PHISHCASE / Privacy

Privacy: technical principles

This page explains current technical behavior. The service owner must review final legal documents before commercial signup opens.

Processed data

The product stores original EML/MSG files, referenced attachments, hashes, headers, bodies, indicators, analysis results, notes, decisions and history. Cloud adds accounts, memberships, settings, subscription metadata and operational logs. Emails and notes may themselves contain personal or confidential information.

Recipients and external actions

Hosting retains application data. The configured SMTP service receives recipients, subjects and transactional content. Once configured, Stripe receives information needed for subscriptions; card fields are entered at Stripe. VT/urlscan receive only targets explicitly looked up or submitted. Configured webhooks receive limited identifiers and states, without email bodies or attachments. The contractual subprocessors list still requires review. Explicit DKIM verification sends selector and domain names to the server’s configured DNS resolver, without sending message content.

Access and minimization

Roles govern operations and the active Cloud organization. The operator console provides operational metadata; it does not implicitly grant access to customer investigations. Application logs avoid message content and secrets. Also protect proxy and dependency logs: their format and retention are operator responsibilities.

Retention and deletion

Cloud plans provide 90/180/365-day eligibility for analysis purging. The candidate requires an administrator preview and confirmation; automatic deletion at a specific date is not promised. Notes, cases, audit, billing and backups have separate lifecycles. Local deletion does not remove data already sent to a provider. Purge frequency, log retention and archive retention must be defined before launch.

Browser storage and cookies

The public site loads local resources without analytics or third-party pixels. FR/EN preference is kept in local storage. The application uses session cookies for login and preferences needed by its interface. No advertising tool is integrated. The final cookie policy must match the infrastructure actually deployed.

Security and recovery

Evidence is immutable and hash verified; files are not individually encrypted on disk. MFA/provider keys are encrypted in Cloud; backup archives use a separate key. Restorations are tested in an empty database and isolated stack. An independent backup destination and recovery objectives must be agreed with the operator.

Human review before opening signup

Complete and review: publisher/controller identity and contact details, hosting provider and region, data-request contact, terms of use, commercial terms, DPA, Privacy Policy, legal notice, cookie policy, subprocessors including hosting/SMTP/Stripe, retention periods and rights-request procedure. The current contact points to the maintainer profile; it does not replace a formal legal or support channel.

Contact us ↗