Individual & Family Terms of Service
1. Acceptance of Terms
By creating an account, accessing, or using any ThouShaltNotClick service — including our web platform, Chrome extension, phishing simulations, training courses, and breach monitoring ("Services") — you agree to be bound by these Terms of Service ("Terms"). If you do not agree, do not use the Services.
These Terms constitute a legally binding agreement between you and Education Technology Professionals, LLC ("ETP," "we," "us," or "our"), the company that operates ThouShaltNotClick.
2. Description of Services
ThouShaltNotClick provides personal cybersecurity awareness services including:
• Simulated phishing emails sent to your personal email to test your awareness
• Interactive training courses on phishing, passwords, social engineering, and safe browsing
• A Chrome browser extension with email scanning and a "Report Suspicious" button
• Personal email breach monitoring via third-party data sources
• A personal dashboard tracking your training progress and simulation results
For Family plans, these services extend to up to 5 additional family members you invite. As the primary account holder, you are responsible for ensuring invited family members consent to receiving simulated phishing emails.
3. No Guarantee of Complete Protection
IMPORTANT: ThouShaltNotClick is a cybersecurity awareness and training platform — NOT a comprehensive cybersecurity solution. We do not guarantee that our Services will prevent all phishing attacks, data breaches, or security incidents.
• Our Chrome extension and email scanning tools help identify many suspicious emails, but they cannot catch 100% of phishing attempts. Phishing techniques evolve rapidly, and new attack methods emerge constantly. While we continuously update our detection capabilities, no tool can guarantee complete protection.
• AI-Enhanced Analysis provides an additional layer of detection but is not infallible. AI models can produce false positives (flagging legitimate emails) or false negatives (missing real threats). AI analysis results should be considered advisory, not definitive.
• Community Threat Protection helps share threat intelligence within your organization, but it depends on at least one person identifying and analyzing a suspicious email first. It cannot protect against novel, targeted attacks that no one has analyzed yet.
• Our phishing simulations are training exercises. They test awareness using known techniques, but real-world attacks may use novel methods not covered in our simulations.
• Breach monitoring relies on third-party data sources and can only report breaches that have been publicly discovered and cataloged.
• In cybersecurity, defensive measures inherently lag behind offensive innovation. We are committed to staying at the forefront of phishing prevention, but we cannot guarantee our Services will detect every new threat.
You acknowledge that cybersecurity is a shared responsibility and that our Services are one layer of a comprehensive security strategy — not a replacement for email filtering, endpoint protection, network security, and organizational security policies.
4. Simulated Phishing Emails
By using our Services, you consent to receiving simulated phishing emails at your registered email address. These emails are designed to appear realistic and may use urgency, authority impersonation, and social engineering tactics for training purposes.
• Clicking links in simulated emails is recorded to track your progress.
• Your simulation results are private to you (and your family plan administrator, if applicable).
• You may opt out of simulations at any time by cancelling your account.
For Family plans: family members you invite also consent to receiving simulations upon accepting their invitation.
5. Chrome Extension
The Chrome extension provides several features:
EMAIL ANALYSIS (LOCAL): When you open an email in Gmail, the extension analyzes it for phishing indicators using a local analysis engine that runs entirely inside your browser. Full email content is never transmitted to our servers.
AI-ENHANCED ANALYSIS (OPT-IN): You may choose to click the "AI Analysis" button on any email to request a deeper analysis. This is entirely optional and requires explicit action each time. When used, the email's sender address, subject line, visible headers, full link URLs with display text, and up to 3,000 characters of the body are sent to our AI service for analysis, with your own name and email addresses stripped out of the body first. The AI returns a score and explanation and retains nothing. Analysis results (score and verdict) are logged for organizational security monitoring. If the AI scores the email BELOW 30/100 we additionally keep up to 3,000 characters of that body as a phishing sample — see WHERE WE KEEP BODY TEXT below. The administrator review-queue entry created for a below-30 email carries the sender and subject only; it holds no body text.
COMMUNITY THREAT PROTECTION: When AI analysis identifies an email as dangerous (score below 30), the sender address, subject line, score, and the AI's written explanation are stored in our database and shared with other members of your organization. This helps protect your colleagues from the same phishing attack. The body text itself is not shared with your organization. Administrators can dismiss false positives.
