Privacy Policy

Last updated: June 2026

Phantom Defender is a privacy tool, so our own privacy practices matter. This policy explains what we collect, what we deliberately cannot see, and how our zero-knowledge architecture works. Plain language, no dark patterns.

What we cannot see

Your data is encrypted on your device with your master password before it ever reaches our servers (AES-256-GCM; keys derived with PBKDF2). We store only encrypted blobs. We never receive your master password, and we cannot read your forwarding address, email contents, or notes — even if compelled. If you lose your master password, your encrypted data cannot be recovered, by us or anyone.

What we collect

Account: a username and a salted hash of your password. No email is required to sign up.

Operational metadata: the aliases and phone numbers you create, tracker/leak counts, and audit events needed to run the service. This is scoped to your account and protected by row-level security.

Billing: if you subscribe, payments are processed by Stripe. We never store your card details.

Email and phone handling

Aliases forward mail to your real inbox with trackers stripped. We process the minimum metadata needed to detect leaks and strip trackers. Burner phone numbers are receive-only (for OTPs and inbound SMS); we never send messages on your behalf.

Third parties

We rely on infrastructure providers (hosting, database, email forwarding, SMS, and payments) strictly to deliver the service. We do not sell your data, and we do not run advertising or third-party trackers in the app.

Your controls

You can export all of your data (JSON or CSV) at any time, and the Emergency Nuke feature deletes your identities and soft-deletes your account with a 30-day recovery window.

Contact

Questions about this policy? Reach out via the project repository on GitHub. This document is provided for transparency and is not legal advice.