Effective 1 August 2026 · Version 1.0
Privacy policy
Phishing Protect is designed so that there is almost nothing to write here. The extension runs entirely inside your browser and does not send your browsing anywhere — including to us.
1. Summary
- The extension has no server. It makes no network requests of its own.
- Your browsing history is never collected, logged, uploaded or shared.
- The addresses of pages you visit are examined in memory and discarded immediately.
- The only data kept is your own configuration — your protected domains, allowlist and settings — held in your browser profile.
- There is no account, no login, no analytics, no advertising and no tracking of any kind.
2. Who we are
Phishing Protect is operated from Queensland, Australia. For any privacy question, or to exercise a right described in this policy, write to [email protected]. We are the data controller for the limited personal information described in sections 7 and 8.
3. What the extension collects
Nothing. The extension does not transmit data to us or to any third party. It contains no analytics library, no crash reporter, no advertising identifier and no remote configuration.
When you open a page, the extension reads that page's address and compares it, in your browser's memory, against the domains you have listed. The address is not written to disk, not queued, not batched and not sent anywhere. When the comparison finishes, it is gone.
We therefore hold no record of which sites you visit, when you visited them, how often a warning was shown to you, or whether you dismissed one.
4. What is stored on your device
The extension writes the following to your browser's own extension storage:
- The domains you have chosen to protect, and any alternate domains you have associated with them.
- Domains you have marked as allowed after dismissing a warning.
- Your settings: sensitivity level, per-domain overrides, whether the toolbar icon changes colour, and whether sync is enabled.
This data belongs to you. It stays on your device unless you enable browser sync (section 5) or export it yourself. Removing the extension deletes it. You can also clear it at any time from the extension's settings page.
5. Browser sync
Sync is off by default. If you turn it on, your configuration is handed to your browser's built-in sync service so it follows your browser profile onto your other devices. From that point the data is handled by Mozilla or Google under their own privacy terms, not ours — we never see it. Turning sync off keeps the configuration local to each device.
6. Permissions
Browsers describe extension permissions in broad terms, so the request can look larger than the use. What we ask for and why:
- Access to the addresses of pages you visit. Your browser may present this as access to your browsing history or to data on the sites you visit. It is what allows the comparison to happen at all. The extension uses the address only, and only at the moment the page loads.
- Storage. To keep the configuration described in section 4.
- Scripting on the current page. To draw the warning over a page that has been flagged. Nothing is injected into pages that pass.
The extension requests no permission to make network requests, because it makes none.
7. This website
This site is static. It sets no cookies, runs no analytics and embeds no tracking pixels or social widgets. Web fonts are loaded from Google Fonts, which receives your IP address as part of that request; if you would prefer that not to happen, the fonts can be blocked without affecting how the site works.
Our hosting provider and content delivery network keep standard server logs — IP address, timestamp, requested page, user agent — for security and abuse prevention. These are retained for a short period and are not used to profile visitors.
8. Email you send us
If you write to one of the addresses on our contact page, we receive your email address, your message and anything you choose to include in it. We use it to answer you and to keep a record of the issue. We do not add you to a mailing list and we do not pass your message to anyone else unless you ask us to, or unless we are required to by law.
Please don't send passwords, session cookies, identity documents or other credentials. If you need to report a security issue, see the security address on the contact page.
9. Legal bases
For people in the United Kingdom, the European Economic Area and other regions with equivalent law, we rely on:
- Legitimate interests — to answer correspondence, to keep server logs for security, and to operate the site.
- Legal obligation — where we are required to retain or disclose information.
We do not rely on consent for the extension, because the extension processes no personal data on our behalf.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal information, to receive it in a portable format, and to complain to a supervisory authority. In Australia this is the Office of the Australian Information Commissioner; in the UK, the Information Commissioner's Office; in the EEA, your national data protection authority.
In practice the only personal information we hold is correspondence, so a request usually means deleting an email thread. Write to [email protected] and we will respond within 30 days.
We do not sell or share personal information, and we have not done so in the preceding twelve months. There is nothing to opt out of.
11. Retention
- Configuration data: kept on your device until you change or delete it, or remove the extension.
- Correspondence: kept for up to 24 months after the matter is closed, then deleted.
- Server logs: kept for up to 30 days.
12. Children
The extension is not directed at children and we do not knowingly collect information from anyone under 16. Since the extension collects nothing, this concerns correspondence only; if a child has written to us, tell us and we will delete the message.
13. Add-on stores
The extension is distributed through Mozilla Add-ons and the Chrome Web Store. Those platforms collect their own information about installs, updates, ratings and crashes under their own privacy policies, and share aggregate statistics with us — install counts and version breakdowns, never anything identifying an individual user. We have no way to link that data to a person.
14. Changes to this policy
If this policy changes, the version number and effective date at the top of the page change with it. Material changes — anything that alters what is collected or where it goes — will also be noted in the extension's release notes and on its store listings. Continuing to use the extension after a change means you accept the updated policy.
15. Contact
Privacy questions and rights requests: [email protected]
Everything else: see the contact page.