🔒

Privacy Policy

Last updated: August 2026

The Short Version

We built ThouShaltNotClick to protect people, not to exploit them. In the ThouShaltNotClick browser extension, your email is analyzed on your device and the content never leaves it. You may also opt in, per email, to deeper AI analysis; our AI partner stores nothing. We keep body text in four narrow cases — a report you submit, an email the AI judges dangerous, an admin telling us we scored one wrong, and short phrases lifted out of confirmed phishing so our detector learns them — each described in detail below. When AI catches a phishing attack, only the sender and subject are shared with your organization. If you use the support chat on this site, what you type goes to our AI provider to compose the reply and the transcript is stored — that too is described below. We use one privacy-first analytics tool, configured cookieless and anonymous, and signed-in student sessions are excluded. We will never sell your data to anyone, ever. This isn't a legal loophole — it's a promise.

Footnote: we also publish a separate Outlook add-in, currently in beta. Microsoft's add-in platform cannot run our analyzer on the device, so it sends up to 3,000 characters of the open email to our servers to be scored. The on-device statement above describes the browser extension; details on the add-in are below.

What We Collect & Why

DataWhyStored Where
Name & emailYour accountOur secure servers (encrypted at rest)
PasswordAuthenticationBcrypt hash only — we never see your password
Simulation resultsTrack if you caught or clicked the phishing testOur server
Training progressKnow which courses you completedOur server
Extension install statusHelp admins see who has protection activeOur server (yes/no + last seen)
Online Kindness statsAggregate counts of polite language signalsYour device + server (aggregate only, daily sync)
AI Analysis data (opt-in only)Deeper phishing analysis when you click the AI buttonSent to our AI service in real time; it stores nothing. We log the score and verdict. Body text is kept only when the AI scores the email below 30 — see “AI-Enhanced Analysis” below.
Reported emails (you press Report)So your admin can judge what you flaggedSender, subject, link URLs, message headers, and a 500-character body excerpt. The excerpt is erased after 30 days.
Phishing samples (AI score below 30)Learn how attacks are written; improve detectionUp to 3,000 characters of body, with your own name and addresses stripped out. Filed under the sender. Visible only to TSNC platform admins. Erased 30 days after that sender was last flagged.
“You missed this phish” reportsAdmin-only: tell us our scoring got one wrongSender, subject, and a 500-character body excerpt — only when an admin chooses to send it. Excerpt erased after 90 days.
Learned phishing phrasesTeach the detector the wording attackers reuse3-to-5-word fragments of the subject and 500-character excerpt of reports an admin confirmed as phishing, kept with the IDs of the source reports and organizations — no sender, no recipient, no reporter. Identifying details are removed before the fragments are cut. See “Learned Phishing Phrases” below.
Support chat on this websiteAnswer your question; hand off to a human if askedWhat you type, our replies, your IP address and browser string — and, if you ask for a human, the name, email and note you enter. Sent to Anthropic to compose each reply. Deleted after 90 days unless you escalated to a human, in which case it is kept.
Community threat alertsProtect your org when AI confirms a phishing attackSender, subject, and the AI's written explanation — no body text
Org email domainsRecognize emails from colleagues (familiar sender detection)Domain names only — cached locally on your device

What We Never Collect

Full email content — ever, on any surface (the browser extension analyzes it on your device; the Outlook add-in sends at most a 3,000-character excerpt)
Your prompts or conversations on other companies’ AI platforms — Online Kindness counts politeness signals on your device and stores none of the text. (Our own support chat on this website is a different thing and we do store those transcripts — see below.)
A record of your browsing — we do not build, keep or sell one. Two exceptions we would rather name than round off: the optional, school-enabled Content Filter records blocked-site attempts, and the toolbar risk badge sends an unrecognized site’s hostname for a live reputation check. Page content is never collected.
Keystrokes, form inputs, or message content from Online Kindness tracking
Location data
Contact lists or address books
Files, documents, or attachments
Data from other extensions
Email body content in Community Threat alerts (only sender + subject)
Any data from AI Analysis without your explicit, per-email opt-in

Browser Extension — How It Works

📧 Email Analysis (Local)

When you open an email in Gmail, our extension analyzes it for phishing indicators using a local analysis engine (analyzer.js) that runs entirely inside your browser. The email content is never transmitted to our servers or any third party. The trust score, findings, and recommendations are all computed on your device.

