Privacy Policy

Last updated: July 30, 2026

OUTSMARTER is in limited pre-launch testing. If you join the waitlist, we collect the information you give us there plus standard website information. If you take part in testing and connect an account, the app handles your information as described below. The sections below describe how the app handles information when you use it.

The short version

OUTSMARTER is designed to minimize the private communications that reach our servers. Email and text analysis happens on your device. Call Shield and voicemail require limited processing described below. We retain the least data each feature needs.

We do not sell personal information or share it for cross-context behavioral advertising. We do not use the content of calls, texts, or email, or data from connected email accounts, to train generalized artificial-intelligence or machine-learning models.

Who we are

OUTSMARTER, Inc. provides scam protection across calls, texts, email, and links. This policy explains how we access, collect, use, disclose, retain, and delete information through:
– The OUTSMARTER mobile app.
– outsmarter.ai
– Call Shield, Text Shield, Email Guard, and Link Shield.
– Related account, support, subscription, caregiver, and partner services.
Together, these are the Service.

This policy also explains our limited handling of information about callers, senders, and other people who communicate with an OUTSMARTER user. Privacy questions and requests can be sent to privacy@outsmarter.ai.

How the shields handle information

Call Shield

If you enable Call Shield, calls that meet your screening settings may be forwarded to our call-screening system. The system may process:

– The caller’s phone number, call metadata, signaling data, called number data, and caller-ID information.

– Call audio and a live transcript.

– The time, duration, routing status, and outcome of the call.

– Scam indicators, a threat score, a verdict, and the reasons for that verdict.

The caller hears a disclosure before recording or transcription begins. The call may be processed by OUTSMARTER and contracted telephony providers so the system can interview the caller, assess the call, and decide how to route it.

OUTSMARTER is designed to avoid retaining call audio or screening transcripts after the screening session ends. We retain the resulting signals, score, verdict, timing, and outcome so we can show your protection history, keep the Service secure, and improve scam detection using permitted data.

Voicemail

If a caller leaves a voicemail, we may store:

– The caller’s number, call metadata, signaling data, called number data, and caller-ID information.

– The voicemail audio.

– A transcript, if transcription is enabled.

– The time, duration, status, and associated threat information.

Voicemails are encrypted in transit and at rest where they are stored under our control. They remain available until you delete them or delete your account.

Text Shield

Text Shield works differently by device:

On iPhone and iPad: Apple’s message-filtering tools allow Text Shield to analyze SMS and MMS messages from unknown senders. Apple does not give the filter access to iMessage conversations or messages from your contacts.

On Android: If you grant notification access, Text Shield may access sender information and message content visible in notifications from supported messaging apps. The permission may expose notifications from people you know, even when Text Shield is configured to protect you from unknown or suspicious senders.

Share to check: If you choose to share a message, screenshot, or link with OUTSMARTER for review, the app accesses the content you selected.

Message analysis happens on your device. Raw message content and screenshots are not sent to or retained on OUTSMARTER’s servers. The backend may receive a threat score, pattern category, verdict, timestamp, and limited sender or link signals needed to show protection history and detect repeat threats.

Email Guard

Email Guard is optional. It works only after you connect an eligible email account and approve the requested permission.

For Gmail, OUTSMARTER requests read-only access through the `gmail.readonly` scope. This may allow the app to access message bodies, headers, sender information, links, attachments, and message metadata so it can identify phishing links, impersonation, spoofed senders, and social-engineering patterns. OUTSMARTER does not send, modify, delete, archive, or label Gmail messages.

For Microsoft accounts, OUTSMARTER uses read-only permissions through Microsoft Graph to provide the same user-facing scam-detection function.

Email analysis happens on your device. Raw email content is not transmitted to or stored on OUTSMARTER’s servers. When a message is flagged, the backend may receive a threat score, pattern category, verdict, and timestamp so the app can show your protection history. We also keep a running count of the messages Email Guard has checked, which is what the app uses to show your protection summary. Messages that are not flagged produce no other record. We also process the account identifiers, subscription or push-notification information, and OAuth credentials needed to maintain the connection.

