Privacy Policy
Last Updated: September 8, 2026 · Effective Date: January 1, 2026
At SentinelPhish ("SentinelPhish", "we", "us", or "our"), we provide advanced heuristic phishing detection, zero-day optical analysis (QR Shield), and community-driven threat intelligence. We are dedicated to maintaining the trust of our users through rigorous security practices and transparent data handling policies.
This Privacy Policy details how we collect, process, protect, and disclose information when you access or use the SentinelPhish website, web applications, scanning APIs, or associated security tools.
1. Information We Collect
A. Account Information (Clerk / Google OAuth)
When you create an account or sign in using identity providers (including Google OAuth via Clerk), we collect basic profile details:
- Your full name and verified primary email address
- OAuth identity identifiers and profile avatar image URL
- Account creation timestamp and active plan entitlement
We strictly limit our Google OAuth scopes to standard identity verification (profile, email, openid). We never request, access, or inspect your private Google Drive, Gmail, or contacts data.
B. Threat Scan Data
When you submit a URL or QR code for security analysis, our automated ingestion engine captures:
- The target URL, resolved hostname, protocol, and IP destination
- Automated heuristic red flags, redirection hops, and calculated risk scores
- HTTP status codes, DOM entropy metrics, and submission timestamps
C. Community Accuracy Feedback
When users rate a scan verdict ("Helpful" or "Inaccurate"), we store the rating vote, associated target URL, and optional user identifier to calibrate our neural heuristic models and establish community consensus.
2. How We Use Your Information
We process collected data exclusively to deliver, maintain, and enhance cyber threat intelligence services:
- Zero-Day Heuristic Analysis: Extracting multi-hop redirection chains, deceptive homographs, and credential harvesting patterns to protect users against weaponized links.
- Public Threat Intelligence Feed (/reports): Sharing collective zero-day intelligence modeled after PhishTank. All public threat feed entries strictly strip personal user identities—only defanged URLs, domains, risk scores, heuristics, and consensus votes are visible.
- Account Management & Rate Limiting: Managing account tiers, enforcing daily guest quotas, and authenticating developer API access.
3. Third-Party Service Providers
We partner with industry-leading cloud infrastructure providers who adhere to strict data security standards:
4. Data Security & Retention
We implement comprehensive defense-in-depth safeguards to protect data against unauthorized disclosure or tampering:
- Encryption in Transit: Enforced TLS 1.3 encryption across all client-to-server and inter-service communications.
- Encryption at Rest: Database records and telemetry encrypted using AES-256 standards.
- URL Defanging: Malicious or suspicious URLs are defanged by default in database views and public feeds to prevent accidental client execution.
- Data Deletion Rights: You may request the permanent deletion of your account and personal identifiers by contacting us at any time.
5. Contact Information & Data Inquiries
Have questions regarding your personal data or privacy rights?
For privacy inquiries, account data deletion, or verification requests, reach out directly to our security & compliance team: