Privacy policy · effective September 27, 2026
What MakoSift keeps, and what it never does
MakoSift is a service from Mako Logics LLC of Montgomery, Texas. A business connects its Microsoft 365 account, chooses which mailboxes MakoSift may read, and MakoSift checks incoming email in those mailboxes for invoice fraud, impersonation and unwanted marketing. We run it for that business. We are its service provider, not a seller of its data.
The email we check
MakoSift reads only the mailboxes the business chose. Microsoft enforces that limit, and MakoSift tests it continually and stops reading if it ever fails. For each email MakoSift keeps the sender, the mailbox, what it decided, the reasons, and the times. It keeps the subject for up to 90 days so people can review decisions, then removes it. It never stores an email's body or attachments. When an email shows bank details, MakoSift keeps a one-way fingerprint of the account so it can spot a changed account later. It never keeps the account number itself.
MakoSift never deletes email. It labels email, or moves it to a folder in the same mailbox, and every move can be undone.
The AI that helps decide
To judge an email, MakoSift sends an AI model the sender, the mailbox, the subject, attachment names, key message headers and the opening text. For the closer fraud and impersonation check it also sends up to the first 2,000 characters of the text, which can include link addresses as plain text. MakoSift never opens attachments and never visits links in email. Most checks run on Amazon Bedrock. The closer fraud check currently runs on Anthropic's Claude API, because that model is not yet available to MakoSift on Bedrock; businesses marked as handling health information use Bedrock only. Neither provider may train its models on this data. Anthropic may keep API requests for up to 30 days to detect misuse, then deletes them.
Email the filters already held
For email that Microsoft 365 or AppRiver quarantined, MakoSift keeps the sender, subject and the reason it was held for 30 days, then deletes that record, so people can see and release it in one place.
Unsubscribing
MakoSift notes which mailing lists send to each mailbox: the sender and the web address of their unsubscribe service, never the unsubscribe link itself, because that link identifies the person. When someone presses Unsubscribe, MakoSift reads the link from the newest email at that moment and sends the sender the standard one-click unsubscribe request. It does this only for senders it can verify, never for spam. It then keeps the date it asked and whether mail kept arriving, as a record.
People who sign in
People sign in to the MakoSift portal with their Microsoft work account. We receive their name, work email address and company, and use them only to show each person their own mailboxes. Company administrators see counts and settings, not other people's email.
Payments
Businesses that pay by card enter the card on Stripe's own pages. Stripe keeps the card; MakoSift never sees or stores card numbers. We keep Stripe's reference numbers for the business, its plan, and whether payments went through.
This website
makosift.com uses no cookies, no analytics and no advertising trackers. Like any website, its host keeps ordinary server logs (such as IP addresses) for security.
Who helps run MakoSift
Amazon Web Services hosts MakoSift in the United States and runs Amazon Bedrock and our email sending. Anthropic provides the Claude API. Microsoft provides the business's own Microsoft 365. Stripe handles card payments. Cloudflare runs our domain names and forwards mail to support@makosift.com. Vercel hosts this website. We do not sell or rent personal information, share it for advertising, or use it for anything except running MakoSift for the business that signed up.
How long we keep it
Subjects: 90 days. Records of quarantined email: 30 days. Decisions, mailing list notes and unsubscribe records: while the business uses MakoSift. When a business leaves, we delete its data within 30 days and confirm that in writing.
Security
Data is encrypted in storage and in transit. MakoSift signs in to Microsoft with a certificate whose key never leaves Amazon's key vault. Consoles need a password and a one-time code, and access is logged. If we learn that someone got to a business's data without permission, we tell that business without unreasonable delay, and we give notice as Texas law requires (Tex. Bus. & Com. Code §521.053).
Your choices
Because we work for the business, a person who wants to see, correct or delete information about them should ask the business, and we help it answer. You can also write to us directly at support@makosift.com. California residents have rights under the CCPA; we act as a service provider under it and handle requests on the business's instructions. MakoSift is for businesses and is not directed at children.
Changes
If we change this policy, we update the date at the top and tell businesses that use MakoSift by email before a change that affects how their data is used takes effect.
Questions: support@makosift.com · Mako Logics LLC, Montgomery, Texas.