Privacy Policy
Last Updated: June 2026 · Attest Security Ltd.
01. Our Privacy Commitment
Attest is built around a privacy-first, zero-knowledge architecture.
The Attest browser extension processes your email body locally within your browser solely to generate a secure SHA-256 cryptographic hash for verification. Your raw email body, subject line, and attachments are never transmitted to or stored on our servers.
Only the minimum information required to verify an email and operate the Attest service is collected.
02. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Full name
- Email address
- Account credentials and authentication information
2.2 Verification Information
When you verify an email send event, we collect:
- Sender email address
- Recipient email address
- SHA-256 hash of the email body
- Verification timestamp (UTC)
- Verification result and verification type
- Internal verification identifiers necessary to maintain verification records
2.3 Human Verification Data
While composing an email, the browser extension temporarily analyzes mouse movement characteristics, including movement coordinates, timing, and velocity, to distinguish genuine human interaction from automated activity.
This interaction telemetry is securely transmitted to our verification API, processed only in volatile memory, and immediately discarded after verification. It is never stored permanently.
2.4 Website & Usage Information
When you use our website, we may collect:
- IP address
- Browser type
- Operating system
- Device information
- Pages visited
- Error logs
- Basic usage analytics necessary to improve the security and reliability of our services
2.5 Communications
If you contact us, we may collect:
- Your name
- Email address
- Messages you send us
- Support correspondence
2.6 Payment Information
Subscription payments are securely processed by Stripe.
Attest does not collect or store your credit card numbers or full payment details. Payment information is processed directly by Stripe in accordance with its Privacy Policy.
03. Information We Never Collect
Attest is intentionally designed not to collect or store:
- Raw email body content
- Email subject lines
- Email attachments
- Attachment filenames
- Gmail message contents after verification
- Browser history
- Browsing activity outside Gmail
- Passwords
- Session cookies from third-party services
- Google OAuth access tokens beyond what is temporarily required for authentication
- Biometric information such as fingerprints or facial recognition data
We also do not collect any content from emails you receive.
04. How We Use Your Information
We use your information solely to provide and improve the Attest service.
Specifically, we use information to:
- Create and manage your account
- Verify email authenticity
- Generate public verification records
- Display verified sender information
- Detect bots and fraudulent activity
- Send security notifications and verification emails
- Process subscription payments
- Respond to customer support requests
- Maintain platform security
- Comply with applicable legal obligations
We do not sell, rent, or use your information for advertising or behavioral profiling.
05. Legal Basis for Processing (GDPR)
Where the GDPR applies, we process personal data under the following legal bases:
5.1 Performance of a Contract
- Providing the Attest verification service
- Creating user accounts
- Maintaining verification records
5.2 Legitimate Interests
- Fraud detection
- Platform security
- Abuse prevention
- Service improvement
- System monitoring
5.3 Legal Obligation
- Compliance with applicable laws
- Responding to lawful requests
5.4 Consent
- Marketing communications (if you choose to receive them)
06. Information Sharing & Third-Party Services
We only share personal information where necessary to provide our services.
6.1 Stripe
We use Stripe to process subscription payments securely.
Stripe receives the information necessary to process payments, including billing information and payment details. Stripe processes this information under its own Privacy Policy.
6.2 Google SMTP
We use Google's SMTP infrastructure through Nodemailer to send transactional emails, including:
- Verification emails
- Account notifications
- Security alerts
- Password reset emails
- Contact form responses
To deliver these emails, Google processes:
- Sender email address
- Recipient email address
- Sender and recipient display names (where available)
- Email subject
- Email content required to deliver the message
These emails are transmitted through Google's secure mail infrastructure.
6.3 Legal Requirements
We may disclose information when required by law, legal process, or governmental request.
6.4 Transfers
If Attest is involved in a merger, acquisition, or sale of assets, user information may be transferred as part of that transaction.
We never sell personal information to advertisers or data brokers.
07. Data Security
We implement industry-standard security measures to protect your information, including:
- TLS 1.3 encryption during transmission
- AES-256 encryption for stored data
- Encrypted PostgreSQL databases
- Multi-factor authentication for administrative access
- Access controls based on least privilege
- Continuous monitoring
- Regular security assessments
While we employ strong safeguards, no system can guarantee absolute security.
08. Data Retention
Unless a longer retention period is required by law:
- Verification records are retained for 2 years
- Support communications are retained for up to 2 years
- Security logs are retained only as long as necessary for security and operational purposes
- Payment records are retained as required by financial and tax regulations
If you delete your account, associated personal information will be permanently deleted within 30 days, except where retention is legally required.
09. International Data Transfers
Your information may be processed in countries outside your country of residence.
Where required, we implement appropriate safeguards, including Standard Contractual Clauses or equivalent legal mechanisms, to protect personal data transferred internationally.
10. Cookies & Similar Technologies
Our website uses essential cookies required for authentication, security, and maintaining user sessions.
We may also use limited analytics cookies to understand website performance and improve user experience.
You can control cookies through your browser settings, although disabling essential cookies may affect website functionality.
11. Your Privacy Rights
Depending on your jurisdiction, you may have the right to:
- Access your personal data
- Correct inaccurate information
- Delete your personal data
- Restrict processing
- Object to processing
- Receive a portable copy of your data
- Withdraw consent where processing relies on consent
California residents may also have rights under the California Consumer Privacy Act (CCPA).
If you are located in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.
To exercise any privacy right, contact us at support@attest.page.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology, or legal obligations.
When material changes are made, we will update the "Last Updated" date and, where appropriate, notify users through the website or by email.
13. Contact Us
For privacy questions or requests, please contact:
If you have questions about this Privacy Policy or how we process your information, we are happy to assist.
Questions about your privacy?
We're happy to explain anything in this policy. Reach out to our team and we'll respond promptly.
✉️ support@attest.page