Legal
How We Use Your Data
Transparency about training data and your information
Our Commitment to Transparency
At Phishing Detection Training, we believe in complete transparency about how we construct our training datasets and use your data. This page explains our data practices in detail.
Your trust is important to us. We handle all data with the highest standards of security and privacy, in full compliance with GDPR regulations.
Privacy First
Your personal data is never sold to third parties. All research uses aggregate statistics only.
1. Training Dataset Construction
1.1 Email Sources
Public Phishing Datasets
- Publicly available phishing email repositories
- Academic research datasets
- Security community shared samples
- All personally identifiable information removed
Synthetic Email Generation
- AI-generated phishing emails with realistic patterns
- Legitimate email templates (anonymized)
- Multi-language support (EN, FR, ES, EL, NL)
- Various threat type representations
EU-Funded Research Projects
- GEIGER Project - SME cybersecurity training
- CyberSuite - Integrated security solutions
- NERO - Network security research
- All data sanitized and anonymized
1.2 Data Sanitization
All training emails undergo rigorous sanitization:
1.3 Dataset Characteristics
1000+
Training Emails
10+
Threat Types
5
Languages
2. How We Use Your Training Data
2.1 Real-Time Training & Feedback
When you analyze an email, we collect:
- Your classification: Phishing or Legitimate
- Suspicious elements: Which parts you identified (sender, content, links, etc.)
- Threat assessment: Attack type and risk level (Level 3)
- Response time: How long you took to decide
- Accuracy metrics: Correctness of your assessment
Purpose: Provide immediate feedback, track progress, and personalize difficulty
2.2 Learning Progress & Skill Development
We maintain your learning journey:
- Total emails analyzed
- Accuracy rate per difficulty level
- Skill improvements over time
- Streak milestones
- Certificates and badges earned
Purpose: Show your improvement, motivate continued learning, issue certificates
2.3 Gamification & Competition
For leaderboards and challenges:
- Public display: Username and scores only
- Hidden: Email address, detailed responses, timestamps
- Control: You can use a pseudonym
- Organization: admins in your organization can see your name, email and individual training statistics
Purpose: Encourage engagement, healthy competition, team building
3. Privacy Protections & Aggregation
We protect your privacy through access controls and aggregation while improving the platform:
What stays private
Your identifiers are never exposed on public surfaces:
- →Leaderboards show your chosen display name and score — never your email or user ID
- →IP addresses are not collected by the app
- →Per-email answers and timestamps are readable only by you (Firestore security rules)
- →No analytics or advertising trackers run in the app
Aggregation
Combining data from multiple users:
- →Overall accuracy rates
- →Common mistakes patterns
- →Platform usage statistics
- →Feature effectiveness metrics
What "anonymous" means here
Public surfaces display only your display name and score. We do not apply formal anonymization techniques (k-anonymity, differential privacy) to account-level data — access to it is controlled by Firestore security rules instead.
4. Research & Development
Aggregate statistics help us advance cybersecurity education:
Algorithm Improvement
Analyzing which phishing patterns are most deceptive helps us:
- Develop better detection heuristics
- Create more effective training examples
- Improve difficulty progression
Academic Research
Contributing to cybersecurity research:
- Publishing findings in academic journals (aggregate data only)
- Sharing insights with security community
- Improving phishing awareness methodologies
EU Project Contributions
Supporting European cybersecurity initiatives:
- GEIGER, CyberSuite, NERO project reports
- SME cybersecurity training effectiveness
- Cross-cultural phishing awareness studies
What We DON'T Do
- Sell your data to third parties
- Share identifiable data with researchers
- Use your data for advertising
- Disclose your individual performance to anyone outside your organization
5. Data Retention & Deletion
Active Use
Your personal training data is retained while your account is active
Inactive Period
Personal data retained for 3 years after last login, then automatically deleted
After Deletion
Only aggregate statistics that cannot identify you are retained for research
How to Delete Your Data:
Option 1: Visit your Profile Settings and click "Delete Account"
Option 2: Email privacy@montimage.eu with your deletion request
Personal data will be permanently deleted within 30 days. Anonymized statistics may be retained for research.
6. Your Control & Transparency
You have full control over your data:
View Your Data
Request a copy of all your personal data at any time
Correct Mistakes
Update your profile information anytime
Export Data
Download your training history in JSON format
Delete Everything
Permanently delete your account and personal data
Questions or Requests?
Contact our Data Protection Officer at privacy@montimage.eu
Questions About Your Data?
We're here to help. Contact our Data Protection Officer for any questions or requests.