Effective August 31, 2026
We built the Backgrounder anti-scam platform for one simple reason: to help prevent the harm created by scams and fraudulent behavior. Scams create confusion, pressure, and fear. People deserve clarity before they act. Backgrounder helps individuals, families, executives, and small businesses verify suspicious messages, profiles, websites, payment requests, and other interactions that do not feel right. We combine fast AI analysis with experienced human security researchers so you can make informed decisions with confidence.
Backgrounder, Inc. ("Backgrounder," "we," "our," or "us") is committed to protecting your privacy and handling your information responsibly. This Privacy Policy explains what information we collect, how we use it, how we protect it, and the choices you have when using our website, platform, and related services (the "Services"). Information you provide to allow us to perform the Services is referred to herein as "Personal Data." Information related to suspected scammers (such as names, aliases, domains, and communications) is referred to as "Scammer Data."
This consolidated document comprises four parts: (1) the main Privacy Policy body (Sections 1 through 11), (2) Addendum A, which addresses data practices specific to the Carmen Guardian mobile application for iOS, (3) Addendum B, which addresses data practices specific to the Carmen Monitor browser extension, and (4) Addendum C, which addresses data practices specific to the Carmen Guardian mobile application for Android. Where an Addendum addresses a topic, it supplements (and does not replace) the main Privacy Policy. The Android and iOS applications are described separately because the capabilities available to them differ materially; neither addendum should be read as describing the other platform.
We believe privacy, transparency, and user control should be standard, especially in moments when trust feels uncertain. If you have questions about how your Personal Data is handled, we encourage you to reach out using the contact information provided in Section 11.
We collect Personal Data through your interaction with our Services and information we may receive from other sources, such as security and safety partners and marketing or advertising businesses. We collect and process only the Personal Data necessary to provide the specific Service features you use. We do not request access to device capabilities, sensors, or data categories beyond what is required for scam and fraud detection.
The following table describes the categories of Personal Data we collect, the sources from which we collect it, and the business purposes for which it is used.
| Category | Sources | Business Purpose |
|---|---|---|
| Identifiers (e.g., name, date of birth, social media account information, profile data, IP address) | Directly from you or your use of the Service; cookies and other tracking technologies; third parties (such as affiliates, agents, service providers, and other users) | Developing, improving, and providing the Service; identification; communications; marketing; analytics; security; legal, compliance, and regulatory obligations |
| Account Profile Information (e.g., email address, home address, billing address, phone number) | Directly from you or your use of the Service; third parties (such as affiliates, agents, service providers, and other users) | Developing, improving, and providing the Service; identification; communicating with you; marketing; analytics; security; legal, compliance, and regulatory obligations |
| Commercial Information (e.g., transaction data including services offered, considered, or purchased) | Directly from you or your use of the Service | Developing, improving, and providing the Service; identification; communications; marketing; analytics; security; legal, compliance, and regulatory obligations |
| Sensitive Personal Information (e.g., health-related data or biometric data to assist with scam detection) | Directly from you or your use of the Service | Providing the Service |
| Financial Data/Payment Information (e.g., credit card or other financial account information) | Directly from you or your use of the Service; third parties (such as affiliates, agents, service providers, and other users) | Improving and providing the Service; identification; communications; security; legal, compliance, and regulatory obligations |
| Internet or Device Activities (e.g., IP address, browser type, operating system, access dates and times, interaction logs) | Directly from you or your use of the Service; cookies and other tracking technologies; third parties (such as affiliates, agents, service providers, and other users) | Developing, improving, and providing the Service; identification; communications; marketing; analytics; security; legal, compliance, and regulatory obligations |
| Geolocation Information (approximate or precise location) | Directly from you or your use of the Service; cookies and other tracking technologies; third parties | Developing, improving, and providing the Service; identification; communications; marketing; analytics; security; legal, compliance, and regulatory obligations |
| Customer Support Interactions | Directly from you or your use of the Service; service providers; third parties (such as affiliates) | Providing and improving the Service; identification; communications; marketing; security; legal, compliance, and regulatory obligations |
| Platform Communications (e.g., your name, contact information, and the contents of any communications) | Directly from you, your use of the Service, and users with whom you communicate | Developing, improving, and providing the Service; security; legal, compliance, and regulatory obligations |
Backgrounder uses Personal Data only to operate, secure, and improve the Services, and not for advertising, resale, or AI model training.
