Skip to content
Vigil
Back to Legal

Legal

Privacy Policy

Effective 13 May 2026 · Governed by the laws of New South Wales, Australia

Google API Services — Limited Use

Vigil's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The Vigil Report Phishing add-on accesses only the single email message a user explicitly chooses to report by clicking “Report Phishing.” That message is transmitted to Vigil's security backend solely to assess whether it is a real threat or a Vigil security-awareness simulation and to return a verdict to the reporting user and their organization's security team. Vigil does not use this data for advertising, does not sell it, and does not use it to train generalized AI or machine-learning models. No other messages in the mailbox are accessed, and nothing is read in the background.

Any automated analysis Vigil applies to a reported email, to help determine whether it is a genuine threat or a Vigil security-awareness simulation, is performed only by a self-hosted model that Vigil operates within its own isolated infrastructure in Australia. The reported message is processed locally within Vigil's environment, is never shared with any third-party AI or machine-learning provider, and is never used to train or improve any AI or machine-learning model.