Privacy Policy

PhishDestroy + FFraud Guard
Effective date: 27 August 2026

Summary: The extension handles website hostnames and, for blocked pages, may store the full blocked URL locally. When live protection is enabled, hostnames and resolved public server IP addresses are sent over HTTPS to the security services identified below. Page text, form contents, passwords, keystrokes, URL paths and query strings are not sent to those services by the extension.

1. Purpose

PhishDestroy + FFraud Guard has one purpose: to reduce exposure to known or strongly indicated phishing websites and malicious web infrastructure. It checks top-level HTTP and HTTPS navigation against PhishDestroy domain intelligence and, when enabled, FFraud public-IP reputation. When a configured blocking condition matches, the extension replaces navigation with a local warning page.

2. Data the extension handles

Website hostnames and URLs

The extension reads the current top-level HTTP or HTTPS URL so it can extract the hostname and perform a protection decision. The hostname is web-browsing activity under Chrome Web Store policy.

The full URL is used locally to display the requested address on a block page and to return to the address if the user deliberately allows it. For blocked pages, a local record may contain the full URL, hostname, time, score, severity, intelligence source, reason and resolved server IP. The extension keeps no more than 100 of these local block records.

Public server IP addresses

If FFraud checking is enabled, the extension asks Cloudflare DNS-over-HTTPS for the hostname's public IPv4 and IPv6 addresses. It may check up to three returned public server IP addresses with FFraud. It excludes local and private-network addresses.

Settings and security data

The extension stores protection settings, thresholds, feature toggles, the user's domain allowlist, checked and blocked counters, per-source feed results, refresh progress, compact-database metadata, the downloaded PhishDestroy Primary, Active Domains, Community, Community Live and Root Domains feeds, the official allowlist, and short-lived lookup caches locally in Chrome.

The deduplicated threat data is packed into approximately 1,024 IndexedDB buckets to reduce storage overhead. An upgrade from the earlier per-domain format deletes the obsolete threat store and rebuilds the compact database during the next feed refresh.

Data the extension does not inspect or transmit

The extension does not analyse page text, images or other page content. It does not inspect form contents, passwords, authentication credentials, personal communications or keystrokes. It does not send URL paths or query strings to PhishDestroy, Cloudflare or FFraud.

3. External services and sharing

The extension shares only the data needed to provide its security checks:

Requests use HTTPS. Like other internet services, these providers necessarily receive connection information such as the user's public IP address and may derive an approximate region from it. Their own logging and retention practices are governed by their respective privacy policies and terms.

The extension publisher does not sell user data, use it for advertising, build advertising profiles, or transfer it for creditworthiness or lending decisions. Data is used or transferred only to provide and maintain the extension's stated security purpose, for security or abuse prevention, to comply with applicable law, or in another use permitted by Chrome Web Store policy.

4. Local retention

5. User choices and control

Users can disable all protection, disable live PhishDestroy fallback, disable FFraud checks, change thresholds, remove domains from the personal allowlist, or remove the extension. Disabling a live feature prevents the corresponding future live checks. Removing the extension clears its locally stored extension data through Chrome.

6. Security

All external requests made by the extension use HTTPS. The executable JavaScript is included in the installed extension package; the extension does not download and execute remote JavaScript or WebAssembly. No method of storage or transmission is completely risk-free, and the extension cannot guarantee that a malicious site will always be detected.

7. Chrome Web Store Limited Use

The use and transfer of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. The extension uses browsing information only to provide its user-facing website-protection features.

8. Changes to this policy

This policy may be updated when the extension's functionality or data practices change. The effective date at the top of this page will be revised, and material changes will be disclosed as required.

9. Contact

Privacy questions may be sent through the publisher support channel displayed on the extension's Chrome Web Store listing.