What PhishTriage sees
What PhishTriage looks at, what it sends to us, what we keep, and how to have it deleted. The short version: it sends us an email or a web page only when you press its Analyze button.
This page is a plain summary. The privacy policy is the official version, and it has every detail. The policy also describes the next version of PhishTriage. Where today’s version is different, this page says what today’s version does. If you look after PhishTriage for a company, read Data handling.
When you check an email
When you press Analyze Current Email, PhishTriage reads the email you have open and sends it to us to be checked. In Gmail, for example, it sends:
- who sent it: their email address and name;
- who it was sent to — usually you;
- the address a reply would go to;
- the subject and the date;
- the words of the email, without the older messages quoted under it;
- up to ten links from the email;
- the names of any attachments.
So your own email address is usually part of what is sent.
When you check a web page
When you press Analyze Current Page, PhishTriage sends us:
- the page’s full web address, as it is in the address bar — including anything after a “?”;
- the page’s title;
- the words on the page, up to a limit. This includes words the page hides from view. The add-on stores hand out slightly different copies of version 1.0.0, called builds. In the newest 1.0.0 builds only, it also sends words in windows inside the page, where the browser lets PhishTriage read them;
- up to 15 links from the page.
A web address can contain your name, something you searched for, or a code that keeps you logged in. If it does, that is sent too.
PhishTriage does not read what you type into boxes on a page, such as a password box. But some pages let you write longer text, such as an email in webmail. What you write there can count as words on the page, and then it is sent. Also see the next part, about pictures.
Pictures of dangerous pages
This is on until you switch it off. When you check a web page and the answer is Don’t trust this or Be careful, PhishTriage also sends us:
- a picture of what you can see in that tab, and
- the page’s code (its HTML).
We use them to report the page, so it can be taken down. Nothing is sent when the answer is Looks safe.
If you typed something on the page and it is still on screen, it is in the picture. Some pages also copy what you type into their code, and then it is in the code we receive.
Nothing is ever taken in Gmail, or in Outlook at outlook.office.com, outlook.office365.com or outlook.live.com.
If you read email on any other website — for example Yahoo, Proton, Fastmail, your workplace’s own webmail, or Outlook at outlook.cloud.microsoft — PhishTriage treats it like any other web page. If a check there comes back Don’t trust this or Be careful, the picture is of your inbox. The page’s code we receive also holds the email you had open, and anything else on that page. To stop this, switch off Keep evidence of phishing.
To switch it off:
Click the PhishTriage icon at the top right of your browser. It’s a small drawing of a shark. The PhishTriage window opens. If you can’t see the icon, click the puzzle-piece icon first, then PhishTriage.
Click Settings. The settings open below it.
Click the switch next to Keep evidence of phishing. The switch is blue when it’s on. After your click, it is no longer blue.
phishtriageReadyPage detectedClick Analyze to triage the current page content.▶ Analyze Current Page⚙ SettingsBackground protectionChecks each site you visit. Warns within a few seconds if it’s flagged as dangerous.Keep evidence of phishingWhen you first install PhishTriage, Keep evidence of phishing is on, so its switch is blue, and Background protection is off. Each stays that way until you change it.
If your employer looks after your browser, they may have set this for you. The switch then shows Managed, and you can’t change it.
Who checks it
We first ask an AI model on a computer we run ourselves. An AI model is a computer program that reads the email or page and judges it. If our model can’t give an answer, the email or page goes to Claude, an AI service from a company called Anthropic. Under its terms, Anthropic does not use it to train its AI. The privacy policy names every outside company involved.
Does PhishTriage read my mailbox?
No. PhishTriage does not go through your emails. It reads one email — the one you have open — and only when you press Analyze Current Email.
On other webmail websites (see above), you press Analyze Current Page instead. It reads the whole page, up to a limit, including the list of emails you can see.
In Gmail, and in Outlook at the three addresses above, PhishTriage is loaded on every page, so it can keep its button in place. While it waits, it looks only at how the page is laid out, not at your emails. It sends nothing until you press the button. Background protection, if you switch it on, is separate: see below.
