Privacy Policy

Last updated: July 12, 2026

Flagged PBC, Inc. (“Flagged,” “Flggd,” “we,” “our,” or “us”) operates the Flggd mobile and web application (the “App”). This Privacy Policy explains how we collect, use, and protect your information when you use our services.

By using Flggd, you agree to the practices described below. If you do not agree, please do not use the App.

1. Information We Collect

2. Email Scan Feature

Connecting a mailbox: You may connect a Gmail account (via Google Sign-In, requesting only the read-only gmail.readonly scope — we cannot send, delete, or modify your email) or another email provider via IMAP (your credentials are encrypted and stored only on your device, never on Flagged’s servers).

What we access: From each scanned message we read only the sender name/address, subject line, and a plain-text excerpt of the body (truncated to roughly 3,000 characters). We do not access, parse, or store attachments or HTML-only content, and Email Scan can only read your inbox — it cannot send, delete, or modify email, or access any other Google account data.

How it’s analyzed: Exclusively by Flagged’s own self-hosted AI infrastructure (our Verdict Engine). Email content is never sent to OpenAI or any other third-party AI provider, and is excluded from the aggregated/research data described in Section 5 (unless you explicitly opt in to AI Contribution, Section 3). Emails are processed temporarily to generate a scam verdict — raw emails are not permanently stored on Flagged’s servers during normal scanning.

Google user data: Flggd’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only to provide the scam-detection feature you’ve knowingly enabled — never for advertising, and never sold.

Storage & retention: Scan results (sender, subject, excerpt, verdict, and any URLs found in the message) are stored only on your device, in an encrypted local database — never on Flagged’s servers. They are automatically deleted after 30 days by default (90 days if you enable the optional “Help Improve Flggd AI” contribution described in Section 3), and you can delete individual scans or your entire scan history at any time from the app (Settings → Privacy & AI).

Your control: Email Scan is entirely opt-in and requires you to accept a consent disclosure before your first mailbox connection. You can disconnect a mailbox at any time in-app (for Gmail, you can also revoke access directly from your Google Account permissions); scan history stays on your device until you delete it or it expires per the retention period above.

3. AI Contribution (Optional)

Help Improve Flggd AI: You may optionally help Flggd detect new scams by enabling the “Help Improve Flggd AI” setting (Settings → Privacy & AI). It is OFF by default. While enabled, anonymized copies of emails our AI detects as likely scams are used for AI training. Personal information — such as names, email addresses, phone numbers, postal addresses, bank/card/account numbers, government IDs, tracking/order/invoice numbers, and signatures — is automatically removed before anything is uploaded. Only sanitized content enters our AI training data. You can turn this off at any time; contributors receive extended (90-day) local scan history, early access to new AI detection features, and an AI Contributor badge.

Donate Full Scam Email: From an individual scan result you may choose to donate the complete original scam email, including attachments, to improve Flggd AI. Each donation requires an explicit per-email confirmation, is entirely optional, is used only to improve Flggd’s scam detection, and cannot be undone once uploaded.

4. How We Use Information

5. Sharing of Information

We do not sell your personal information. We may share information with:

6. Data Storage & Security

Scam text and screenshots may be temporarily stored on our servers for analysis. Images are generally retained for no longer than 7 days unless required for troubleshooting.

Email Scan results are stored only on your device in an encrypted local database — never on Flagged’s servers — with the 30-day (90-day for AI Contributors) automatic retention limit described in Section 2. AI training data uploaded under Section 3 is stored on Flagged’s servers after automatic PII sanitization (or, for explicit full-email donations, as donated).

Data is stored securely on Google Cloud infrastructure with encryption and access controls. Despite our efforts, no system is 100% secure. Use Flggd at your own risk.

7. Your Rights

You have the right to:

To exercise these rights, email us at privacy@flggd.com.

8. Children’s Privacy

Flagged is not intended for children under 13. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 13, we will delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted at https://flggd.com/privacy.html with a new “Last updated” date. Continued use of the App means you accept the updated policy.

10. Contact Us

If you have any questions or concerns, please contact us:

Flagged PBC, Inc.
Email: privacy@flggd.com