphertext or written to logs. We do not retain the raw content of scanned mail: only verdict metadata (sender, subject, score, category, timestamps) is kept, and the body of a quarantined message is held only until it is released and is purged automatically (30 days by default).
  • Least-privilege access. Doorcheck requests only the minimum OAuth scopes required for the features you enable, and reads content only to compute a security verdict. We never send mail as you; enforcement is limited to moving a message into a folder.
  • Tenant isolation. Each connected organization’s data is logically segregated and is only accessible to operators that organization has explicitly granted access to.
  • Operator account security. Operator accounts support two-factor authentication (TOTP), enforce role-based access control, expire idle sessions, and can be revoked at any time. Every privileged action (quarantine, release, delete, configuration change) is recorded in an immutable audit log.
  • Data minimization. Only the small fraction of borderline messages that our own models cannot classify is sent to a language-model provider, and only the minimum text needed for a verdict. Operators may run a self-hosted model so that no content leaves their own infrastructure at all.
  • Secrets handling. Credentials and message content are never written to application logs. Access to production systems is restricted to authorized personnel and is not used to read customer content except with your explicit consent, for security, or to comply with law.
  • Deletion on disconnect. Disconnecting a mailbox revokes our access, and associated message data is deleted (see below).

Data storage and retention

Verdict metadata (sender, subject, score, category, timestamps) is retained to power dashboards and reports. The raw body of a quarantined message is stored only as long as needed to release it, and is purged automatically (30 days by default). OAuth refresh tokens and API keys are encrypted at rest with AES-256-GCM. Data is stored on the infrastructure the operator deploys to; self-hosted deployments keep all data within the operator’s own environment.

Sharing

We share data only with the sub-processors an operator explicitly configures (for example, a chosen LLM provider, a SIEM destination, or reputation lookups), each used strictly to deliver the security features. We do not share data with advertisers or data brokers.

Your controls

An administrator can disconnect a mailbox at any time, which revokes our access. On disconnection or account deletion, associated message data is deleted. To request access to, correction of, or deletion of data, contact us at the address below.

Early-access list and communications

If you request early access on our website, we store the email address you submit and use it solely to contact you about your beta seat, Doorcheck availability, and onboarding. We do not add it to third-party marketing lists or share it with anyone. Every such email includes an unsubscribe option, and you can ask us to delete your address at any time using the contact below.

Contact

Questions about this policy or your data: privacy@doorcheck.io. Security reports: security@doorcheck.io.

doorcheck

AI email security that checks the trust behind every message — and purges what doesn't belong before anyone clicks.

Sovereign AI email security.

Platform
Why DoorcheckHow it worksIntegrationsUse casesIndustriesEarly access
Resources
Threat intelligenceGlossaryWho it's forSecurity & compliance
Company
Sign inCareersContact salesSupportReport a vulnerability
Legal
Legal centerPrivacy policyTerms of service
🇺🇸 English🇸🇦 العربية🇪🇸 Español🇫🇷 Français🇩🇪 Deutsch🇵🇹 Português🇮🇹 Italiano🇨🇳 中文
© 2026 Doorcheck — AI email security
Terms of servicePrivacy policy