This Privacy Policy describes how Drakaro (“we,” “us,” or “our”) collects, uses, and handles your information when you use Drakaro Phish Report (“Service”). We built this Service to be as privacy-preserving as possible — we only process what is strictly necessary to analyze the emails you submit and deliver your threat reports.
| Data | Why we collect it |
|---|---|
| Email address | Account creation, authentication (magic link), and delivery of threat reports to your inbox |
| Account plan and scan usage | Enforcing monthly scan limits and displaying usage on your dashboard |
| Emails you forward for analysis | Processing the submission to generate your threat report. See Section 3 for full details. |
| Threat reports generated for your account | Delivered to your registered email address. Not displayed on the website. Your dashboard shows scan count and remaining monthly quota only. |
| URLs and domains extracted from submitted emails | Threat analysis and internal engine improvement. Retained on all plans. See Section 4 for full details. |
| Billing information | Secure payment processing for Pro plan subscriptions. We do not store card details — all billing data is handled directly by our payment processor. |
| Authentication session token | Keeping you signed in to your account |
When you forward a suspicious email to your scan address, it is received by our system and processed as follows:
What is retained after analysis depends on your plan:
URLs and domains extracted from emails you submit are retained on all plans and used to improve our threat detection systems — helping us recognize new phishing patterns, malicious domains, and emerging threats faster. On the Free plan, additional submitted data beyond URLs may also be retained as described in Section 3. On the Pro plan, only URL and domain strings are retained for engine improvement purposes.
We do not sell or share URL-level data with third parties for commercial purposes.
Drakaro Phish Report uses passwordless authentication. When you sign in, we send a one-time magic link to your email address. You may also sign in using a supported social provider (Google, Microsoft, or Yahoo), in which case we receive only your email address from that provider — we do not receive access to your inbox or any other account data.
We store a session token in your browser’s session storage to keep you signed in. This token is not stored on disk and is cleared when you close the browser tab.
To provide the Service, we work with a small number of carefully selected third-party providers. We do not disclose the specific vendors that power our threat detection systems, as that information is proprietary. All providers are contractually required to handle data securely and in accordance with applicable privacy laws.
| Category | Purpose |
|---|---|
| Threat intelligence services | Real-time lookup of URLs, domains, and file hashes against threat databases to identify phishing, malware, and spam. These services receive only the URL, domain, or hash being checked — never your identity, email content, or account information. |
| AI analysis | Automated analysis of email content for deceptive patterns, social engineering indicators, and threat classification. The content processed is limited to the email you submitted and is not used to train models or retained by the provider. |
| Payment processor | Secure processing of Pro plan subscription payments. We do not store your payment card details — all billing data is handled directly by our payment provider. |
| Email delivery | Sending you magic sign-in links and threat report notifications. |
| Cloud infrastructure | Hosting, database storage, and execution of our scanning and analysis systems. All data is encrypted at rest and in transit. |
| Edge network & delivery | Traffic routing, DDoS protection, and fast delivery of the Drakaro application. |
You may request a list of our sub-processors by contacting us at [email protected].
We take security seriously. All data in transit is encrypted with TLS. Data at rest is stored with encryption enabled. Access to production systems is restricted and protected by multi-factor authentication. Our API enforces session-based authentication on every authenticated request.
On the Pro plan, forwarded email body content and attachments are processed in ephemeral, isolated environments and deleted immediately after analysis completes. On the Free plan, submitted data is retained as described in Section 3. All data at rest is stored with encryption enabled.
No system is 100% secure. If you discover a security vulnerability, please contact us responsibly at [email protected].
| Data | Retention |
|---|---|
| Forwarded email body and attachments — Free plan | Retained by Drakaro for internal purposes including threat detection improvement and service research |
| Forwarded email body and attachments — Pro plan | Permanently deleted after analysis completes (typically within minutes of submission) |
| URLs and domains extracted from submitted emails — all plans | Retained for threat detection engine improvement |
| Threat reports | Delivered to your email address. Not stored on the website or accessible via dashboard. |
| Scan count and usage metadata | Retained in your account while active; deleted within 30 days of account deletion |
| Account information (email address, plan) | Retained while your account is active; deleted within 30 days of account deletion |
| Session tokens | Expire after 24 hours or on sign-out, whichever comes first |
You have the right to:
Drakaro is operated from North Carolina, United States.
Drakaro Phish Report is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice on your dashboard at least 14 days before changes take effect. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
For privacy-related questions, data requests, or to exercise your rights:
Drakaro
Email: [email protected]
Website: https://drakaro.com