Our use of Google Workspace data

OUTSMARTER’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google Workspace data and information derived from it are used only to provide or improve the Email Guard features visible to the user who connected the account. In particular:

– We do not use Google Workspace data for advertising.

– We do not sell Google Workspace data.

– We do not transfer, sell, or use Google Workspace data, or anything derived from it, to determine credit-worthiness or for lending purposes.

– We do not use Google Workspace data or its derivations to create, train, or improve a generalized artificial-intelligence or machine-learning model or a model for other users.

– A person may review specific Google Workspace data only with the user’s documented permission, when necessary to investigate a security incident or abuse, or when required by law.

– We do not transfer Google Workspace data except to provide the user-facing feature with the user’s consent, protect security, comply with law, or complete a merger, acquisition, or asset sale after obtaining the user’s explicit prior consent.

You can disconnect Gmail in the OUTSMARTER app or through Google’s account-permissions page. Disconnecting stops new access immediately. Within 24 hours, the locally cached Gmail data on your device is erased, the OAuth credentials are deleted, and the push-subscription record is canceled. Within 30 days, any remaining records associated with the connection are deleted from our active systems and backups. Instructions for managing and deleting connected data are available on the OUTSMARTER.ai website at Gmail data help.

Link Shield

If you enable Link Shield, the app may evaluate domains or URLs that you open or choose to check. Depending on the device and how the link is checked, the Service may access:

– The domain or URL.

– DNS requests needed to determine which site a device is trying to reach.

– The app or channel from which a link was opened, if the device provides it.

– Your IP address, device or app identifier, timestamp, threat score, and verdict.

We use this information to identify and block scam sites, explain the warning, maintain security, and recognize repeat threats. We do not use it to create an advertising profile or a general history of your browsing.

Other information we access or collect

Account and contact information

We may collect your name, email address, phone number, account identifier, authentication information, communication preferences, account settings, and confirmation of your eligibility to use the Service. If you join the waitlist before launch, we collect the name, email address, and phone number you give us.

Subscription and transaction information

We may receive your subscription tier, purchase status, renewal and expiration dates, transaction identifiers, and limited billing information from an app store or payment processor. Payment providers process payment-card information under their own privacy policies. OUTSMARTER does not receive or store a full payment-card number when a payment provider handles the transaction.

Device, network, and usage information

We may collect IP address, device type, operating system, app version, language, time zone, permission status, feature settings, device or app identifiers, push-notification tokens, crash reports, diagnostics, security logs, and information about how you use the Service.

Support, research, and feedback

We collect information you choose to provide in support requests, surveys, product research, beta feedback, or other communications. If you give support personnel permission to review a specific message, email, voicemail, screenshot, or event, we use that content only for the support or security purpose you approved.

Protection history and dollars-protected ledger

We may store threat scores, verdicts, event times, affected channels, pattern categories, actions taken, and your estimated avoided loss or other information you add to your protection history.

Caregiver and family features

If you use a caregiver or family feature, we may collect the relationship between participating accounts, invitations, enrollment and consent records, sharing settings, and the protection alerts that the protected adult chooses to share. The protected adult can review or end that sharing through the Service.

Caregiver access does not authorize the caregiver to read the protected adult’s calls, messages, email, or voicemail unless the protected adult separately and clearly chooses to share specific content.

Enterprise and membership partners

If you receive the Service through a credit union, employer, association, or other organization, we may collect a partner identifier, eligibility or enrollment information, subscription status, and information needed to provide and account for the benefit.

Partners receive aggregate or de-identified reports about enrollment and protection results. They do not receive the content of calls, messages, email, or voicemail.

Where information comes from

We may receive information:

– Directly from you.

– From your device and your use of the Service.

– From callers, senders, and the communications they direct to an OUTSMARTER user.

– From a carrier, app store, payment processor, authentication provider, connected email provider, or other service you choose to connect.

– From an enterprise or membership partner that makes the Service available to you.

– From service providers that help us operate and secure the Service.

– From public, commercial, and community sources of scam, caller, sender, domain, and threat-reputation information.

