Privacy Policy
Effective Date: August 15, 2026  ·  Last Updated: August 15, 2026

This Privacy Policy describes how Drakaro (“we,” “us,” or “our”) collects, uses, and handles your information when you use Drakaro Phish Report (“Service”). We built this Service to be as privacy-preserving as possible — we only process what is strictly necessary to analyze the emails you submit and deliver your threat reports.

The core principle: Drakaro Phish Report does not connect to your inbox and does not monitor your email. You choose which suspicious emails to forward for analysis. What we retain after analysis depends on your plan — see Section 3 for full details.

1. What We Collect

DataWhy we collect it
Email address Account creation, authentication (magic link), and delivery of threat reports to your inbox
Account plan and scan usage Enforcing monthly scan limits and displaying usage on your dashboard
Emails you forward for analysis Processing the submission to generate your threat report. See Section 3 for full details.
Threat reports generated for your account Delivered to your registered email address. Not displayed on the website. Your dashboard shows scan count and remaining monthly quota only.
URLs and domains extracted from submitted emails Threat analysis and internal engine improvement. Retained on all plans. See Section 4 for full details.
Billing information Secure payment processing for Pro plan subscriptions. We do not store card details — all billing data is handled directly by our payment processor.
Authentication session token Keeping you signed in to your account

2. What We Never Do

We never connect to your email inbox, request access to your Gmail or Outlook account, or monitor your email in any way. The Service is entirely on-demand — nothing is analyzed unless you choose to forward it to us.

3. How We Handle Forwarded Emails

When you forward a suspicious email to your scan address, it is received by our system and processed as follows:

What is retained after analysis depends on your plan:

Free Plan — Full Data Retention: On the Free plan, all data extracted from emails you submit — including message body content, headers, links, domains, attachments, and associated metadata — is retained by Drakaro for internal purposes including threat detection improvement and service research. By using the Free plan, you consent to this retention. If you do not wish your submitted email data to be retained beyond URL-level information, please upgrade to the Pro plan.
Pro Plan — URL Data Retained: On the Pro plan, URLs and domains extracted from your submitted emails are retained for threat detection engine improvement. Email message bodies and attachment contents are permanently deleted after analysis is complete, typically within minutes of submission.
Attachments (Pro Plan): Attachments in forwarded emails are extracted and analyzed in a secure, isolated environment. They are permanently deleted immediately after the scan completes. They are never retained, opened by staff, or used for any purpose other than threat analysis.

4. URL and Domain Data

URLs and domains extracted from emails you submit are retained on all plans and used to improve our threat detection systems — helping us recognize new phishing patterns, malicious domains, and emerging threats faster. On the Free plan, additional submitted data beyond URLs may also be retained as described in Section 3. On the Pro plan, only URL and domain strings are retained for engine improvement purposes.

We do not sell or share URL-level data with third parties for commercial purposes.

5. How We Use Your Data

6. Authentication

Drakaro Phish Report uses passwordless authentication. When you sign in, we send a one-time magic link to your email address. You may also sign in using a supported social provider (Google, Microsoft, or Yahoo), in which case we receive only your email address from that provider — we do not receive access to your inbox or any other account data.

We store a session token in your browser’s session storage to keep you signed in. This token is not stored on disk and is cleared when you close the browser tab.

7. Third-Party Services

To provide the Service, we work with a small number of carefully selected third-party providers. We do not disclose the specific vendors that power our threat detection systems, as that information is proprietary. All providers are contractually required to handle data securely and in accordance with applicable privacy laws.

CategoryPurpose
Threat intelligence services Real-time lookup of URLs, domains, and file hashes against threat databases to identify phishing, malware, and spam. These services receive only the URL, domain, or hash being checked — never your identity, email content, or account information.
AI analysis Automated analysis of email content for deceptive patterns, social engineering indicators, and threat classification. The content processed is limited to the email you submitted and is not used to train models or retained by the provider.
Payment processor Secure processing of Pro plan subscription payments. We do not store your payment card details — all billing data is handled directly by our payment provider.
Email delivery Sending you magic sign-in links and threat report notifications.
Cloud infrastructure Hosting, database storage, and execution of our scanning and analysis systems. All data is encrypted at rest and in transit.
Edge network & delivery Traffic routing, DDoS protection, and fast delivery of the Drakaro application.

You may request a list of our sub-processors by contacting us at [email protected].

8. Data Security

We take security seriously. All data in transit is encrypted with TLS. Data at rest is stored with encryption enabled. Access to production systems is restricted and protected by multi-factor authentication. Our API enforces session-based authentication on every authenticated request.

On the Pro plan, forwarded email body content and attachments are processed in ephemeral, isolated environments and deleted immediately after analysis completes. On the Free plan, submitted data is retained as described in Section 3. All data at rest is stored with encryption enabled.

No system is 100% secure. If you discover a security vulnerability, please contact us responsibly at [email protected].

9. Data Retention

DataRetention
Forwarded email body and attachments — Free plan Retained by Drakaro for internal purposes including threat detection improvement and service research
Forwarded email body and attachments — Pro plan Permanently deleted after analysis completes (typically within minutes of submission)
URLs and domains extracted from submitted emails — all plans Retained for threat detection engine improvement
Threat reports Delivered to your email address. Not stored on the website or accessible via dashboard.
Scan count and usage metadata Retained in your account while active; deleted within 30 days of account deletion
Account information (email address, plan) Retained while your account is active; deleted within 30 days of account deletion
Session tokens Expire after 24 hours or on sign-out, whichever comes first

10. Your Rights

You have the right to:

Drakaro is operated from North Carolina, United States.

11. Children’s Privacy

Drakaro Phish Report is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice on your dashboard at least 14 days before changes take effect. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

13. Contact

For privacy-related questions, data requests, or to exercise your rights:

Drakaro
Email: [email protected]
Website: https://drakaro.com