Last updated: 20 July 2026
PhishPredict is a browser extension designed to help users identify phishing websites in the cryptocurrency and Web3 ecosystem through real-time URL and HTML analysis. We are committed to protecting your privacy and being fully transparent about how the extension operates, what data is processed, and how that data is handled.
This policy applies to the PhishPredict Chrome extension and describes our practices regarding any information processed while you use it.
When you visit a website, PhishPredict reads the URL of the active tab and extracts technical characteristics from the page's HTML structure. This information is sent to our own analysis API, which uses a combination of machine learning and deep learning models to classify the site's phishing risk. The result is returned to your browser and displayed as an on-page warning card or through the extension's popup interface
This process happens automatically for every page you visit, requiring minimal effort from you, so that potential threats can be flagged before you interact with a malicious site — for example, before connecting a wallet or signing a transaction.
URL data. The extension reads the URL of the page you are currently viewing in order to send it to our analysis API for classification.
HTML content. The extension may extract structural elements and technical features from the HTML of the page you are viewing (such as page structure, embedded scripts, forms, and links) for the purpose of phishing classification. We do not extract or process the visible text content, images, or media of the page beyond what is technically required for classification.
What we do not collect. PhishPredict does not collect wallet private keys, seed phrases, passwords, personal identifiers, payment information, or any form-input data you type into a page. The extension does not track your keystrokes, mouse movement, or clicks.
All analysis is performed through our own API infrastructure, which we develop and operate ourselves. The extension does not send your data to any third-party service, advertising network, or analytics provider. URL and HTML data submitted for analysis is processed in real time solely to generate a classification result, and is not retained in any server-side database after the result is returned. Once a scan result is delivered to your browser, the corresponding request data is discarded on our end.
Certain information is stored only in your browser's local storage (chrome.storage), which stays on your device and is never transmitted to us for storage purposes. This may include:
Cached scan results, so previously analyzed URLs do not need to be re-sent to the API
Extension settings and preferences
This local data is never uploaded to any external database or server. You remain in full control of it and can clear it at any time by removing the extension or clearing its local storage through your browser settings.
PhishPredict requests the following permissions, each limited to what is required for its core function:
storage — used to cache scan results and store extension settings locally on your device, so the extension does not need to repeatedly call the API for URLs that have already been analyzed.
Host permission (<all_urls>) — used by the background service worker to read the URL of the active tab as you navigate, enabling real-time detection across any website, since phishing sites can appear on any domain unpredictably. This same permission also allows the extension to send classification requests from the background service worker to our backend API without being blocked by cross-origin restrictions.
PhishPredict does not request permissions unrelated to its single purpose of phishing detection.
PhishPredict does not require you to create an account, sign in, or provide any registration information. No email address, name, or other personal identifier is collected in order to install or use this extension.
We do not sell, rent, or share any data processed by PhishPredict with third parties. We do not use the data collected through this extension for advertising, profiling, or any purpose unrelated to phishing detection. We do not use or transfer any data to determine creditworthiness or for lending purposes.
We take reasonable technical measures to protect data in transit between the extension and our analysis API, including the use of encrypted connections. Because request data is not retained after a scan result is generated, the primary risk window is limited to the time it takes to complete a single analysis request.
PhishPredict is not directed at children, and we do not knowingly collect data from children. The extension's function is limited to technical analysis of webpage characteristics and does not involve any age-gated or personally identifying data collection.
PhishPredict may be used by individuals located outside of Indonesia. Because request data is processed in real time and not stored server-side, no persistent cross-border data retention occurs beyond the momentary processing needed to return a classification result.
You can disable or remove PhishPredict at any time through your browser's extension settings, which will stop all data processing associated with the extension. You can also clear locally cached scan data at any time without affecting your ability to continue using the extension.
We may update this privacy policy from time to time to reflect changes in the extension's functionality or applicable requirements. Material changes will be reflected in the extension's update notes and in the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
If you have any questions, concerns, or feedback about this privacy policy or how PhishPredict handles data, please contact us at ilmanclasher@gmail.com