To Provide and Maintain the Service. Backgrounder uses the Personal Data and information you submit (e.g., screenshots, links, descriptions, contact details) to analyze suspicious activity and deliver scam assessments. We also use identifiers (name, email, phone) and conversation history to provide the Services and communicate with you.
To Detect and Prevent Scams and Fraud. Backgrounder uses both your case submissions and scammer-related data ("Scammer Data") to detect fraud patterns and prevent malicious activity. This data includes scammer names, aliases, email addresses, phone numbers, domains, exploits, and communications.
To Improve the Service. Backgrounder improves its Services using Scammer Data only. Such improvements result from model training and use of aggregated or de-identified information, but never Personal Data.
To Communicate with You About Your Account or Case. Backgrounder uses your identifiers (name, email, phone) and conversation data to send you case status updates, Service-related communications, and account notices.
To Process Payments Securely. Payment information you provide is used only to complete the transaction via Stripe. More information about Stripe may be found at: https://stripe.com/privacy.
To Comply with Legal Requirements. Backgrounder may use or disclose Personal Data when legally required, such as in response to a court order or subpoena.
To Respond to Your Requests. If you direct Backgrounder to report a scam, your conversation data may be shared with authorities or partners upon such direct request.
Third-Party AI Services. Backgrounder uses third-party artificial-intelligence and machine-learning services to analyze submissions for scam and fraud indicators. When you submit content for analysis, that content may be transmitted to our AI service providers solely for the purpose of generating a scam or fraud assessment. These providers are contractually prohibited from using your data for any other purpose, including training their own models on your Personal Data. We do not share your Personal Data with third-party AI for advertising, profiling, or any purpose unrelated to delivering the Services.
Where you have connected a mailbox through Google or Microsoft OAuth, and only where you have separately enabled it, Carmen can act on a message you ask it to act on: it can move a suspected scam out of your inbox into a folder or label named "Carmen Quarantine". This is available on the web only. The Carmen Guardian mobile applications hold read-only mailbox access on every platform and cannot move, modify, send, or delete your email.
Three commitments govern this capability, and each is enforced in our systems rather than by policy alone:
gmail.modify) deliberately excludes permanent deletion, and we do not request Google's full-access mail scope. We do not move messages to Spam or Junk, because doing so trains your provider's own filters in a way we cannot undo on your behalf. Nothing Carmen does removes a message from your mailbox.You can undo any action Carmen has taken from the inbox activity view in your account. Undo remains available even if the capability is later withdrawn from your account, so that messages are never stranded.
We disclose your Personal Data only in the following circumstances:
Vendors and Service Providers. To assist us in meeting business operations needs and to perform certain services and functions, we disclose Personal Data to vendors and service providers, including providers of hosting services, customer service vendors, cloud services, content delivery services, support and safety services, email communication software, web analytics services, payment and transaction processors, marketing service providers, and information technology providers. We also work with service providers who help us with age and identity verification. Based on our instructions, these parties will access, process, or store Personal Data only while performing their duties to us.
Business Transfers. If we are involved in strategic transactions, reorganization, bankruptcy, receivership, or transition of service to another provider (collectively, a "Transaction"), your Personal Data may be disclosed in the diligence process with counterparties and others assisting with the Transaction and transferred to a successor or affiliate as part of that Transaction along with other assets.
Government Authorities or Other Third Parties. We may share your Personal Data, including information about your interaction with our Services, with government authorities, industry peers, or other third parties in compliance with the law: (i) if required to do so to comply with a legal obligation, or in the good faith belief that such action is necessary to comply with a legal obligation; (ii) to protect and defend our rights or property; (iii) if we determine, in our sole discretion, that there is a violation of our terms, policies, or the law; (iv) to detect or prevent fraud, harm, or other illegal activity; (v) to protect the safety, security, and integrity of our products, employees, users, or the public; or (vi) to protect against legal liability.
Business Account Administrators. When you subscribe through a business account, the administrators of that account may access and control your Backgrounder account, including your content. If you create an account using an email address belonging to your employer or another organization, we may share the fact that you have an account and certain account information, such as your email address, with your employer or organization to enable you to be added to their business account.