WHERE WE KEEP BODY TEXT: four cases, and only these four. (1) REPORTS — pressing "Report Suspicious" sends and stores the sender, subject, link URLs, message headers, and a 500-character excerpt of the body, so your administrator can judge the report without asking you to forward the email; the excerpt is erased 30 days later. (2) PHISHING SAMPLES — an email the AI scores below 30/100 has up to 3,000 characters of its body kept as a study sample, with your own name and addresses stripped out, filed under the sender's address rather than yours, and readable only by ThouShaltNotClick platform administrators — not by your organization's administrators and never by another organization. We keep one sample per sender, the worst-scoring example we have seen, and it is erased 30 days after that sender was last flagged by anyone. (3) MISSED-PHISH REPORTS — an administrator can tell us our scoring wrongly cleared a real phishing email, and that report includes a 500-character excerpt so we can diagnose it; that excerpt is erased after 90 days. (4) LEARNED PHRASE SIGNALS — when an administrator confirms a report as phishing, we pull the most distinctive 3-to-5-word fragments out of its subject and excerpt and keep them as detection signals with the IDs of the reports and organizations they came from — no sender, no recipient, no reporter. Identifying details, including names, email addresses, links and phone numbers and your own name and address, are removed from the text before any fragment is cut, and a fragment that still carries one is discarded rather than stored; if we cannot resolve the reporter's identity in order to remove it, the report is skipped entirely. We do not publish the redaction rules themselves, because setting them out precisely would tell an attacker how to compose a message that evades both the redaction and the detector. Fragments do nothing until a ThouShaltNotClick platform administrator promotes one; a promoted fragment is then published to every ThouShaltNotClick browser extension from an endpoint that needs no login, so treat a promoted fragment as public. A fragment stops being used for scoring 365 days after it was last seen in a new confirmed report, restarting on each sighting — and, stated plainly rather than flatteringly, at that point we mark it unused rather than erasing the text; erasing expired fragments is queued work. Fragments extracted before 28 July 2026 predate the redaction described here. You may request earlier purging of any of these at privacy@thoushaltnotclick.com. A complete email body is never stored, and attachments are never transmitted or stored.
HOW THE ERASURES ABOVE RUN: not on a timer. Each is a sweep attached to the part of the product that uses that store (filing a report, filing or reviewing a phishing sample, filing or opening the missed-phish queue), throttled to at most once an hour. In ordinary use content past its window is erased within about an hour of the next time that surface is used; on an idle system it can sit longer. Every sweep re-counts what should be gone and alerts if anything remains, so the promise cannot fail silently — and you can ask us to purge anything immediately.
ONLINE KINDNESS SCORE: The extension monitors your communication patterns across email, chat, and AI platforms for polite language. This analysis runs 100% in your browser. Only aggregate statistics (not message content) are synced daily to the server for organizational leaderboards if you are part of an organization. Your actual messages are never recorded or transmitted.
REPORT & REPORT SAFE: The "Report Suspicious" and "Report Safe" buttons let you flag emails for your administrator to review. A "Report Suspicious" submission includes the sender address, subject line, trust score, the link URLs, the message headers, and a 500-character excerpt of the body, so your administrator can review what you flagged without asking you to forward the email. The excerpt is erased 30 days after the report. The full email content is never sent. "Report Safe" sends the sender address and subject line only.
EXTENSION PERMISSIONS, STATED PLAINLY: the extension requests access to ALL WEBSITES — Chrome presents this at install as "read and change all your data on all websites" — and we would rather write that here than let you find it only in the manifest. It is needed because five capabilities have to be able to run on an arbitrary page: the QR-code scanner, the AI-generated-image check, the breach warning on login forms, password-manager autofill, and the optional Content Filter (which uses the browser's own request-blocking API to redirect a blocked page). Chrome offers no narrower grant for those. The other permissions the extension declares are storage (your settings, on your device), notifications (breach and threat alerts), context menus (the right-click items), alarms (periodic background refresh), and tabs (the toolbar risk badge). The general-web features listed above are user-initiated or feature-gated: the QR and AI-image scanners run when you invoke them, auto-scanning for QR codes is an opt-in setting that is off by default, and the two password features do nothing unless the password manager is enabled for you. To colour the toolbar badge for the site you are on, the extension sends that site's hostname — not the page, not its content, not the full URL — to us for a reputation check when you are signed in. We do not build, retain or sell a record of the sites you visit. These permissions are used solely for the stated functionality — not for surveillance, advertising, or unnecessary data collection. The permission-by-permission breakdown is on our Security page. The extension cannot guarantee detection of all phishing attempts.
