Privacy Policy
Effective and last updated: August 24, 2026
1. Who operates PhishSure
PhishSure is operated by Optimaize (“PhishSure”, “we”, “us”). Privacy and data-rights questions can be sent to privacy@optimaize.io.
2. PhishSure’s single purpose
PhishSure’s sole purpose is to analyze an email that a user has opened in Gmail and explicitly chooses to scan, then display phishing indicators, a risk assessment, and recommended actions.
3. Data processed when you scan
Depending on what Gmail makes available, a scan can process the original email source or the visible message. This can include:
- sender, recipient and reply-to addresses and names;
- subject, message body, message identifiers, date and relevant email headers;
- link destinations and visible link text; and
- attachment names, content types and sizes. PhishSure does not open attachments.
Collection begins only after you click Scan. The extension does not continuously monitor Gmail, read unopened messages, access your contacts, or use the Gmail API or your Google password.
4. How the data is used
The PhishSure backend parses the selected message, runs security heuristics, applies access and abuse controls, and sends structured message data to OpenAI for the requested phishing analysis. Before that transfer, PhishSure replaces recognizable email addresses, telephone numbers and IBANs in text with placeholders. Automated redaction cannot guarantee removal of every piece of personal information, so other personal details present in the chosen message may still be processed.
5. What is stored and for how long
| Data | Storage and retention |
|---|---|
| Raw email content | Processed in memory for the scan and not stored in the PhishSure database after the request completes. |
| Scan metadata | Hashed subject/message identifiers, sender domain, plan tier, risk result, security signals, provider/model and error metadata are automatically deleted after 30 days. |
| Feedback | Your selected feedback verdict and a hash of any optional comment are linked to a scan and deleted with its scan metadata after 30 days. |
| Free-tier abuse controls | Random access-token hashes, hashed IP addresses, dates and counters are automatically deleted after 31 days of inactivity. |
| Paid subscription data | Stripe identifiers, billing email, subscription scope/status and access-key records are kept while needed to provide the subscription, resolve billing issues and meet legal obligations. |
| Extension-local data | An optional paid access key and a random free-tier token are kept in Chrome extension-local storage until you clear the key, remove the extension, or clear extension data. |
6. Service providers and data sharing
We transfer data only when necessary to provide, secure or operate the requested service:
- OpenAI processes the structured email data to create the phishing assessment.
- Railway hosts the backend and its operational database.
- Stripe processes subscriptions and payments. PhishSure does not receive full payment-card details.
- Google Analytics 4 processes limited website usage data only after you accept analytics cookies.
We may also disclose information when legally required or when necessary to investigate security, fraud or abuse. We do not sell user data, use it for personalized advertising, or permit humans to read email content except with the user’s specific consent, for security/abuse investigation, or where required by law.
7. Website analytics and cookies
Google Analytics 4 is optional. Analytics storage, advertising storage, advertising user data, and ad personalization are denied by default. When analytics is configured, the Google tag is present in the page source, but automatic page views are disabled and no measurement event is sent until you explicitly accept. Advertising consent remains denied even after analytics is accepted.
If accepted, Google Analytics receives a manual page view and a small set of fixed website-funnel events, such
as selecting the extension download. Event data uses only a fixed page label and path. Query strings, fragments,
verification tokens, personal data, and internal record identifiers are not sent. Google may set _ga
cookies after acceptance. Your accept or reject choice is stored in localStorage. You can change it through
Cookie settings; rejecting analytics also removes accessible Google Analytics cookies.
8. Security
Message data is transmitted over HTTPS. Production secrets are kept outside the extension package, access is restricted, stored message fields are minimized or hashed, and raw message content is not retained by the PhishSure database. No security system can eliminate every risk.
9. Your choices and rights
You can avoid processing by not clicking Scan. You can clear the paid key from the PhishSure panel and remove all extension-local data by uninstalling the extension or clearing its storage. Depending on your location, you may request access, correction, deletion, restriction, portability or an objection to processing. Email privacy@optimaize.io with the billing email or paid-key identifier needed to locate your account. We may ask for verification and may retain records where required by law. Subscription cancellation is available through the Stripe customer portal from the extension.
10. Children
PhishSure is not directed to children under 13 and is not intended for use without any consent required by local law.
11. International processing and changes
Our providers may process data in countries other than yours, subject to their contractual safeguards. We will update this page when our practices materially change and will provide any additional notice or consent required before new collection begins.
12. Chrome Web Store Limited Use
PhishSure’s use and transfer of information received from Google services adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide or improve the extension’s disclosed phishing-analysis purpose, to maintain security, or as otherwise permitted by that policy.