It does not look through your browsing history. It can’t see which account your browser is signed in with.
Does it open attachments?
No. When you check an email, PhishTriage reads only the names of its attachments. It never reads what is inside them.
Files you download are different. See Downloaded files below.
What does Background protection send?
Background protection is off until you switch it on. When it is on, each time you open a page, PhishTriage sends us the name of its website — for example, shop.example — so it can warn you if the site is known to be dangerous. It sends only the name: not the rest of the address, and not what is on the page.
Under Advanced there are two more options. Both are off until you switch them on:
- Send full URLs sends the full address of every page you open.
- Cache domains for 1 hour sends each website’s name at most once an hour, however many of its pages you open.
When you switch Background protection on, your browser asks for permission. The message may say PhishTriage can read and change all your data on the websites you visit, and read your browsing history. This is expected. It lets PhishTriage notice each new page you open from then on. It does not read the pages you visited before.
If your employer looks after your browser, they can switch these on or off for you. The switch then shows Managed, and you can’t change it.
What is kept, for how long, and who can see it
- Your checks: what PhishTriage sent when you pressed Analyze — including the words of the email, or the page’s address — and our answer. We keep them for a year, unless you or your team’s owner chose a shorter time (see How long we keep your checks). Then they are deleted automatically, except in our server’s log (below).
- Background protection: the website names, or full addresses, it sent. Kept for the same time as your checks, except in our server’s log (below).
- Downloaded files, if File protection is on: each file’s fingerprint, name and size, and our answer. Kept for the same time as your checks. The exception is older file checks: those made before we began giving every record a deletion date, shortly before 4 October 2026, were each given a year from the day they were made. The computer that checks files for us also writes a line in its own log for each file. The line holds the start of the file’s name, but not your internet address. Nothing in PhishTriage deletes that log automatically. If you ask, we clear your lines by hand.
- Pictures of dangerous pages: kept for 12 months after Don’t trust this, and for 30 days after Be careful. If a person reviews a picture and finds the page was not phishing, it is deleted at once. If they find that a Be careful page was phishing, its picture is kept for 12 months instead.
- Your device record: PhishTriage’s random number for your browser, which browser it is, when it was set up and when it was last used. It is not deleted automatically. To have it deleted, write to us.
- Your account, if you sign in. It is not deleted automatically either.
- Changes to how long we keep checks: each time you or your team’s owner change it, we note who changed it, from what to what, and when. The note holds nothing from your checks. It is not deleted automatically.
- Our server’s log: our server also writes a line in its log each time it checks an email or a page for you. It writes one, too, each time Background protection sends it a website name or address. A check’s line includes your internet address (your IP address), and enough to work out who sent the email or which website you checked. It does not include the words of the email or the page. A Background protection line includes the website name or address, and a coded form of your IP address. Nothing in PhishTriage deletes this log automatically. If you write to privacy@phishtriage.com and ask, we clear your lines by hand.
What we keep is stored in a database on our own computers, in Estonia.
Who can see it. In the PhishTriage portal, your checks are shown only to you, unless you are part of a team at work. Then it depends on how the team is set up:
- In some teams, everyone in the team can see these lists:
- the team’s checks, and our answers;
- the website names or addresses that Background protection sent;
- the pictures of dangerous pages;
- the team’s browsers.
- In other teams, the portal shows only totals, to everyone, you included. No one in the team sees a list of checks, not even of their own.
Either way, the team sees and counts your checks only from the moment you joined it. While you are in the team, the portal does not show your checks from before you joined, not even to you.
How long we keep your checks
We keep your checks for a year. Then they are deleted automatically. The same goes for your Background protection records and your downloaded-file records.
If you sign in to the portal, you can choose a shorter time, from 7 days up:
Open the PhishTriage portal and sign in. Your Dashboard opens.
Scroll down to Your data. Under it is How long we keep your scans.
Next to Keep my scans for, choose a time.
Click Save. A message below it starts with “Saved.”
- The time you choose applies to checks you make from then on. Older checks keep the time they had when they were made. To delete them now, use Delete my scan history (below).
