PhishOut AI
How it works Features Pricing FAQ Sign in
Sign in Try Now
Legal

Privacy Policy

PhishOut AI Portugal · EU Last updated: March 2026 Version 1.1
Contents
  • 1. Who We Are
  • 2. Data We Collect
  • 3. How We Use Your Data
  • 4. Legal Basis (GDPR)
  • 5. Data Retention
  • 6. Third Parties
  • 7. International Transfers
  • 8. Your Rights
  • 9. Children
  • 10. Security
  • 11. Changes

This policy applies to all services at phishoutai.com and app.phishoutai.com. It complies with the EU GDPR and the Portuguese Lei n.º 58/2019. Questions? Contact us.

01

Who We Are

PhishOut AI ("we", "us", "our") operates phishoutai.com and the associated analysis application at app.phishoutai.com. We are the data controller for personal data processed through our services.

  • Contact: phishoutai.com/contact-us
  • Website: https://phishoutai.com
02

Data We Collect

2.1 Account Data

When you register, we collect your name, email address, and hashed password (managed via WordPress/WooCommerce). We never store plaintext passwords.

2.2 Content Submitted for Analysis

Content you submit (email text, URLs, uploaded files, screenshots) is processed exclusively to generate a threat analysis report.

Free plan: submitted content is processed in real-time and permanently discarded after the report is returned — nothing is stored. Pro users (active credit balance): analysis results (not raw content) are stored in your encrypted history for your exclusive access, while your credit balance remains positive.

2.3 Credit & Purchase Data

When you purchase a credit pack, we store your credit balance, the number of credits purchased, the pack size, and the transaction date. Credits never expire and accumulate across purchases. Payment processing is handled exclusively by Stripe — we do not store card numbers or full payment details.

2.4 Usage & Technical Data

Data PointPurposeRetention
IP addressRate limiting, abuse prevention24 hours
Browser / OS (User-Agent)Session management (Pro)Session duration
Credit balance & usage logQuota enforcement, billing dispute resolutionAccount lifetime + 30 days
Analysis result (Pro — active credits)History featureWhile credit balance > 0; 30 days after depletion

2.5 Cookies

See our Cookie Policy for full details.

03

How We Use Your Data

PurposeData UsedLegal Basis
Provide analysis serviceSubmitted content, account IDContract performance
Authentication & sessionsEmail, session token, IPContract performance
Credit management & billingCredit balance, Stripe customer IDContract performance
Rate limiting & abuse preventionIP address, usage countLegitimate interest
Service improvementAggregated, anonymised statsLegitimate interest
Transactional emailsEmail addressContract performance
Legal complianceAs required by lawLegal obligation

We never sell, rent, or share your personal data with third parties for marketing purposes. We do not use your submitted content to train AI models.

04

Legal Basis (GDPR Art. 6)

  • Art. 6(1)(b) — Contract: Processing necessary to provide the service you signed up for (analysis, credit management, billing, account management).
  • Art. 6(1)(c) — Legal obligation: Compliance with EU / Portuguese law, tax obligations, anti-fraud regulation.
  • Art. 6(1)(f) — Legitimate interest: Security monitoring, abuse prevention, aggregate service analytics.
  • Art. 6(1)(a) — Consent: Where we use non-essential cookies or send non-transactional communications.
05

Data Retention

CategoryRetention Period
Free plan — submitted contentDeleted immediately after analysis
Pro — analysis historyWhile credit balance > 0, then +30 days
Credit balance & purchase logAccount lifetime + 30 days after deletion
Account dataUntil account deletion + 30 days
IP / rate-limit logs24 hours
Payment records7 years (tax / legal obligation)
Session tokens2 hours inactivity or logout

You may request deletion of your account at any time via our contact page. Deletion will be completed within 30 days, except where retention is required by law. Note: unused credit balances are forfeited upon account deletion.

06

Third-Party Sub-Processors

We use a limited set of sub-processors, each bound by GDPR-compliant Data Processing Agreements (DPAs):

Sub-processorRoleData SharedLocation
Google (Gemini API)AI threat analysis engineSubmitted content (transient)EU / US (SCCs)
StripePayment processing for credit packsEmail, billing metadataUS (SCCs)
HostingerWeb hosting & databaseAll service dataEU (Lithuania)
VirusTotal (Pro)URL reputation lookupSubmitted URLs onlyUS (SCCs)
URLScan.io (Pro)URL visual inspectionSubmitted URLs onlyEU (Germany)

We do not use advertising networks, social media trackers, or analytics services that process personal data without your consent.

07

International Data Transfers

Some sub-processors (Google, Stripe) are located outside the EU/EEA. All transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission, supplementary technical measures (encryption in transit and at rest), and adequacy decisions where applicable. You may request a copy of the applicable transfer mechanisms by contacting us.

08

Your Rights

Under GDPR (Chapter III) you have the following rights. Contact us via our contact page. We will respond within 30 days.

RightWhat it means
AccessRequest a copy of the personal data we hold about you, including your credit balance and purchase history.
RectificationCorrect inaccurate or incomplete data.
ErasureRequest deletion of your account and data. Note that unused credits are forfeited upon erasure.
RestrictionRequest that we limit processing of your data in certain circumstances.
PortabilityReceive your data in a structured, machine-readable format.
ObjectionObject to processing based on legitimate interest.
Withdraw consentWithdraw consent at any time for consent-based processing (e.g. cookies).

You also have the right to lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD).

09

Children

PhishOut AI is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.

10

Security

  • TLS 1.2+ encryption for all data in transit (HTTPS enforced).
  • AES-256 encryption for data at rest.
  • Bcrypt password hashing (cost factor 12) for all credentials.
  • CSRF double-submit tokens on all authenticated endpoints.
  • IP-based rate limiting and brute-force lockout protection.
  • Atomic credit decrement to prevent race conditions on concurrent analysis requests.
  • Role-based access control for administrative functions.
  • Complete audit log of all administrative actions.

If you discover a security vulnerability, please report it responsibly via our contact page.

11

Changes to This Policy

When we make material changes, we will update the "Last updated" date, notify registered users by email at least 14 days in advance, and where required by law, ask for renewed consent. Continued use of the service after the effective date constitutes acceptance.

PhishOut AI

Your personal cybersecurity expert,
available 24/7.

🔒 SSL Safe 🇪🇺 GDPR

Product

  • How it works
  • Features
  • Plans & Pricing
  • FAQ

Account

  • Sign in
  • Create Account
  • Phishout AI Free
  • Phishout AI Pro

Legal

  • Privacy Policy
  • Terms of Service
  • Cookies
  • Contact us

© 2026 PhishOut AI. All rights reserved.

PhishOut AI uses strictly necessary cookies to operate the service, and optional functional cookies to remember your language preference. We never use advertising or tracking cookies. Cookie Policy

Cookie Preferences

Strictly Necessary Always active

Required for the website to function. Includes WordPress authentication, WooCommerce cart, and CSRF security tokens. Cannot be disabled.

wordpress_logged_in_* woocommerce_cart_hash woocommerce_items_in_cart phishout_cookie_consent
Functional

Remember your selected language preference (EN / PT) so you don't have to choose every visit. No personal data is shared with third parties.

phishout_lang
Analytics Not used

We do not currently use analytics cookies or services that track your behaviour across sites.

Marketing & Advertising Not used

We do not use advertising cookies, retargeting pixels, or tracking from Facebook, Google Ads, or any other ad network.

Cookie Policy ↗