Privacy Policy
1. Purpose
PhishDestroy + FFraud Guard has one purpose: to reduce exposure to known or strongly indicated phishing websites and malicious web infrastructure. It checks top-level HTTP and HTTPS navigation against PhishDestroy domain intelligence and, when enabled, FFraud public-IP reputation. When a configured blocking condition matches, the extension replaces navigation with a local warning page.
2. Data the extension handles
Website hostnames and URLs
The extension reads the current top-level HTTP or HTTPS URL so it can extract the hostname and perform a protection decision. The hostname is web-browsing activity under Chrome Web Store policy.
The full URL is used locally to display the requested address on a block page and to return to the address if the user deliberately allows it. For blocked pages, a local record may contain the full URL, hostname, time, score, severity, intelligence source, reason and resolved server IP. The extension keeps no more than 100 of these local block records.
Public server IP addresses
If FFraud checking is enabled, the extension asks Cloudflare DNS-over-HTTPS for the hostname's public IPv4 and IPv6 addresses. It may check up to three returned public server IP addresses with FFraud. It excludes local and private-network addresses.
Settings and security data
The extension stores protection settings, thresholds, feature toggles, the user's domain allowlist, checked and blocked counters, per-source feed results, refresh progress, compact-database metadata, the downloaded PhishDestroy Primary, Active Domains, Community, Community Live and Root Domains feeds, the official allowlist, and short-lived lookup caches locally in Chrome.
The deduplicated threat data is packed into approximately 1,024 IndexedDB buckets to reduce storage overhead. An upgrade from the earlier per-domain format deletes the obsolete threat store and rebuilds the compact database during the next feed refresh.
Data the extension does not inspect or transmit
The extension does not analyse page text, images or other page content. It does not inspect form contents, passwords, authentication credentials, personal communications or keystrokes. It does not send URL paths or query strings to PhishDestroy, Cloudflare or FFraud.
3. External services and sharing
The extension shares only the data needed to provide its security checks:
- PhishDestroy API: receives a website hostname when live PhishDestroy fallback is enabled and a live lookup is required.
- Cloudflare DNS-over-HTTPS: receives a website hostname when FFraud checking is enabled, so the hostname can be resolved to public server IP addresses.
- FFraud: receives resolved public server IP addresses when FFraud checking is enabled.
- GitHub: hosts the five public PhishDestroy intelligence feeds and official allowlist downloaded by the extension.
Requests use HTTPS. Like other internet services, these providers necessarily receive connection information such as the user's public IP address and may derive an approximate region from it. Their own logging and retention practices are governed by their respective privacy policies and terms.
The extension publisher does not sell user data, use it for advertising, build advertising profiles, or transfer it for creditworthiness or lending decisions. Data is used or transferred only to provide and maintain the extension's stated security purpose, for security or abuse prevention, to comply with applicable law, or in another use permitted by Chrome Web Store policy.
4. Local retention
- PhishDestroy live lookup results are cached locally for up to six hours.
- FFraud results are cached locally for up to 30 minutes.
- The local block log retains only the 100 most recent blocked-page records.
- The downloaded and deduplicated threat feeds remain locally in the compact database until they are replaced by a refresh, Chrome clears extension data, or the extension is removed.
- Settings, allowlists, counters and feed metadata remain until changed, Chrome clears extension data, or the extension is removed.
5. User choices and control
Users can disable all protection, disable live PhishDestroy fallback, disable FFraud checks, change thresholds, remove domains from the personal allowlist, or remove the extension. Disabling a live feature prevents the corresponding future live checks. Removing the extension clears its locally stored extension data through Chrome.
6. Security
All external requests made by the extension use HTTPS. The executable JavaScript is included in the installed extension package; the extension does not download and execute remote JavaScript or WebAssembly. No method of storage or transmission is completely risk-free, and the extension cannot guarantee that a malicious site will always be detected.
7. Chrome Web Store Limited Use
The use and transfer of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. The extension uses browsing information only to provide its user-facing website-protection features.
8. Changes to this policy
This policy may be updated when the extension's functionality or data practices change. The effective date at the top of this page will be revised, and material changes will be disclosed as required.
9. Contact
Privacy questions may be sent through the publisher support channel displayed on the extension's Chrome Web Store listing.