Last updated:
PhishClean is built on a simple principle: your browsing data stays on your device. We never see, collect, or transmit your passwords, URLs, page content, or browsing history.
The only data that touches our server:
That's it from the extension. No browsing history. No URLs. No domains. No passwords. No page content. No record of what the extension detected or where.
There is no code path in the extension that transmits a URL, a domain name, page content, form input, or a detection result. The one exception is the leaked-password check below, which sends 5 characters of a hash of your password and never the password itself. Detection runs entirely in your browser and its output stays there. To our server, the extension makes network requests to exactly four endpoints — license registration, license status, sign-in, and the billing portal — plus, from version 1.5.0, a plain download of the reported-phishing list described below. You can verify this yourself by unpacking the extension and searching for network calls; the source is published for that purpose.
The extension also talks to Have I Been Pwned, a public breach database. These requests go straight from your browser to Have I Been Pwned, never through our server, and carry nothing about you:
Like any website, Have I Been Pwned sees your IP address when your browser makes these requests. Breach data from Have I Been Pwned is licensed under CC BY 4.0.
About twice a day the extension downloads /feeds/phish-v1.bin from phishclean.com: the same file for every user, built from the public Phishing.Database list (MIT licence) with popular sites removed. The file holds short hashes of reported phishing hostnames, not the names themselves. Each page you open is hashed and looked up in that file on your device; neither the address nor its hash is sent anywhere. The download request carries no install ID and nothing about you. Like any web request, it reveals your IP address to our hosting provider.
Don't take our word for it. The complete extension source is public at github.com/chidhu07/phishclean-extension, with a README that lists every outbound request and the exact functions that make them. It is the same code that ships to the stores, unminified, so you can diff it against the package your browser downloaded.
Our website — separately from the extension — uses Vercel Analytics, Google Analytics, and Microsoft Clarity to measure page visits and, in Clarity's case, to record anonymised interaction sessions on the website itself. These run on phishclean.com pages only. They are not part of the extension, they cannot see anything the extension does, and they have no access to the pages you visit elsewhere.
If you use the contact form or affiliate application form on our website, we collect the name, email, and details you provide. This data is used solely to respond to your inquiry, review affiliate applications, and manage partner communications. It is not sold to third parties.
Payments are processed by Dodo Payments. We do not store credit card numbers. Your payment is linked to your install ID and account so paid protection can activate on the correct extension install.
License records are retained as long as the extension is installed. Contact messages are retained for support purposes. You can request deletion at any time by contacting us.
We collect limited account and billing data only: install ID, account email, license status, extension version, license check-in times, browser family, uninstall events, and support messages you choose to send. We process these to operate and enforce your licence and to keep the service working — we do not use them to build a profile of you, and we do not sell or share them. EU users retain full rights under GDPR including data access, rectification, and deletion. Contact us at the address below to exercise these rights.
We may update this policy as needed. Significant changes will be noted on this page with an updated date.
For privacy questions or data deletion requests, use the contact form on our website.