1. Introduction
GliPpiN Toys, LLC ("Company," "we," "us," or "our") operates the MailShield Guardian mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the App, including its community social features (Scam Radar, Community Feed, Confession Booth, comments, and badges).
By using the App, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the App.
2. Information We Collect
2.1 Information You Provide
- Email content (temporary access only): If you connect your Gmail or Outlook account, we access your emails in read-only mode solely to scan for potential scams. We do not store, copy, or retain the raw content of your emails.
- Photos of physical mail: You may photograph mail pieces for scanning. Images are uploaded to secure cloud storage for processing and are automatically deleted after analysis.
- Text you paste: SMS messages, email text, or phone numbers you manually enter for analysis.
- ZIP code: If you use the Scam Radar or community features, you may provide a ZIP code so we can display local threat activity and deliver your Weekly Area Digest notification. Your ZIP code is not linked to a precise address or GPS location. We collect the ZIP code only, not any street address or coordinates.
- Community scam reports: If you submit a report to the Community Feed (BlockBrief), we collect the report text, scam type category, and your ZIP code. Reports are visible to other authenticated users within your area. No name, email, or personal identifier is ever displayed or stored with a report.
- Confession Booth posts: Anonymous scam near-miss posts you submit. We collect the post text (up to 280 characters) and your ZIP code. Posts are anonymous — no account name, email, or personal identifier is shown or stored with the post.
- Comments on community reports: If you comment on a community report, we collect the comment text (up to 280 characters). Comments are attributed only to an anonymous internal user identifier — your name is never shown.
- Reactions to reports: If you react to a community report (helpful, scary, happened to me, spreading), we store the reaction type. Reactions are attributed to an anonymous internal user identifier.
- Report flags: If you flag a community post as inappropriate, we store the flag to facilitate content moderation. Flags are not shown to other users.
- A phone number you look up (Pro feature): If you use "Who's Calling" caller-name lookup, the phone number you submit is sent to our caller-ID data provider to return the associated name and line type. See Section 5.
2.2 Information Collected Automatically
- Anonymous authentication token: We use Firebase Anonymous Authentication. No username, password, or personal login credentials are collected.
- Scan results: We store the risk level, category, and reasoning for each scan in Cloud Firestore. We do not store the original email text, SMS content, or mail images in scan results.
- Gamification data: If you use community features, we track your Fraud Resilience Score components (scans run, reports submitted, near-misses confessed, comments made, reactions given) and any Community Defender Badges earned. This data is stored under your anonymous user ID.
- Anonymous usage analytics: We collect anonymized usage data (e.g., feature usage counts, app launch events) to improve the App. This data cannot be tied to an individual.
- Device information: Basic device type and operating system version for compatibility and debugging purposes.
- Push notification tokens: If you opt in, Firebase Cloud Messaging (FCM) tokens are stored to deliver notifications including Weekly Area Digest alerts and comment notifications.
2.3 Information We Do NOT Collect
- Names, email addresses, or other personally identifiable information
- Passwords or login credentials
- Financial or payment card information (subscriptions are handled entirely by Apple/Google via RevenueCat)
- Precise GPS or device location data (we collect only a user-provided ZIP code for local community features)
- Contact lists
- Message content in its original form (analyzed in memory; not stored)
3. How We Use Your Information
| Purpose | Data Used |
| Scan emails for scam indicators | Email content (read-only, not stored) |
| Scan physical mail photos | Uploaded image (deleted after processing) |
| Scan pasted SMS/email/phone text | Text you provide (not stored after analysis) |
| Display scan history and results | Risk level, category, reasons (stored in Firestore) |
| Label potential scam calls (iOS) | Phone numbers flagged as high risk (stored on-device only via CallKit) |
| Look up who's calling (Pro feature) | Phone number you submit (sent to our caller-ID data provider; cached 90 days, shared across users so the same number is only looked up once) |
| Process subscriptions | Handled by Apple/Google via RevenueCat; we receive subscription status only |
| Send push notifications (alerts, comments, weekly digest) | Firebase Cloud Messaging token, ZIP code (digest only) |
| Display local Scam Radar and area threat activity | ZIP code (user-provided, not GPS) |
| Deliver Weekly Area Digest push notification | ZIP code, FCM token, anonymized local threat counts |
| Operate Community Feed (BlockBrief) and Confession Booth | Anonymous post text, scam type, ZIP code |
| Enable comments and reactions on community reports | Comment text, reaction type, anonymous user ID |
| Track Fraud Resilience Score and award Community Defender Badges | Anonymous usage counts (scans, reports, comments, reactions) |
| Moderate community content | Report flags, automated profanity/PII filter results |
| Improve the App | Anonymous, aggregated usage analytics |
Free trial billing: Pro and Family subscriptions include a 7-day free
trial for eligible new subscribers. Your payment method is not charged during the trial;
it is billed automatically for the plan price shown at signup when the trial ends,
unless you cancel before then. Manage or cancel anytime in your App Store or Google Play
account settings.
4. User-Generated Content and Content Moderation
4.1 Community Content
When you submit a community scam report, Confession Booth post, or comment, that content becomes part of the community feed and may be visible to other authenticated users within your ZIP area. You are responsible for the content you submit. Do not include personally identifiable information (PII), contact information, or content that identifies specific individuals.
4.2 Automated Moderation
All community content is automatically processed before publication or shortly after:
- Profanity filtering: Content containing prohibited language is blocked at submission (for new reports) or removed shortly after posting (for comments, which post first and are moderated asynchronously).
