Separate confirmationFive fixed report fields
After Suspicious, Share privacy-safe report requires another explicit action after a fresh current-message check. Choosing No sends nothing. Choosing Yes sends only the exact current From address, bounded displayed name, Suspicious decision, one fixed reason code, and policy version.
Separate default-No choiceExact preview only.
A second choice may add only the exact visible link-free local preview after the user sees it and selects Yes. It remains limited to two sentences and 220 characters, encrypted for at most 30 days, and never stored by the extension or published in Cues.
Never sentNo full email or hidden content
No full email message, subject, headers, Reply-To, recipients, attachments, images, HTML, links, URLs, hostnames, score, result, Gmail mark, arbitrary text, or message or account identifier leaves the browser.
Server boundaryExact domain, derived on the server
The Worker derives the exact sender domain from the canonical From address. Exact shared-provider domains on the reviewed suppression list cannot become Community Cues; suppression is exact only and is never inherited by subdomains.
Private moderationTwo isolated review surfaces
The authenticated owner can deliberately open a consented excerpt detail containing its exact address and shown name until it expires. Separately, after at least five eligible Suspicious report events for one exact domain, the owner can review an aggregate-only publication candidate. Evidence review never publishes content or approves an email.
Possible public cueNeutral and query-only
After privacy and policy review, the owner may publish a neutral Community Cue for the exact domain. It can show a coarse report-event band, evidence coverage, observed months, and fixed categories—but never exact Trusted or Suspicious counts or raw totals. Public Cues are query-only, not a browseable directory.
Deletion and recoveryActive removal, limited recovery
Encrypted active report values are kept for no more than 180 days. A confirmed deletion removes the active row; encrypted D1 recovery history may remain for up to 30 days. PhishCues does not promise immediate physical erasure or provide an application-level undelete.