Privacy Policy
Effective Date: 1 September 2026
Last updated: 1 September 2026
Trust & Data Safety Summary
IsThisSpam is designed to check suspicious content without requiring signup for the first scan. We process your threat indicators with minimal retention:
- Guard your secrets: Do not paste passwords, OTPs, bank logins, or full identity documents.
- Safe to redact: You can redact names, addresses, and account numbers before scanning.
- SuperScan comfort: For high-risk cases, use SuperScan only when you are comfortable sharing the details needed for analysis.
1. Overview
IsThisSpam helps users assess suspicious emails, messages, links, and websites. We aim to minimise data collection, be transparent about what is processed, and give users meaningful control over how scans are handled.
This policy explains what data is processed, how it is used, and how different features affect data handling.
2. What data IsThisSpam processes
IsThisSpam processes content submitted for analysis, either manually or through optional automated features.
Depending on your settings and usage, this may include:
- a) Personal communications: Email content or message text submitted for scam or phishing analysis.
- b) Website content: Website URLs or domain names submitted or checked for reputation and risk indicators.
IsThisSpam does not require or intentionally request passwords, authentication credentials, full financial credentials, or sensitive identity documents. Users should not submit these items.
Connected Gmail and Outlook protection
If you explicitly connect an inbox from the dashboard, IsThisSpam uses provider OAuth access to provide the connected-email protection feature. For Gmail, the application requests onlyhttps://www.googleapis.com/auth/gmail.modify. This is needed to read recent Inbox messages for classification and to apply Gmail labels when a message is classified as spam.
- Gmail access is limited to recent messages matching the Inbox surface and the Inbox change notifications needed for monitoring.
- For classification, we process message headers and text content and send only the sender, subject, and a bounded body excerpt to Cloudflare Workers AI as a real-time inference service.
- When a message is classified as spam, we add the Gmail
SPAMandMoved by IsThisSpamlabels and removeINBOXandUNREAD. We do not send messages, permanently delete messages, or change message content. - We do not request Gmail contacts, Drive data, Gmail settings, IMAP/SMTP access, or the broader
https://mail.google.com/scope. - We store the connected account address, encrypted OAuth access/refresh tokens, provider message ID, sender, subject, classification, confidence, bounded reason metadata, and scan timestamp to provide connection and scan-history features.
- We do not intentionally store raw Gmail message bodies or attachment bytes in IsThisSpam's scan-history database.
Google user data obtained through connected email is used only to provide inbox spam protection. It is not sold, used for advertising, used for retargeting, or used to train, fine-tune, or improve generalized or non-personalized artificial-intelligence or machine-learning models. Cloudflare processes the bounded inference request to provide the classification service and does not use Workers AI customer content to train models or improve Cloudflare or third-party services without consent.
Product analytics and campaign measurement
For campaign landing pages such as /protect, IsThisSpam may record limited first-party product analytics such as a normalized traffic source, campaign dimensions, device platform, an opaque session funnel identifier, and whether a checkout step was reached. These dimensions are used to understand the performance of the product journey and are not joined to scan content or mailbox contents.
Google Ads and Meta may receive limited browser-level page-view, checkout, and purchase events, together with coarse product or transaction values, and may use cookies or similar browser technologies for measurement and retargeting. In regions where opt-in consent is required, these integrations remain disabled until you allow them. For United States visitors, advertising measurement may be enabled by default, subject to an available opt-out. We honour supported Global Privacy Control browser signals as an opt-out. You can review or change the applicable setting through the site's Privacy choices control. IsThisSpam does not send these providers scan content, verdicts, sender details, phone numbers, scanned URLs, email content, connected mailbox data, email addresses, account identifiers, Stripe identifiers, or arbitrary query data. Declining advertising does not prevent you from using the scam checker or other core product features. The/protect funnel does not copy gclid, fbclid, referrer URLs, or arbitrary query parameters into its dedicated first-party event properties.
3. Manual checks vs automated protection
Manual checks
When you explicitly click to check content (for example, pasting an email or clicking “Check this site”):
- The submitted content is processed to generate a verdict and explanation.
- Processing occurs only in response to your action.
Browser social investigation beta
When you choose “Check this profile or page”, “Check link without opening”, or “Check selected message”, the extension first shows a preview of the information proposed for analysis. Nothing is submitted until you confirm.
- The preview may include the visible Instagram or TikTok handle, canonical profile URL, visible profile description, external links, or the message text you selected. The source page and visible display name remain on the device.
- Email addresses, phone-shaped values, credentials, URL query parameters, and fragments are removed before submission where detected.
- Exact profile handles or link domains may be sent to Brave Search for public-web matching. Selected message text is not used as a public search query.
- The extension does not submit social-media cookies, login tokens, passwords, full page HTML, screenshots, or browsing history through this feature.
Social investigation requests are processed to return the requested result and are not added to public scan logs. Public-search providers may process request data under their own privacy and retention terms.
Automated protection (optional)
If you enable automated protection features in the extension settings:
- URLs of websites you visit may be automatically checked against our threat detection services.
- This occurs only when the feature is enabled by the user and can be disabled at any time.
IsThisSpam does not perform background scanning unless these features are explicitly enabled.
4. Free use & public scans (no login)
When you use IsThisSpam without signing in:
Scan content retention
- Standard public checks, excluding SuperScan, may be retained after automated PII scrubbing to improve scam detection accuracy, identify emerging threats, and prevent abuse. SuperScan conversational investigations use the separate 90-day investigation-history retention described in Section 5 below.
