ThunderSweep Help Center

Getting Started

1

Connect Your Accounts

Click the ThunderSweep icon in your browser toolbar, then click "Connect Account". You'll be asked to sign in with Google and grant access to your Gmail and Google Drive.

2

Start a Scan

Once connected, click "Scan Gmail & Drive". ThunderSweep will scan your emails and Drive files locally for sensitive information like tax documents, SSNs, and financial records.

3

Review Results

After the scan completes, click "View Full Results" to open the dashboard. You can filter, search, download, or delete sensitive emails from there.

How Scanning Works

All processing happens locally in your browser. Your emails are never sent to any external server. ThunderSweep uses pattern matching and keyword analysis to detect sensitive content.

What We Detect

Category Examples
Tax Documents W-2s, 1099s, tax returns, IRS forms
Financial Bank statements, credit card statements, loan documents
SSN Social Security Numbers in filenames or email body text
Medical Medical records, prescriptions, HIPAA documents
Legal Contracts, legal agreements, court documents
Business EINs, LLC documents, business filings, incorporation papers
Employment Pay stubs, offer letters, I-9s, W-4s
Suspected Attachments with sensitive keywords that couldn't be fully verified

Supported File Types

ThunderSweep scans the content of: PDF, DOCX, XLSX, CSV, TXT, RTF, ODT, ODS, and ZIP archives. Files over 10 MB are scanned by filename only.

Limitations & Unsupported Files

Understanding Results

Results are grouped by email conversation (thread). Each result shows:

Suspected Items

Items marked as "Suspected" have filenames containing sensitive keywords but could not be fully verified (e.g., the file content couldn't be read). Review these manually to determine if they need action.

Deleting Emails

Deleted emails are moved to Gmail Trash and can be recovered for 30 days. After 30 days, they are permanently deleted by Gmail.

To delete sensitive emails:

  1. Select emails using the checkboxes in the results table
  2. Click "Delete Selected"
  3. You'll be offered to download attachments or a CSV report before deleting
  4. Confirm the deletion to move the emails to Trash

Real-Time Monitoring (Shield/Family)

Shield and Family subscribers get continuous background monitoring and real-time outbound protection for both Gmail and Google Drive. ThunderSweep will:

Outbound scanning does not block sending — it's an informational warning so you can review your attachments before clicking Send.

Privacy & Security

How Zero-Knowledge Works: TS Share & TS-X-Port

At ThunderSweep, we believe that true security means you are always in control of your data. We've designed our core features around "zero-knowledge" principles—meaning we process your data without ever having the ability to read it.

TS Share: Secure File Sharing

When you send a secure file, our servers never see your private data or the key needed to unlock it.

  1. Local Decryption: ThunderSweep first decrypts the file on your local machine.
  2. One-Time Key: A brand new, random, single-use encryption key is generated.
  3. Local Re-encryption: The file is re-encrypted on your device using this one-time key (via AES-256-GCM).
  4. Secure Upload: Only this fully encrypted, unreadable blob of data is sent to our servers.
  5. The Magic URL: A sharing link is created. The one-time encryption key is appended to the end of the URL, after a hash symbol (#). (e.g. https://thundersweep.app/share/file123#SecretKey)
  6. Zero-Knowledge Transfer: Browsers are hard-coded to never send anything after a # fragment to a web server. We see the request for the file, but we never receive the secret key.
  7. Recipient Decryption: When your recipient clicks the link, their browser queries our server for the encrypted file, reads the key from their address bar's # fragment, and decrypts the file locally.

TS-X-Port: Digital Sovereignty

Security shouldn't be a trap. TS-X-Port ensures you own your ciphers and can access your data forever, independent of ThunderSweep.

  1. Industry-Standard Encryption: Files are secured in your ThunderVault using AES-256-GCM, and your password is strengthened using PBKDF2.
  2. Export Your Vault: You can export all your encrypted files (.enc) and your configuration file containing your cryptographic "salt" (.tsv1).
  3. No Proprietary Lock-in: Because we use open cryptographic standards, your data can be decrypted using any standard programming language.
  4. The Unlocking Script: We provide a standalone, open-source script (like our manual_decrypt.js) that runs completely offline.
  5. Local Execution: You provide the script your master password, salt, and the exported file. The script acts offline to verify integrity and decrypt your data perfectly.