Other Users and Third Parties You Interact or Share Information With. Certain Services allow you to interact or share information (such as scam reports) with other users or third parties. Information you share with third-party partners is governed by their own terms and privacy policies, and you should review those terms and policies before sharing information with them.
We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, including providing our Services, complying with legal obligations, and resolving disputes. Because our Services access data types with varying levels of sensitivity, we apply different retention practices depending on the category of data. The table below describes what we store, how long we keep it, and how you can request deletion.
For SMS and MMS messages processed through our spam and fraud protection features on iOS and Android, we do not access, transmit, or store the content of your messages. Message content is analyzed on your device, and only the outputs of that analysis — a set of risk indicators and a general explanation of the result — are sent to our servers to generate a spam or fraud score. We apply the same security and access controls to these outputs that we apply to other sensitive communications data, such as email content.
| Data Type | What We Store | Retention Period | Deletion Mechanism |
|---|---|---|---|
| SMS/MMS content (iOS filtering) | Not stored on our servers. Message content is analyzed locally on your device (on iOS, within Apple's on-device message-filtering extension where applicable) and discarded immediately after a spam/fraud classification is generated. Content is not transmitted to us in a form we retain. | No retention (real-time, discard after scoring) | No deletion needed; content is not persisted |
| SMS/MMS risk indicators | Structured, non-reversible signals used to generate a spam/fraud score (for example, whether a message contains a suspicious link, a sender risk flag, or message structure/timing metadata). Does not include message text. | Retained as long as necessary to provide the Services and protect users, or as required by law. | request deletion via support@backgrounder.com |
| SMS/MMS classification summary | A general, human-readable explanation of why a message received its spam/fraud classification (for example, “message contained an unfamiliar shortened link and urgency language”). Written to exclude verbatim message text. | Retained as long as necessary to provide the Services and protect users, or as required by law. | request deletion via support@backgrounder.com |
| Email content (Gmail/Outlook via OAuth) | Message metadata (sender, subject, date) and fraud indicators extracted during analysis. Full email bodies are not stored on Backgrounder's servers; analysis is performed on content accessed via the OAuth connection. | Extracted metadata and indicators: retained while your account is active or until you disconnect the mailbox. | Disconnect the mailbox in-app; revoke OAuth access from your Google/Microsoft account; or request deletion via support@backgrounder.com |
| Message content from monitored sites (browser extension) | Scrubbed message content (with PII redacted on-device by default) and extracted indicators, stored as part of your submission history. | Retained while your account is active, subject to any shorter retention period you configure in the extension settings. | Pause or disable monitoring; remove the extension; or request deletion via support@backgrounder.com |
| User-submitted content (screenshots, links, files, URLs) | The content you submit for analysis, associated verdicts, and any case reports generated. | Retained while your account is active and for up to 180 days after account deletion for legal compliance purposes. | Delete individual submissions in your case history; delete your account; or request deletion via support@backgrounder.com |
| Scammer Data (names, aliases, domains, communications) | Scammer identifiers and fraud patterns derived from submissions. Personal Data of users is removed; only scammer-related data is retained. | Retained as long as necessary to provide the Services and protect users, or as required by law. | Not subject to individual deletion requests, as this data protects the broader user base. |
| Account and profile data (name, email, phone, credentials) | Your account information and conversation history with Backgrounder. | Retained while your account is active. Deleted within 30 days of account deletion, except where retention is required by law. | Delete your account in-app (Settings > Account > Delete Account) or via support@backgrounder.com |
| Payment data | Not stored by Backgrounder. Processed and retained by Stripe per its PCI-compliant practices. | Per Stripe's retention policy. | Contact Stripe or cancel your subscription. |
| Device/installation identifiers | Random per-installation ID (not IDFA/IDFV). | Removed when you delete the app or remove the extension. | Delete the app or remove the extension. |
| Mailbox actions (opt-in, web only) | For each message you ask Carmen to move: the provider's message identifier, the labels or folder the message was in before the move, the verdict that prompted it, and timestamps. Message content is not stored by the action itself. Recorded so that every move can be undone and audited. | Retained while your account is active, and for up to 180 days after account deletion for legal compliance purposes. Deliberately retained after a message is deleted or purged: the record that we acted must outlive the thing acted upon. | Undo an action in the app, which reverses the move and marks the record reverted; or request deletion via support@backgrounder.com |
| Outbound alert records | For each alert we email you: the kind of alert, the recipient address, the subject, the outcome (sent, failed, or deliberately suppressed), and what it concerned. Recorded so you can see what we told you about a threat, and when we did not. | Retained while your account is active, and deleted with your account. | Delete your account or request deletion via support@backgrounder.com |
| Push notification tokens (APNs/FCM) | Apple Push Notification service token (iOS) or Firebase Cloud Messaging token (Android). Used only to deliver verdict and safety alerts. | Retained while notifications are enabled. Invalidated when you disable notifications or delete the app. | Disable notifications in iOS Settings or Android Settings, or delete the app. |
| Spam/fraud verdict and score | The final classification result (e.g., spam, fraud, safe) and associated confidence score generated for a message. | Retained as long as necessary to provide the Services and protect users, or as required by law. |
Users have the following rights regarding their personal information, which they may exercise by contacting support@backgrounder.com.
