Privacy policy for Carmen Monitor
Carmen Monitor by Backgrounder INC
Addendum B: Browser Extension (Carmen Monitor)
This addendum describes data practices specific to the Carmen Monitor browser extension and supplements the main Privacy Policy. Terms not defined here have the meanings given in the main Privacy Policy.
B.1 Scope. Carmen Monitor extends Backgrounder's scam- and fraud-detection service to Chrome, Brave, Edge, Firefox, and Safari. We access only the data necessary to detect scams; we do not sell it, use it for advertising or cross-site tracking, and the extension contains no third-party analytics or telemetry SDKs. The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
B.2 Messages and Webmail on Monitored Sites. On configured messaging, social, and webmail sites (such as Gmail, Outlook, Facebook, Messenger, Slack, X/Twitter, WhatsApp, Microsoft Teams, Google Messages, Discord, TikTok, Snapchat, Reddit, and LinkedIn), the extension reads message content (sender, subject, body) and email-authentication signals (SPF/DKIM/DMARC) to analyze for phishing, impersonation, and fraud. It does not read passwords, intercept network traffic, or read your browser's saved history, cookies, or clipboard data. The addresses of pages you open are covered separately in Section B.5.
B.3 Personal-Information Scrubbing. The extension includes an on-device scrubber that redacts personal information (email addresses, phone numbers, government ID numbers, payment-card and bank numbers, and names and street addresses where they are introduced, for example after "my name is" or in a greeting) in a message and in the earlier messages of its thread that the extension captures with it. So that scams can still be recognised, it keeps links, the domain of an email address that does not belong to a consumer email provider, and toll-free phone numbers. It applies only to messages the extension collects on its own from the sites it monitors, and only when personal-detail removal is turned on. You choose this during setup: the setup screen preselects "Full message," which sends message content without scrubbing, and you can instead choose "Text, personal details removed" or "Sender only" (a metadata-only mode), or change the setting later in the extension. Content you send yourself, including "Scan open email," "Ask Carmen," hover and right-click checks, page scans, and any link, screenshot, or file you attach, is sent as you submitted it and is not scrubbed; site addresses sent under Section B.5 are not scrubbed either. Where it runs, scrubbing is best-effort.
B.4 Where Analyzed Data Goes. Message content (scrubbed where Section B.3 applies) and extracted indicators are sent to the Carmen backend you configure (by default ingest.backgrounder.com), where they are stored and analyzed to produce a scam or fraud verdict. Submissions are retained under your account so you can review verdicts and history. Retention is governed by Section 4.
B.5 Automatic Site Checks. While you are signed in, the extension checks the website in your active tab for scams. Each time you switch to a tab or a page finishes loading, it sends the address of that page — the site and its path, without the query string or anything after "#", which can carry sign-in and password-reset tokens — to the Carmen backend, which returns a safety verdict for the site. The page's content is not sent, and the personal-information scrubbing described in Section B.3 does not modify addresses. The addresses of known-good sites, of sites you add to your "don't check this site" list, of browser-internal and local pages, and of your own Carmen account pages are never sent. A checked address is processed to produce the verdict and is kept in your account's check history, subject to Section 4. Automatic site checks are on by default, and you can turn them off at any time in the extension under Protection, Automatic site checks. When they are off, a site is checked only when you press "Check this site," and the optional site-blocking feature can act only on sites that have been checked.
B.6 Blocking Dangerous Sites. The optional site-blocking feature is off by default. When you turn it on, it asks for permission to see the addresses of pages you open (so it can explain what it stopped), and then stops pages from loading on sites that Carmen has already checked and rated dangerous (or, if you choose, also suspicious). The list of blocked sites is built on your device from verdicts the extension already holds. The addresses this feature sees are not sent to Backgrounder, and stopping a page sends nothing to Backgrounder. Site blocking is not available in Firefox. In Chrome and Edge, the ability to stop page requests is part of the extension's install permissions (shown as "Block content on any page") and is not used until you turn this feature on. You can turn it off, or revoke its permission, at any time; revoking it removes every block.
