Privacy Policy
Effective date: August 24, 2026
1. Scope and contact
This Privacy Policy explains how the PhishMare Chrome extension and the PhishMare services at phishmare.com (together, “PhishMare”) collect, process, store, protect and share information. Questions and privacy requests can be sent to privacy@phishmare.com.
2. Information we collect
Automatic URL protection
When automatic protection is enabled, PhishMare processes the URL of the active page, including its hostname, path and any query string in that URL, together with technical detection results. The request also necessarily exposes standard connection information to our servers, such as the requesting IP address, request time, endpoint, response status and latency. PhishMare does not collect a complete browser history or track pages while the extension is disabled.
User-initiated Gmail analysis
PhishMare reads an open Gmail message only after the user chooses to scan it. The extension may send the sender, subject, plain-text and HTML message body, extracted links, and attachment metadata such as file names and available cryptographic hashes. It does not request or send Gmail account passwords, session cookies or authentication tokens.
User-initiated sandbox analysis
When the user submits a URL to the sandbox, that URL is sent to PhishMare and opened in an isolated browser. The service analyzes page and redirect behavior. If the user requests a screenshot, the resulting page screenshot is returned to the extension and may be held temporarily for delivery and operational cleanup.
Issue reports
If the user submits a report, PhishMare collects the report type, the affected URL, the selected action, an optional note, risk metadata, a privacy-safe installation identifier and the submission time. Before a report URL is stored, credentials, query strings and fragments are removed. Reports are voluntary.
Website feedback and launch-discount reservations
If a visitor submits product feedback, PhishMare collects the supplied email address, rating and written feedback. If a visitor reserves the six-month launch discount, PhishMare collects the supplied work email, optional company name, team-size range, expected monthly-price range, expected purchase timing and optional message. These forms are voluntary, and a reservation is not a purchase or payment commitment.
Extension-local information
The extension stores settings and temporary warning overrides in Chrome local storage. A temporary override expires after no more than 24 hours. This local information is removed when the extension is uninstalled, subject to Chrome's own behavior.
3. How we use information
We use the information described above only to:
- analyze URLs, emails and submitted pages for phishing and other threats;
- display risk results, warnings and high-risk blocking pages;
- provide sandbox results requested by the user;
- prevent abuse, enforce rate limits and protect service availability;
- investigate failures and maintain the security and reliability of PhishMare; and
- use voluntary reports to validate and improve threat reputation and detection quality.
PhishMare does not use user data for advertising, user profiling, creditworthiness, lending, or purposes unrelated to its phishing and threat-protection function. PhishMare does not sell user data.
PhishMare's use and transfer of information received from Google APIs and Google services adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Access to Gmail message content is limited to the user-facing email analysis feature, occurs only when the user requests a scan, and is not used for advertising or transferred for unrelated purposes.
4. Processing, storage and retention
- Email scan content: sender, subject, bodies, links and attachment metadata are processed to produce the requested result and are not intentionally written to PhishMare's persistent application databases. They remain in memory only for the time needed to complete the request, except where temporary infrastructure processing is required for security or fault handling.
- URL scan cache: URL analysis results may be cached to improve speed and reliability. Current cache lifetimes range from one hour for high-risk results to 24 hours for safe results. A URL supplied in a scan may therefore remain in the cache for up to 24 hours.
- Threat reputation: URL, domain and file reputation indicators that are needed to identify threats may be kept while they remain useful and accurate for security detection.
- Issue reports: sanitized report URLs, report details, optional notes and associated metadata are retained while needed to investigate reports, prevent report manipulation and improve detection, or until a valid deletion request is completed where applicable.
- Feedback and reservations: website feedback and launch-discount reservations are retained while needed to evaluate product demand, respond to the submitter and prepare the relevant launch offer, or until a valid deletion request is completed.
- Sandbox artifacts: browser processes are terminated after analysis. Requested screenshots and temporary artifacts are kept only long enough to return the result and perform operational cleanup, unless retention is required to investigate abuse or a security incident.
- Operational and security logs: limited connection and service metadata may be retained for up to 30 days, unless a longer period is reasonably necessary to investigate abuse, fraud, outages or security incidents. Logging is designed to exclude email bodies, passwords, cookies and authorization tokens.
5. Sharing and service providers
PhishMare does not sell or rent user data. Information is shared only as needed to provide and secure the service:
- hosting, database, caching, networking and security providers process limited information on PhishMare's behalf to operate the service;
- OpenPhish and URLhaus data may be used to compare submitted URLs with threat intelligence. RDAP/WHOIS providers may receive a domain name to obtain public registration information;
- a sandboxed destination website necessarily receives the sandbox browser's request and may observe the sandbox host's network address; and
- information may be disclosed when required by law or when reasonably necessary to protect users, PhishMare or the public from fraud, abuse or security threats.
Gmail message bodies are not shared with advertising networks or sold to data brokers. Third-party services process information under their own privacy terms.
6. Security
PhishMare uses encrypted HTTPS transport, access controls, input limits, restricted service networking, privacy-conscious logging and isolated sandbox execution. No technical system can guarantee absolute security, but we work to limit collection and access to what is necessary for the service.
7. User choices and rights
Users can avoid Gmail processing by not starting an email scan, avoid sandbox processing by not submitting a sandbox URL, disable the extension, or uninstall it. Depending on applicable law, a user may ask to access, correct or delete personal information associated with them, or object to or restrict its processing. Send a request to privacy@phishmare.com and include enough information to identify the relevant report or record without sending passwords, cookies or authentication tokens. We may need to verify the request and may retain information where required for security, legal compliance or the rights of others.
8. Children
PhishMare is not directed to children under 13 and does not knowingly collect personal information from children under 13. If such information is identified, contact us to request its deletion.
9. International processing
Information may be processed in countries other than the user's country where PhishMare or its service providers operate. We apply the safeguards described in this policy regardless of processing location.
10. Changes to this policy
We may update this policy when PhishMare's practices or legal obligations change. The effective date above will be updated, and material changes will be communicated through the website or extension where appropriate.
Anonymous download measurement
When a visitor follows the Chrome Web Store link from our download page, PhishMare records an anonymous click event and sets a first-party cookie named pm_store_visitor. The cookie contains only the value 1, is not linked to an account or identity, and is used solely to avoid counting repeated clicks from the same browser as additional unique visitors. It expires after one year. Aggregate click totals are processed using Cloudflare Analytics Engine and are not sold or used for advertising.
When a visitor opens the feedback and early-reservation page, PhishMare records an aggregate page-view event and sets a first-party cookie named pm_feedback_visitor. It also contains only 1, expires after one year and is used to distinguish repeat page views from unique browsers so that aggregate reservation conversion can be measured.