6. Data Privacy and Security
We take the privacy and security of your data seriously. Our complete data practices are described in our Privacy Policy at thoushaltnotclick.com/privacy, which is incorporated into these Terms by reference.
• We collect only data necessary to provide our Services.
• Simulation data (click rates, report rates, training scores) is used for analytics and reporting. We do not sell data to third parties.
• In the ThouShaltNotClick browser extension, your email is analyzed on your device and the content never leaves it. (Footnote: our separate Outlook add-in, currently in beta, cannot work that way — Microsoft's add-in platform does not allow it — so the add-in sends the sender, subject, link URLs and up to 3,000 characters of the body to our servers to be scored whenever a user opens its panel on an email. That is the add-in's normal behavior, not an opt-in.)
• AI-Enhanced Analysis is opt-in and clearly marked. When used, limited email data (sender, subject, visible headers, full link URLs, and up to 3,000 characters of body text) is sent to our AI service for real-time analysis. Your own name and email addresses are stripped out of the body first. Our AI provider does not store it or train on it.
• Community Threat Protection shares only the sender address, subject line, score, and the AI's written explanation of AI-confirmed dangerous emails within your organization. The body text itself is not shared.
• WE DO RETAIN EMAIL BODY TEXT IN FOUR NARROW CASES, and we would rather list them than let a general reassurance stand in for the detail: (1) when you press Report Suspicious, a 500-character excerpt is kept for your organization's administrators and erased 30 days later; (2) when AI analysis scores an email below 30/100, up to 3,000 characters is kept as a phishing sample, with your own name and addresses stripped out, filed under the sender's address, readable only by ThouShaltNotClick platform administrators, and erased 30 days after that sender was last flagged; (3) when one of your administrators reports that our scoring missed a real phish, a 500-character excerpt is included so we can diagnose it, and erased after 90 days; (4) when an administrator confirms a report as phishing, we extract distinctive 3-to-5-word fragments of its subject and excerpt, word for word, and keep them as detection signals. 3,000 characters is the ceiling on what we may send to the AI and on what we may store, and it is the same ceiling — we never keep more of an email than we were permitted to transmit. You may ask us to purge any of these sooner at privacy@thoushaltnotclick.com. We never retain a complete email body, and we never retain attachments.
• ABOUT THOSE PHRASE FRAGMENTS (case 4), because a store we did not previously describe deserves more than a clause: a fragment is three to five words and is kept with the IDs of the confirmed reports and organizations it came from — no sender, no recipient, no reporter. Before any fragment is cut, identifying details are removed from the text: links, email addresses, phone numbers, names, and the reporter's own name and address. A fragment that still carries one is discarded rather than stored, and if the reporter's identity cannot be looked up so as to be removed, the report is skipped entirely rather than extracted. We deliberately do not publish the redaction rules themselves — setting them out precisely would tell an attacker how to compose a message that evades both the redaction and the detector — and we will walk any customer through them directly on request at privacy@thoushaltnotclick.com. Fragments are then inert until a ThouShaltNotClick platform administrator reviews and promotes one; a promoted fragment is served to every ThouShaltNotClick browser extension from an endpoint that requires no login, so a promoted fragment should be treated as public, which is why both the redaction and the review step exist. A platform administrator may also enter a phrase by hand when reviewing a missed-phish report; that path is human judgment rather than the automatic one. A fragment stops being used for scoring 365 days after it was last seen in a new confirmed report, and every fresh sighting restarts that clock. We are not going to claim more than that: at present expiry marks a fragment unused rather than erasing the text, and erasure of expired fragments is work we have queued but not shipped. Fragments extracted before 28 July 2026 predate the redaction described here. Removal on request at privacy@thoushaltnotclick.com.