Vault — Button Guide

File Actions (⋯ menu)

Open

Decrypts the file and opens it in a secure temporary preview. Nothing is permanently decrypted to your disk.

↩ Restore to Drive

Decrypts the file and places it back in your Google Drive as a regular file. Use this to permanently un-vault a document.

↩ Restore to Gmail

Puts an archived email back into your Gmail inbox, exactly as it was.

📥 Export .eml

Downloads an archived email as a standard .eml file you can open in any email client (Outlook, Apple Mail, etc.).

📅 Set Expiry / Edit Expiry

Set a personal reminder date to review or remove a file from your Vault. This does not auto-delete the file or expire any shared link — it simply sends you a notification so you remember to take action. Useful for tax records you only need for 7 years, contracts with renewal deadlines, or any time-sensitive document you don't want to forget about.

🔗 TS Share

Securely send the file to another ThunderSweep user. Files are encrypted end-to-end — only the recipient can open them. Free plan: 5 sends/month. Shield: unlimited.

🏷️ Tags

Add custom labels to organise your files (e.g. "2024", "reviewed", "urgent"). Tags appear as filter shortcuts in the sidebar.

🗑️ Delete

Moves the file to Trash. Files in Trash can be restored for up to 30 days before permanent deletion.

Toolbar Buttons (Bulk Actions)

Select All

Checks all visible files so you can act on them in bulk. You can also check files individually using the checkbox on each row.

Restore Selected

Decrypts and restores all checked files to Google Drive in one go.

TS Share

Sends all checked files to a recipient as a single encrypted transfer. The recipient must have ThunderSweep installed to accept.

TSxport

Packages all checked files into a standard password-protected ZIP file. Ideal for sharing with someone who doesn't have ThunderSweep — they can open the ZIP with any standard app (7-Zip, WinZip, WinRAR, Keka). Set a strong password and share it separately from the file, never together.

Troubleshooting

Scan seems stuck or very slow

Large inboxes can take several minutes. If the scan shows no progress for over 60 seconds, try pausing and resuming, or close the popup and reopen it. Your scan progress is saved.

"Unable to connect" error

Make sure you're signed into Gmail in your browser. Try disconnecting and reconnecting your account. If using multiple Google accounts, ensure the correct one is selected.

No results found but I know I have sensitive emails

ThunderSweep scans emails from the last few years. Very old emails or emails with unsupported attachment types may not be detected. Try running the scan again — it will pick up where it left off.

Download or delete not working

These features require a paid plan (Scan Unlock, Shield, or Family). If you have a license key, enter it in the popup or dashboard sidebar to activate.

"You're offline" message

ThunderSweep needs an internet connection to access the Gmail API. Check your network connection and try again.

Extension not showing in toolbar

Click the puzzle piece icon in Chrome's toolbar and pin ThunderSweep. If you don't see it, go to chrome://extensions and make sure it's enabled.

Plans & Pricing

Plan Price Features
Free $0 2 scans/week, view up to 3 results per scan
Clean Sweep $14.99 one-time Unlock all results from one scan, download & delete
Shield $4.99/mo Unlimited scans, all results, real-time inbound & outbound monitoring, security score
Family $9.99/mo Everything in Shield for up to 5 Gmail accounts

Managing Your Subscription

How do I cancel or unsubscribe?

Because ThunderSweep does not have backend servers or maintain user accounts, we do not store your payment information. All payments and subscriptions are handled securely through Gumroad.

If you need to cancel your Shield or Family subscription, you must do so directly through your Gumroad receipt or account:

  1. Open the email receipt you received from Gumroad when you purchased (Search your inbox for "ThunderSweep").
  2. Click the Manage membership or Generate License Key link.
  3. Click Cancel Subscription at the bottom of the page.
Note: We cannot manually cancel subscriptions for you because we do not have access to your payment profile data.