Depending on where you live, you may have certain statutory rights in relation to your Personal Data. For example, you may have the right to:
Access your Personal Data and information relating to how it is processed
Rectify or update your Personal Data
Transfer your Personal Data to a third party (right to data portability)
Withdraw your consent where we rely on consent as the legal basis for processing
Lodge a complaint with your local data protection authority
Account Deletion. You may delete your account at any time directly within the Carmen Guardian app by navigating to Settings > Account > Delete Account, or within your account settings on the Backgrounder website. You may also request account deletion by contacting support@backgrounder.com. Upon deletion, we will remove your Personal Data in accordance with Section 4, subject to any legal retention obligations.
Our Services are not directed to, and are not intended for, individuals under the age of 18. Backgrounder does not knowingly collect Personal Data from anyone under 18, and does not knowingly collect Personal Data from children under 13 in compliance with the Children's Online Privacy Protection Act (COPPA).
If you have reason to believe that a person under 18 has provided Personal Data to Backgrounder through the Services, please contact us at support@backgrounder.com. We will investigate any such notification and, if appropriate, delete the Personal Data from our systems.
You must be at least 18 years old, or the minimum age required to consent to use the Services in your location, whichever is higher, to use the Services. This matches the eligibility requirement in our Terms of Service.
We implement commercially reasonable technical, administrative, and organizational measures designed to protect Personal Data from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. These measures include, but are not limited to:
Encryption of Personal Data in transit (TLS), and at rest on our servers;
Access controls that limit Personal Data access to authorized personnel on a need-to-know basis;
Regular security assessments and vulnerability testing;
Employee training on data protection and security practices;
Incident response procedures to address potential data breaches.
No method of internet transmission or electronic storage is fully secure or error-free. While we strive to protect your Personal Data, we cannot guarantee absolute security. You should exercise care in deciding what information you provide to the Services.
We are not responsible for the circumvention of any privacy settings or security measures contained on the Services or on third-party websites. If you become aware of any unauthorized access to your account or Personal Data, please contact us immediately at support@backgrounder.com.
The following disclosures supplement the information in the Sections above and apply to residents of California, Colorado, Connecticut, and other U.S. states with comparable consumer privacy statutes.
Depending on where you live and subject to applicable exceptions, you may have the following privacy rights in relation to your Personal Data:
The right to know information about our processing of your Personal Data, including the right to access your Personal Data, often in a portable format;
The right to correct your Personal Data;
The right to delete your Personal Data;
The right to be free from retaliation relating to the exercise of any of your privacy rights.
We do not "sell" Personal Data or "share" Personal Data for cross-contextual behavioral advertising, and we do not process Personal Data for "targeted advertising" purposes (as those terms are defined under applicable state privacy laws).
Global Privacy Control. We recognize the Global Privacy Control (GPC) signal as a valid opt-out request under California, Colorado, and Connecticut privacy laws. When we detect a GPC signal from your browser, we automatically disable analytics tracking and data sharing for your session. You can enable GPC in your browser settings or by installing a GPC-compatible browser extension. Learn more at globalprivacycontrol.org.
