Privacy Policy

Last updated: 12 January 2026

1. Introduction

ScamChecked ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share information when you use our service.

2. Information We Process

We process the following types of data:

  • Message text: The text you paste into our service for analysis
  • Analytics data: Anonymous usage statistics (page views, session duration)
  • Payment metadata: Transaction information when you make a payment (processed by Stripe)

3. How We Use Your Information

We use your information to:

  • Provide the scam detection analysis service
  • Prevent abuse and ensure service security
  • Process payments and manage billing
  • Improve our service through anonymous analytics

4. Third-Party Services

We share your information with the following third-party services:

OpenAI

We send the text you paste to OpenAI's API to generate the analysis. We do not store your message in our own database.

Data retention: OpenAI may retain API logs for up to 30 days for abuse monitoring purposes (unless legally required to retain longer, or if you qualify for zero data retention).

Training: OpenAI states that API data is not used to train their models by default (unless you opt in).

Vercel Analytics

We use Vercel Web Analytics to understand how visitors use our service. This service is cookieless and identifies visitors via a hash.

Data retention: Sessions are discarded after 24 hours.

Stripe

When you make a payment, Stripe processes your payment information. We receive transaction metadata but do not store your full payment details.

Stripe's privacy practices are governed by their own privacy policy and data processing addendum.

5. Data Retention

  • Message text: We do not store pasted messages in our database
  • Vercel Analytics: Session data is discarded after 24 hours
  • OpenAI: API logs may be retained for up to 30 days
  • Payment data: Retained by Stripe according to their policies and legal requirements

6. International Transfers

Some of our service providers (including OpenAI, Vercel, and Stripe) are based in the United States. When we transfer your data to these providers, we rely on appropriate safeguards including:

  • Data Processing Addendums (DPAs)
  • Standard Contractual Clauses (SCCs) for EU transfers
  • UK Addendum for UK transfers

OpenAI, Vercel, and Stripe each provide DPAs that include UK and EU transfer terms.

7. Your Rights

Under UK GDPR and GDPR, you have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to processing of your data
  • Request restriction of processing
  • Data portability
  • Withdraw consent where processing is based on consent

To exercise these rights, please contact us at [email protected].

Note: Since we do not store pasted messages, there is no message data for us to delete from our systems. However, OpenAI may retain API logs for up to 30 days as described above.

8. Security

We implement appropriate technical and organizational measures to protect your information. However, no method of transmission over the internet is 100% secure.

9. Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

11. Contact Us

If you have questions about this Privacy Policy, please contact us at [email protected].