Privacy Policy

Version 2026-04-26 · Effective 2026-04-26

Who we are

BeSecure operates the BeSecure service at besecure.adams-ai.com. Postal address: — address pending —.

For any privacy or data-rights request, write to privacy@linkdetect.io. We respond within 30 days.

What this service does

BeSecure analyzes emails users forward to it for phishing indicators. The forwarded message's subject, body, headers, and attachments are passed through six analyzers (URL inspection, sandboxed page rendering, threat-feed lookup, business-email-compromise detection, and others). A scan verdict is emailed back to the sender.

What we collect, why, and the lawful basis

When you forward an email to us

  • Sender address, subject, body, headers, attachment metadata. Required to perform the scan you asked for. Lawful basis: contract / legitimate interest in detecting phishing.
  • Attachments are read, not stored. Files are streamed into a hardened sandbox for macro and content analysis, then discarded. Filenames and content-types are recorded; raw bytes are not.
  • Extracted URLs. The links present in the message are scanned and the per-analyzer results stored against your submission so you can review them later.

When you create an account

  • Email and password (hashed). Required to authenticate you. Contract.
  • Display name, account type, organization name (optional). Used in the dashboard. Contract.
  • Two-factor authentication secret and backup codes (if enabled). Stored hashed; backup codes shown to you once. Legitimate interest in account security.

Whenever you interact with the site

  • IP address, user-agent, audit log of authentication events. For rate-limiting, brute-force defense, and security investigations. Legitimate interest. IP addresses are normalized (IPv6 collapsed to /64) before storage.
  • A single session cookie. Strictly necessary to keep you signed in. We don't use third-party analytics or advertising cookies, so we don't need a cookie consent banner under the EU ePrivacy Directive.

Marketing

If you tick the optional “product updates” box at signup, we may email you about new features. You can withdraw consent at any time via the unsubscribe link in those emails or by writing to us. Lawful basis: consent.

Where your data lives, who else processes it

The service runs in United States (DigitalOcean SFO3). If you access it from outside the United States, your data is transferred there for processing. Where required (e.g. EEA, UK, Switzerland), this transfer is covered by appropriate safeguards including our hosting provider's Standard Contractual Clauses.

Sub-processors:

  • DigitalOcean — virtual server hosting (compute and storage).
  • Mailgun — receives forwarded mail, sends scan-result and account emails. Mailgun briefly holds message contents to deliver them.
  • Cloudflare — sits in front of the site as a reverse proxy + DDoS shield. CDN logs the request URL, IP, and user-agent.
  • Let's Encrypt — issues TLS certificates. Sees only domain names, not user data.
  • abuse.ch URLhaus — public threat-intelligence feed mirrored locally each hour. We send no user data to them.

We do not sell personal data, share it with advertisers, or use it to train machine-learning models outside our own analyzers.

How long we keep things

  • Submissions and link verdicts are kept for as long as you have an account, plus 90 days, so you can review past scans. After that they're deleted automatically.
  • Audit log entries are kept for 13 months for fraud-investigation purposes, then deleted.
  • Error tracking events are kept for 30 days; aggregated error counts indefinitely.
  • Backups rotate on a 30-day window, encrypted at rest by the hosting provider.
  • Anonymous (no-account) submissions are kept for 90 days then anonymized further (sender-email hashed) so the threat-feed analytics remain useful.

Your rights

Most privacy regimes — including the EU GDPR, UK GDPR, California's CCPA/CPRA, Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, South Africa's POPIA, and others — give you a similar set of rights over your personal data. We honor them globally even where local law would not strictly require it:

  • Access. Get a copy of the data we hold about you. Use the “Export my data” button on the Settings page, or write to us.
  • Rectification. Correct anything that's wrong. Edit your account on Settings, or email us.
  • Erasure. Delete your account and all directly linked data. Use the Danger Zone on Settings, or email us.
  • Portability. Receive a machine-readable copy of what you've given us. The export above returns JSON.
  • Restriction or objection. Ask us to stop processing for a specific purpose (e.g. marketing, profiling). Email us.
  • Withdraw consent. Where we rely on consent (marketing emails), you can withdraw it any time without affecting prior lawful processing.
  • Complain. If you're in the EEA / UK, you can lodge a complaint with your national supervisory authority. Other regions have analogous regulators.

We don't make automated decisions with legal or significant effects about you. The phishing verdict is informational; you decide what to do with it.

Children

BeSecure is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has registered, contact us and we'll delete the account.

Security

Passwords are hashed with bcrypt (cost 12). Sessions are random 256-bit tokens marked Secure + HttpOnly + SameSite=Lax. TLS 1.2/1.3 only. Two-factor authentication is available. We log authentication events and rate-limit logins; we kill all sessions when a security-state change occurs (password change, 2FA disable, account deletion).

If we discover a security breach affecting your data, we'll notify you and (where applicable) relevant supervisory authorities within 72 hours of becoming aware, in line with GDPR Art. 33/34 and equivalents.

Changes

We'll update this policy as the service evolves. Material changes get a new version stamp at the top and a notice the next time you sign in.