Exercising Your Rights. You can exercise the privacy rights described in this Section by submitting a request to support@backgrounder.com.
Verification. To protect your Personal Data from unauthorized access, change, or deletion, we may require you to verify your credentials before you can submit a request to know, correct, or delete Personal Data. If you do not have an account with us, or if we suspect fraudulent or malicious activity, we may ask you to provide additional Personal Data for verification. If we cannot verify your identity, we will not be able to honor your request.
Authorized Agents. Depending on where you reside, you may submit a rights request through an authorized agent. If you do so, the agent must present authority to act on your behalf, such as signed written permission, and you may also be required to independently verify your identity with us. Authorized agent requests can be submitted to support@backgrounder.com.
Appeals. Depending on where you live, you may have the right to appeal a decision we make relating to requests to exercise your rights. To appeal a decision, please send your request to support@backgrounder.com.
If you are located in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation provide you with rights regarding your Personal Data. In addition to the rights described in Section 5, you have the right to:
Be informed of the existence, use, and disclosure of your Personal Data and be given access to it;
Challenge the accuracy and completeness of your Personal Data and have it amended;
Withdraw consent to the collection, use, or disclosure of your Personal Data;
Lodge a complaint with the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated.
Cross-Border Data Transfers. Backgrounder is based in the United States, and your Personal Data is stored and processed on servers located in the United States. By using our Services, you acknowledge and consent to the transfer of your Personal Data to the United States, where data protection laws may differ from those in Canada. We apply the same security safeguards described in Section 7 regardless of where data is stored, including encryption at rest and in transit, access controls, and regular security assessments.
Commercial Electronic Messages. We comply with Canada's Anti-Spam Legislation (CASL). We will only send you commercial electronic messages if you have provided express consent. You may withdraw consent at any time by using the unsubscribe mechanism in our emails or by updating your preferences in your account settings.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we do, we will publish the updated version on our website and within the applicable Service interfaces, along with a revised effective date at the top of the policy.
If we make changes that materially affect how we collect, use, or disclose your Personal Data, we will provide you with reasonable prior notice before the changes take effect. Such notice may be delivered by posting a prominent announcement on our website, sending a notification to the email address associated with your account, or displaying an in-app notice within the Carmen Guardian app or Carmen Monitor extension, unless a different form of notice is required by applicable law.
Your continued use of the Services after the updated Privacy Policy becomes effective constitutes your acceptance of the revised terms. If you do not agree with any changes, you should discontinue use of the Services and, if applicable, delete your account as described in Section 5. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
If you have any questions about this Privacy Policy, wish to exercise any of the privacy rights described herein, or need to report a concern regarding the handling of your Personal Data, please contact us at: support@backgrounder.com
We will respond to all inquiries and rights requests in accordance with applicable law. When submitting a request related to your Personal Data, please include sufficient information to allow us to verify your identity and locate your records, such as the email address associated with your account.
This contact mechanism applies to the main Privacy Policy, Addendum A (Carmen Guardian for iOS), Addendum B (Carmen Monitor browser extension), and Addendum C (Carmen Guardian for Android).
This addendum describes data practices specific to the Carmen Guardian iOS app and supplements the main Privacy Policy. Terms not defined here have the meanings given in the main Privacy Policy.
A.1 Scope. Carmen Guardian extends Backgrounder's scam- and fraud-detection service to your phone. It accesses only the data categories below, does not sell your data, and does not use it for advertising or cross-app tracking.
A.2 Data We Access. (a) Email (Gmail/Outlook): read-only access via Google or Microsoft OAuth to analyze messages for phishing and fraud. You may disconnect a mailbox at any time. We do not modify, send, or delete your email. (b) Google User Data: our use adheres to the Google API Services User Data Policy, including Limited Use requirements. (c) SMS/MMS: with your permission, the iOS SMS Filtering extension classifies messages from unknown senders by transmitting content to ingest.backgrounder.com for a spam or fraud verdict. (d) Shared Content: URLs, images, or text you submit via the share sheet are processed to produce a verdict. (e) Device Identifier: a random, per-installation identifier (not IDFA or IDFV) associates submissions with your account and is removed when you delete the app. (f) Push Notifications: an Apple Push Notification service token is stored to deliver alerts.
