Phishwash — Terms of Service

Last updated: 6 October 2026 Provider: Cadwynbloc Ltd, United Kingdom Contact: hello@cadwynbloc.com


1. Agreement

These terms are between Cadwynbloc Ltd ("we", "us") and the person or organisation that installs Phishwash into a Discord server ("you", "the operator").

By adding Phishwash to a server you confirm that you have the authority to do so, and that you accept these terms. If you do not accept them, remove the bot.

Your use of Discord is separately governed by Discord's own terms.

2. What the service does

Phishwash monitors channels you select, identifies likely phishing, impersonation and DM-solicitation, and takes the enforcement actions you have configured. Where you supply a knowledge base, it may also answer member questions from it.

You control: which channels are monitored, which roles are exempt, whether enforcement is active, whether automatic banning is enabled, and whether questions are answered.

3. What you are responsible for

You remain responsible for moderation of your server. Phishwash is a tool that assists your moderators; it does not replace them.

You are responsible for:

Phishwash in your own privacy notice where you are required to have one

You must not use Phishwash to monitor channels for purposes unrelated to safety and support, or in any way that breaks Discord's terms or applicable law.

4. Accuracy, and its limits

Phishwash will make mistakes. It uses automated classification, including a large language model, and no such system is perfect. It will occasionally miss a scam, and it will occasionally act on a message that was not one.

Measured against real moderation logs on a live server, Phishwash detected 98.5% of known attacks with no staff members wrongly actioned. That figure describes past performance on one server's traffic and is not a guarantee of results on yours.

We provide the service on an "as is" basis. We do not warrant that it will detect any particular attack, that it will be free of false positives, or that it will be available without interruption.

Every enforcement action is reported to your moderator channel with a one-click undo. Every new installation begins in demo mode, which reports without acting, so you can judge accuracy on your own traffic before enabling enforcement.

5. Plans, payment and refunds

Paid plans are billed in advance, monthly or annually, through Stripe. Prices are shown at the point of purchase.

Each plan includes a monthly allowance of AI analyses. If you exhaust it, the free filtering layer continues to operate — protection degrades, it does not stop.

You may cancel at any time. Cancellation takes effect at the end of the current billing period, and the service continues until then. We do not provide pro-rata refunds for partial periods, except where required by law.

If we materially reduce the service during a period you have paid for, contact us and we will put it right.

6. Free trial

New servers receive a free trial of 30 days with a fixed allowance of AI analyses, without a card. When the trial ends the bot stops performing AI analysis; the free filtering layer continues until you choose a plan or remove the bot.

The trial is one per server.

7. Suspension

We may suspend or terminate the service to a server that:

Where practical we will contact you first.

8. Service changes and availability

Phishwash is an actively developed product. We may add, change or remove features. Where a change materially reduces functionality you rely on, we will give reasonable notice through the support server.

We do not currently offer a service level agreement. The bot runs on a single server and may be unavailable during maintenance, upstream provider incidents, Discord outages, or interruptions to the AI provider.

9. Liability

Nothing in these terms limits liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot lawfully be limited.

Subject to that, our total liability to you in any twelve-month period is limited to the amount you paid us in that period. We are not liable for indirect or consequential loss, for loss of profit or goodwill, or for any loss arising from a scam Phishwash failed to detect or from an enforcement action it took. You retain responsibility for moderating your community.

10. Your data and content

You retain ownership of any knowledge base content you supply. You grant us the limited licence needed to store and process it in order to provide the service.

Handling of personal data is described in the Privacy Policy, which forms part of these terms.

On uninstallation your configuration and knowledge base are retained for 30 days, so that reinstalling does not mean starting again, and are then deleted. Email us if you want them removed immediately.

11. Self-hosting and resale

Phishwash is provided as a hosted service. You may not resell it, or offer it as part of another service, without our written agreement.

12. Law

These terms are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

13. Changes to these terms

We may update these terms. Material changes will be announced in the support server and reflected in the date above. Continuing to use the service after a change means you accept it.


Annex A — Data Processing Agreement

This annex forms part of the Terms. It applies to the processing Cadwynbloc carries out on your instructions — monitoring the channels you nominate, applying the enforcement you configure, and answering questions from the knowledge base you supply. For that processing you are the controller and Cadwynbloc is the processor.

It does not cover processing Cadwynbloc carries out for its own purposes. At present there is none: nothing derived from your server is used for any purpose other than protecting your server. Nothing is shared with, or pooled across, other servers. If that changes we will tell you before it does.

