Privacy Policy

    Last updated: August 12, 2026

    ScamMessage ("we," "our," or "the service") provides tools that help people identify suspicious digital messages and protect themselves and the people they care about from scams. This Privacy Policy explains what information we handle, how we use it, and the choices you have. It applies to both the ScamMessage website and the ScamMessage mobile application (collectively, "the service").

    By using the service, you agree to the practices described in this policy.

    Overview

    ScamMessage lets you analyze suspicious messages and screenshots for scam warning signs, and offers optional protection features such as scam call labeling, SMS filtering, family activity monitoring, and bank-transaction monitoring. The website provides the scan tool, informational pages, and email confirmation; there are no web accounts, dashboards, or web login. Account-based features are available only in the mobile app and require you to register.

    We have designed the service to collect as little as necessary and to avoid storing the actual content of the messages you scan. We do not sell your personal information, and we do not use it for advertising.

    Information We Handle

    Account information

    When you create an account in the mobile app, we collect and store:

    • Your email address and a securely hashed password (managed by our authentication provider)
    • A unique account identifier
    • Your subscription tier (free, or one of the paid tiers Protect, Family, or Household), which affects daily scan limits and how many other people you can protect
    • Your profile display name, which may be visible to active family monitoring counterparts
    • Limited app settings and preferences (for example, your bank-alert threshold)

    The website's scan tool can be used without an account. Creating an account, signing in, managing a subscription, and using account-based features happen in the mobile app only.

    Messages and screenshots you scan

    When you scan a message or screenshot, the content is sent to our servers and to third-party analysis providers solely to generate your scam analysis.

    • We do not store the raw text of scanned messages.
    • We do not store uploaded screenshots. Screenshots are used only to extract text for analysis and are then discarded.
    • After your analysis is generated, the original content is not retained.

    To improve scam detection across the service, we may store non-identifying, one-way fingerprints (hashes) of content and short anonymized snippets of phrases commonly found in scams. These are not linked to your account and cannot be reversed back into your original message. Phone numbers and web domains detected within scanned messages are stored only in masked or hashed form (for example, "+1 (917) XXX-XXXX").

    Scan results and history

    We store the results of your scans (such as the risk level, scam type, detected warning signs, and the date), linked to your account so you can view your activity history. These results describe the analysis — they do not contain the original message content.

    Financial information (optional Bank Monitoring)

    If you choose to connect a bank account through Plaid, our third-party financial-data provider:

    • We receive and store a secure access credential that allows the service to retrieve transaction information from your connected institution, along with the institution's name and connection status. We do not receive or store your banking login credentials — those are handled by Plaid.
    • We store the minimum transaction data needed to provide alerts: transaction amounts, dates, and merchant categories.
    • Your bank connection is governed by Plaid's Privacy Policy.
    • You can disconnect your bank account at any time, which revokes our access. Disconnecting your bank, or deleting your account, permanently deletes the stored financial data and access credential associated with it.

    Family / monitoring connections

    ScamMessage offers a consent-based monitoring feature that allows one account holder (a "monitor") to view certain activity from another account holder, only after the monitored account approves the connection through an invitation. We store the relationship between the two accounts and the invitation status. Display names are set on each user's own profile and may be visible to their active family counterparts; we do not store a separate display name on the monitoring relationship itself.

    A person can be monitored by at most two other people at a time. When a connection is active, each direct monitor may receive alerts and may view the monitored account's scan results, SMS protection events, and bank-monitoring alerts. Alerts are delivered only to direct monitors and are never forwarded further. The monitored account holder must approve the connection before any activity is shared, and either party can end the connection.

    When a monitoring connection ends, coverage for that relationship is fully removed: the bank connection is disconnected through Plaid, stored transaction and financial-event data associated with that monitoring coverage is deleted, and related protection preferences for that coverage are cleared. Re-establishing the connection later requires connecting the bank again and setting up protection features anew.

    See the Children and Family Accounts section below for important information about minors.