A.3 Where Analyzed Data Goes. Submissions are transmitted to ingest.backgrounder.com, stored under your account, and retained per Section 4.
A.4 Third-Party AI Processing. Content may be transmitted to third-party AI providers solely for scam or fraud assessment. These providers are contractually prohibited from using your data for any other purpose.
A.5 SMS/MMS Classification Criteria. Messages are classified using known scam patterns, suspicious URLs, impersonation signals, urgency language, and matches against our scam-intelligence database.
A.6 Tracking. Carmen Guardian does not track you across other companies' apps or websites. We do not use IDFA or request App Tracking Transparency authorization.
A.7 Your Controls. You may withdraw consent at any time: (a) disconnect mailboxes in Settings; (b) disable SMS filtering in iOS Settings > Messages > Unknown & Spam; (c) disable notifications in iOS Settings > Notifications > Carmen Guardian; (d) revoke Google or Microsoft access from your account security settings.
A.8 Account Deletion. Delete your account within the app at Settings > Account > Delete Account, via the Backgrounder website, or by contacting support@backgrounder.com. Deletion is handled per Section 4.
A.9 Retention and Control. Retention periods for each data type accessed by the Carmen Guardian app are set out in Section 4 of the main Privacy Policy. In particular: SMS/MMS classification content is not retained after scoring; email content accessed via OAuth is retained while your account is active or until you disconnect the mailbox, and permanently deleted within 90 days of disconnection or account deletion; and user-submitted content is permanently deleted within 180 days of account deletion. You can disconnect mailboxes, disable SMS filtering, disable push notifications, and delete the app to stop further collection. Contact support@backgrounder.com to request deletion of previously submitted data.
This addendum describes data practices specific to the Carmen Monitor browser extension and supplements the main Privacy Policy. Terms not defined here have the meanings given in the main Privacy Policy.
B.1 Scope. Carmen Monitor extends Backgrounder's scam- and fraud-detection service to Chrome, Brave, Edge, Firefox, and Safari. We access only the data necessary to detect scams; we do not sell it, use it for advertising or cross-site tracking, and the extension contains no third-party analytics or telemetry SDKs.
B.2 Messages and Webmail on Monitored Sites. On configured messaging, social, and webmail sites (such as Gmail, Outlook, Facebook, Messenger, Slack, X/Twitter, WhatsApp, Microsoft Teams, Google Messages, Discord, TikTok, Snapchat, Reddit, and LinkedIn), the extension reads message content (sender, subject, body) and email-authentication signals (SPF/DKIM/DMARC) to analyze for phishing, impersonation, and fraud. It does not read passwords, intercept network traffic, or access browsing history, cookies, or clipboard data.
B.3 Personal-Information Scrubbing. Before message content leaves your browser, an on-device scrubber redacts personal information (email addresses, phone numbers, government IDs, payment-card and bank numbers, physical addresses) while preserving URLs and scam indicators. This scrubbing is best-effort and adjustable, including a metadata-only mode, in extension settings.
B.4 Where Analyzed Data Goes. Scrubbed content and extracted indicators are sent to the Carmen backend you configure (by default ingest.backgrounder.com), where they are stored and analyzed to produce a scam or fraud verdict. Submissions are retained under your account so you can review verdicts and history. Retention is governed by Section 4.
B.5 Scan This Page. The optional "scan this page" feature requests permission to access other websites so the extension can read the visible text and address of the page you are viewing. This broad site access is requested only when you enable the feature and is used solely for scans you initiate.
B.6 Hover to Check (Magic Mouse). The optional hover-check feature displays a card listing scam indicators and images found in the content under your cursor. Detection runs entirely on your device; content is submitted to Carmen for a verdict only when you click "Ask Carmen." Extending this feature to all sites requires the same optional permission as "scan this page," requested only when enabled and revocable at any time.
B.7 Links, Screenshots, and Submitted Files. When you submit a URL or attach an image, screenshot, PDF, or email (.eml) file through "Ask Carmen," that content is uploaded to the Carmen backend to produce a verdict and may be retained as part of a case and report.