Footnote — the Outlook add-in (beta). We also publish a separate Outlook add-in, currently in beta. It does not work the way the extension does: Microsoft's add-in platform gives us no way to run our analyzer on your device, so when you open the TSNC panel on an email the add-in sends the sender, subject, link URLs, and up to 3,000 characters of the body to our servers, where the same scoring engine runs. That is its normal, default behavior every time you open the panel — there is no separate opt-in for it. We score the message and return a verdict; the body is not written to our database on this path. The cases where body text is stored are listed below and apply to the add-in exactly as they apply to the extension. The on-device statement above describes the browser extension.

🔑 What the Extension Asks Permission For — Including “All Websites”

When you install our extension, Chrome tells you it can “read and change all your data on all websites”. That is accurate — the extension requests access to every site, not only Gmail and Outlook — and you should hear it from us rather than discover it in the manifest. Here is why, and what it does not mean.

  • Mail sites (Gmail, Outlook web) — where the phishing analyzer runs. This is the core of the product.
  • All other sites — four features have to be able to run on whatever page you are looking at: the QR-code scanner, the “is this image AI-generated?” check, the breach warning on login forms, and password-manager autofill. Chrome has no narrower way to grant that. The optional Content Filter also needs it to redirect a blocked page.
  • The general-web features are user-initiated. The QR and AI-image scanners run when you click them or right-click; auto-scanning pages for QR codes is an opt-in checkbox that is off unless you turn it on. The two password features do nothing at all unless the password manager is enabled for you.
  • Other permissions — storage (your settings, on your device), notifications (breach and threat alerts), context menus (the right-click items), alarms (background refresh), tabs (the toolbar risk badge), and the browser's own request-blocking API for the Content Filter.
  • One transmission worth naming. To colour the toolbar icon for the site you are on, when you are signed in the extension sends that site's hostname — not the page, not its content, not the full URL — to us for a reputation check, and caches the answer. We do not build, keep or sell a record of where you browse.

The full permission-by-permission breakdown is on our Security page.

🚩 Report Suspicious / Report Safe

When you press Report Suspicious, we send and store more than metadata, so here is the full list: the sender address, the subject, the link URLs, the message headers (up to 16 KB), and a 500-character excerpt of the body. The excerpt exists so your administrator can review what you flagged without having to ask you to forward the email. It is visible to administrators at your organization. The excerpt is erased 30 days after the report; the sender, subject and verdict remain. Two follow-on notes that belong here rather than in fine print: if an administrator confirms the report as phishing, short fragments of that excerpt — with identifying details removed first — are kept separately as detection signals (see Learned Phishing Phrases below), and the 30-day erasure is a sweep rather than a timer (see How the Erasures Above Actually Run). Report Safe sends the sender and subject only.

🤖 AI-Enhanced Analysis (Opt-In)

You may optionally click the “AI Analysis” button on any email's trust badge for a deeper, AI-powered review. This is entirely voluntary and requires your explicit action each time — it never happens automatically. When used:

  • What is sent: The sender address, subject line, visible email headers (Date, To, Reply-To), full link URLs with display text, and up to 3,000 characters of the email body.
  • Where it goes: Our server forwards this to our AI service for real-time analysis.
  • What is returned: A score (0–100), verdict, and explanation.
  • What our AI provider does with it: Anthropic processes the request and does not store the content or train models on it.
  • What we log routinely: the sender address, subject line, and the analysis results (score, verdict, and the AI's written explanation). We do not retain the links, the headers, or the body of a normally-scoring email.
  • The one case where we do keep body text: if the AI scores the email below 30/100 — i.e. it judged the message dangerous — we keep up to 3,000 characters of that body as a phishing sample, so we can study how the attack was written and improve detection for everyone. That is the same 3,000-character ceiling we send to the AI: we never store more of an email than we were allowed to transmit. Before it is stored we strip your own name and email addresses out of it. The sample is filed under the sender's address, not yours; it is visible only to ThouShaltNotClick platform administrators, never to your school's admins or anyone at another organization. We keep one sample per sender — the worst-scoring example we have seen. The sample is erased 30 days after the last time anyone flagged that sender, so a sender nobody has seen in a month keeps no stored content. You may also ask us to purge one sooner at privacy@thoushaltnotclick.com.
  • What is NOT kept: the complete body, ever. Nor does the administrator review-queue entry created for a below-30 email carry any body text — sender and subject only.

