Cookie Policy
This Cookie Policy explains how PhishOut AI uses cookies and similar technologies on phishoutai.com and app.phishoutai.com. It should be read alongside our Privacy Policy.
What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work correctly, improve performance, and provide information to site owners.
We also use similar technologies:
- Session storage: Temporary data stored in your browser for the duration of a tab session only.
- HTTP-only cookies: Cookies set with the
HttpOnlyflag that cannot be accessed by JavaScript — used exclusively for authentication security. - Local storage: Used minimally and only for non-personal UI preferences (e.g. language selection).
Under EU law (ePrivacy Directive / GDPR), non-essential cookies require your prior, freely given, and informed consent.
Types of Cookies We Use
Specific Cookies
3.1 phishoutai.com (Marketing Website + WordPress)
| Cookie Name | Type | Purpose | Duration |
|---|---|---|---|
wordpress_logged_in_* | Necessary | WordPress authentication — keeps you logged in | Session / 14 days |
wordpress_sec_* | Necessary | WordPress secure cookie (admin panel) | Session |
wp-settings-* | Functional | WordPress UI preferences (admin only) | 1 year |
woocommerce_cart_hash | Necessary | WooCommerce — tracks whether the cart has changed | Session |
woocommerce_items_in_cart | Necessary | WooCommerce — indicates items in cart | Session |
phishout_lang | Functional | Remembers your selected interface language (EN / PT) | 1 year |
phishout_cookie_consent | Necessary | Records your cookie consent decision | 1 year |
3.2 app.phishoutai.com (Application)
| Cookie Name | Type | Purpose | Duration |
|---|---|---|---|
phishout_csrf | Necessary | CSRF double-submit token — prevents cross-site request forgery. HttpOnly, SameSite=Strict. | Session |
phishout_session | Necessary | Pro user session management — links your browser to your active session. HttpOnly, Secure. | 2 hours (inactivity) |
phishout_lang | Functional | Selected analysis language preference. | 1 year |
The PhishOut AI app deliberately uses zero localStorage for sensitive business data. All authentication and subscription state is managed server-side. This is a deliberate security design decision.
Consent
When you first visit phishoutai.com, a cookie banner will appear before any non-essential cookies are placed:
You may change your consent preferences at any time by:
- Clicking "Cookie Preferences" in the footer of any page.
- Clearing your browser's cookies (resets consent; the banner will reappear).
- Contact us
Strictly necessary cookies cannot be refused as they are required for the service to function.
Third-Party Cookies
We use a minimal number of third-party services that may set their own cookies:
| Service | Why | Their Policy |
|---|---|---|
| Stripe | Payment processing — sets cookies to prevent fraud and manage the checkout session. | stripe.com/privacy |
| Google Fonts | Typography — fonts loaded from Google's CDN may set cookies. We are transitioning to self-hosted fonts to eliminate this. | policies.google.com/privacy |
We do not integrate with Facebook Pixel, Google Ads, LinkedIn Insight Tag, TikTok Pixel, or any other advertising trackers.
Browser-Level Cookie Controls
All modern browsers allow you to manage, restrict, or delete cookies independently. Note that disabling all cookies will prevent the Service from functioning correctly.
On mobile: iOS → Settings → Safari → Privacy & Security. Android → check your browser's settings menu.
Do Not Track (DNT)
Because there is no agreed-upon standard for DNT signals, we do not currently alter our data collection practices in response to them. However, since we do not use advertising or cross-site tracking cookies in the first place, the practical impact on your PhishOut AI experience is minimal. Your preferences set through our cookie banner are fully honoured.
Updates to This Policy
When we update this policy, we will change the "Last updated" date at the top of this page. If we add new non-essential cookies, we will re-request your consent. Registered users may be notified by email for material changes.
Contact
If you have any questions about our use of cookies or wish to withdraw your consent: