PRIVACY POLICY
Last updated: September 7, 2026.
Educational purpose
PHREAKSAFE is a cybersecurity-awareness and educational project. Interactive scenarios simulate phishing and social-engineering decisions in a controlled environment.
Challenge data
The built-in challenge system does not require an account. Challenge IDs, your most recent selected action and outcome for each attempted challenge, achievement state, and local progress metrics are stored in your browser using localStorage. PHREAKSAFE's built-in challenges do not transmit passwords, MFA codes or other authentication secrets. The built-in progress system does not send your challenge results to PHREAKSAFE's server.
Technical data
Your hosting provider and WordPress installation may process ordinary server-log information such as IP address, browser type, requested pages, timestamps and error information for security and operation. Any analytics, forms or plugins installed by the site operator may have separate data practices and must be configured consistently with this policy.
Sensitive information
Do not enter real passwords, authentication codes, financial credentials, government identifiers, medical information, customer records or other sensitive secrets into an educational scenario.
Third parties and retention
Third-party services should be limited and disclosed when enabled. Server and security logs should be retained only as reasonably necessary for operation, abuse prevention and legal obligations.
Contact
Privacy questions may be directed through the contact information published by the site operator.
This policy describes the theme's built-in behavior. WordPress plugins, analytics, hosting and custom forms can change actual data practices and should be reviewed before deployment.