B.8 Connected Mailboxes. Where available, mailbox connections are established server-side through Google or Microsoft OAuth; the extension only directs the backend to analyze specific messages and displays results. A connection is read-only unless you separately grant permission for Carmen to act on the mailbox and that capability is enabled for your account, in which case Carmen can move a message you ask it to move into a "Carmen Quarantine" folder or label. It cannot delete, send, or alter the contents of any message, and every move can be undone. See "Acting on a connected mailbox" in Section 2. Use of Google user data adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including Limited Use requirements: data is used only for scam-detection features, is not used for advertising, is not transferred to third parties except as needed to provide those features or comply with law, and is not read by humans except with your consent, for security, to comply with law, or on aggregated or anonymized data.
B.9 Identifiers and Local Storage. The extension generates a per-installation identifier to associate submissions and verdicts with your account. This identifier is not an advertising identifier and is not used for cross-site tracking; it is removed when you uninstall the extension. Captured messages awaiting analysis, settings, and credentials are stored locally in your browser. Cached message data is encrypted at rest, and your access credential is obtained through a standard OAuth sign-in to your Carmen account.
B.10 Safari. The Safari version of Carmen Monitor requests access only to the specific monitored sites listed in Section B.2. It does not request or use broad website access permissions. The optional "scan this page" and "hover to check" features requiring all-sites permission are not available in the Safari version.
B.11 Notifications. If you enable alerts, the extension shows local browser notifications (and may play a sound) to warn you about scam verdicts. These notifications are rendered locally by your browser.
B.12 Retention and Control. Retention periods for each data type accessed by the Carmen Monitor extension are set out in Section 4 of the main Privacy Policy. In particular: scrubbed message content from monitored sites is retained while your account is active, subject to any shorter retention period you configure in the extension settings, and permanently deleted within 90 days of account deletion; and user-submitted content (links, screenshots, files) is permanently deleted within 180 days of account deletion. You can pause or disable monitoring per platform, decline or revoke the optional all-sites permission, disconnect the extension from your account, and remove the extension to stop further collection. Contact support@backgrounder.com to request deletion of previously submitted data.
This addendum describes data practices specific to the Carmen Guardian Android app and supplements the main Privacy Policy. Terms not defined here have the meanings given in the main Privacy Policy.
Android and iOS are described separately because what each operating system permits differs materially. On iOS, the system narrows what the app can see: the message filter is shown only messages from senders you do not know, and the call extension can label a number without reading your call log. On Android those limits do not exist, so the app asks for broader permissions and this addendum states plainly what it does with them. Addendum A does not describe the Android app, and this addendum does not describe the iOS app.
C.1 Scope and Defaults. Carmen Guardian extends Backgrounder's scam- and fraud-detection service to your phone. Every category below is off by default. Each becomes active only when you both grant the Android permission and turn on the matching control inside the app; turning that control off stops collection even while the system permission remains granted. We access the minimum needed to detect scams, we do not sell your data, and we do not use it for advertising or cross-app tracking.
C.2 Text Messages (SMS). With your permission, the app reads the sender and full body of incoming text messages to detect smishing and fraud, and message content may be sent to our analysis service to return a spam or fraud verdict. If you make Carmen Guardian your default SMS app, it becomes responsible for your inbox: legitimate messages are written to your inbox normally, and messages judged to be scams may be withheld and shown to you separately, where you can release them. We do not read the content of multimedia (MMS) messages, and we do not send texts on your behalf except at your direction.
C.3 Calls. With your permission, the app screens incoming calls to warn you about or block likely scam callers. We receive the caller's number, the direction of the call, and whether it was allowed or blocked together with the reason. The app does not record, listen to, or transmit call audio — it holds no audio-capture permission of any kind — and it does not capture call duration or the caller's name.
C.4 Contacts. If you grant contacts access, your contacts are read only on your device, and only to check whether an incoming caller is someone you know so that we do not flag them. No contact record, and no contact's name, is transmitted to us — not for analysis, not for advertising, and not for profiling. Nothing derived from your contacts leaves the device.
C.5 Notifications and On-Screen Content. If you enable the notification listener and/or the accessibility service, the app reads notification content and, for the accessibility option, text visible on screen — but only for the messaging, social, banking, and crypto apps you specifically choose to monitor. The accessibility service does not read password fields, does not log keystrokes, and captures only what is already visible on screen. This is a powerful capability, it is off by default, and it is used solely for scam detection.