B.7 Diagnostic Records. The extension can send Backgrounder diagnostic records describing what happened to each message capture and check: when it happened, whether it was skipped or dropped on your device and why, which Carmen service it was sent to, any error, and, for a site check, the address that was checked. Diagnostic records never contain message text, page content, screenshots, or files, and are used only to show what happened to a check and to find and fix problems with the extension. They are sent only if you turn on "Share diagnostic records" in the extension under Permissions & privacy, What Carmen sends, which is off by default; in Firefox, Firefox also asks for your permission. Records made while the setting is off are discarded on your device and never sent. Diagnostic records we receive are deleted automatically 30 days after we receive them, or at the end of the longer retention period you chose for your checks (60 or 90 days).
B.8 Scan This Page. The optional "scan this page" feature requests permission to access other websites so the extension can read the visible text and address of the page you are viewing. This broad site access is requested only when you enable the feature and is used solely for scans you initiate.
B.9 Hover to Check (Magic Mouse). The optional hover-check feature displays a card listing scam indicators and images found in the content under your cursor. Detection runs entirely on your device; content is submitted to Carmen for a verdict only when you click "Ask Carmen." Extending this feature to all sites requires the same optional permission as "scan this page," requested only when enabled and revocable at any time.
B.10 Links, Screenshots, and Submitted Files. When you submit a URL or attach an image, screenshot, PDF, or email (.eml) file through "Ask Carmen," that content is uploaded to the Carmen backend to produce a verdict and may be retained as part of a case and report.
B.11 Connected Mailboxes. Where available, Outlook mailbox connections are established server-side through Microsoft OAuth; the extension only directs the backend to analyze specific messages and displays results. A connection is read-only unless you separately grant permission for Carmen to act on the mailbox and that capability is enabled for your account, in which case Carmen can move a message you ask it to move into a "Carmen Quarantine" folder. It cannot delete, send, or alter the contents of any message, and every move can be undone. See "Acting on a connected mailbox" in Section 2. Reading messages on webmail pages you open, including Gmail, is covered by Section B.2 and does not use a mailbox connection.
B.12 Identifiers and Local Storage. The first time it is needed, the extension generates a random identifier for its installation and sends it with the messages it submits for analysis, so they can be associated with your account. It is also sent when you connect your account, so that reconnecting the same installation replaces its earlier connection rather than adding another. This identifier is not derived from your device, browser, or account, is not an advertising identifier, and is not used for cross-site tracking. It is kept only in the extension's local storage, is removed when you uninstall the extension, and a new one is generated if you reinstall. Captured messages awaiting analysis and your credentials are stored locally in your browser; your settings are stored in your browser's synchronized storage. Your access credential is obtained through a standard OAuth sign-in to your Carmen account.
B.13 Safari. The Safari version of Carmen Monitor requests access only to the specific monitored sites listed in Section B.2. It does not request or use broad website access permissions. The optional "scan this page" and "hover to check" features requiring all-sites permission are not available in the Safari version.
B.14 Notifications. If you enable alerts, the extension shows local browser notifications (and may play a sound) to warn you about scam verdicts. These notifications are rendered locally by your browser.
B.15 Retention and Control. Retention periods for each data type accessed by the Carmen Monitor extension are set out in Section 4 of the main Privacy Policy. In particular: message content from monitored sites is retained while your account is active, subject to any shorter retention period you configure in the extension settings, and permanently deleted within 90 days of account deletion; and user-submitted content (links, screenshots, files) is permanently deleted within 180 days of account deletion. You can pause or disable monitoring per platform, decline or revoke the optional all-sites permission, disconnect the extension from your account, and remove the extension to stop further collection. Contact support@backgrounder.com to request deletion of previously submitted data.