    Call and SMS protection events

    If you enable the mobile app's protection features:

    • Call labeling matches incoming numbers against a known scam-number list on your device and can show a “Scam Risk” label before you answer. Matching happens on-device; we do not receive a log of which calls were labeled.
    • SMS filtering evaluates incoming messages using the sender's number only. We do not read, store, or transmit the body or content of your text messages.

    Notifications

    We store a device push token so we can send you (and, where applicable, a connected monitor) alerts such as high-risk scan or large-transaction notifications. We store the notifications we generate for you within your account.

    Payment information

    Paid subscriptions are purchased through Apple In-App Purchase and are billed and managed by Apple. We do not store your full payment card details; those are handled by Apple. We store your subscription and entitlement status (including which tier you are on) so we can provide the features you have paid for. RevenueCat processes subscription and entitlement data on our behalf.

    Basic technical data

    Like most online services, we automatically receive limited technical data used to keep the service secure and reliable, such as IP address (stored in hashed form), device identifiers, app/browser and device type, and timestamps of requests. This is used for security, abuse prevention, and service performance.

    How We Use Information

    We use the information above to:

    • Provide and operate the service and its features
    • Generate scam analyses and protection alerts
    • Maintain your account and subscription
    • Keep the service secure and prevent abuse (including rate limiting)
    • Communicate with you about the service

    We use information only to provide and improve the service. We do not sell your personal information, and we do not use it for advertising or to build advertising profiles.

    Analytics: We use Ahrefs Analytics, a third-party web analytics service, to understand how the website is used (for example, which pages are visited and how visitors find the site) so we can improve the service. Ahrefs Analytics collects limited usage data such as page views, referrers, and approximate location derived from IP address. It is not used for advertising profiles. The mobile app does not use Ahrefs Analytics.

    Third-Party Providers

    We share information with service providers only as needed to operate the service. These include:

    • Supabase — secure hosting, database, and authentication infrastructure
    • Google Cloud Vision — extracts text from screenshots you submit for analysis
    • Google (Gemini API) — performs the automated scam analysis of message text
    • Plaid — connects to your bank if you enable Bank Monitoring
    • Apple — processes In-App Purchases for paid subscriptions through the App Store
    • RevenueCat — processes subscription and entitlement data on our behalf
    • Apple Push Notification service — delivers notifications to your device
    • Ahrefs Analytics — website usage analytics (page views and related traffic data) to help us improve the site

    When you scan a message, its text may be transmitted to Google Cloud Vision and/or the Google Gemini API solely to generate your analysis. Each provider handles data under its own privacy terms. We do not sell or share your data for advertising purposes.

    Children and Family Accounts

    The monitoring feature is consent-based and intended for use between account holders who agree to be connected. If a monitored user is under the age of 18, the account must be set up and consented to by that user's parent or legal guardian, who is responsible for the connection.

    The service is not intended for anyone under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it. If you are a parent or guardian and believe we have collected information from a child under 13, please contact us using the form in the Contact section below to request deletion.

    Data Retention

    • Account data (such as your email, settings, and scan history) is retained until you delete your account.
    • Transaction and financial data (including the Plaid access credential and stored transaction and financial-event information) is retained until you disconnect your bank account or delete your account. We do not currently apply a fixed time-based retention period for this data.
    • Scanned message content and screenshots are not retained — they are processed to generate your analysis and then discarded.

    You may request deletion of your account and associated data at any time (see Your Choices and Contact).

    Your Choices

    • Access and deletion: You can delete your account, which removes your associated personal data as described above.
    • Bank disconnection: You can disconnect a linked bank account at any time to revoke access and delete stored financial data.
    • Monitoring connections: A monitored account can decline or end a monitoring connection.
    • Notifications and permissions: You can manage notification, call, and message permissions through your device settings.

    Security

    We take reasonable measures to protect the service and the data we handle, including rate limiting, abuse monitoring, and access controls. No method of transmission or storage is completely secure, but we work to protect your information appropriately.

    Changes to This Policy

    We may update this policy from time to time to reflect changes to the service or legal requirements. Updates will be posted on this page with a revised effective date.

    Contact

    If you have questions about this Privacy Policy, your data, or a request to delete your data, you can reach us using the contact form below (or the feedback form on this page).

    What's this about?