How we use information

We use information to:

– Provide Call Shield, Text Shield, Email Guard, Link Shield, voicemail, caregiver features, and protection history.

– Create and manage accounts, subscriptions, connected services, and customer support.

– Deliver threat warnings, service notices, security alerts, and communications you request.

– Diagnose failures, maintain performance, prevent abuse, investigate security incidents, and protect users.

– Measure Service use and improve features.

– Comply with law, enforce our agreements, and establish or defend legal claims.

– Send product news or marketing only when permitted by law and subject to your communication choices.

De-identified scam-pattern data from permitted sources may help improve detection across users. We do not use private communication content for that purpose. Google Workspace data, connected-email data, and information derived from connected email accounts are excluded from generalized model training and from model improvement for other users.

Automated threat decisions

OUTSMARTER uses automated systems to produce threat scores, warnings, and routing recommendations. These results help protect you from suspected scams. They do not determine eligibility for credit, employment, housing, insurance, education, health care, or another decision with legal or similarly significant effects.

You can review the reason for a warning, bypass a warning when the Service allows it, turn off individual shields, or contact us about a result.

When we disclose information

We may disclose information in the following circumstances.

Service providers

Service providers process information under contracts that limit their use of it to providing services to OUTSMARTER, subject to their legal and security obligations. Provider categories may include:

Provider categoryInformation involvedPurpose
Cloud hosting, storage, and database providersAccount data, signals, scores, settings, voicemail, and service logsOperate and secure the Service
Telephony and transcription providersCaller information, call audio, transcripts, routing data, and voicemailScreen, route, transcribe, and deliver calls and voicemail
App stores and payment processorsAccount identifiers, subscription status, and transaction recordsProcess and manage subscriptions
Authentication and connected-account providersAccount identifiers, OAuth credentials, permission records, and connected-service dataAuthenticate users and maintain user-approved connections
Push-notification and email-delivery providersContact information, device tokens, and message-routing dataDeliver requested communications and alerts
Analytics, crash-reporting, and performance providersDevice, usage, diagnostic, and event dataMaintain performance and understand Service use
Security and fraud-prevention providersAccount, device, network, signal, and event dataProtect accounts, users, and the Service
Customer-support providers Account information and support communicationsRespond to requests and resolve problems

Caregivers and family members

We disclose information to a caregiver or family member according to the protected adult’s sharing choices and consent.

Enterprise and membership partners

We disclose aggregate or de-identified reports to organizations that make OUTSMARTER available to their members, customers, or employees. Any individual-level disclosure must be described during enrollment and in this policy before it begins.

Legal, safety, and security matters

We may disclose information when we reasonably believe disclosure is required by law or legal process, or is necessary to investigate fraud or abuse, protect a person from harm, enforce our agreements, or protect rights and property.

Business transfers

Information may be disclosed as part of due diligence or transferred in a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets. The recipient must honor this policy for information it receives unless users are given notice and any consent required by law.

Google Workspace data will not be transferred in a merger, acquisition, or asset sale unless we first obtain the user’s explicit prior consent.

At your direction

We may disclose information when you direct us to do so or give specific consent.

Sale, advertising, and sensitive information

OUTSMARTER does not sell personal information. We do not share personal information for cross-context behavioral advertising or use personal information for targeted advertising. We have not sold or shared personal information for these purposes during the preceding 12 months.

We do not knowingly sell or share personal information belonging to anyone under 18.

We use sensitive personal information only to provide and secure the Service, process a request you make, and meet our legal obligations. We do not use sensitive personal information to infer characteristics about you outside the scam-protection features you choose to use.

Notice at collection

The categories below describe information that may be accessed or collected when you use the associated feature. Some content is processed only on your device. Information marked as not sold or shared is not sold and is not shared for cross-context behavioral advertising.