- Stored public scan content undergoes automated PII scrubbing to redact sensitive information such as email addresses, phone numbers, and credit card numbers before storage.
⚠️ Please do not submit sensitive personal information (such as passwords, financial details, or government identifiers) to the public checker. While we use automated scrubbing, avoiding submission of sensitive data is the safest practice.
Abuse prevention
We generate anonymised identifiers, such as cryptographic hashes of IP addresses, solely for:
- Rate limiting
- Abuse detection
- Preventing automated misuse
These identifiers are not used for tracking or advertising. Public scan data is not linked to named accounts and is never sold or used for marketing purposes.
5. Optional sign-up, private scanning & SuperScan investigations
Creating an account is optional. Data handling depends on whether you use standard private scanning or the conversational SuperScan investigation tool:
Standard private scans
For logged-in users and authenticated license holders using standard single-turn checks (e.g. homepage, website, or extension scanners):
- Ephemeral processing: Both text and website/domain checks are processed in real-time in memory and immediately discarded.
- No Caching: Results for standard private scans are not saved to the global cache or public logs.
- No Training: Your private submissions are never used to train our detection models or added to public datasets.
SuperScan investigation history
SuperScan is an interactive, multi-turn scam investigation assistant. When you use SuperScan:
- Investigation history retention: User messages, follow-up inquiries, assistant risk verdicts, and structured check summaries (such as public reputation lookups for domains, social profiles, and phone numbers) are securely stored server-side.
- 90-Day retention period: SuperScan conversation history is retained for 90 days from creation to enable case continuity, follow-up analysis, debugging, and product safety improvements, after which records are automatically purged.
- Investigation linkage & ownership metadata: Each investigation uses an opaque investigation identifier. Server-side ownership metadata may also associate an investigation with an anonymous guest identity or authenticated account where required for access control and investigation continuity.
- Anonymous-to-account continuity: If you start an anonymous SuperScan investigation and subsequently sign in or create an account, your investigation history can be claimed and associated with your account so you can continue your case.
- No advertising or PostHog leakage: Raw SuperScan conversation content, message text, and uploaded attachment text are never sent to advertising platforms, third-party brokers, or PostHog product analytics. PostHog receives only non-sensitive categorical metadata (such as risk levels and tool names).
- User safety guideline: Please do not submit passwords, one-time verification codes (OTPs), authentication credentials, payment card numbers, banking passwords, or sensitive government identity documents into SuperScan.
Account data
We store:
- Email address
- Subscription or feature access status
Account data is not used for profiling, advertising, or resale.
Service and marketing communications
When we send an account, product, or marketing email, we may record whether it was delivered, opened, or clicked, together with the IsThisSpam destination path. We use this limited engagement data to understand whether communications are useful, troubleshoot delivery, honour opt-outs, and avoid repeatedly contacting disengaged recipients.
Campaign reporting uses a cryptographic recipient identifier rather than storing the email address in the reporting tables. We do not use email engagement data to track browsing outside IsThisSpam or sell it to advertisers.
6. How data is used
We process data strictly to operate and improve IsThisSpam:
- Scam & spam detection: To generate risk assessments and explanations.
- Detection improvement: Public scan submissions (anonymized and scrubbed) may be analyzed to improve accuracy and identify new scam patterns. Standard private scans are never used for this purpose.
- Community safety signals: Anonymous indicators (e.g. “this message has been reported multiple times”) may be shown without exposing personal content.
7. Data retention
- Public scans: Retained with PII redaction to improve detection, research scams, and prevent abuse.
- Standard private scans: NOT retained. All content is processed in memory and discarded immediately after the result is returned.
- SuperScan investigations: Retained securely server-side for 90 days for investigation continuity, safety analysis, and debugging, linked by an opaque investigation identifier and purged automatically thereafter.
- Cached results: Only public, unauthenticated scans contribute to the global cache.
- Connected email content: Raw Gmail message bodies and attachment bytes are not written to the IsThisSpam scan-history database after processing. The bounded classification request is handled by the configured inference service for the time needed to return a verdict.
- Connected accounts and scan history: Encrypted OAuth token material and reduced scan metadata are retained while a connected account is active to provide ongoing protection and history. Disconnecting an account stops normal sync and future use of the account; the inactive account record and associated scan history may remain until an account-data deletion request is processed.
You may request deletion of account-related data, including connected-account token material and connected-email scan history, at any time by contacting privacy@isthisspam.org. You can also revoke the Google grant from your Google Account security settings. We may retain a minimal record where needed to honour a deletion request, prevent abuse, or meet a legal obligation.
8. What IsThisSpam does NOT do
IsThisSpam does not:
- Sell personal data
- Use scan data for advertising
- Track unrelated browsing history
- Monitor keystrokes or unrelated browsing behaviour; limited clicks from IsThisSpam emails may be measured as described above
- Intentionally request or collect passwords, authentication secrets, or financial account credentials
9. Security
We apply industry-standard safeguards, including:
- Encryption in transit and at rest
- Restricted access to stored data
- Abuse-prevention mechanisms designed to minimise personal identification
10. Changes to this policy
We may update this policy as features evolve or legal requirements change. The latest version will always be available on this page.
11. Contact
For privacy questions or data requests: privacy@isthisspam.org