A1. Subject matter, duration, nature and purpose

Cadwynbloc processes personal data in order to detect phishing, impersonation and DM solicitation in the Discord channels you nominate, and to answer member questions from documentation you supply. Processing continues for as long as Phishwash is installed in your server, plus the retention periods in A3.

A2. Categories of data subject and personal data

Data subjects: members of your Discord server who post in the channels you have nominated.

Personal data: message text, Discord user ID, display name, account age and time in the server are processed transiently to assess a message. None of it is written to our database: it has no field that can hold message content or the Discord ID of any person. A member's Discord user ID is held in memory, for at most two hours, by the per-user rate limit; it is never written to disk.

Message text is not stored. Every message — acted upon or not — is examined in memory and discarded. Where a moderator needs to review a decision, they read the report Phishwash posted in their own server, which is held by Discord rather than by us. What we keep about moderation is a daily count per kind of action, not a record of any individual action.

No special category data is sought. Because message text is never retained, such data cannot persist in our records even where a member's message happened to contain it. Where a message is sent to our sub-processor for classification, Cadwynbloc retains nothing of it; the sub-processor keeps API logs for the short period described in the Privacy Policy.

A3. Retention and deletion

DataRetained
Message textNot retained
Discord user IDsNot retained (rate-limit counter: in memory, 2 hours at most)
One-way fingerprint of normalised message text (not the text)24 hours
Daily action counts (numbers only — no IDs, names or text)365 days
Your configuration, knowledge base and settings historyUninstall + 30 days
Backups of the database (on our server, and encrypted off-site in the EU)14 days

Deletion is automatic and scheduled. Data deleted from the database can remain in a backup until that backup expires. On request we will delete or return your configuration data sooner.

A4. Instructions

Cadwynbloc processes personal data only on your documented instructions, which for these purposes means these Terms together with the settings you configure through Phishwash's commands. We will tell you if we believe an instruction infringes data protection law.

A5. Confidentiality

Personnel authorised to process personal data are bound by confidentiality obligations.

A6. Security

Data is held on a server in Germany, under a service account with no interactive login, in a hardened systemd unit with a read-only filesystem outside its state directory. No message content is stored, so there is none at rest to encrypt. The host accepts no inbound connections other than administrative SSH with key authentication. Credentials are stored outside the application directory with restricted permissions. Backups are encrypted on the server before an off-site copy is made, with a key that is not kept on the server or by the storage provider.

A7. Sub-processors

You authorise the following sub-processors:

Sub-processorPurposeLocation
Anthropic PBCAI analysis of escalated messagesUnited States
Hetzner Online GmbHHostingGermany
Cloudflare, Inc.Storage of encrypted database backups (it holds no key to read them)European Union
StripePayment processing (operator billing only)EU / United States

We will give notice before adding or replacing a sub-processor, and you may object.

Only the message text, display name, account age, days-in-server and whether the message has an attachment are sent to Anthropic. No Discord user ID or other account identifier is transmitted, and no image or file, and no text read from one. Images posted by newer members are read on our own server and discarded immediately, as the Privacy Policy describes; that does not involve a sub-processor.

A8. Assistance with data subject rights

Cadwynbloc will assist you in responding to data subject requests.

You instruct us to handle deletion requests directly. By accepting these Terms you instruct Cadwynbloc to respond to member erasure requests without requiring your involvement: any member may email hello@cadwynbloc.com and we will erase the records we hold about them. We will notify you where a request concerns your server. This is a standing instruction under A4, not action we take of our own initiative — you may withdraw it in writing at any time, in which case such requests will be referred to you.

In practice there is nothing to erase: Cadwynbloc stores no message content and no Discord user IDs, so no record in our systems can be attributed to one of your members. Requests are still checked and answered.

This also means erasure cannot be used against you. A member cannot have their moderation history in your server deleted by asking us, because we do not hold it — the reports are in your moderator channel, under your control.

A9. Assistance with obligations

Taking into account the nature of processing, Cadwynbloc will assist you with security, breach notification, data protection impact assessments and prior consultation. We will notify you without undue delay on becoming aware of a personal data breach affecting your server.

A10. Deletion or return at the end

On termination Cadwynbloc will delete your configuration, knowledge base, settings history and every count kept for your server after 30 days, or sooner on request. Copies in backups expire within a further 14 days.

A11. Audit

Cadwynbloc will make available the information necessary to demonstrate compliance with this annex, and allow for and contribute to audits, on reasonable notice and no more than once a year unless required by a supervisory authority.

A12. International transfers

Data is held in Germany. Transfers to Anthropic in the United States are made under appropriate safeguards. Cadwynbloc will not otherwise transfer personal data outside the UK or EEA without an adequacy decision or appropriate safeguards.