A clear disclaimer (“Email content was sent to our AI for this analysis”) is shown every time you use this feature.

👥 Familiar Sender Detection

Your organization's email domains (e.g. yourschool.edu) are synced to the extension so it can recognize emails from colleagues. This only includes the domain names — no staff names, email addresses, or other data. Internal senders receive a small trust score boost. This runs locally in your browser using the cached domain list.

🛡️ Community Threat Protection

When AI analysis identifies an email as clearly dangerous (score below 30/100), the sender address and subject line only are stored in our database and shared with other members of your organization. This protects your colleagues from the same phishing attack.

  • What is shared: Sender email address, subject line, AI score, and the AI's written explanation of why it flagged the message. That explanation is prose and may quote a distinctive phrase from the email in describing the tactic.
  • What is NOT shared: The body text itself, links, attachments, the recipient's identity, or any other personal data.
  • Scope: Only shared within your organization — never across organizations.
  • Expiry: Threat alerts expire automatically after 30 days.
  • Admin control: Organization administrators can dismiss false positives at any time.
  • Safeguards: Known legitimate senders (major brands, ESPs) and admin-verified safe senders are exempt from community flagging.

💛 Online Kindness Score

The Online Kindness Score monitors your communication patterns across email, chat, and AI platforms for polite language signals (such as greetings, gratitude, and considerate phrasing). This analysis runs 100% in your browser. Your actual messages, emails, and conversations are never recorded, transmitted, or stored. Only an aggregate kindness grade (Average, Good, or Excellent) is synced daily to the server for organizational leaderboards if you are part of an organization. Organization administrators can disable this feature for their organization.

🔗 URL Scanner

When you manually scan a suspicious URL, that URL is sent to our server for real-time threat analysis — similar to how Google Safe Browsing works in every web browser. The URL is processed immediately and never stored, logged, or associated with your account. No page content, browsing history, or personal data is included.

📉 “You Missed This Phish” (administrators only)

Administrators have a button to tell us our scoring got one wrong — that a real phishing email slipped through with a good score. Because we cannot diagnose that without seeing what we mis-scored, that report includes the sender address, the subject, our scores, and a 500-character excerpt of the body. This is the third of the four places we hold body text. It is never automatic — an administrator has to choose to send it — and it goes only to ThouShaltNotClick's own engineering team, never to another school. The excerpt is erased 90 days after the report — longer than the 30 days we give a staff report, because this queue is reviewed by hand and infrequently. Administrators who would rather not include the excerpt should describe the email in words instead.

🧩 Learned Phishing Phrases — the fourth place

Attackers reuse wording. When an administrator marks a report as confirmed phishing, we run its subject and its 500-character excerpt through a phrase extractor and keep the most distinctive 3-to-5-word fragments, word for word, as candidate detection signals. This is a fourth store of body text and it belongs on this page as much as the other three.

  • What is kept: the fragment itself, its length, and the IDs of the confirmed reports and organizations it came from. No reporter, no recipient, no sender, no message.
  • What is removed before a fragment is ever cut. Identifying details — names, email addresses, links and phone numbers, including the reporter's own name and address — are removed from the text before any fragment is taken, not filtered out afterwards. A fragment that still carries one is discarded rather than stored. We deliberately do not publish the redaction rules themselves: stating them precisely would hand an attacker a recipe for writing a message that slips past both the redaction and the detector. If that level of detail matters for your assessment, write to privacy@thoushaltnotclick.com and we will walk through it with you directly.
  • If we cannot remove it, we do not learn. If we are unable to resolve the reporter's identity in order to remove it, the whole report is skipped rather than extracted. Losing a little detection signal is the correct trade; storing an unredacted fragment is not.
  • What that leaves is what we actually want: lowercase turns of phrase like “wire the funds immediately” or “kindly confirm your login”.
  • Nothing is used until a human promotes it. Extracted fragments sit as pending and affect no one's score. Only a ThouShaltNotClick platform administrator can promote one. A platform administrator can also enter a phrase by hand when reviewing a missed-phish report; that path is a human judgment rather than the automatic one.
  • Promoted fragments are published. Once promoted, a fragment is served to every ThouShaltNotClick browser extension so it can be matched on-device, from an endpoint that requires no login. Assume a promoted fragment is public. That is precisely why the redaction and the human review step both exist.
  • Retention, stated accurately: a fragment stops being used for scoring 365 days after it was last seen in a new confirmed report, and each fresh sighting restarts that clock. What we are not going to claim is that it is then deleted: today the expiry job marks the fragment unused, it does not erase the text. Erasing expired fragments is queued work, and this sentence will change when it ships and not before.
  • Fragments extracted before 28 July 2026 predate the redaction described here and were not machine-redacted. Ask us and we will review and remove them.
  • On request: write to privacy@thoushaltnotclick.com and we will remove fragments derived from your report or your organization.

