Analysis stayslocal.Sharing isyour choice.

0
automatic reports
0
message-content uploads
0
raw-link uploads

Effective August 26, 2026 · Public beta · Independent review planned when funding permits

01 / Scope and contact

One notice for the extension and website.

Operator

PhishCues is an owner-operated public beta. Privacy, deletion, correction, and Community Cue disputes may be sent to admin@phishcues.com. Do not email passwords, authentication tokens, full messages, attachments, or sensitive mailbox exports.

Local extension data

Analysis of one opened Gmail message stays in the browser. Up to 100 exact Trusted or Suspicious mailbox choices may be stored in Chrome local storage. These choices are not company verification and are never uploaded automatically.

Website data

The public website has no advertising tracker or behavioral analytics. A Cues lookup sends only the exact normalized domain to the site service. Cloudflare hosts the website, same-origin adapters, reporting APIs, security, and D1 storage. It may process data and ordinary request metadata only as needed to deliver and protect those services. GitHub hosts the optional release download and source repository, and Google operates Chrome and the Chrome Web Store under their own notices.

Admin access

The private Operations area uses an eight-hour secure session cookie, a password verifier, lockout state, and a bounded audit trail. It is unavailable to ordinary beta users, and private records are never returned by public Cues.

02 / Optional community reporting

Every share is explicit.

Current beta status: explicit privacy-safe reporting and optional weekly installation counting are available. The reporting control sends nothing by itself and does not upload past local decisions. Trusted and Suspicious stay local.

Separate confirmation

Five fixed report fields

After Suspicious, Share privacy-safe report requires another explicit action after a fresh current-message check. Choosing No sends nothing. Choosing Yes sends only the exact current From address, bounded displayed name, Suspicious decision, one fixed reason code, and policy version.

Separate default-No choice

Exact preview only.

A second choice may add only the exact visible link-free local preview after the user sees it and selects Yes. It remains limited to two sentences and 220 characters, encrypted for at most 30 days, and never stored by the extension or published in Cues.

Never sent

No full email or hidden content

No full email message, subject, headers, Reply-To, recipients, attachments, images, HTML, links, URLs, hostnames, score, result, Gmail mark, arbitrary text, or message or account identifier leaves the browser.

Server boundary

Exact domain, derived on the server

The Worker derives the exact sender domain from the canonical From address. Exact shared-provider domains on the reviewed suppression list cannot become Community Cues; suppression is exact only and is never inherited by subdomains.

Private moderation

Two isolated review surfaces

The authenticated owner can deliberately open a consented excerpt detail containing its exact address and shown name until it expires. Separately, after at least five eligible Suspicious report events for one exact domain, the owner can review an aggregate-only publication candidate. Evidence review never publishes content or approves an email.

Possible public cue

Neutral and query-only

After privacy and policy review, the owner may publish a neutral Community Cue for the exact domain. It can show a coarse report-event band, evidence coverage, observed months, and fixed categories—but never exact Trusted or Suspicious counts or raw totals. Public Cues are query-only, not a browseable directory.

Deletion and recovery

Active removal, limited recovery

Encrypted active report values are kept for no more than 180 days. A confirmed deletion removes the active row; encrypted D1 recovery history may remain for up to 30 days. PhishCues does not promise immediate physical erasure or provide an application-level undelete.

03 / Public boundary

Report counts are evidence about reports.

Private aggregates and reviewed public Cues are evidence about report events only. They are not proof that a person, company, domain, or message is legitimate or malicious, and they never affect the four-field score, analysis result, or safety state.

04 / Anonymous usage count

Weekly installation counting is optional.

The extension's Anonymous weekly usage count is OFF by default. After explicit opt-in, the extension derives a different token every UTC week and sends only that token, policy version, and week-start date. It sends no email, message, domain, URL, account, browsing data, or stable cross-week identifier. The service stores only a keyed token digest for up to 21 days after week start; authenticated Admin sees only current and previous weekly active-installation counts. These are installation counts, not people or unique users.

05 / Choices and retention

Control stays with the person sharing.

Turn sharing off

Community reporting can be turned off in the extension. Turning it off stops new shares and starts capability-bound cleanup for reports owned by that installation. Failed deletions remain pending for an explicit retry.

Delete and correct

Use the extension's report controls when available, or contact the operator for a privacy, correction, or Community Cue dispute. A confirmed deletion removes the active row. Encrypted D1 recovery history can remain for up to 30 days and is not normally served.

Retention limits

Active structured reports expire within 180 days. Explicitly consented private excerpts expire within 30 days and never extend the report lifetime. Optional weekly installation-count rows are retained for no more than 21 days after the week starts.

Changes

A material expansion of collected data or purpose requires a new prominent notice and affirmative consent before the new collection begins. The effective date above will change when this notice materially changes.

06 / Chrome Web Store Limited Use

Access is limited to the feature you request.

PhishCues uses information accessed from Gmail only to provide the visible email-analysis features described on this site. The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. PhishCues does not use extension user data for advertising, creditworthiness, lending, or sale to data brokers. Human access is limited to the separate, explicit, default-No private-evidence choice described above, security or abuse response, legal compliance, or another action the user specifically authorizes. All extension-to-service transfers use HTTPS; exact shared addresses, shown names, and consented excerpts are encrypted at rest.