- It covers checks from each browser where you pressed Log in.
- If you are in a team, its owner can choose a time for the whole team. You can choose a shorter time for your own checks, but not a longer one.
- If your workplace set up PhishTriage in your browser for you, that browser follows your team’s time, whatever you choose.
- Checks and Background protection records made before 4 October 2026 are deleted after 90 days.
- Pictures of dangerous pages, and our server’s log, don’t follow this time. See above.
The two buttons under an answer
Under every answer are two buttons: Looks safe to me and Looks dangerous. In version 1.0.0, pressing one keeps your answer on your computer only. It is not sent to us. The panel then says “Thanks — saved on this device.”
Do I need an account?
No. PhishTriage works without an account and without a password.
When you install it, PhishTriage gives your browser a random number, so our server can tell its checks apart from everyone else’s. It also tells us which browser you use. The number is not made from your name, your email address or your computer. Setting this up sends nothing you have typed.
To see the start of this number: open the PhishTriage window, click Settings, then Advanced. It is next to Device ID.
If you sign in to the portal
Signing in is up to you. The portal is our website where you can see your checks. To sign in, click Log in under Settings. Then sign in with Google on the page that opens. When you sign in:
- we keep your email address and name from Google. If you use a work or school Google account, we may also keep your organisation’s domain, usually the part of your address after the @;
- checks you make from then on are shown to you in the portal, unless you are in a team that shows only totals;
- checks your browser made before you signed in are not moved into your account.
Every page of the portal loads Google’s sign-in button. So Google learns that you visited the portal, even if you don’t sign in. Nothing from your checks is sent to Google.
If you sign in with a work email address, your employer’s PhishTriage team may add you to the team automatically, without asking. People in that team may then see your checks from that moment on, and its owners can see that they are yours. If you don’t want that, don’t sign in with that address. PhishTriage works fine without an account.
How do I get my data deleted?
- If you have signed in: in the portal, on your Dashboard, under Your data, press Delete my scan history. A message asks if you are sure. Click OK. This deletes your checks, your Background protection records, the records of files File protection checked, and the pictures of dangerous pages kept under your account, straight away. It can’t be undone. It does not delete your device record, our server’s log, the log of file checks, the notes of changes to how long we keep checks, or checks your browser made before you signed in.
- For everything else, including our server’s log, or if you never signed in, email privacy@phishtriage.com. Tell us your Device ID. The first eight characters shown in the PhishTriage window are enough. Also tell us which browser you use, and roughly when you installed PhishTriage. We answer within 30 days. Write to the same address to have your account deleted.
If you use PhishTriage in more than one browser, each one has its own number. Tell us about each.
Removing PhishTriage from your browser does not delete anything we keep. Write to us for that.
Downloaded files
File protection is off until you switch it on. If your browser has it, it is under Settings. Your employer can also switch it on for you.
When you switch it on, your browser asks for permission. The message may say PhishTriage can manage your downloads, and read and change all your data on the websites you visit. This is expected. While File protection is on, part of PhishTriage runs on every page you open, so it can catch a file that a page makes itself.
When it is on, PhishTriage checks every file you download, on your own computer. For each file, it sends us:
- a fingerprint of the file — a short code worked out from the file, which can’t be turned back into the file;
- the file’s name and size;
- PhishTriage’s own answer, and the short reasons for it. If you download a zip file with a program inside, the reasons can include that program’s name.
The web address a file came from is checked on your computer. It is not sent to us.
The file itself stays on your computer, unless:
- a warning about that file offers Check it properly, and you press it — then that one file is sent to be checked; or
- you switch on Deep scan every file — then every file you download is sent. It is off until you switch it on. Your employer can also switch it on for you. It then shows Managed, and you can’t change it.
A file sent to us is checked in memory and not stored.
To check an ordinary download, PhishTriage downloads the file a second time, from the same website and with your same login there. A download link that works only once may not work for that second try.
File protection does not look at files that are already on your computer, and it does not watch your Downloads folder.
Questions about your data? Write to privacy@phishtriage.com. For anything else, the support page has a person who answers.