Privacy Policy
Effective: August 20, 2026
PhishMare processes the URL of pages you visit for automatic threat analysis. When you explicitly scan Gmail, the sender, subject, text and HTML body, extracted links, and attachment names or hashes are sent to PhishMare. A submitted sandbox URL is loaded by an isolated browser; a screenshot is returned only when requested.
Storage and logs
URL reputation results and issue reports may be retained to improve detection. Reports can include URL, category, action, note and risk metadata. Operational logs record service status and errors; production logging is designed not to record email bodies, cookies, passwords or authorization tokens. Temporary warning overrides remain locally in Chrome for up to 24 hours.
Third parties
PhishMare may query OpenPhish, URLhaus and RDAP/WHOIS providers. A domain or URL may be transmitted to them. Gmail content is read locally after installation and transmitted only when the user initiates a scan. PhishMare does not sell personal information or use message content for advertising.
Retention and choices
Launch-stage retention periods are not yet contractually fixed. Reputation and feedback records may remain until no longer useful or a valid deletion request is completed. Uninstalling removes extension-local data. Use Support for access or deletion requests.