Privacy Policy
Last updated: July 23, 2026
1. Introduction
PhishSim AI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our phishing simulation and security awareness platform at www.phishsimai.com (the "Service"). Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.
2. Information We Collect
Account Information: When you register, we collect your name, email address, organization name, and authentication credentials.
Employee / Target Data: Organizations using our platform may upload employee names, email addresses, and department assignments for the purpose of running phishing simulations. This data is processed solely on behalf of the subscribing organization and is not used for any other purpose.
Campaign Data: We collect data about phishing simulation campaigns including send times, email open events, link click events, and credential submission events. This data is used exclusively to generate security awareness reports for your organization.
Usage Data: We automatically collect certain information about how you interact with the Service, including IP addresses, browser type, pages visited, and time spent on pages, for the purpose of improving the platform.
3. How We Use Your Information
We use the information we collect to: (a) provide, operate, and maintain the Service; (b) generate phishing simulation reports and compliance documentation for your organization; (c) send administrative communications such as account confirmations and security alerts; (d) comply with legal obligations; and (e) improve and personalize the Service. We do not sell, trade, or rent your personal information to third parties.
4. Data Retention
We retain your account and campaign data for as long as your subscription is active. Upon account termination, we will delete your data within 90 days unless a longer retention period is required by law. Employee simulation data (opens, clicks, submissions) is retained for up to 3 years to support compliance reporting requirements under HIPAA, GLBA, CMMC, and similar frameworks.
5. Data Security
We implement industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest, role-based access controls, and regular security audits. However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security but are committed to protecting your data using commercially reasonable means.
6. HIPAA Compliance
If your organization is a HIPAA-covered entity or business associate, PhishSim AI can execute a Business Associate Agreement (BAA) upon request. Employee simulation data does not constitute Protected Health Information (PHI) under HIPAA. Contact us at privacy@phishsimai.com to request a BAA.
7. MSP and Reseller Partners
Managed Service Providers (MSPs) using the PhishSim AI white-label portal are considered data processors acting on behalf of their customer organizations. MSPs are responsible for ensuring their customers are informed about data collection practices and for maintaining appropriate data processing agreements with their customers.
8. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal data. To exercise these rights, contact us at privacy@phishsimai.com. We will respond to all requests within 30 days.
9. Contact Us
If you have questions about this Privacy Policy, please contact us at:
PhishSim AI
Email: privacy@phishsimai.com
Phone: 443-594-1184
Website: www.phishsimai.com