🐟 LooksPhishy

Privacy Policy

Last updated: March 26, 2026

LooksPhishy.org is a non-profit, open-source service for reporting phishing URLs. This policy explains what data we collect, why, and what happens to it.

Responsible for data processing: Simon Köck — reachable at privacy@looksphishy.org

What we collect

When you submit a report via the website

When you forward an email to report@looksphishy.org

We do not store the original phishing email body after URLs have been extracted.

Automatically collected data

What we do NOT collect

How we use your data

Reported URLs are:

  1. Verified against threat intelligence sources (such as urlscan.io) to confirm they are malicious.
  2. Relayed to security providers including Google Safe Browsing, Cloudflare, APWG, PhishTank, and others. This is the entire purpose of the service.
  3. Stored in our database to prevent duplicate reports and to allow us to track the status of each relay.

Reported URLs are shared with third-party security providers by design. That is what this service does. The URLs themselves are suspected phishing sites, not personal data of the reporter.

Third-party services

ServicePurposeTheir privacy policy
CloudflareHosting, DNS, email routing, Turnstilecloudflare.com/privacypolicy
AWS SESSending confirmation emailsaws.amazon.com/privacy
urlscan.ioURL verificationurlscan.io/about/privacy

Data retention

Your rights

If you are located in the EU/EEA, you have the right to:

To exercise any of these rights, contact privacy@looksphishy.org.

Children

This service is not directed at children under 16. We do not knowingly collect data from minors.

Changes to this policy

We may update this policy from time to time. Changes will be posted on this page with an updated date. For significant changes, we will note it on the GitHub repository.

Contact

For any questions about this policy or your data:

Simon Köck privacy@looksphishy.org