Terms of Service
Last updated September 18, 2026
phish.co ("phish.co," "we," "us," or "our") provides phishing, smishing, and vishing security-assessment services. These Terms are an agreement between you and us. By creating an account or using phish.co, you agree to them. If you use phish.co on behalf of an organization, you represent that you are authorized to bind that organization.
The service
phish.co is a subscription software service that lets your organization run simulated phishing (email), smishing (SMS), and vishing (voice) assessment campaigns against your own employees, to test and improve their ability to recognize and report real attacks. Every account must verify ownership of a company domain before it can run a campaign, and every campaign is restricted to that domain's own people — see Responsible Use & Authorization for the full description of how this works and what it guarantees.
Your account
You sign in with your email address using a one-time code or link. Keep your email secure and don't share sign-in links; you are responsible for activity under your account. We may suspend or close accounts that violate these Terms.
Authorized use — read this carefully
Simulated attacks are a serious capability, and this section is the core of what you're agreeing to when you use phish.co. By creating an account and running any campaign, you represent and warrant that:
- You will target only your organization's own current employees and contractors, at a domain you have verified ownership of. You will never use phish.co to target anyone outside your own organization, including former employees, customers, vendors, or any other third party.
- You hold the organizational authority to authorize security-awareness testing of the people you target — whether that authority comes from your role, your organization's policies, or an internal delegation.
- You have given, or will give, internal notice consistent with your own organization's policies (for example, an acceptable-use or security-awareness policy informing staff that periodic assessments occur) — a general notice that assessments happen, not advance warning of any specific campaign, since advance warning would defeat the purpose of the test.
- Where you enable the SMS (smishing) channel, you are solely responsible for obtaining whatever consent or authorization the Telephone Consumer Protection Act (TCPA) and any applicable state law require before messaging the phone numbers you enroll. The SMS channel is off by default for this reason.
- Where you enable the voice (vishing) channel with full call-audio capture (rather than the metadata-only default — see Security), you are solely responsible for confirming that your organization operates only in one-party call-recording consent jurisdictions, or that you have independently obtained all-party consent where required.
We may suspend or terminate any account we reasonably believe is being used to target people outside a verified, authorized engagement, without notice, in addition to any other remedy available to us.
Other acceptable use
- Don't use the service for any unlawful, infringing, or harmful purpose beyond the authorized-use terms above.
- Don't probe, interfere with, overload, reverse-engineer, or attempt to gain unauthorized access to the service or other tenants' data.
- Don't resell or provide the service to third parties except as expressly permitted in writing.
Subscriptions, fees, and billing
phish.co is offered on paid subscription plans billed through Stripe, with a free Starter tier and metered add-ons for SMS and voice usage on paid tiers. Prices, tiers, and billing intervals are shown at checkout; by subscribing you authorize recurring charges to your payment method until you cancel. Taxes may apply. We may change prices on renewal with reasonable notice.
Cancellation and refunds
You may cancel at any time; cancellation takes effect at the end of the current billing period and you retain access until then. Refund eligibility, including for metered SMS/voice usage, is described in our Refund & Cancellation Policy.
Data and privacy
What we store, how long, and with which sub-processors is described in our Privacy Policy. Because campaigns target your employees rather than just your own account data, that policy also describes our role in handling their information on your behalf.
Disclaimers
The service is provided "as is" and "as available," without warranties of any kind, express or implied, to the maximum extent permitted by law. A phishing, smishing, or vishing assessment is a simulation and cannot guarantee any particular security outcome; you remain responsible for your own organization's security posture and decisions.
Limitation of liability
To the maximum extent permitted by law, we are not liable for indirect, incidental, special, or consequential damages, and our total liability for any claim relating to the service is limited to the amounts you paid us in the three months before the event giving rise to the claim.
Termination
You may stop using the service and cancel at any time. We may suspend or terminate access for violation of these Terms, including the authorized-use terms above. Sections that by their nature should survive (data rights, disclaimers, liability limits) survive termination.
Changes
We may update these Terms from time to time. If we make material changes we will post the updated Terms here with a new date. Continued use after changes take effect means you accept them.
Governing law
These Terms are governed by the laws of the United States and the State of Louisiana, without regard to conflict-of-law rules.
Contact
Questions about these Terms: hello@phish.co.