πŸ”’

Privacy Policy

Last updated: April 2026

The Short Version

We built ThouShaltNotClick to protect people, not to exploit them. Your email content never leaves your browser. Your AI conversations are never seen by us. We use zero third-party trackers. We will never sell your data to anyone, ever. This isn't a legal loophole β€” it's a promise from one Catholic community to another.

What We Collect & Why

DataWhyStored Where
Name & emailYour accountOur server (Supabase)
PasswordAuthenticationBcrypt hash only β€” we never see your password
Simulation resultsTrack if you caught or clicked the phishing testOur server
Training progressKnow which courses you completedOur server
Extension install statusHelp admins see who has protection activeOur server (yes/no + last seen)
Etiquette statsTrack your please/thank you countsYour device only

What We Never Collect

βœ•Email content, subjects, or bodies
βœ•Email sender or recipient addresses
βœ•AI prompts or conversations
βœ•Browsing history or page content
βœ•URLs you scan (processed in real-time, never stored)
βœ•Keystrokes or form inputs
βœ•Location data
βœ•Contact lists or address books
βœ•Files, documents, or attachments
βœ•Data from other extensions

Chrome Extension β€” How It Works

πŸ“§ Email Analysis

When you open an email in Gmail, our extension analyzes it for phishing indicators using a local analysis engine (analyzer.js) that runs entirely inside your browser. The email content is never transmitted to our servers or any third party. The trust score, findings, and recommendations are all computed on your device.

πŸ˜‡ AI Etiquette Checker

When you visit an AI tool (ChatGPT, Claude, Gemini, etc.), the etiquette checker monitors your prompts for politeness indicators like β€œplease” and β€œthank you.” This analysis runs 100% in your browser. Your actual prompts and conversations are never recorded, transmitted, or stored. Only aggregate counts (e.g., β€œsaid please 12 times”) are kept in your browser's local storage on your device.

πŸ”— URL Scanner

When you manually scan a suspicious URL, that URL is sent to our server for real-time threat analysis β€” similar to how Google Safe Browsing works in every web browser. The URL is processed immediately and never stored, logged, or associated with your account. No page content, browsing history, or personal data is included.

No Third-Party Tracking

We use zero third-party analytics, advertising, or tracking tools. No Google Analytics. No Facebook Pixel. No Mixpanel, Amplitude, Segment, HotJar, PostHog, or Sentry. No ad networks. No data brokers. Our code has been audited to confirm this. You can verify it yourself β€” our privacy commitments are embedded directly in the source code of every file in the Chrome extension.

School & Organization Data

For schools using ThouShaltNotClick, we store organizational data necessary to run phishing simulations and training: staff rosters (name, email, role), campaign results, and training completion records. This data is accessible only to authorized school administrators and is never shared with other schools, organizations, or third parties.

Organization-wide benchmarking (e.g. Diocese-wide) uses anonymized, aggregated statistics only β€” click rates and catch rates averaged across schools. No individual staff member's data is ever visible to other schools or the parent organization.

Data Deletion

You can request complete deletion of your account and all associated data at any time by contacting us. School administrators can remove staff members from their roster, which removes their simulation and training data. Etiquette checker data is stored locally on your device and can be cleared by removing the Chrome extension.

Children's Privacy

ThouShaltNotClick is designed for adult staff, teachers, and parents β€” not students. We do not knowingly collect personal information from children under 13. The Chrome extension is intended for use by adults managing school cybersecurity, not by students.

Contact

Questions about our privacy practices? Email us at privacy@thoushaltnotclick.com

β€œWhatever you did for one of the least of these brothers and sisters of mine, you did for me.”— Matthew 25:40

We treat your data with the same dignity we owe every person.