PhishGuard Local
Privacy Policy
Privacy information for PhishGuard Local, a Microsoft Edge extension that helps detect phishing, suspicious links, domain impersonation, credential traps, scam or fake stores, risky webmail links, and correlated threat signals.
Overview
PhishGuard Local is a Microsoft Edge extension that helps detect phishing, suspicious links, domain impersonation, credential traps, scam or fake stores, risky webmail links, and correlated threat signals.
The core protection stack runs locally in Microsoft Edge. PhishGuard Local does not include advertising, analytics, behavioral tracking, or data brokerage.
Information accessed for the extension's security features
To provide its user-facing protection features, PhishGuard Local can locally inspect supported webpages, including page URLs, links, form structure, domain information, and limited visible security-related page text.
This access is used only to determine whether the current page, form, store, or link appears suspicious.
PhishGuard Local is designed not to read, collect, or store:
- password values
- credit or debit card numbers
- CVV/CVC values
- typed checkout-field contents
- clipboard contents
- email message bodies
- email subjects
- sender email addresses
- raw webmail message text
- raw storefront page text
Credential and checkout protection responds to field presence, form destinations, page/domain context, and security scores rather than reading secret field values.
Local incident history
PhishGuard Local can store up to 200 security incident records locally in Microsoft Edge.
For ordinary web incidents, stored URLs are sanitized to remove usernames/passwords, query strings, and fragments.
For Webmail Guard incidents, the stored destination is reduced to its HTTP/HTTPS origin. Message text, sender information, URL paths, query parameters, and fragments are not persisted.
Incognito alerts are not written to persistent incident history.
Users can clear incident history from the Protection Center.
Microsoft Edge storage
PhishGuard Local uses Microsoft Edge extension storage for settings and security data.
Local extension storage may contain:
- the user's optional Google Safe Browsing API key
- Google Safe Browsing reputation cache entries
- sanitized incident history
- release and migration metadata
Preference storage may contain:
- protection toggles
- sensitivity settings
- credential protection mode
- trusted-site entries
- custom protected domains
- protected login domains
If Microsoft Edge Sync is enabled and the browser syncs extension settings, eligible preference data may be synchronized by Microsoft Edge according to the user's browser account and sync settings.
Optional Google Safe Browsing integration
Google Safe Browsing reputation checks are optional and disabled by default.
A user must explicitly configure and enable this feature. When enabled, URLs checked for reputation are sent to Google's Safe Browsing service using an API key supplied by the user.
The local protection stack continues to function when Google Safe Browsing is disabled.
PhishGuard Local does not sell Safe Browsing data or use it for advertising or analytics.
Data sharing
PhishGuard Local does not sell user information.
The extension does not transmit locally inspected webpage content to the developer.
The only optional third-party URL transmission in version 1.0.0 is the user-enabled Google Safe Browsing reputation request described above.
Exports
The Protection Center can export incident summaries as JSON or CSV only when the user explicitly requests an export.
Exports do not include:
- Google Safe Browsing API keys
- password or payment values
- raw email content
- raw storefront content
- reputation-cache keys
User controls
Users can:
- disable individual protection layers
- disable all PhishGuard protection
- keep Google Safe Browsing disabled
- remove a configured Safe Browsing API key
- clear reputation cache data
- clear incident history
- remove trusted or protected domains
- uninstall the extension through Microsoft Edge
Microsoft Edge Store data disclosure
For Microsoft Edge Add-ons disclosure purposes, PhishGuard Local may access the following categories only as needed to provide its security features:
- Personal communications: limited visible webmail link text and nearby security-related context may be inspected locally to detect phishing. Email bodies, subjects, and sender addresses are not persisted.
- Web history: the current page URL is analyzed for security risk. Security incident history may contain sanitized URLs with credentials, query strings, and fragments removed.
- User activity: PhishGuard reacts to security-relevant actions such as clicking suspicious links, submitting credential forms, or attempting checkout actions. It does not perform keystroke logging.
- Website content: links, form structure, domain information, and limited visible security-related page text may be analyzed locally.
PhishGuard Local does not access or store password values, payment-card values, health information, precise location data, or other secret authentication values.
Changes to this policy
This policy will be updated if PhishGuard Local adds new data-access, storage, analytics, advertising, or network behavior.
Contact
For support, privacy questions, or security-related inquiries about PhishGuard Local, contact:
kylehillier323@live.ca