Privacy Policy

This policy describes how the Phishport Outlook Addon and Gmail Addon, and the connected Phishport service, process data when a user signs in, scans an email, or manages a paid subscription.

Data We Process

  • Microsoft or Google identity data needed to authenticate the user, such as subject identifier, display name, tenant metadata, and email address.
  • The currently open email message exported as raw EML when the user explicitly starts a scan.
  • Derived analysis output, including verdict, reasons, suspicious URL findings, suspicious attachment findings, and quota state.
  • Billing and subscription metadata needed to provision paid tiers through the website account flow.

How We Use Data

  • Authenticate the Outlook Addon and Gmail Addon user.
  • Run phishing analysis and return results in the task pane.
  • Prevent duplicate processing, enforce plan quotas, and manage plan upgrades.
  • Investigate service abuse, failures, billing issues, and support requests.

Operational Notes

The Outlook Addon and Gmail Addon only send the message currently selected by the user for analysis. The Phishport service may retain scan metadata, verdict state, and subscription state for operational, anti-abuse, and support purposes.

If you delete your account, all associated data — including scan history, linked emails, and subscription records — is permanently deleted and cannot be recovered.