Legal

How We Use Your Data

Transparency about training data and your information

Our Commitment to Transparency

At Phishing Detection Training, we believe in complete transparency about how we construct our training datasets and use your data. This page explains our data practices in detail.

Your trust is important to us. We handle all data with the highest standards of security and privacy, in full compliance with GDPR regulations.

Privacy First

Your personal data is never sold to third parties. All research uses aggregate statistics only.

1. Training Dataset Construction

1.1 Email Sources

Public Phishing Datasets

  • Publicly available phishing email repositories
  • Academic research datasets
  • Security community shared samples
  • All personally identifiable information removed

Synthetic Email Generation

  • AI-generated phishing emails with realistic patterns
  • Legitimate email templates (anonymized)
  • Multi-language support (EN, FR, ES, EL, NL)
  • Various threat type representations

EU-Funded Research Projects

  • GEIGER Project - SME cybersecurity training
  • CyberSuite - Integrated security solutions
  • NERO - Network security research
  • All data sanitized and anonymized

1.2 Data Sanitization

All training emails undergo rigorous sanitization:

Remove real email addresses
Replace real names with pseudonyms
Anonymize IP addresses
Remove phone numbers
Replace URLs with safe examples
Strip metadata and headers

1.3 Dataset Characteristics

1000+

Training Emails

10+

Threat Types

5

Languages

2. How We Use Your Training Data

2.1 Real-Time Training & Feedback

When you analyze an email, we collect:

  • Your classification: Phishing or Legitimate
  • Suspicious elements: Which parts you identified (sender, content, links, etc.)
  • Threat assessment: Attack type and risk level (Level 3)
  • Response time: How long you took to decide
  • Accuracy metrics: Correctness of your assessment

Purpose: Provide immediate feedback, track progress, and personalize difficulty

2.2 Learning Progress & Skill Development

We maintain your learning journey:

  • Total emails analyzed
  • Accuracy rate per difficulty level
  • Skill improvements over time
  • Streak milestones
  • Certificates and badges earned

Purpose: Show your improvement, motivate continued learning, issue certificates

2.3 Gamification & Competition

For leaderboards and challenges:

  • Public display: Username and scores only
  • Hidden: Email address, detailed responses, timestamps
  • Control: You can use a pseudonym
  • Organization: admins in your organization can see your name, email and individual training statistics

Purpose: Encourage engagement, healthy competition, team building

3. Privacy Protections & Aggregation

We protect your privacy through access controls and aggregation while improving the platform:

What stays private

Your identifiers are never exposed on public surfaces:

  • →Leaderboards show your chosen display name and score — never your email or user ID
  • →IP addresses are not collected by the app
  • →Per-email answers and timestamps are readable only by you (Firestore security rules)
  • →No analytics or advertising trackers run in the app

Aggregation

Combining data from multiple users:

  • →Overall accuracy rates
  • →Common mistakes patterns
  • →Platform usage statistics
  • →Feature effectiveness metrics

What "anonymous" means here

Public surfaces display only your display name and score. We do not apply formal anonymization techniques (k-anonymity, differential privacy) to account-level data — access to it is controlled by Firestore security rules instead.

4. Research & Development

Aggregate statistics help us advance cybersecurity education:

Algorithm Improvement

Analyzing which phishing patterns are most deceptive helps us:

  • Develop better detection heuristics
  • Create more effective training examples
  • Improve difficulty progression

Academic Research

Contributing to cybersecurity research:

  • Publishing findings in academic journals (aggregate data only)
  • Sharing insights with security community
  • Improving phishing awareness methodologies

EU Project Contributions

Supporting European cybersecurity initiatives:

  • GEIGER, CyberSuite, NERO project reports
  • SME cybersecurity training effectiveness
  • Cross-cultural phishing awareness studies

What We DON'T Do

  • Sell your data to third parties
  • Share identifiable data with researchers
  • Use your data for advertising
  • Disclose your individual performance to anyone outside your organization

5. Data Retention & Deletion

Active Use

Your personal training data is retained while your account is active

Inactive Period

Personal data retained for 3 years after last login, then automatically deleted

After Deletion

Only aggregate statistics that cannot identify you are retained for research

How to Delete Your Data:

Option 1: Visit your Profile Settings and click "Delete Account"

Option 2: Email privacy@montimage.eu with your deletion request

Personal data will be permanently deleted within 30 days. Anonymized statistics may be retained for research.

6. Your Control & Transparency

You have full control over your data:

View Your Data

Request a copy of all your personal data at any time

Correct Mistakes

Update your profile information anytime

Export Data

Download your training history in JSON format

Delete Everything

Permanently delete your account and personal data

Questions or Requests?

Contact our Data Protection Officer at privacy@montimage.eu

Questions About Your Data?

We're here to help. Contact our Data Protection Officer for any questions or requests.