💬 The Support Chat on This Website

The chat bubble on thoushaltnotclick.com is answered by an AI assistant, not a person, and it is not a local feature — it is the one place on this site where what you type is sent to a third party as you type it.

  • Where it goes: your message, the recent conversation history, and the help articles we matched to it are sent to Anthropic to compose the reply. Do not paste passwords, student records, or anything else confidential into it.
  • What we store: the full transcript — your messages and ours — plus your IP address and browser string. If you are signed in we attach your name and account email; if you are not, the conversation is anonymous unless you tell us who you are.
  • If you ask for a human: the name, email address and note you enter are stored with the conversation, and the whole transcript is emailed to our team so we can reply.
  • Retention: an ordinary conversation is deleted 90 days after it started, by a job that runs daily. A conversation you escalated to a human — or that we flagged for review — is kept beyond that so we can honor the follow-up; ask us at privacy@thoushaltnotclick.com and we will delete it.
  • Who can read it: ThouShaltNotClick platform administrators. Not your school's administrators, not other organizations.

⏱️ How the Erasures Above Actually Run

We would rather describe the mechanism than let “erased after 30 days” imply a precision we do not have. The 90-day support-chat delete runs on a daily scheduled job. The three body-text erasures — report excerpts at 30 days, phishing samples at 30 days from the sender's last flag, missed-phish excerpts at 90 days — are not on a timer. Each is a sweep that fires when the matching part of the product is used: submitting a report sweeps the report excerpts, filing or reviewing a phishing sample sweeps the sample corpus, and submitting or opening the missed-phish queue sweeps that one. Each sweep is throttled to at most once an hour.

In practice that means content past its window is erased within about an hour of the next time anyone touches that surface — usually the same day. On a genuinely idle system it can sit longer. What we will promise without qualification is that every sweep re-counts what should be gone and raises an alert if anything remains, so a retention promise cannot fail silently — and that you can always ask us to purge something immediately at privacy@thoushaltnotclick.com. Putting these three sweeps on the same daily schedule as the chat delete is queued work.

🚫 Content Filter (optional, off by default)

Schools may optionally enable a Content Filter that blocks categories of websites on managed devices. It is off by default — most users are never affected. When a school turns it on, the extension blocks sites locally on the device (your browsing is not sent to us to be filtered) and records policy events only: attempts to reach a blocked site, and staff “proceed anyway” bypasses (domain + category + time), shown to administrators as aggregate counts by default. It does not record your general browsing — sites that aren't blocked are never logged. Full terms are in the Content Filter Addendum.

Analytics & Third-Party Tracking

We use one third-party analytics tool — PostHog — and we run it locked down: cookieless (no tracking cookies, so no consent banner), anonymous by default (we never attach your name or email to analytics events), no session recording ever, and it honors your browser's Do Not Track setting. Signed-in student sessions are excluded entirely. That's the whole list. No Google Analytics. No Facebook Pixel. No ad networks. No data brokers. No advertising or marketing trackers of any kind. You can verify this yourself: the analytics configuration is plain, readable source in our web app, and the browser extension ships no analytics at all — its privacy commitments are embedded directly in the source code of every file.