CategoryExamplesMain purposes Sold or shared for behavioral advertisingRetention
Identifiers and account records Name, email, phone number, IP address, account ID, device ID, OAuth account ID Account, authentication, connected services, support, security NoAccount term plus the deletion period below; longer only when legally required
Subscription and commercial information Subscription tier, transaction ID, renewal status, protection history, estimated avoided lossSubscription management, account history, user-requested ledgerNoAccount term plus the deletion period below; transaction records as required for accounting and legal obligations
Device and electronic-activity information App activity, settings, permissions, diagnostics, links or domains checked, DNS requests, notification dataProvide shields, maintain performance, prevent abuseNoAccording to the feature and security criteria described below
Communication and audio informationCall audio, transcripts, voicemail, message or email content accessed on-device, screenshots shared to the appScreen communications, identify threats, provide voicemail or supportNoRaw content is handled according to the feature-specific rules; voicemail remains until deletion
InferencesThreat scores, scam categories, verdicts, reasons, and routing recommendationsIdentify and explain suspected scams NoAccount term plus the deletion period below, unless deleted sooner
Sensitive personal informationAccount credentials, contents of mail or messages, and other sensitive content a feature needs to processProvide and secure user-requested featuresNoMinimized by design and handled according to the feature-specific rules
Relationship and partner information Caregiver relationship, sharing consent, partner ID, eligibility and enrollment statusFamily protection and partner-provided benefitsNoWhile the relationship or benefit remains active, plus the deletion period below
Support and research information Support emails, survey responses, beta feedback, content submitted with permission Support, research, security, and product improvementNoFor the period reasonably needed for the request, research record, security need, or legal claim

The sources of these categories are described in Where information comes from. The provider and recipient categories are described in When we disclose information.

Cookies and website technologies

Our website may use:

– Essential cookies for security, account access, and requested site functions.

– Preference cookies that remember settings.

– Performance and analytics technologies that help us understand whether the site works.

– Embedded content, such as a video, that may allow its provider to receive your IP address, device information, and activity involving that content.

We do not use cookies for targeted advertising. Where law requires it, we request consent before using nonessential cookies or similar technologies. You can also manage cookies through your browser and any controls provided on the website.

For the full list of cookies this website uses, what each one does, and how long it lasts, see our Cookie Policy. You can review or change your cookie choices at any time on the Opt-out preferences page.

Retention and deletion

We keep personal information only for as long as needed for the purposes described in this policy. We consider the feature involved, the user’s choices, security needs, applicable legal obligations, and the time needed to resolve disputes.

Our intended retention rules are:

InformationIntended retention
Call-screening audio and live transcriptsProcessed during the screening session and not retained afterward
Voicemail audio and transcriptsUntil you delete the voicemail or the account
Raw text, email, and screenshot content analyzed on-deviceNot retained on OUTSMARTER servers; local copies follow device and app-cache controls
Threat signals, scores, verdicts, and protection history While the account is active, unless the user deletes them sooner
Locally cached Gmail and connected-email content on the deviceErased within 24 hours of disconnecting the account or deleting the OUTSMARTER account
Google and Microsoft OAuth credentials and push-subscription recordsRevoked and deleted within 24 hours of disconnecting the account or deleting the OUTSMARTER account
Remaining records tied to a connected email accountDeleted from active systems and backups within 30 days of disconnection
Account and caregiver relationship data While the account or relationship is active
Subscription and transaction records For the period needed for account administration, accounting, disputes, and legal obligations
Support communicationsFor the period reasonably needed to resolve the matter, improve support, address security, or manage legal claims
Security and access logs One year
BackupsDeleted from backups within 30 days after removal from active systems
De-identified dataAs long as it remains de-identified and useful for the permitted purpose

When you delete your account, we delete or de-identify associated personal information from active systems within 30 days, unless we need to retain limited information for security, fraud prevention, accounting, legal compliance, or legal claims. Information in protected backups is isolated from ordinary use and deleted through the regular backup-rotation process.

When we retain de-identified information, we maintain measures designed to prevent it from being associated with an individual. We do not attempt to re-identify it except to test whether our de-identification measures work, and we require recipients to follow the same restriction.

You can delete your account through the app or submit a deletion request at privacy@outsmarter.ai.

Security

We use administrative, technical, and physical safeguards designed for the nature of the information we handle. These include encryption in transit, encryption at rest for information stored under our control, access controls, authentication protections, monitoring, and security testing.

