Data and Privacy
Understand what data RedPhish collects, stores, and how your privacy is protected.
Last updated: February 2026Privacy by Design
RedPhish is built to protect you without compromising your privacy. We collect the minimum data necessary to provide protection and never log your browsing history.
What RedPhish Does Not Collect
- Browsing history: We do not track which websites you visit
- Page content: The content of pages you view is never sent to our servers
- Personal information: We do not collect names, addresses, or other personal details beyond your email
- Scan verdicts: Results of URL scans are not logged on our servers
What RedPhish Does Collect
Account Information
- Email address (for authentication and account identification)
- Subscription status (to determine your plan and quota)
Usage Metrics
- Total number of URLs scanned (not the URLs themselves)
- Total number of malicious links detected (not the URLs themselves)
Enterprise Metrics
For organizations using RedPhish Enterprise:
- Aggregate counts of blocked threats per user (ads blocked, adult content blocked, malicious links blocked)
- These are counts only, not the specific URLs or pages
- Metrics are associated with user IDs for organizational reporting
Data in Transit
When you browse with RedPhish active:
- URLs of links on pages are sent to our scan API
- The API returns a verdict (safe or unsafe)
- URLs are not stored on our servers after the scan completes
- All communication uses HTTPS encryption
Data Stored Locally
RedPhish stores data on your device:
- Authentication: To keep you signed in
- Scan cache: Results of URL scans cached locally to improve performance
- Settings: Your extension preferences
- Usage statistics: Counts displayed in the popup
This data stays on your device and syncs to your browser profile if you use browser sync.
Deleting Your Account
To permanently delete your RedPhish account and all associated data:
- Sign in to your account at redphish.app
- Go to your profile page
- Click "Delete Account"
- Confirm the deletion
This removes:
- Your authentication records
- Your usage statistics
- Your subscription information
- Any organization memberships
Account deletion is permanent and cannot be undone.
Related Topics
Was this helpful?