Operator and contact
SteelGaze is operated by Muhammad Hanif Khan, an individual trading as SteelGaze. The public business location is Beijing, China. Privacy and account-deletion requests can be sent to support@steelgaze.app.
Information we process
- Account data, including your email address, user identifier, authentication records, plan, and preferences.
- Emails, headers, links, attachments, sender and recipient details, and related content you submit or authorize a connected inbox to submit for analysis.
- Scan results and saved evidence, including cleaned content, model scores, decisions, limitations, redacted link metadata, provider verdicts, and stable reason codes.
- Feedback, quota usage, connected-inbox configuration, opt-in notification preferences, connection labels, encrypted delivery credentials or browser subscriptions, and redacted delivery records.
- Security and usage data such as timestamps, browser information, truncated or hashed network identifiers where implemented, and service logs.
- Messages you send to support, security, sales, or the operator.
How we use information
- Provide accounts, phishing analysis, saved history, connected-inbox monitoring, support, and security operations.
- Authenticate users, enforce quotas, diagnose failures, prevent abuse, and maintain service reliability.
- Communicate about your account, authentication, service changes, support requests, security incidents, and monitored messages when you opt in to a notification channel.
- Improve models only when you have explicitly enabled an applicable data-contribution setting. Model-improvement use is disabled by default.
Google and Microsoft user data
When you choose to connect Gmail, SteelGaze requests Gmail read-only permission through Google OAuth. When you choose Microsoft Outlook, SteelGaze requests equivalent read-only mail and profile permissions through Microsoft OAuth. SteelGaze checks only new messages that arrive in Inbox after connection. It does not scan messages already in the mailbox when the connection is created and does not monitor Sent, Drafts, Spam, or Trash. New Inbox messages may include content, headers, sender and recipient details, links, and attachments used to provide phishing analysis and saved results.
SteelGaze stores your email address, encrypted OAuth access and refresh tokens, connection status, monitoring history, and the submitted message data and analysis results described above. Authorization remains stored until you disconnect the account, access expires, or the account is deleted. Disconnecting disables future SteelGaze access and removes stored OAuth tokens, but does not automatically delete messages or analysis results already saved. For Microsoft organizational accounts, you or a tenant administrator may also need to remove the application consent in Microsoft; see Data Retention Policy.
Google and Microsoft user data is processed by SteelGaze and the service providers identified below only as needed to operate, secure, and support the user-facing email monitoring and phishing-analysis features. This can include sending URLs from messages to Google Web Risk for threat-reputation checks. We do not sell Google user data, use it for advertising or credit decisions, or use Gmail-derived data for general AI/ML model training. We apply the same restrictions to Microsoft user data. Human access is restricted to cases where you give affirmative permission for specific data or where access is necessary for security or legal compliance.
SteelGaze's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We will update this policy and the in-product notice, and obtain consent where required, before using Google or Microsoft user data for a new purpose.
Service providers and transfers
We use Contabo for infrastructure, Supabase for database, authentication, queues, and scheduling, Resend for authentication and opt-in notification email, Slack and Telegram when you connect those notification channels, Google Cloud KMS for credential encryption, Purelymail for scan@steelgaze.app and support, security, sales, and operator correspondence, Cloudflare for network, security, and performance measurement, Google and Microsoft for email integration, Google for Web Risk threat-reputation checks, and a Merchant of Record for paid orders.
URLs found in submitted messages may be disclosed to Google Web Risk. Saved structured link evidence removes credentials, fragments, query values, and opaque tokens; sensitive account-action URLs are not fetched.
These providers may process data in countries outside yours under their own service terms and safeguards. Our Merchant of Record processes billing, tax, fraud-prevention, and transaction information.
Retention and deletion
Saved scan history and mailbox content currently remain until you delete history, delete the account, or SteelGaze performs an operational deletion. Automatic 90-day deletion is scheduled but is not yet enforced. Redacted notification delivery history and aggregate worker-run records are automatically removed after 90 days.
Disconnecting an inbox stops future monitoring but does not itself erase previously saved records. Account deletion disables monitoring, clears stored credentials and cursors, deletes the authentication account, and removes connected-inbox records through verified cascade deletion. Settings provides self-service history deletion, JSON export, and password-verified account deletion. See the Data Retention Policy for details.
Your choices
You may download a JSON export, delete saved history, disconnect notification channels, or permanently delete your account through Settings. Notification exports include sanitized preferences, channel states, and delivery summaries, not credentials. You may also request access or correction, subject to identity verification, applicable law, security needs, and records we must retain.
Data-contribution controls are opt-in, off by default, and apply only to eligible non-Google/non-Microsoft submissions. Data derived from Google or Microsoft integrations is not eligible. Withdrawing a contribution setting stops future contribution and triggers deletion of contributed samples associated with that consent.
Security, children, and changes
We use access controls, encryption in transit, provider security features, and restricted administrative access, but no online service can guarantee absolute security. Do not submit emails you are not authorized to disclose.
The service is not directed to children under 18. We may update this policy as the service changes and will revise the date above; material changes may also be communicated through the service or email.