Privacy Policy
This policy explains what ScamCheck collects when you forward or submit a suspicious message.
What We Collect
- Submitted message content.
- Your sender email address so ScamCheck can send a response.
- Basic metadata such as timestamps and message headers when applicable.
Why We Use It
We use submitted information to analyze suspicious messages, send plain-English responses, troubleshoot service issues, and prevent abuse. Message text and basic sender/header context may be sent to the configured AI provider, currently OpenAI. The model has no authority to click links, access accounts, contact organizations, or take action.
Retention
- Submitted message text and email-address fields: up to 7 days.
- Analysis metadata needed for troubleshooting: up to 30 days.
- Hashed abuse and rate-limit events: up to 30 days.
- Sanitized operational logs: up to 30 days.
Data may be preserved longer only when required for a specific security incident or legal obligation.
What We Do Not Do
- We do not sell submitted data.
- We do not use submitted data for advertising.
- We do not share submitted data except as needed for security, abuse prevention, service operation, or legal reasons.
Security Note
Do not submit passwords, Social Security numbers, banking details, credit card numbers, medical information, or other sensitive personal information.