Privacy policy

Last updated 23 August 2026.

Who we are

Postwarden ("we", "us") provides a free, read-only scan of a Microsoft 365 tenant's recent mail flow, and a paid email security gateway. For the purposes of UK GDPR and the EU GDPR, Postwarden is the data controller for account and billing information, and a data processor for the mail data it accesses on a customer's behalf while running a scan or providing the gateway service. Contact us about any of this at [email protected].

What the free scan reads

When you sign in with Microsoft to run a scan, you grant a read-only permission scoped to mail metadata. In the standard scan, we read:

If you opt into the deeper scan, we additionally read message bodies and attachments for the messages the standard scan has already flagged as suspicious, so that a finding can be verified rather than guessed at.

The email address you type

Before a scan can start, we send a confirmation link to the address you enter, and the scan only proceeds if you follow it. This is what stops someone starting a scan, or receiving a report, in your name. The link is single-use and expires after 30 minutes.

The address is then used for one further thing only: sending you the link to your finished report. It is stored with the scan and deleted with it after 30 days. We do not add it to a mailing list and we do not pass it to anyone else.

Message bodies and attachments are never stored

Where the deep scan reads a message body or an attachment, that content is held in memory only, for as long as it takes to analyse it, and is discarded immediately afterwards. It is never written to disk, never logged, and never included in any report we retain. Only the resulting finding — for example, "this message impersonated a lookalike domain" — is kept.

How long we keep findings

Scan findings, including subjects, are stored in a redacted form: obvious personal or financial details are stripped before the finding is saved. These redacted findings are retained for 30 days after the scan completes and are then automatically and permanently deleted. We do not keep a copy beyond that window for any reason, including for our own analytics.

The permission is read-only and yours to revoke

The permission you grant for a scan cannot send mail, change mail flow rules, or modify anything in your tenant. It is visible in your own Microsoft Entra portal, under Enterprise applications, and you can revoke it at any time without contacting us. Once revoked, we can no longer access your tenant, and nothing of yours remains with us beyond any redacted findings still inside their 30-day retention window.

Where your data is processed

All processing and storage — for both the free scan and the paid gateway — takes place on infrastructure located in the United Kingdom and the European Union only. Data does not leave the UK/EU, and no sub-processor outside the UK/EU is used for mail data.

Contact and complaints

For questions about this policy, to request a copy of the data we hold about you, or to raise a complaint, email [email protected]. UK-based customers also have the right to complain to the Information Commissioner's Office (ICO); EU-based customers may complain to their local supervisory authority.