Cookie Policy
This Cookie Policy explains how PhishOut AI uses cookies and similar technologies on phishoutai.com and app.phishoutai.com. It should be read alongside our Privacy Policy.
What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work correctly, improve performance, and provide information to site owners.
We also use similar technologies:
- Session storage: Temporary data stored in your browser for the duration of a tab session only.
- HTTP-only cookies: Cookies set with the
HttpOnlyflag that cannot be accessed by JavaScript — used exclusively for authentication security. - Local storage: Used minimally and only for non-personal UI preferences (e.g. language selection).
Under EU law (ePrivacy Directive / GDPR), non-essential cookies require your prior, freely given, and informed consent.
Types of Cookies We Use
Specific Cookies
3.1 phishoutai.com (Marketing Website + WordPress)
| Cookie Name | Type | Purpose | Duration |
|---|---|---|---|
wordpress_logged_in_* | Necessary | WordPress authentication — keeps you logged in | Session / 14 days |
wordpress_sec_* | Necessary | WordPress secure cookie (admin panel) | Session |
wp-settings-* | Functional | WordPress UI preferences (admin only) | 1 year |
woocommerce_cart_hash | Necessary | WooCommerce — tracks whether the cart has changed | Session |
woocommerce_items_in_cart | Necessary | WooCommerce — indicates items in cart | Session |
phishout_lang | Functional | Remembers your selected interface language (EN / PT) | 1 year |
CookieConsent | Necessary | Stores your cookie consent state for this domain. Set by Cookiebot (Usercentrics). | 1 year |
3.2 app.phishoutai.com (Application)
| Cookie Name | Type | Purpose | Duration |
|---|---|---|---|
phishout_csrf | Necessary | CSRF double-submit token — prevents cross-site request forgery. Secure, SameSite=None (shared across subdomains). | 1 hour |
phishout_session | Necessary | Pro user session management — links your browser to your active session. Secure. | 2 hours (inactivity) |
phishout_guest | Necessary | Counts free analyses for visitors without an account (2/day). HttpOnly, Secure. | 30 days |
phishout_lang | Functional | Selected analysis language preference. | 1 year |
The PhishOut AI app deliberately uses zero localStorage for sensitive business data. All authentication and subscription state is managed server-side. This is a deliberate security design decision.
Consent
Consent is managed through Cookiebot (a consent management platform by Usercentrics). When you first visit phishoutai.com, the Cookiebot banner appears before any non-essential cookies are placed:
Your choice is recorded in the CookieConsent cookie and documented by Cookiebot. You may change or withdraw your consent at any time by:
- Clicking the "Cookie Preferences" link in the footer of any page, which reopens the Cookiebot dialog.
- Clearing your browser's cookies (resets consent; the banner will reappear).
- Contact us
Strictly necessary cookies cannot be refused as they are required for the service to function.
Third-Party Cookies
We use a minimal number of third-party services that may set their own cookies:
| Service | Why | Their Policy |
|---|---|---|
| Cookiebot (Usercentrics) | Consent management — stores and documents your cookie consent decision. Sets the CookieConsent cookie. | cookiebot.com/privacy |
| Stripe | Payment processing — sets cookies to prevent fraud and manage the checkout session. | stripe.com/privacy |
| Google Fonts | Typography — fonts loaded from Google's CDN may set cookies. We are transitioning to self-hosted fonts to eliminate this. | policies.google.com/privacy |
We do not integrate with Facebook Pixel, Google Ads, LinkedIn Insight Tag, TikTok Pixel, or any other advertising trackers.
Browser-Level Cookie Controls
All modern browsers allow you to manage, restrict, or delete cookies independently. Note that disabling all cookies will prevent the Service from functioning correctly.
On mobile: iOS → Settings → Safari → Privacy & Security. Android → check your browser's settings menu.
Do Not Track (DNT)
Because there is no agreed-upon standard for DNT signals, we do not currently alter our data collection practices in response to them. However, since we do not use advertising or cross-site tracking cookies in the first place, the practical impact on your PhishOut AI experience is minimal. Your preferences set through our cookie banner are fully honoured.
Updates to This Policy
When we update this policy, we will change the "Last updated" date at the top of this page. If we add new non-essential cookies, we will re-request your consent. Registered users may be notified by email for material changes.
Contact
If you have any questions about our use of cookies or wish to withdraw your consent: