NOTRAPSocial engineering defense

Privacy and data use

Your message is analyzed for you, not collected about you.

This policy describes the NOTRAP website and the user-triggered NOTRAP Chrome extension. It explains what is processed, what may be stored, and what the product deliberately does not do.

Effective date: July 14, 2026 ยท Private Beta candidate

Purpose

NOTRAP provides decision support for social-engineering, phishing, impersonation, credential, payment-redirection, and related message risks. Results are evidence-based assessments, not guarantees that a message is safe or malicious.

How the extension works

The extension acts only after a user gesture. It does not automatically scan an inbox, continuously monitor Gmail, inspect unopened messages, or install a persistent Gmail content script.

Privacy mode

After you click the NOTRAP toolbar icon, the extension extracts the currently visible Gmail message into extension memory and shows a local preview. The preview is sent to the NOTRAP analysis service only after you click Analyze and accept the required disclosure.

Quick Analysis mode

Quick Analysis is optional and requires a separate, versioned disclosure. After it is enabled, clicking the NOTRAP toolbar icon on an open Gmail message extracts and immediately sends that current-message preview for analysis. Opening Gmail, navigating between messages, or opening the side panel alone does not start analysis.

Data processed for analysis

Depending on the available message layout, a requested Gmail analysis may transiently process the current message subject, sender display name and address, Reply-To address, visible body text, and visible link text and destinations. The website can also process text, URLs, or an uploaded email when a user explicitly submits them.

This content is transmitted over HTTPS to the fixed NOTRAP service at notrap.aimovement.online. The application analyzes it in memory. NOTRAP does not intentionally write the analyzed subject, sender, body, links, Gmail message identifier, or complete analysis request to its application database or application logs.

Operational logs are designed to contain only bounded metadata such as request ID, client/version, input-size and link-count buckets, duration, response status, stable error code, and risk category. Hosting infrastructure may maintain security or HTTP metadata under its own terms; the exact provider-level retention configuration must be verified before tester distribution.

Local and short-lived extension data

The extension may persist only language, theme, selected analysis mode, and accepted disclosure versions. It may keep short-lived workflow metadata such as numeric tab/window identifiers, page category, revision, timestamps, source, expiry, and consumed state.

Email subjects, senders, Reply-To values, body text, links, request snapshots, Gmail message identifiers, and evidence-bearing results are not placed in persistent extension storage. Content and request snapshots are cleared after completion, cancellation, navigation, reset, expiry, or panel closure according to the workflow state.

Analysis is separate from optional feedback

Chrome extension analysis requests set feedbackOptIn to false and do not create feedback records. On the website, feedback is a separate, explicit opt-in flow with a preview and confirmation step.

Confirmed metadata feedback may include a random record ID, timestamps, language, engine and input type/size, predicted and corrected risk labels, attack/evidence codes, source, review status, and a redacted note. Full email content cannot be stored as feedback. A user-created text sample may be retained only when the user separately attests that it is synthetic, chooses content inclusion, reviews the redacted preview, and confirms again.

Retention and deletion

  • Ordinary analysis content is not intentionally persisted in the application database or application logs.
  • Pending confirmed feedback expires after 90 days.
  • Rejected feedback expires 30 days after rejection.
  • Promoted, redacted synthetic samples may remain in a local reviewed dataset until removed or superseded by a new governance rule.
  • Neon feedback storage is capped and stores confirmed, redacted records rather than original analysis requests or complete emails.

Local website feedback controls can export or delete local records. Cloud feedback deletion requires a record identifier and an operator process. A verified public contact for individualized deletion requests has not yet been published, so tester distribution remains blocked.

Service providers and external data

  • Vercel hosts the public website and analysis service.
  • Neon provides the database used only for explicitly confirmed feedback when that feature is enabled.
  • PhishTank supplies a periodically downloaded public threat-intelligence feed. NOTRAP does not visit or submit a user-provided suspicious URL to PhishTank.
  • DNS may be used by the website's complete-email analysis to verify mail authentication. DNS failure does not by itself increase risk.
  • Chrome and Gmail provide the browser and message interface. The extension does not use a Google mailbox API or request permanent Gmail host access.

Use and sharing commitments

NOTRAP does not sell analyzed message data. It does not use message data for advertising, cross-site tracking, or user profiling. It does not use message data to determine credit, employment, insurance, lending, housing, or other eligibility.

Humans are not given routine access to analyzed email content. Human review is limited to feedback a user explicitly confirms in the separate feedback workflow, or exceptional access that is necessary for security, legal compliance, or user-authorized support.

Chrome Web Store Limited Use disclosure: Data obtained through extension permissions is used only to provide or improve NOTRAP's single purpose and user-facing security analysis. It is transferred only when necessary to provide that analysis, comply with law, protect security, or support an applicable organizational transaction. It is not used or transferred for personalized advertising, and humans do not read it except under the limited circumstances described above.

Safeguards

  • HTTPS-only transmission to a fixed API origin.
  • Manifest V3 with an explicit extension Content Security Policy and no remotely hosted executable code.
  • Temporary activeTab access instead of permanent Gmail access.
  • Validated extension messages, bounded requests and responses, one-request workflow guards, and cancellation on navigation.
  • Metadata-only operational logging and explicit feedback redaction and retention controls.

These safeguards reduce risk but do not constitute a regulatory or security certification.

Your choices

  • Keep Privacy mode enabled, which is the default.
  • Enable or disable Quick Analysis at any time.
  • Cancel an extraction or analysis and clear the current in-memory workflow.
  • Decline feedback without affecting analysis.
  • Clear extension preferences by removing the extension or clearing its site data.
  • Uninstall the extension to end extension access.

Policy changes and contact

Material changes will be reflected on this page with a new effective date and, when practicable, communicated through the available beta distribution channel before they apply to new processing.

Release blocker: The repository does not yet contain a verified public support/privacy contact or confirmed legal entity name. These fields must be supplied and this notice replaced before Private Beta tester distribution. No postal address, deletion deadline, certification, or data-protection officer is claimed.