PRIVACY POLICY
Overview and scope
This policy applies to the Signalam web interface, authenticated public API, and paired Chromium extension. Signalam provides decision support and does not guarantee that a website, email, or sender is legitimate.
The organization operating a Signalam deployment is responsible for that deployment and its support channel. This policy describes the behavior of the Signalam software in this version.
PRIVACY POLICY
Information we handle
- Account information: your first name, optional middle name, last name, normalized email address, password hash, role, account status, registration date, and last sign-in time.
- Session and device information: protected session and CSRF credentials, paired-device credential hashes, device labels, pairing and last-seen times, revocation state, and limited security or operational events.
- Website detection: the exact active-tab address is sent over HTTPS for transient server detection. Routine activity history stores only its normalized origin—scheme, hostname, and optional port—plus the outcome, timing, device, and cloud status. Paths, queries, fragments, HTML, and page content are not kept in routine history.
- Email detection: on supported Gmail, Outlook, and Yahoo Mail pages, the visible provider, sender, subject, and message content are sent for transient checking. Routine history stores the provider, sender, subject, outcome, timing, device, and cloud status. It does not store the routine email body.
PRIVACY POLICY
Cloud AI review
Cloud AI is an additional contextual layer and does not replace Signalam’s server models or deterministic email decision rules. Provider credentials remain on the backend.
- When the URL model warns, cloud URL review receives only the minimized website origin.
- Email cloud review receives bounded email context after reasonably detectable email addresses, phone numbers, OTPs, card values, and account identifiers are redacted. Truncation keeps only compact beginning and ending context when needed.
- The optional AI Message Check sends privacy-redacted pasted text after you explicitly submit it. The optional AI Website Check uses the full address only to retrieve one public page, then sends the origin and redacted readable text—not the path, query, or fragment—to cloud AI.
- On-demand cloud inputs and responses are not added to routine activity history or training data by those features. Cloud failures return an unavailable state rather than a reassuring result.
Signalam currently uses Google Gemini as its cloud AI provider. The provider processes the minimized request to return the review. Its processing may also be subject to the deployment operator’s agreement with Google and applicable provider terms.
PRIVACY POLICY
Optional reports and training data
These workflows are separate from routine detection and collect data only after a user action or opt-in:
- Website reports and result feedback may store the full address, including its path, together with the shown result and your proposed correction so an administrator can review it.
- Email reports and feedback may store the provider, sender, subject, displayed outcome, proposed label, and email body. The body is protected with authenticated application-layer encryption. Administrator pages and CSV exports do not display, return, or decrypt it.
- Automatic training contribution is optional. When enabled, each completed check has the displayed sampling chance—currently 10%—of contributing an encrypted full URL or encrypted email content. These samples can contain personal information and are not confirmed training labels.
- Approved user reports may become de-identified future training candidates. Model training is a separate, later process; submitting data does not retrain or change the live models automatically.
PRIVACY POLICY
How information is used
- Authenticate accounts, maintain secure sessions, and pair or revoke devices.
- Run website and email detection, cloud contextual review, deterministic fusion, and user-requested explanations.
- Display personal activity, outcome distributions, connection status, and aggregate administrative metrics.
- Investigate user-submitted corrections and prepare separately approved data for a future, authorized model-training cycle.
- Protect the service, enforce rate limits, diagnose availability, and prevent duplicate activity.
PRIVACY POLICY
Retention
- Routine activity, submitted reports, and automatic training samples are removed after 90 days by the current retention process.
- Approved, de-identified training candidates may remain beyond ordinary report retention for a future separately authorized training cycle.
- Single-use pairing codes expire after five minutes. Expired or revoked sessions and consumed or expired pairing codes are cleaned up.
- Account and paired-device records remain while needed to operate or administer the account. Revoked devices remain marked as revoked for account security and audit context.
PRIVACY POLICY
Security measures and cookies
Signalam uses Argon2id password hashing, opaque server-side sessions, secure HttpOnly cookies in production, SameSite protections, CSRF checks, rate limits, credential hashing, restricted origins, and authenticated application-layer encryption for protected stored fields. Production traffic is intended to use HTTPS.
The dashboard uses essential session and CSRF cookies to keep you signed in and protect account actions. These are not advertising cookies. No security measure can remove every risk, so users should protect their account password and revoke unfamiliar paired devices.
PRIVACY POLICY
Your choices and controls
- Update your name or change your password from Profile. A password change closes your other web sessions.
- Review and revoke paired devices from Paired Devices, or sign out to end the current session.
- Choose whether to submit a website or email report and whether to use the on-demand AI Message or Website Check.
- Enable or disable automatic training contribution from Profile. Disabling it stops future automatic collection and deletes that account’s stored automatic samples.
- Contact the administrator responsible for your Signalam deployment for account access, correction, deletion, or privacy questions. This version does not provide a self-service account deletion control.
PRIVACY POLICY
Policy changes and contact
This policy may be updated when Signalam’s features, providers, retention rules, or legal obligations change. Material changes should be presented with a revised effective date before they apply to new optional data-collection consent.
For privacy questions or requests, contact the administrator or organization that provided or operates your Signalam account. They can identify the appropriate support and privacy contact for that deployment.