School & Organization Data

For schools using ThouShaltNotClick, we store organizational data necessary to run phishing simulations and training: staff rosters (name, email, role), campaign results, and training completion records. This data is accessible only to authorized school administrators and is never shared with other schools, organizations, or third parties.

Organization-wide benchmarking (e.g. Diocese-wide) uses anonymized, aggregated statistics only — click rates and catch rates averaged across schools. No individual staff member's data is ever visible to other schools or the parent organization.

Data Deletion

You can request complete deletion of your account and all associated data at any time by contacting us. School administrators can remove staff members from their roster, which removes their simulation and training data. Online Kindness data is stored locally on your device and can be cleared by removing the browser extension. Community threat alerts you contributed will be removed when your account is deleted.

SMS & Text Messaging

SMS verification is an optional security feature. We send text messages only when you have explicitly opted in from your Security Settings page by ticking a standalone consent checkbox. SMS opt-in is never a requirement for using ThouShaltNotClick — you can use the platform without it.

What we send. One-time 6-digit verification codes when you log in or perform sensitive actions on your account. We do not send marketing, promotional, or bulk SMS messages of any kind. Message frequency varies based on how often you log in — typically a few messages per month per active user. Message and data rates may apply per your carrier's plan.

What we store. Your phone number is stored only while SMS verification is enabled on your account. We also record the date and IP address of your initial opt-in (TCPA compliance) and the version of the consent text you agreed to. Phone numbers are never sold, rented, or shared with third parties for marketing.

How to opt out. Reply STOP to any verification message — your number is immediately removed and SMS verification is disabled. You can also disable SMS verification from your Security Settings page. Reply HELP for help. We will never charge you to opt out, and we will never message a number that has opted out without a fresh, explicit opt-in.

SMS messages are delivered through Twilio, our verified communications partner. For full SMS program details, see the SMS Verification Policy.

Children's Privacy & Student Data

The default: no student data at all

A ThouShaltNotClick school account is created with staff coverage only, and in that default state we store no student names, no student email addresses, and no student records of any kind. The core platform — phishing simulations and staff training — is built for adult staff and teachers.

  • Every directory group a school connects is imported as staff unless an administrator changes it — “staff” is the stored default, not a setting we ask schools to pick.
  • Our Clever and OneRoster roster connectors are restricted to staff roles and cannot be pointed at a student role. Clever accepts only teacher, staff, district admin, school admin; OneRoster only administrator, teacher, aide, proctor, staff.
  • Signed-in student sessions are excluded from analytics entirely — not anonymized, excluded.

If your school takes student coverage

Student coverage is a separate add-on — either purchased, or granted to your school under a contract with us. No student record is created anywhere in our system unless both of the following are true. Neither one alone is enough, and if we cannot verify either one, we store nothing:

  1. Your school holds student coverage — purchased student seats, or a contracted allocation we have granted you — and
  2. A principal, IT administrator or enterprise administrator at your school has separately accepted the Student Coverage terms, at their current version. That acceptance is its own act, not part of general signup, and we record who accepted, when, from what address, and which version — see below.

Both are checked on every path that could store a student's name, by one shared gate. There are two such paths: a directory sync, which additionally requires an administrator to have designated a specific directory group as a Student group; and a parent invitation, where a parent creating their account types their child's first name, last name and grade so the school can link them. If the gate refuses the parent path, the parent's own account is still created normally and the child's name is discarded before it is written anywhere — including our logs, which record the refusal but never the name.

There are three different things that can exist for a student, and they hold very different amounts of data. Conflating them is the sort of thing a privacy policy should not do, so here they are separately.

0. The parent-invitation link. The smallest of the three: a parent's account, the child's first name, last name and grade as the parent typed them, and the school it belongs to. Nothing else, and no login for the child.

1. The roster record (what a directory sync creates). For each student in a designated Student group we store first name, last name, school email address, and grade level, plus whether the record is still active. That is the complete list for a roster record. It has no login, no password, and no activity attached to it. We do not collect student browsing history, message or email content, grades, test scores, academic records, disciplinary records, location, biometric data, or device identifiers.

