Phishing Trust Initiative

PHISHING-STORY CAMPAIGN

Privacy policy

Version 1.1
Effective date:

Who we are

This campaign is operated by Stephen McLeish, Phishing Trust Initiative. For privacy questions, requests or complaints, email privacy@phishtrust.com.

Why we collect stories

We collect phishing experiences to understand what makes deceptive messages convincing and test warning approaches. Sharing a story does not establish that our product would have prevented an incident. This is a research campaign, not an incident-response or money-recovery service.

Your choices

You may submit anonymously. No account or name is required. Contact email is optional and is used only for agreed follow-up about your story, not marketing. We do not sell contributor contact information.

Consent to analysis for research and product testing is required to submit. Permission for anonymous publication is separate and optional. Leaving publication permission unticked keeps your story for internal research and product testing.

Information we collect

We collect the channel used for the phishing attempt, what made it look legitimate, your narrative, what happened next, your consent choices and any optional contact email. We also keep a submission identifier, submission date, the notice and consent versions shown, and internal review and testing notes.

Our hosting and security providers receive technical connection information when you visit. The application uses short-lived, pseudonymous network identifiers to limit abuse; these are not published or included in evidence exports. The campaign pages do not install third-party trackers or send story contents or email addresses through analytics hooks.

What not to share

Do not submit passwords, login credentials, card or bank details, account numbers, home addresses, active malicious links or unnecessary personal information about other people. Leave out names, phone numbers, email addresses and web addresses from the story itself. Describe events in your own words rather than pasting the original message. There are no file uploads.

How we use and share information

We analyse stories and test scenarios internally according to your research consent. Only with separate publication consent may we use your story in educational, campaign or product material, including Kickstarter material or future policy discussions.

Publication consent is not automatic approval to publish. A person must review the material and remove identifying details before publication. We do not publish your contact email. De-identification reduces identification risks but cannot guarantee that nobody will recognise an experience.

Hosting and security service providers may process or store submissions, backups and technical information to operate and protect the service. Depending on the provider and hosting location, processing may occur outside Australia. This policy does not promise Australia-only storage.

Storage, security and retention

We use restricted access, encrypted connections in production, input checks and controlled operator processes to protect information. Raw submissions are not publicly searchable or available through the website. No online service can guarantee absolute security.

Our initial operational retention target for raw submissions is 180 days. Removal is reviewed and performed manually, not automatically on a fixed day. Contact email should be removed when no longer needed for agreed follow-up. Exports and backups require separate retention and deletion handling; removal from the live database does not instantly remove every backup copy.

Reviewed, de-identified material used with publication consent may remain in educational or campaign outputs beyond the raw-submission target.

Access, correction and withdrawal

Email the privacy contact to request access to or correction of information about you, or withdrawal of an unpublished story. Provide only enough detail to help locate it, such as the approximate submission date and a brief description. We may need to clarify the request or check that it relates to you before disclosing or changing information. Anonymous submissions can be harder to locate.

Withdrawal applies to unpublished material. We cannot promise to recall material already publicly distributed, including copies held by others. We will explain what action we can take and any limitations.

Questions and complaints

Contact Stephen McLeish at privacy@phishtrust.com with your concern and preferred reply method. We will review it, ask for clarification if needed, and respond with the outcome or next steps. Do not include passwords or other unnecessary sensitive information.

This policy describes our campaign practices. It does not claim compliance certification or establish whether the Australian Privacy Act applies to this initiative. Future changes will be published with an updated version and date; earlier consent records are not silently rewritten.

Back to the phishing-story form