Privacy Policy

Last updated September 18, 2026

This policy explains what phish.co ("phish.co," "we," "us," or "our") stores when your organization uses phish.co, why, and who processes it on our behalf.

Two kinds of data, and two roles we play

Most privacy policies describe one relationship: a company and its own users. phish.co has two. Your organization is our direct customer, and we hold your account and billing information the way any subscription service would. But a phishing, smishing, or vishing assessment necessarily involves data about your employees — people who never signed up for phish.co and have no account with us. For that data, we act as a processor on your organization's behalf, not as the party that decides why it was collected. Your organization remains responsible for its own employees' notice and rights under applicable law; we process what you configure a campaign to use, for the purpose you configure it for, and nothing else.

What we store

DataWhy
Account email address, organization nameSign-in (magic-link / one-time code) and service notifications for your organization's account.
Domain verification recordsProof that your organization owns the domain(s) it runs campaigns against — a role-email confirmation and, for higher tiers, a DNS record check.
Subscription status & plan tierTo grant access to paid features. Payment card details are handled by Stripe — we never see or store your full card number.
Target roster entries (your employees)Name, work email, and — only if you enable SMS/voice and the employee is enrolled — phone number, so a campaign can reach them. Every entry is checked against your verified domain(s) before it can be added.
Campaign content and configurationThe templates, channels, and schedule you choose for an assessment.
Interaction metadataWhether a message was opened, a link was clicked, a form was submitted, or the message was reported — the outcomes your reporting is built from.
Operational logsSecurity and reliability. Logs are scrubbed of secrets and credential-shaped values before they're written.

What we deliberately do not store

If a simulated landing page captures a submission (for example, someone types a username and password into a fake login form), we record only that a submission occurred — a boolean and a timestamp — never the actual values typed. This is a hard rule in how the product is built, not a configurable setting, and it applies regardless of what a customer's landing-page template asks for.

Health and other sensitive information (HIPAA)

phish.co is not intended to touch protected health information (PHI), and the product is deliberately designed to minimize the chance any does. Landing-page templates that mimic clinical or electronic-health-record-style portals are not permitted on the platform, and interaction data is captured in structured form (clicked / did not click, submitted / did not submit) rather than freeform text wherever the product can do so — freeform text is exactly the shape a person might paste real patient information into by mistake. We do not offer or sign a Business Associate Agreement, and no customer should treat phish.co as a venue for handling PHI.

Sub-processors

We rely on the following processors to run the service. Each receives only the data needed for its function:

Sending-domain separation

Simulated assessment traffic (email, SMS links, vishing callback numbers) is sent from infrastructure kept entirely separate from the domain we use for your account's trusted, transactional mail. This is deliberate: assessment traffic is meant to look suspicious to mail and phone security systems, and keeping it on its own infrastructure means that reputation never affects your receipts, sign-in codes, or other real correspondence from us. See Security for detail.

Retention, deletion, and revocation

Your organization can remove target roster entries, campaigns, and connected data at any time from your account. On account closure we delete your organization's account data and campaign activity within a reasonable period, except where we must retain limited records to meet legal or accounting obligations. To request deletion or a copy of your data, contact us.

Security

We protect data with encryption in transit and at rest, tenant isolation enforced at the database level, least-privilege access, and secrets kept out of source and logs. See our Security page for the full model.

Changes

We may update this policy from time to time and will post the updated version here with a new date.

Contact

Privacy questions or data requests: hello@phish.co.