2. The student account (only if your school issues students their own logins). A student account is a real account, and it accumulates what any account accumulates. It is not limited to the four roster fields. Alongside their name and school email it can hold:

  • Sign-in and security data — a password hash or a linked Google/Microsoft sign-in, multi-factor settings if they turn them on, last-login time, and which version of these terms they accepted.
  • Training progress — which courses they started and finished, and their quiz scores, visible to administrators at their school.
  • Breach-monitoring data, if they set it up — a personal email address they enter and verify themselves, and the list of known breaches that address appears in.
  • Extension status — whether the browser extension is installed, its version, and when it last checked in.
  • Anything they do with the extension. This is the part most easily missed: a student account with the extension can press Report Suspicious, and that creates the same record it creates for a teacher — sender, subject, link URLs, message headers and a 500-character excerpt of the email body, readable by administrators at their school. If they use the opt-in AI analysis, the same paths described above apply to them, including the phishing-sample store when the AI scores an email below 30. If your school leaves the Online Kindness Score on, their daily aggregate politeness counts sync too (never the messages).

If that last point is not what your school wants for students, the controls are yours: do not issue student logins, or do not deploy the extension to student devices, or turn Online Kindness off for your organization.

Phishing simulations: staff by default, students only if your administrator turns them on. Simulations are addressed to the staff target list. Student participation is a separate decision that belongs to your school's administrator and is off by default for every organization — we do not enable it, and it does not switch itself on because a student appears on a roster. In this release there is no control in the admin interface to turn it on: the setting ships in the off position and the screen for changing it comes in a later release. When it does arrive and a school turns it on, students get their own campaigns on their own send volume — set independently of the staff cadence — drawn from a separate pool of templates an administrator has marked age-appropriate. That pool starts empty, and adult-financial lures (payroll and direct-deposit changes, wire transfers, vendor and invoice fraud, tax, benefits, banking and W-2 scams) are refused for student recipients even if someone tags one of them age-appropriate.

One honest caveat, because the alternative is a promise we cannot yet keep: historically a student could be enrolled in a staff campaign by accident, simply by being on the roster a campaign was built from. We are removing that. The check that identifies students and holds them out of staff campaigns — and that refuses to launch at all rather than guess when it cannot tell who on a roster is a student — is in place on the main campaign-launch path, and we are extending it to the remaining automatic campaign-generation paths. Until that is finished we will not claim that no student is ever enrolled by accident. If you want certainty in the meantime, keep student accounts off the target roster your campaigns are built from, and write to privacy@thoushaltnotclick.com if you think a student received a simulation — we will tell you what happened.

Student coverage is governed by additional terms — the Student Coverage & Student Data section of our Organization Terms of Service — which apply on top of the base agreement and set out the school's consent obligations before any student is added.

How student data is protected

  • Your school is the data controller. TSNC acts as a school official / service provider under FERPA, processing student data only on your school's instructions.
  • Your school is responsible for parental notice and consent required by FERPA, COPPA, or local law before adding students. We do not collect personal information directly from children.
  • Never sold, never shared, never used for advertising, profiling, or AI training. Not now, not under new ownership.
  • Scoped to your school. Student records are visible only to authorized administrators at that school — never to other schools, never to a parent diocese or district as individual records.
  • Encrypted at rest, and deleted when you ask us to delete it — that is the commitment, and here is exactly how it is honored. Student deletion is performed by our team when you write to privacy@thoushaltnotclick.com. There is no self-service “delete students” control in the admin interface yet. Removing a student from your directory, or un-designating a Student group, does not by itself erase a record we already hold. Offboarding does not erase it either: offboarding deactivates your organization and stops all product activity — simulations, campaigns, staff access, billing — but it deliberately preserves stored records for the FERPA retention window rather than deleting them, and it does not touch the student roster at all. If you want student records erased at offboarding, tell us and we will do it as part of the offboard.
  • Students are excluded from our public Hall of Fame unless an administrator at your school separately turns on student participation, which is off by default.

Separately, some schools deploy our optional Content Filter to student devices. The same controller relationship applies, and the school is responsible for any parental notice or consent required before deploying it. We practice strict data minimization there too: the filter records only blocked-site attempts (never general browsing), defaults to aggregate counts, and is governed by the Content Filter Addendum.

Contact

Questions about our privacy practices? Email us at privacy@thoushaltnotclick.com

“Every person's data deserves the same care and respect we owe every person.”

That's not just our policy — it's our promise.