PhishGuard Local

Privacy Policy

Privacy information for PhishGuard Local, a Microsoft Edge extension that helps detect phishing, suspicious links, domain impersonation, credential traps, scam or fake stores, risky webmail links, and correlated threat signals.

Version 1.0.0 Stable Last updated September 4, 2026 Microsoft Edge
Local-first privacy design PhishGuard Local does not include advertising, analytics, behavioral tracking, or data brokerage. Core protection runs locally in Microsoft Edge.

Overview

PhishGuard Local is a Microsoft Edge extension that helps detect phishing, suspicious links, domain impersonation, credential traps, scam or fake stores, risky webmail links, and correlated threat signals.

The core protection stack runs locally in Microsoft Edge. PhishGuard Local does not include advertising, analytics, behavioral tracking, or data brokerage.

Information accessed for the extension's security features

To provide its user-facing protection features, PhishGuard Local can locally inspect supported webpages, including page URLs, links, form structure, domain information, and limited visible security-related page text.

This access is used only to determine whether the current page, form, store, or link appears suspicious.

PhishGuard Local is designed not to read, collect, or store:

Credential and checkout protection responds to field presence, form destinations, page/domain context, and security scores rather than reading secret field values.

Local incident history

PhishGuard Local can store up to 200 security incident records locally in Microsoft Edge.

For ordinary web incidents, stored URLs are sanitized to remove usernames/passwords, query strings, and fragments.

For Webmail Guard incidents, the stored destination is reduced to its HTTP/HTTPS origin. Message text, sender information, URL paths, query parameters, and fragments are not persisted.

Incognito alerts are not written to persistent incident history.

Users can clear incident history from the Protection Center.

Microsoft Edge storage

PhishGuard Local uses Microsoft Edge extension storage for settings and security data.

Local extension storage may contain:

Preference storage may contain:

If Microsoft Edge Sync is enabled and the browser syncs extension settings, eligible preference data may be synchronized by Microsoft Edge according to the user's browser account and sync settings.

Optional Google Safe Browsing integration

Google Safe Browsing reputation checks are optional and disabled by default.

A user must explicitly configure and enable this feature. When enabled, URLs checked for reputation are sent to Google's Safe Browsing service using an API key supplied by the user.

The local protection stack continues to function when Google Safe Browsing is disabled.

PhishGuard Local does not sell Safe Browsing data or use it for advertising or analytics.

Data sharing

PhishGuard Local does not sell user information.

The extension does not transmit locally inspected webpage content to the developer.

The only optional third-party URL transmission in version 1.0.0 is the user-enabled Google Safe Browsing reputation request described above.

Exports

The Protection Center can export incident summaries as JSON or CSV only when the user explicitly requests an export.

Exports do not include:

User controls

Users can:

Microsoft Edge Store data disclosure

For Microsoft Edge Add-ons disclosure purposes, PhishGuard Local may access the following categories only as needed to provide its security features:

PhishGuard Local does not access or store password values, payment-card values, health information, precise location data, or other secret authentication values.

Changes to this policy

This policy will be updated if PhishGuard Local adds new data-access, storage, analytics, advertising, or network behavior.

Contact

For support, privacy questions, or security-related inquiries about PhishGuard Local, contact:

kylehillier323@live.ca