C.6 Email (Gmail / Outlook). If you connect a mailbox, you authorize access through Google or Microsoft OAuth using read-only scopes (gmail.readonly for Google, Mail.Read for Microsoft). We read recent message content, metadata, and email-authentication results (SPF/DKIM/DMARC) to analyze messages for phishing, impersonation, and fraud. The Android app cannot modify, move, send, or delete your email, and holds no permission that would allow it to. The separate, opt-in ability for Carmen to move a message described in Section 2 is a web capability and is not available to this app. You can disconnect a mailbox in the app at any time, and revoke access from your Google or Microsoft account security settings.
C.7 Google User Data. Carmen Guardian's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the scam-detection features you request; we do not transfer it to third parties except as necessary to provide those features, to comply with applicable law, or in connection with a merger or acquisition; we do not use it for advertising; and no human reads your data except with your explicit consent, to comply with law, for security purposes, or where the data is aggregated or anonymized.
C.8 Shared Links, Screenshots, and Text. When you share a URL, image, PDF, email file, or text into the app, we process that content to produce a verdict. Files you attach to an "Ask Carmen" request are uploaded to our service and may be retained as part of the case and report you asked for.
C.9 Website Blocking and DNS. If you enable website blocking, the app runs a local, on-device VPN whose only function is to filter DNS lookups against a scam-site blocklist we sync to your device. Your browsing history and DNS queries are not sent to Backgrounder and we do not store them. So that blocking can work, DNS lookups made while this feature is enabled are resolved through Cloudflare's public resolver at 1.1.1.1 rather than the resolver your network would otherwise use; queries reach Cloudflare and are subject to its privacy commitments, not ours. This VPN carries no traffic other than DNS, and is not used to route, inspect, or collect your general web traffic. Disabling website blocking restores your device's normal DNS resolution.
C.10 Installed Applications. To let you choose which apps to monitor and which browser to open links in, the app queries your device for the applications that can handle those functions. This is read on your device to populate those settings, and the list of your installed applications is not transmitted to us or stored on our servers.
C.11 Device Identifier. The app generates a random identifier for your installation to associate submissions and push notifications with your account. It is not a hardware identifier, advertising ID, IMEI, or Android ID. It is not used for tracking, and it is regenerated if you reinstall the app.
C.12 Push Notifications. If you enable notifications, we register a Firebase Cloud Messaging token so we can deliver verdicts and safety alerts. The token is used only to deliver those alerts.
C.13 Recording Your Consent. When you turn a monitoring category on — or, for content you submit yourself, when you submit it — the app records a consent entry consisting of an anonymous identifier and a timestamp, so that the basis on which each item was processed is auditable. Turning a category off deletes its entry. The identifier records the grant, not you.
C.14 Region. Each event is tagged with the region your device reports, taken from its SIM, network, or locale, so the correct privacy rules are applied. This is a country code, not your location.
C.15 Your Controls. You may withdraw consent at any time: disable any monitoring category in the app; disconnect a mailbox in the app; remove Carmen Guardian as your default SMS app in Android Settings > Apps > Default apps; revoke SMS, call, or contacts permissions in Android Settings > Apps > Carmen Guardian > Permissions; turn off the notification listener or accessibility service in Android Settings; disable website blocking in the app; disable notifications in Android Settings; or uninstall the app.
C.16 Account Deletion. You can permanently delete your Backgrounder account from inside the app at Settings > Delete account. This asks our servers to delete your account and the data it holds, revokes your sessions, and stops the app capturing anything further on this device. A 30-day grace period applies — signing in again within 30 days cancels the deletion. This is in addition to disabling categories or disconnecting mailboxes, which stop collection without deleting your account.
C.17 Retention and Control. Retention periods for each data type are set out in Section 4 of the main Privacy Policy. In particular: SMS content is not retained after scoring; email content accessed via OAuth is retained while your account is active or until you disconnect the mailbox, and is permanently deleted within 90 days of disconnection or account deletion; and user-submitted content is permanently deleted within 180 days of account deletion. Contact support@backgrounder.com to request deletion of previously submitted data.