Our service providers must protect the information they process for us. Access to personal information is limited to people and providers that need it for an approved purpose.

No system can eliminate every security risk. If a security incident affects your personal information, we will investigate and provide notice when required by law.

Your choices

You can:

– Turn individual shields on or off.

– Change feature permissions through the app or device settings.

– Disconnect a Gmail or Microsoft account.

– Manage caregiver and family sharing.

– Delete individual voicemail and protection-history items where the feature allows.

– Unsubscribe from marketing messages.

– Delete your OUTSMARTER account.

Turning off Call Shield stops new OUTSMARTER screening. Because Call Shield may rely on carrier call forwarding, you may need to confirm that forwarding has been removed through the setup provided in the app or with your carrier.

Your privacy rights

Depending on where you live, you may have the right to:

– Confirm whether we process your personal information.

– Access specific personal information and learn how we use and disclose it.

– Correct inaccurate personal information.

– Delete personal information, subject to legal exceptions.

– Obtain a portable copy of personal information you provided.

– Obtain information about the third parties that received personal information where applicable law provides that right.

– Withdraw consent when processing is based on consent.

– Object to or restrict certain processing.

– Use an authorized agent.

– Appeal a decision on a privacy request.

– Receive equal service and pricing after exercising a privacy right.

We honor access, correction, deletion, and portability requests from every user, regardless of state, subject to reasonable verification and legal exceptions.

Submit a request through the app, or by emailing privacy@outsmarter.ai. Describe the right you want to exercise and the account or information involved.

We may ask for information needed to verify your identity and protect the account. An authorized agent may submit a request using the same methods, but we may require proof of authority and direct verification with the user when permitted by law.

We aim to respond within 45 days. A shorter period applies when required by law. If we need a permitted extension, we will explain the reason and expected timing.

If we deny a request, you may appeal by emailing [privacy@outsmarter.ai](mailto:privacy@outsmarter.ai) with the subject line Privacy appeal. We will explain our decision and any right to contact a regulator or state attorney general.

We do not retaliate or discriminate against anyone for exercising a privacy right.

Because OUTSMARTER does not sell personal information or share it for cross-context behavioral advertising, no sale or advertising opt-out is needed for our current practices. We recognize legally required browser-based opt-out preference signals, including Global Privacy Control, if our practices change in a way that makes an opt-out applicable.

Children

The Service is intended for adults age 18 and older. We do not knowingly collect personal information directly from children under 18.

Caregiver features are designed to protect an adult through that adult’s own account, enrollment, and consent. If we learn that we collected personal information directly from a child in a way that is not permitted by law, we will delete it.

International users

OUTSMARTER is based in the United States. If the Service is offered to people in the European Economic Area, United Kingdom, Switzerland, or another country with similar requirements, OUTSMARTER, Inc. is the controller of the personal information described in this policy.

Depending on the processing involved, we rely on:

– Performance of our contract with you to provide the features you request.

– Your consent for connected accounts, optional permissions, marketing, and nonessential cookies where consent is required.

– Our legitimate interests in securing the Service, preventing abuse, supporting users, and improving permitted features, balanced against your rights.

– Compliance with legal obligations.

You may withdraw consent at any time without affecting processing that occurred before withdrawal. You may object to processing based on legitimate interests.

Information may be transferred to and processed in the United States and other countries where our service providers operate. When required, we use recognized transfer safeguards, such as the European Commission’s Standard Contractual Clauses and the applicable United Kingdom transfer mechanism. Contact us to request information about the safeguards relevant to your data.

You may lodge a complaint with the data-protection authority where you live or work.

Changes to this policy

We will post an updated policy and change the date at the top when our practices change. We will provide notice in the app before a material change takes effect when required by law.

If we plan to use Google Workspace data for a new purpose, we will update our disclosures and obtain any consent required by Google policy before the new use begins.

Contact us

OUTSMARTER, Inc.  

11575 SW Pacific Hwy #1095

Tigard, OR 97223

1 (347) 762-7837

Privacy questions and rights requests: privacy@outsmarter.ai  

Customer support: support@outsmarter.ai

Website: outsmarter.ai