Privacy policy

Fish Catcher works for you, not on you.

Applies to the Fish Catcher extension View source
On your device

Summary

Fish Catcher does its checks on your device, with detection lists that ship inside the extension, and works with no internet connection. No account, no tracking, and nothing from the pages you visit is sent anywhere by default. A few optional features look things up online; each is off until you turn it on.

What stays on your device

Optional online features

Threat-list updates

Downloads one Bloom-filter file a day from the Fish Catcher registry, which merges three keyless public feeds: Phishing.Database, URLhaus by abuse.ch, and OpenPhish. Download only; every check against the list happens on your device. Like any web request, the host sees your IP address and that a file was requested.

Domain-age check (RDAP)

Asks a public directory service how old a domain is. Sends only the domain name.

Google Safe Browsing

Sends the address you visit to Google and needs your own free Google API key.

Download guard

Local. Needs download and notification access to warn you about a disguised download. Nothing is uploaded.

Family mode

Local. A larger, plainer alert and, if you add a helper's email, a one-tap button that opens a pre-filled email in your own mail app. Nothing is sent until you press send; the helper address stays on your device.

Report this site opens a pre-filled GitHub issue in a new tab with only the site's hostname, never the full address. Nothing is sent until you submit it yourself.

What is stored on your device

In your browser's local storage:

It never leaves your device and is removed when you uninstall.

Permissions

Network permissions are requested only when you turn a feature on.

What we never do

It is open source; verify all of this in the code.

Changes and contact

Changes are posted here and in the source repository. Questions go to the GitHub project.