Phishwash — Privacy Policy
Last updated: 6 October 2026 Provider: Cadwynbloc Ltd, United Kingdom Contact: hello@cadwynbloc.com
In short
Phishwash does not store your messages, and does not store who sent them.
Every message is examined in memory and then discarded. Our database has no field that can hold message content, and none that can hold the Discord ID of any person — not a member's, not a moderator's, not the server owner's. What it keeps about moderation is a daily count of what happened, not a record of any one action, so nothing it holds can be connected to the person who wrote a message. Nothing we keep identifies you.
Two things about a message outlive it, both short-lived and both described in section 3: a counter that stops one account exhausting a server's analysis capacity, held in memory and never written to disk (2 hours at most), and a one-way fingerprint of message text so a repeated attack is recognised rather than re-analysed (24 hours).
The report your moderators read is posted into your own server. It lives in Discord, where your message already was, and your moderators can delete it.
1. Who we are and what this covers
Phishwash is a Discord bot that removes phishing, impersonation and DM-solicitation scams from Discord servers, and answers member questions from documentation the server operator supplies.
This policy covers personal data processed by the Phishwash bot and its supporting infrastructure. It does not cover Discord itself — your use of Discord is governed by Discord's own privacy policy.
Who decides what. For the server operator who installs Phishwash, Cadwynbloc is a data controller in respect of their account and billing.
For the members of that server, responsibility is shared, and it is more useful to say plainly who decides what than to apply a single label:
| The server operator decides | Cadwynbloc decides |
|---|---|
| Which channels are monitored | How long data is kept (section 3) |
| Which roles are exempt | That analysis uses Anthropic (section 4) |
| Whether enforcement is active | Where data is hosted (section 6) |
| Whether automatic banning is on | What the system treats as a scam |
| What the knowledge base contains | How the service is secured and operated |
Server operators should account for Phishwash in their own privacy notice.
Whatever the formal characterisation, we do not use it to avoid helping you. Every server operator instructs us, in our Terms, to handle member deletion requests ourselves — so you can come to us directly and we will act, rather than being passed back and forth between us and your server's moderators. See section 8.
2. What Phishwash reads
Phishwash reads messages in the channels a server administrator explicitly selects during setup. It reads nothing in any other channel, and it never reads direct messages.
For each message in a monitored channel, the bot has access to the message text, attachments, the author's display name, their account age, and how long they have been in that server. This requires Discord's Message Content privileged intent, which is fundamental to the service: an anti-phishing tool that cannot read messages cannot identify a phishing message.
Images are read on our own server, never stored, and never sent to anyone. Scams are often posted as a picture of text, which has no message text to check. So when a member who is new to the server (30 days or less by default, or whose time in the server is unknown) posts a PNG, JPEG, WebP or GIF image, Phishwash downloads it into memory, reads any words in it using open-source text-recognition software (Tesseract) running on our server, and discards the image immediately. Nothing is written to disk. The image is never sent to Anthropic or to any other third party, and the words read from it are checked only by Phishwash's built-in rules — they are never sent to Anthropic either. If those words match a scam pattern, the server's moderators are told, with the words shown in the report. Nothing is deleted and nobody is punished because of text read from an image: a moderator decides.
Images from moderators, from exempt roles, and from members who have been in the server for longer than that, are not downloaded or read. Neither are files that are not images, such as documents, videos and archives, and neither are images over 5 MB or larger than 4,096 pixels on a side. For every other attachment Phishwash uses only the fact that the message has one — enough to recognise a message that urges people to scan or open it.
Phishwash does not use Discord's Server Members intent or Presence intent. It never downloads or stores a server's member list.
3. What is stored, and for how long
The overwhelming majority of messages are never stored at all. A message that is not acted upon leaves no record beyond an anonymous daily counter of how many messages were seen.
| What | Contains | Retained |
|---|---|---|
| Daily action counts | Per server and per day: how many scams, DM solicitations, answers and unanswered questions there were, how each kind was caught, what was done, and how many a moderator undid. Numbers only — no user ID, no name, no text, and no record of any individual action | 365 days |
| Verdict cache | A one-way SHA-256 fingerprint of normalised message text, the verdict as numbers, and — for a question Phishwash answered — the answer it gave from the server's knowledge base. Not the message, and not the reasoning — see below | 24 hours |
| Rate-limit counter | A Discord user ID and a count of analyses triggered this hour. Held in memory only and never written to disk; lost if the service restarts | 2 hours at most |
| Usage records | Per-server counts and costs. No user identifiers, no message content | Aggregated after 7 days, retained indefinitely as totals |
| Server configuration | Channel IDs, role IDs, settings, and the knowledge base text the operator supplied | Until the operator removes it, or 30 days after uninstalling |
| Settings history | Which setting changed, when, and its old and new value — not who changed it. Knowledge-base edits are recorded by size only | While installed, and 30 days after uninstalling |
We do not store the text of your messages. A message is read, analysed in memory, reported to that server's moderator channel, and discarded. Our database has no field capable of holding message content, nor any field for Phishwash's reasoning about a message, which can quote it. An automated test blocks any release that adds a field able to hold message text or a person's Discord ID.
The copy a moderator reviews is the report Phishwash posted in their own server. That report is a Discord message, held by Discord, subject to Discord's policies and deletable by that server's moderators at any time.
About the fingerprint. One row above holds a SHA-256 hash of message text rather than the text, and we would rather explain the difference than let the word "hash" do the work.
A hash is a one-way fingerprint. It cannot be turned back into the message, and we cannot read a message from one. What it can do is confirm a guess: anyone holding the hash who already knows what a message said could verify it. That is why we treat it as personal data rather than as anonymous, and limit it:
- The verdict cache is deleted after 24 hours, carries no user ID, and never
leaves the server it came from. It can show that identical text was posted in a server, never who posted it.
