Legal · Mailbox Monitoring
Mailbox Monitoring
How it works and what we see
Effective Date: 14 September 2026 · Last Updated: 14 September 2026
Mailbox monitoring is an optional service. You choose to turn it on, and you can turn it off at any time.
This notice covers mailbox monitoring only. Office Guard's general Privacy Notice covers our website, your account and our dealings with you as a customer, and continues to apply to those. Where the two differ about your mailbox or its contents, this notice governs. Mailbox contents are never used for advertising and are never shared with our advertising or analytics partners.
What you give us
To monitor your mailbox we need access to it, and how that works depends on your provider.
If you use Outlook.com or another Microsoft account, you authorize us on Microsoft's own sign-in screen. We receive a token, never your password, and only the permissions you approve there.
If you use Gmail or Yahoo, you create an app password in your own account settings and give it to us. We store it. It is not your account password, and you can delete it from your provider at any time without involving us.
You should understand what an app password covers. It is not limited to part of your mailbox. It grants access to your whole mailbox — every folder, including the ability to change or delete messages. Your email provider does not offer a narrower option. We limit ourselves to checking your Inbox, Drafts and Sent folders, and we never change, move, file or delete anything. That is a commitment we make in how our software is built, not a restriction your provider enforces on us.
What we check
We check the messages in your Inbox, Drafts and Sent folders as they arrive or as you write them. We check incoming mail for signs of fraud, and we check what you are about to send for sensitive client information.
We only see mail that arrives after you connect. We do not look at anything that was already in your mailbox, and we do not go through your archive or your other folders.
What we keep
We do not keep your messages. Message contents are examined in memory and are not stored.
What we store is a record of what we found: which check matched, how serious it is, when it happened, and the identifier your email provider gave the message. For a warning about a message you received, we also store the sender's name and email address as shown on the message, so that when we warn you we can tell you who it came from. We do not store the message, its subject, or anything a check matched on.
When we warn you that a draft contains sensitive client information, we record what kind it was — a Social Security number, bank details — and never the number itself. The number is not stored and is not sent anywhere, including to us.
We also store a record that your mailbox connection was working, so we can tell you honestly whether you were covered.
Who you correspond with
To tell a genuine contact from someone imitating one, we keep a record of the people you correspond with: the email address and display name on messages you receive and messages you send, how often and when, and whether you have written to them as well as heard from them. From that we can warn you when a message uses a familiar name from an unfamiliar address, comes from an address that closely imitates a company you work with, or redirects your reply somewhere new.
Two further details are kept in a form we cannot turn back into the original: the reply-to address on a contact's messages, and any phone numbers that appear in them. Each is stored as a one-way hash, which lets us answer "is this the same as before" and nothing else. This is how we can notice that a contact you know has asked you to call a number they have never used, which is the pattern of a voice-impersonation attack.
This record is not shared with your brokerage or anyone else, is never used for any purpose other than warning you, and is deleted the moment you disconnect your mailbox or your subscription ends. If your mailbox connection stops working and is not repaired, it is deleted after 30 days.
Where it goes
We check web addresses found in your mail against Google's Web Risk service, which tells us whether a site is known to be malicious. That means the web address itself is sent to Google. Nothing else from the message goes with it — not the text, not who sent it, not your name or your account.
If we need to warn you, we send a notification to the phone and browsers you have set up, through Apple's, Google's or Mozilla's notification service. The notification says what kind of warning it is and, for a dangerous link, the site it points to. It never names who the message was from. That detail is shown only once you open your Office Guard dashboard.
Nothing else about your mail leaves Office Guard. Your messages are not used to train anything, are not shared, and are not sold. We may disclose information where the law requires it.
Improving our checks
We look at how often our checks fire across all customers, so we can tell when a check is too sensitive or is missing something. That means counts and patterns, not messages — we cannot see the text that triggered a check, only that it did and, for incoming mail, who the sender was.
If you tell us a check is getting something wrong, we can see how often it fired on your account, but not what it matched on. Working out the cause means going through it with you.
If you work with a brokerage
If your brokerage subscribes to Office Guard, they can see the risks we found in mail sent to you — what was detected, when, and the sites any dangerous links pointed to — but only with your express agreement. You give it when you accept their invitation, where we say exactly what they will and will not see, and you can withdraw it at any time from your Office Guard portal. While it is withdrawn they see nothing about you; your protection is unaffected.
If we warn you that you are about to send sensitive client information, your brokerage sees that a warning happened and what kind, not what it was about. If the message is sent, they see the finding itself.
They cannot see your messages, their contents, who a warning concerned, or the record of who you correspond with. Before you connect your mailbox we tell you which brokerage that is.
If you leave that brokerage, they stop seeing anything new from the day you leave, and a new brokerage sees nothing from before you joined them. Records from the period you were with a brokerage remain part of their history.
Turning it off
You can disconnect your mailbox at any time from your Office Guard dashboard. It takes effect immediately.
You can also revoke our access directly with your email provider, from your own account settings, without involving us.
If your subscription lapses
If your payment fails, monitoring keeps running for 30 days. A card that expires is usually not a decision to leave, and we would rather keep protecting you while you sort it out.
Reporting stops at the point your subscription lapses.
You can disconnect at any point during those 30 days.
After 30 days we delete your mailbox credentials and the findings we hold for you. We will offer you a copy of your findings and coverage history before that happens. That copy contains your findings, not your messages, because we do not have your messages.
How long we keep findings otherwise
While your subscription is active, we keep findings for 12 months.
If Office Guard is sold
If Office Guard is ever acquired or merges with another company, your mailbox connection and your findings would transfer with the service, so your protection continues without interruption. We would tell you when that happened. Any company that acquired us would be bound by this notice, and would have to tell you and ask you again before changing how your mailbox is handled.
We would not hand over mailbox credentials, message contents or findings to any company evaluating such a transaction.
If this notice changes
If we make a material change to how your mailbox is handled, we will tell you and ask you to accept the new terms. Monitoring pauses until you do rather than continuing under terms you have not accepted.
Questions about any of this? Email us at [email protected].