Privacy policy
This sets out what ScamZam processes about you, why, who gets to see it, and how long it stays. None of it is written to impress a lawyer.
In force from 31 August 2026. Version 1.1.
In short
- We do not know who you are. No account, no name, no email address, unless you write one yourself in an error report or in the contact form.
- We only get the domain.
shop.com/order/1234?token=abcbecomesshop.combefore it leaves your browser. - We do not see the pages you visit. Only the single page you press the button on, and only at the moment you press it.
- Your history stays on your computer. It is never sent anywhere, and you can delete it with one click.
- No ads, no tracking, no cookies. We sell nothing on, because there is nothing to sell.
- The page text is read by an AI service in the United States. Emails, phone numbers and card numbers are stripped in your browser first. That is the only transfer outside the EU.
Who is responsible
ScamZam is run by a private individual and not by a company. There is no ad network, no investors and no third party making money from your use of the service. If you write to the address above, a person reads and replies.
What we process, and why
There are only five things. Three of them arise automatically when you press the button, and the last two only if you choose to write to us.
| What | Why | How long |
|---|---|---|
| A random user id such as szam_9f3c… |
So we can count your checks against the daily limit and see that the same user is not reporting the same site ten times. It is created in your browser, it contains nothing about you, and it cannot be traced back to a person. | The counter is deleted after about 25 hours. The id itself stays in your browser until you remove the extension. |
| The domain of the page you check | That is the job itself. Path, parameters and fragment are cut away in your browser, because we only look up the domain, and because that is exactly where personal details tend to hide. | The answer itself is kept for 6 hours in a shared cache, so the next lookup of the same domain is faster. It is tied to the domain, not to you. |
| An extract of the page's visible text plus title, language, payment methods and similar signals |
Scams give themselves away in the language: false urgency, offers that are too good, invented company names. Email addresses, phone numbers and long strings of digits are stripped in your browser before the text is sent. | Not stored. The text is used in the assessment itself and discarded afterwards. |
| Your IP address | It accompanies every request on the internet automatically. We use it to count checks per address, so one machine cannot use the whole capacity. | We do not store it at all. A salted digest of it is made, usable only as a counter, and the salt is replaced every day. Both the counter and the salt are deleted after about 25 hours, after which the digest cannot be traced back to any address, not even by us. We keep no log of which domains an address has looked up. |
| What you write yourself in an error report or when you flag a site |
So we can correct a wrong verdict and warn others. The email address is optional and used only to reply to you. | Error reports for 400 days. Flags on a site for 1 year. |
| The contact form name, email address, subject and your message |
So we can read and reply. The form does not send email, it puts the message in a database we read ourselves. Here the email address is required, because otherwise you cannot get a reply. | 1 year, and then it is deleted automatically. Ask, and it goes straight away. |
Legal basis
Processing takes place under Article 6(1)(f) of the General Data Protection Regulation, that is our legitimate interest in providing the service you asked for and in preventing misuse of it. The balancing of interests falls in your favour in the sense that we have cut away everything that is not necessary: no account, no address beyond the domain, no tracking across sites, and no profile.
If you write your email address in an error report or in the contact form, the basis is your consent under Article 6(1)(a). You can withdraw it by writing to us, and then we delete what you sent.
Who gets to see the information
Two companies process data on our behalf. Both are processors under an Article 28 agreement.
| Recipient | What they get | Where |
|---|---|---|
| Cloudflare hosting, database and network |
All of the above, because the service runs on their infrastructure. | Processed on Cloudflare's network with servers in the EU and the rest of the world. Cloudflare is covered by the EU-US Data Privacy Framework and also uses the EU standard contractual clauses. |
| Groq the language models that read the page text |
The domain and the cleaned text extract. Not your user id and not your IP address. | The United States. The transfer is made under the EU standard contractual clauses. Groq does not retain what we send. |
Lookups in public registries
To be able to answer, we look the domain up with a number of public sources: domain registries via RDAP and WHOIS, the Certificate Transparency logs, DNS, ASN information about who hosts the site, Tranco's popularity list and the European Commission's VAT register. They only get the domain name. They get neither your user id, your IP address nor the page text, and they cannot see that it was you who asked.
Transfer to the United States
The text from the page is assessed by language models at Groq, which is in the United States. That is the only transfer outside the EU, and it is necessary in order to read a page for the language of scams. The basis is the European Commission's standard contractual clauses.
We have done three things to limit what can be transferred at all: the address is cut down to the domain, the text is cleaned of email addresses, phone numbers and long strings of digits before it leaves your browser, and your user id and IP address are never sent along. In practice there is therefore nothing in what we send that points to you.
Cookies
There are none on this website. No banners, no consent, no analytics. The typeface is on our own server rather than Google's, and there is no embedded video, map or reCAPTCHA.
If you choose the dark theme with the button at the top, that choice is stored in your own browser so the site remembers it. It is a setting you asked for yourself, and it is not sent anywhere.
The extension stores three things locally on your computer: your user id, your choice of language and theme, and your history of checks. None of it leaves the machine. Clear the history in the extension and it is gone.
The assessment is automated
The answer you get is computed by rules and language models without a person having looked at it. It is an advisory assessment of a website, not a decision about you, and it has no legal effect on you. It can be wrong in either direction.
If you think an assessment is wrong, you can report it straight from the extension or write to us, and then a person will look at it. If you own a site that has been assessed wrongly, you can read more on the page for site owners.
Your rights
You have the right of access, rectification and erasure of the information we hold about you, the right to restriction of processing, the right to data portability and the right to object.
There is a practical catch, and it should be said plainly: we do not know who you are. We have no name, no email address and no account to look you up in. If you want access or erasure, you need to send us your user id, which you will find in the extension's settings. Without it we cannot find anything, and nor can we verify that it is your information you are asking about.
You can always delete everything held locally yourself, by clearing the history and removing the extension. The counters on the server expire by themselves within a day.
Complaints
If you are unhappy with the way we process your information, we would like to hear from you first. You can also complain to a supervisory authority. Under Article 77 of the General Data Protection Regulation you may always complain to the authority in the country where you live, and the European Data Protection Board keeps the list.
Changes
If we change what is processed or who receives it, we update this page and put a new date at the top. If a change is significant, you will be told in the extension, not only here.