- It is computed from normalised text — punctuation, mentions and spacing are
stripped before hashing — so the fingerprint does not correspond to anything a member actually typed.
Its purpose is narrow: recognising that the same attack has been seen before in that server, so it is blocked instantly and at no cost rather than analysed again.
We do not store anybody's Discord user ID either — not a member's, a moderator's or the server owner's. Earlier versions of Phishwash kept a member's ID on each record of an action, so that a repeated offence could be punished more heavily than a first; that escalation has been removed, and the decision to ban is made by a moderator pressing a button on the report in their own server. Later versions still kept the IDs of whoever installed Phishwash, changed a setting or pressed Undo. Nothing used them, and they have been deleted.
Nor do we keep a record of each action. Even without an ID, a record of one action could be matched to the report in your server's moderator channel — same moment, same confidence, same reasoning — and the report names the member. Instead we keep a daily count: how many scams, caught how, with what result. That is what the weekly digest and accuracy figures are built from, and it describes nobody. The consequence is that no record in our database can be attributed to any person.
The digest's detail — the catch worth reading, the questions members asked — is read back from Phishwash's own reports in your moderator channel when the digest is written, not from anything we hold. Questions Phishwash could not answer are posted to that channel too, depending on the server's setting: one report each, or one message per week that Phishwash updates as questions arrive. A question's description exists there and nowhere else.
Deletion runs automatically; there is no manual step.
Backups. The database is backed up every night, so that a failure does not lose your server's settings. Each backup is kept for 14 days and then deleted: one copy on our server, and one encrypted on our server before it is sent to Cloudflare's storage, restricted to the European Union, using a key Cloudflare does not have (Cloudflare removes expired copies within a day). Because of this, something deleted from the database can remain in a backup for up to 14 days. Backups are used only to restore the service.
4. Automated processing and AI analysis
Messages that the free filtering layer cannot decide on — roughly 2% of traffic — are sent to Anthropic's Claude API for analysis. What is sent is:
- the message text
- the author's display name (not their username, ID, or any account identifier)
- the age of their account in days, and their time in the server in days
- whether the message has an attachment — never the attachment itself
No Discord user ID, email address, or any other account identifier is ever sent to Anthropic, and no image or file, and no text read from one. Anthropic processes this data as our sub-processor and never uses API inputs or outputs to train models. It holds API logs briefly — currently seven days — and longer only where a request is flagged under its own usage policy. We do not train any model on your data, and we could not: we keep no copy of it.
This is automated decision-making and it can result in a message being deleted and a member being timed out or, where the operator has explicitly enabled it, banned. Two safeguards apply. Every action is reported to the server's moderators with the reasoning and a one-click undo. And automatic banning is off by default — it only ever happens if the server operator turns it on.
If you believe Phishwash has acted against you wrongly, contact the moderators of that server first: they can reverse it immediately. You may also contact us directly at hello@cadwynbloc.com.
5. Sharing between servers
Nothing is shared between servers. What Phishwash learns in one community stays in that community.
A previous version of this policy described an optional scheme for sharing fingerprints of confirmed scams between servers. That feature is not built, no server ever used it, and the description has been removed rather than left standing as a statement of something we do not do. If we build it, this policy will be updated and server operators told before anything is shared.
6. Where data is held
All data is stored on a server in Germany (Hetzner Online GmbH), with encrypted backups in Cloudflare's storage restricted to the European Union (section 3). Data is not transferred outside the European Economic Area, except that AI analysis is performed by Anthropic, which may process data in the United States under appropriate safeguards.
7. Who we share data with
- Anthropic — AI analysis, as described in section 4
- Hetzner Online GmbH — hosting, Germany
- Cloudflare, Inc. — hosts this website, and stores encrypted backups in the
European Union. Backups are encrypted before they leave our server, so Cloudflare cannot read them
- Stripe — payment processing for paid plans (server operators only; no member data)
We do not sell data. We do not use it for advertising. We do not use member messages to train any model.
8. Your rights
If you are in the UK or EEA you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data.
In practice there is nothing for us to give you or delete, and that is the honest answer rather than a way of avoiding the question. We hold no message content and nobody's Discord user ID, so no record in our database can be connected to you. The only place your ID can exist on our side is the rate-limit counter, which is held in memory, never written to disk, and gone within two hours.
You are still entitled to ask, and we will still check. Email hello@cadwynbloc.com with your Discord user ID and we will search, delete anything found, and reply within 30 days telling you what there was — including when the answer is nothing.
What you may actually be looking for is the report about a message of yours, which lives in the moderator channel of the server it happened in. That is a Discord message in your server operator's hands, not ours: ask their moderators, or Discord. We cannot delete it for you and would not want the ability to.
Every server operator instructs us, in our Terms, to handle these requests directly, so you do not need to approach your server's moderators first for anything we do hold.
You may also complain to the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
9. Lawful basis
For server members, the basis is legitimate interests — protecting a community from fraud and impersonation. We consider this balanced because the data held is minimal, retention is short, ordinary conversation is never stored, and every automated action is reviewable and reversible by a human.
For server operators, the basis is contract — providing the service they signed up to.
10. Children
Discord requires users to be at least 13. Phishwash is not directed at children and we do not knowingly process the data of anyone below Discord's minimum age.
11. Security
The database is accessible only to the service account that runs the bot. The server accepts no inbound connections other than administrative SSH. Credentials are held outside the application directory with restricted permissions. Access is limited to Cadwynbloc personnel who need it.
12. Changes
Material changes will be announced in the Phishwash support server and reflected in the "last updated" date above.