- PII redaction: Our system attempts to detect and redact Social Security numbers, card numbers, email addresses, and similar personal data from posts to protect third parties.
- Flagging and auto-hide: Community reports that receive 3 or more user flags are marked for internal review; reports that receive 5 or more user flags are automatically hidden from the public feed pending manual review. The higher hide threshold makes it harder for a small group of throwaway accounts to bury a legitimate scam warning.
4.3 Human Review and Removal
Flagged content may be reviewed by our team. We reserve the right to remove any content that violates our Terms of Service, including false reports, harassing content, or content containing real individuals' personal information. Removed content is deleted from our servers.
4.4 Content Anonymity
Community posts, confessions, and comments are displayed without any name, email, or account identifier. The only link between a post and a user is an internal anonymous ID that is never exposed publicly. We cannot de-anonymize posts on request because we do not store the mapping between posts and any personal identity.
5. Third-Party Services
We use the following third-party services to operate the App:
- Google Cloud / Firebase: Authentication, Cloud Firestore database, Cloud Storage, Cloud Functions, and Cloud Messaging. Firebase Privacy Policy
- Google Cloud Vision API: Optical character recognition (OCR) on mail photos. Image data is processed by Google and not retained after processing.
- Google Gmail API (gmail.readonly): Read-only access to your Gmail inbox for scam scanning. We do not modify, send, or delete emails. We do not store email content.
- Microsoft Graph API (Mail.Read): Read-only access to your Outlook inbox for scam scanning. We do not modify, send, or delete emails. We do not store email content.
- Anthropic (Claude AI): Extracted text (not raw emails or PII) is sent to Anthropic's Claude API for scam classification. Anthropic Privacy Policy
- Twilio (Lookup API): If you use the Pro "Who's Calling" caller-name feature, the phone number you submit is sent to Twilio's Lookup service to return the caller's name and line type. Results are cached for 90 days and shared across users of the App so the same number is not looked up twice. Twilio Privacy Policy
- RevenueCat: Manages in-app subscriptions. RevenueCat receives an anonymous app user ID and subscription transaction data from Apple/Google. RevenueCat Privacy Policy
- Apple CallKit (iOS): Scam phone numbers are stored in an on-device Call Directory Extension to label incoming calls. This data never leaves the device.
6. Data Sharing
We do not sell, rent, or trade your personal information to third parties.
Community posts, confessions, and comments are shared within the app with other authenticated users in your area — this is the core function of the community features. All community content is anonymous (no name or identifier attached). We share data with third-party service providers only as described in Section 5, and only to the extent necessary to provide the App's functionality. We may disclose information if required by law, regulation, or legal process.
7. Data Retention
- Uploaded mail photos: Deleted from cloud storage after OCR processing is complete.
- Email content accessed via OAuth: Read in real time and never stored on our servers.
- Scan results: Retained in your account until you request deletion.
- Community reports and confessions: Retained until removed by moderation or deleted upon account deletion request.
- Comments and reactions: Retained until you delete them or your account is deleted.
- ZIP code: Retained as long as you use community features; removed upon account deletion.
- Caller-name lookup results: Cached for 90 days per phone number, shared across users; not tied to any individual account.
- FCM push tokens: Retained while the App is installed; stale tokens are automatically removed when push delivery fails.
- Anonymous auth tokens: Retained as long as the App is installed.
- Analytics data: Retained in anonymized, aggregated form indefinitely.
8. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS/SSL) for all data transfers
- Encryption at rest for stored data in Firebase/Google Cloud
- AES-256 field-level encryption for sensitive scan data
- Firebase App Check cryptographic verification — only the genuine MailShield Guardian app can read or write community data
- Firebase Security Rules restricting data access to authenticated users and data owners
- API keys and secrets stored securely using Firebase Secret Manager
No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
9. Your Rights and Choices
9.1 All Users
- Revoke OAuth access: You may disconnect your Gmail or Outlook account at any time through your Google or Microsoft account settings.
- Delete your data: You may request deletion of all data associated with your account by contacting us at support@glippintoys.com. This includes community posts, confessions, comments, reactions, and gamification data.
- Disable CallKit: You may disable scam call labeling in iOS Settings → Phone → Call Blocking & Identification.
- Opt out of push notifications: You may disable notifications in your device settings or within the App's notification preferences.
- Opt out of weekly digest: You may disable Weekly Area Digest notifications in the App's notification preferences at any time.
9.2 California Residents (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect about you
- Request deletion of your personal information
- Opt out of the sale of personal information (we do not sell personal information)
- Not be discriminated against for exercising your privacy rights
To exercise these rights, contact us at support@glippintoys.com.
9.3 European Economic Area Residents (GDPR)
If you are located in the EEA, you have the right to:
- Access, correct, or delete your personal data
- Restrict or object to processing of your personal data
- Data portability
- Withdraw consent at any time
- Lodge a complaint with your local data protection authority
Our legal basis for processing is your consent (granted when you use the App and connect accounts) and our legitimate interest in providing fraud protection services.
10. Children's Privacy (COPPA)
The App is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. Community features (reporting, commenting, posting) are also not available to users under 13. If you believe a child under 13 has provided us with personal information or submitted community content, please contact us at support@glippintoys.com.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy within the App and updating the "Effective Date" at the top. Your continued use of the App after changes are posted constitutes your acceptance of the updated policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us: