Skip to main content

Privacy Policy

Effective date: September 4, 2026

1. Who We Are

PhishFence is a domain monitoring and brand protection service operated by MAJUVO LLC, a California limited liability company. This Privacy Policy describes how we collect, use, store, and share information when you use PhishFence at phishfence.io.

2. Information We Collect

Account information. When you register, we collect your name, email address, organization name (optional), and a password. Passwords are hashed with bcrypt before storage. We never store or log plaintext passwords.

Monitored domains. We store the domain names you add for monitoring, along with scan results, detected variants, risk scores, alert history, and any notes you add during investigation.

Payment information. Subscription payments are processed by Stripe. We do not receive, process, or store your credit card number, expiration date, or CVC. Stripe provides us with a customer identifier and your subscription status so we can manage your plan.

Notification settings. If you configure alert delivery, we store your alert email address, Slack webhook URL, and/or outbound webhook URL.

API tokens. If you create API tokens, we store a hashed version of the token and metadata (name, creation date, last used date).

Server logs. Our infrastructure logs HTTP requests for operational and security purposes. Logs include IP addresses, request paths, timestamps, and HTTP status codes. Logs are retained for up to 30 days.

3. How We Use Your Information

We use the information we collect to:

  • Operate the domain monitoring service, including running scans, scoring threats, and generating alerts
  • Send you notifications about detected threats via email, Slack, or webhook, based on your configured preferences
  • Process subscription payments and manage your billing through Stripe
  • Pre-fill registrar abuse reports with your name, organization, and email to save you time when filing complaints
  • Submit phishing reports to third-party databases on your behalf, when you choose to do so
  • Diagnose technical issues, monitor service health, and improve reliability
  • Send you service-related communications such as security notices, billing confirmations, and material changes to these policies

We do not use your data for advertising, profiling, or any purpose unrelated to operating PhishFence.

4. Information We Share

We do not sell, rent, or trade your personal information. We share data only in the following circumstances:

  • Stripe receives your email address and payment details to process subscriptions
  • Resend processes transactional and alert emails on our behalf. Resend receives the recipient email address and message content
  • Netcraft, Google Safe Browsing, and PhishTank receive domain names and your email address when you submit a phishing report through PhishFence. Reports are submitted only when you initiate them
  • URLhaus (abuse.ch) is queried to check domains against known malware distribution feeds. No personal data is included in these queries
  • AWS Route53 is queried to retrieve domain registration pricing. No personal data is included in these queries
  • GitHub receives your email address and plan type when you submit feedback through PhishFence
  • RDAP and WHOIS services receive domain name queries when we look up registrar abuse contacts. No personal data is included in these queries
  • Certificate Transparency logs (crt.sh) are queried with your monitored domain names to detect newly issued certificates. No personal data is included
  • Sentry receives anonymized error reports for debugging purposes. Error reports may include request paths and stack traces but do not include passwords, tokens, or domain scan results
  • PostHog receives product analytics from our public marketing pages only: a pseudonymous device and session identifier, page paths and referrers with any query string removed, performance timings, and session replays in which all text and form input is masked. PostHog never receives your name, email address, account identifier, or anything from pages you see while signed in. See section 8
  • Google Cloud Platform hosts our infrastructure. Data is stored in GCP's us-central1 region
  • Law enforcement or legal process if we are required by law, subpoena, or court order to disclose information, or if disclosure is necessary to protect the rights, safety, or property of MAJUVO, our users, or the public

5. Data Security

We take the following measures to protect your data:

  • All connections to PhishFence are encrypted with TLS (HTTPS)
  • Passwords are hashed using bcrypt with a per-user salt
  • Authentication uses signed JWT tokens with expiration
  • All forms are protected against cross-site request forgery (CSRF)
  • Authentication endpoints are rate-limited to prevent brute-force attacks
  • HTTP security headers are applied, including HSTS, Content-Security-Policy, X-Frame-Options, and X-Content-Type-Options
  • Database access is restricted to the application service account via Cloud SQL IAM
  • Secrets (API keys, database credentials) are stored in GCP Secret Manager, not in code or environment files

No system is completely secure. If you become aware of a security vulnerability in PhishFence, please report it to support@phishfence.io.

6. Data Retention

We retain your account data, monitored domains, scan results, and alert history for as long as your account is active. If you delete your account, we will permanently remove all associated data within 30 days, with the two exceptions described below. Server logs are retained for up to 30 days regardless of account status.

Two kinds of records survive account deletion, by design. First, our audit log of administrative actions taken on your account, which may name your email address, is kept so we can account for who did what to your account and when. Second, email delivery records from our email provider (bounces, complaints and delivery events) and our list of unsubscribed addresses are kept so that bounced and unsubscribed addresses stay suppressed, because honouring an opt-out requires remembering the address. Our legal basis for retaining both is our legitimate interest in security and in honouring opt-out requests.

Stripe retains payment records according to their own retention policies and legal obligations.

7. Your Rights

You can exercise the following rights at any time:

  • Access and update your personal information from the Settings page
  • Export your alert and scan data through the REST API (available on paid plans)
  • Delete your account and all associated data from the Settings page
  • Request a copy of all data we hold about you by emailing support@phishfence.io

If you are located in the European Economic Area, you may also have rights under the GDPR including the right to data portability, the right to restrict processing, and the right to lodge a complaint with a supervisory authority. Contact us if you wish to exercise any of these rights.

8. Cookies and Analytics

PhishFence sets the following first-party cookies:

  • access_token (strictly necessary): stores your authenticated session. Attributes: HttpOnly, Secure, SameSite=Lax.
  • _csrf (strictly necessary): stores a CSRF protection token used to validate form submissions. Attributes: HttpOnly, Secure, SameSite=Strict.
  • _pf_sid (first-party analytics): a random session identifier set by our own JavaScript and kept only for the browser session. It lets us count page views and tie a run of one of our free tools to the same visit. It is sent only to phishfence.io, alongside the page path, the referring page without its query string, and any UTM campaign parameters, and it contains no account information. Attributes: Secure, SameSite=Lax.

PostHog. On our public marketing pages (the home page, pricing, blog, learning resources, and free tools) we use PostHog for product analytics and session replay. PostHog sets its own cookies and local storage entries (prefixed ph_) on those pages to recognise a returning browser. PostHog receives a pseudonymous device and session identifier, the page path and referrer with any query string removed, and performance timings. Session replay on those pages masks all text and all form input, so PostHog does not receive your name, email address, account identifier, or anything you type. PostHog is not loaded on pages reached through a one-time link (such as password reset, email verification, or sign-in links), and it is not loaded on any authenticated page: the dashboard, settings, integrations, reports, and admin pages send no analytics to third parties. We honour the browser Do Not Track setting for PostHog.

We do not use advertising cookies, and we do not share analytics data with advertising networks.

9. Children

PhishFence is not directed at individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will delete it promptly.

10. International Users

PhishFence is hosted in the United States (Google Cloud Platform, us-central1 region). If you access the service from outside the United States, your information will be transferred to and processed in the United States. By using PhishFence, you consent to this transfer.

11. Changes to This Policy

We may update this Privacy Policy when our practices change or when required by law. When we make material changes, we will update the effective date at the top of this page and notify you by email. We encourage you to review this policy periodically.

12. Contact

For privacy questions, data requests, or to report a concern, contact us at:

support@phishfence.io
MAJUVO LLC
28081 Marguerite Pkwy, Ste 2400
Mission Viejo, CA 92690, United States