phishtriage

For everyone · 7 minutes

What PhishTriage sees

What PhishTriage looks at, what it sends to us, what we keep, and how to have it deleted. The short version: it sends us an email or a web page only when you press its Analyze button.

This page is a plain summary. The privacy policy is the official version, and it has every detail. The policy also describes the next version of PhishTriage. Where today’s version is different, this page says what today’s version does. If you look after PhishTriage for a company, read Data handling.

When you check an email

When you press Analyze Current Email, PhishTriage reads the email you have open and sends it to us to be checked. In Gmail, for example, it sends:

So your own email address is usually part of what is sent.

When you check a web page

When you press Analyze Current Page, PhishTriage sends us:

A web address can contain your name, something you searched for, or a code that keeps you logged in. If it does, that is sent too.

PhishTriage does not read what you type into boxes on a page, such as a password box. But some pages let you write longer text, such as an email in webmail. What you write there can count as words on the page, and then it is sent. Also see the next part, about pictures.

Pictures of dangerous pages

This is on until you switch it off. When you check a web page and the answer is Don’t trust this or Be careful, PhishTriage also sends us:

We use them to report the page, so it can be taken down. Nothing is sent when the answer is Looks safe.

If you typed something on the page and it is still on screen, it is in the picture. Some pages also copy what you type into their code, and then it is in the code we receive.

Nothing is ever taken in Gmail, or in Outlook at outlook.office.com, outlook.office365.com or outlook.live.com.

If you read email on any other website — for example Yahoo, Proton, Fastmail, your workplace’s own webmail, or Outlook at outlook.cloud.microsoft — PhishTriage treats it like any other web page. If a check there comes back Don’t trust this or Be careful, the picture is of your inbox. The page’s code we receive also holds the email you had open, and anything else on that page. To stop this, switch off Keep evidence of phishing.

To switch it off:

  1. Click the PhishTriage icon at the top right of your browser. It’s a small drawing of a shark. The PhishTriage window opens. If you can’t see the icon, click the puzzle-piece icon first, then PhishTriage.

  2. Click Settings. The settings open below it.

  3. Click the switch next to Keep evidence of phishing. The switch is blue when it’s on. After your click, it is no longer blue.

    When you first install PhishTriage, Keep evidence of phishing is on, so its switch is blue, and Background protection is off. Each stays that way until you change it.

If your employer looks after your browser, they may have set this for you. The switch then shows Managed, and you can’t change it.

Who checks it

We first ask an AI model on a computer we run ourselves. An AI model is a computer program that reads the email or page and judges it. If our model can’t give an answer, the email or page goes to Claude, an AI service from a company called Anthropic. Under its terms, Anthropic does not use it to train its AI. The privacy policy names every outside company involved.

Does PhishTriage read my mailbox?

No. PhishTriage does not go through your emails. It reads one email — the one you have open — and only when you press Analyze Current Email.

On other webmail websites (see above), you press Analyze Current Page instead. It reads the whole page, up to a limit, including the list of emails you can see.

In Gmail, and in Outlook at the three addresses above, PhishTriage is loaded on every page, so it can keep its button in place. While it waits, it looks only at how the page is laid out, not at your emails. It sends nothing until you press the button. Background protection, if you switch it on, is separate: see below.

It does not look through your browsing history. It can’t see which account your browser is signed in with.

Does it open attachments?

No. When you check an email, PhishTriage reads only the names of its attachments. It never reads what is inside them.

Files you download are different. See Downloaded files below.

What does Background protection send?

Background protection is off until you switch it on. When it is on, each time you open a page, PhishTriage sends us the name of its website — for example, shop.example — so it can warn you if the site is known to be dangerous. It sends only the name: not the rest of the address, and not what is on the page.

Under Advanced there are two more options. Both are off until you switch them on:

When you switch Background protection on, your browser asks for permission. The message may say PhishTriage can read and change all your data on the websites you visit, and read your browsing history. This is expected. It lets PhishTriage notice each new page you open from then on. It does not read the pages you visited before.

If your employer looks after your browser, they can switch these on or off for you. The switch then shows Managed, and you can’t change it.

What is kept, for how long, and who can see it

What we keep is stored in a database on our own computers, in Estonia.

Who can see it. In the PhishTriage portal, your checks are shown only to you, unless you are part of a team at work. Then it depends on how the team is set up:

Either way, the team sees and counts your checks only from the moment you joined it. While you are in the team, the portal does not show your checks from before you joined, not even to you.

How long we keep your checks

We keep your checks for a year. Then they are deleted automatically. The same goes for your Background protection records and your downloaded-file records.

If you sign in to the portal, you can choose a shorter time, from 7 days up:

  1. Open the PhishTriage portal and sign in. Your Dashboard opens.

  2. Scroll down to Your data. Under it is How long we keep your scans.

  3. Next to Keep my scans for, choose a time.

  4. Click Save. A message below it starts with “Saved.”

The two buttons under an answer

Under every answer are two buttons: Looks safe to me and Looks dangerous. In version 1.0.0, pressing one keeps your answer on your computer only. It is not sent to us. The panel then says “Thanks — saved on this device.”

Do I need an account?

No. PhishTriage works without an account and without a password.

When you install it, PhishTriage gives your browser a random number, so our server can tell its checks apart from everyone else’s. It also tells us which browser you use. The number is not made from your name, your email address or your computer. Setting this up sends nothing you have typed.

To see the start of this number: open the PhishTriage window, click Settings, then Advanced. It is next to Device ID.

If you sign in to the portal

Signing in is up to you. The portal is our website where you can see your checks. To sign in, click Log in under Settings. Then sign in with Google on the page that opens. When you sign in:

Every page of the portal loads Google’s sign-in button. So Google learns that you visited the portal, even if you don’t sign in. Nothing from your checks is sent to Google.

If you sign in with a work email address, your employer’s PhishTriage team may add you to the team automatically, without asking. People in that team may then see your checks from that moment on, and its owners can see that they are yours. If you don’t want that, don’t sign in with that address. PhishTriage works fine without an account.

How do I get my data deleted?

If you use PhishTriage in more than one browser, each one has its own number. Tell us about each.

Removing PhishTriage from your browser does not delete anything we keep. Write to us for that.

Downloaded files

File protection is off until you switch it on. If your browser has it, it is under Settings. Your employer can also switch it on for you.

When you switch it on, your browser asks for permission. The message may say PhishTriage can manage your downloads, and read and change all your data on the websites you visit. This is expected. While File protection is on, part of PhishTriage runs on every page you open, so it can catch a file that a page makes itself.

When it is on, PhishTriage checks every file you download, on your own computer. For each file, it sends us:

The web address a file came from is checked on your computer. It is not sent to us.

The file itself stays on your computer, unless:

A file sent to us is checked in memory and not stored.

To check an ordinary download, PhishTriage downloads the file a second time, from the same website and with your same login there. A download link that works only once may not work for that second try.

File protection does not look at files that are already on your computer, and it does not watch your Downloads folder.

Questions about your data? Write to privacy@phishtriage.com. For anything else, the support page has a person who answers.