• HOW THOSE ERASURES ACTUALLY RUN. The 30-day and 90-day erasures above are not driven by a timer. Each is a sweep attached to the code path that uses the store in question — filing a report sweeps report excerpts, filing or reviewing a phishing sample sweeps that corpus, filing or opening the missed-phish queue sweeps that one — and each sweep runs at most once an hour. In ordinary use content past its window is erased within about an hour of the next time that part of the product is used; on an idle system it can sit longer. Each sweep re-counts what should be gone and raises an alert if anything remains, so the promise cannot fail silently, and you can always ask us to purge something immediately.
• OUR WEBSITE SUPPORT CHAT IS A SEPARATE DISCLOSURE and is not covered by anything above. The chat assistant on thoushaltnotclick.com is AI-backed: each message you send, together with the recent conversation history, is transmitted to Anthropic to compose the reply. We store the transcript, your IP address and browser string, and — if you ask to be handed off to a person — the name, email address and note you provide. Ordinary conversations are deleted 90 days after they begin by a job that runs daily; conversations escalated to a person or flagged for review are kept until you ask us to delete them. Please do not paste confidential information, credentials, or student records into it.
• We use industry-standard security measures including encryption in transit (TLS) and at rest.
• For organization accounts, data is isolated per organization. One organization cannot access another's data.
7. Billing, Trials, and Cancellation
• All paid plans begin with a 7-day free trial with full feature access.
• Payment information is collected at signup via Stripe. You will not be charged during the trial.
• After the trial, your subscription automatically converts to paid unless cancelled.
• Subscriptions are billed monthly or annually depending on the plan selected.
• You may cancel at any time through the billing portal. Cancellation takes effect at the end of your current billing period.
• We do not offer refunds for partial billing periods, except as required by law.
• Price changes will be communicated at least 30 days in advance.
8. Acceptable Use
You agree not to: use the Services for any malicious purpose; attempt unauthorized access to other accounts; reverse-engineer our software; use the Services in any way that violates applicable law. Violation may result in account termination.
9. Migrating From an Organization
If you joined ThouShaltNotClick first as a member of an organization (such as a school or diocese) and have now converted to a personal account, the following apply:
• If a 50%-first-year discount was applied to your migration, it applies once. The subscription will renew at the regular annual price after the first year unless you cancel.
10. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW:
• ETP's total liability shall not exceed the amount you paid for the Services in the twelve (12) months preceding the claim.
• ETP shall not be liable for indirect, incidental, special, consequential, or punitive damages, including loss of data, revenue, or damages resulting from a security breach that our Services did not detect.
• ETP is not liable for damages resulting from reliance on our Services as your sole cybersecurity measure.
• Our Services are provided "as is" and "as available" without warranties of any kind, express or implied.
11. Modifications to Terms
We may modify these Terms at any time. For material changes, we will notify active account holders via email at least 30 days before changes take effect. Continued use after the effective date constitutes acceptance. If you disagree, you must cancel your account before changes take effect.
12. Termination
Either party may terminate the relationship. You may cancel your account at any time. We may suspend or terminate your account for Terms violations or non-payment. Upon termination, data is retained for 90 days, then permanently deleted unless legally required otherwise. To be precise about the mechanism rather than imply one we do not have: offboarding and cancellation stop all product activity automatically and immediately, but the deletion at the end of that 90-day window is carried out by our team as a contractual commitment, not by an automated purge job. You may request deletion sooner at privacy@thoushaltnotclick.com and we will perform it. Sections that by nature should survive termination (Liability, Indemnification, IP) shall survive.
13. Governing Law
These Terms are governed by the laws of the State of New Jersey. Disputes shall be resolved through binding arbitration per the American Arbitration Association rules, except that either party may seek injunctive relief in court. The prevailing party may recover reasonable attorney's fees.
14. Contact
Questions about these Terms? Contact us:
Education Technology Professionals, LLC
Email: support@thoushaltnotclick.com
Website: www.thoushaltnotclick.com
Privacy inquiries: privacy@thoushaltnotclick.com