Privacy policy
You are trusting us with messages that sometimes contain private details. This explains exactly what happens to them, what we keep, and what we never keep.
Last updated 6 September 2026
Who is responsible
Astrelisai Ltd is the data controller for the information described here. Our registered address will be published here before public launch. For anything about your data, email hello@scambro.com.
The free check: what we keep is almost nothing
The message you paste into the free check is not stored. It is held in memory long enough to check it, then discarded. We do not keep it, and we cannot show it to you again afterwards.
To limit abuse we keep short-lived usage counters, keyed with a secret and a rotating daily identifier derived from your IP address when our hosting supplies a trusted client address. These identifiers are pseudonymous, not anonymous. Counters expire at the end of their rate-limit window and are removed by scheduled maintenance, normally within another ten minutes.
The message is read by an AI model
With your permission, message text and the supplied sender details are sent to Anthropic through Vercel AI Gateway. Rules also examine the text. If AI is unavailable, the result clearly says it used rules only. The mobile app first tries to read photos on your phone. If that fails, you may explicitly choose to send the photo itself to the same providers. Photos are not saved in our application database. Text redaction is best-effort and may miss personal details. Please review the message before sending.
Because of this, please remove details you would not want processed before pasting a message: full card numbers, passwords, one-time codes, or medical information. You never need any of those for us to spot a scam. And if a message has asked you for a password or a security code, that is itself a warning sign, so never send it on to anyone, including us.
If you have an account
We hold:
- Your email address, so we can sign you in and receive the messages you forward. Sign-in uses an emailed link or a six-digit app code, so we never hold an account password.
- Your name, if you give us one, and a coupon code if you used one.
- Messages you forward: the visible sender, the reply-to address, the subject, and a sanitised copy of the text with markup and scripts stripped out. Attachments are never stored, only their file names, types and sizes.
- The result of each check: the verdict, the reasons, and the suggested next step.
- Your trusted contact, if you add one: their name and email, and whether they have confirmed.
Saved message text and results become inaccessible after 30 days and are removed by scheduled maintenance, normally within another ten minutes. You can delete any check yourself at any time, and it is removed immediately.
Content-free usage reservations are retained for up to 62 days to enforce monthly limits even when checks are deleted. Pending email jobs retain recipient details and minimal notification text for no more than a day; successful jobs have those fields cleared. Expired sessions and codes are removed by maintenance. Provider-side delivery records and backups follow the applicable provider retention settings and must be included in any deletion request.
Alerts to your trusted contact
A trusted contact is only ever added by you, and we email them to ask for their agreement before they are able to receive anything. If a message you check looks seriously wrong, we may tell them that you may need a call. We never include the suspicious message, its links, or any personal details from it in that alert. You can remove a trusted contact at any time.
Why we are allowed to hold it
- To provide the service you asked for: your account, your checks, your forwarding address. This is necessary to perform our contract with you.
- To keep the service working and safe: the hashed-IP rate limiting and security logging. This is our legitimate interest in preventing abuse, balanced against a deliberately minimal record.
- Consent: for a trusted contact to receive alerts, which they give by choosing the agreement button on their invitation page, and can withdraw at any time.
Who else sees it
We use a small number of suppliers, who process data on our instructions and cannot use it for their own purposes:
- Vercel: hosting and the AI Gateway.
- Neon: the database.
- Resend: sending sign-in links and alerts, and receiving forwarded messages.
- Anthropic: the AI model that reads messages, reached through Vercel.
Some of these process data outside the UK. Where they do, transfers rely on the safeguards UK data protection law requires. We do not sell your data, and we do not share it for advertising. We would only disclose it if the law required it.
Cookies
We use essential cookies only: one to keep you signed in, and one to remember a coupon code between entering it and finishing sign-in. There is no advertising, analytics or tracking on this site, which is why you are not being asked to accept anything.
Your rights
You can delete your account in Settings after entering a separate emailed confirmation code. You can also remove your contact, turn off future forwarded-message AI processing, or delete individual checks there. Under UK data protection law you can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Email hello@scambro.com and we will respond within one month.
If you are unhappy with how we have handled your information, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you told us first so we can put it right.
Children
ScamBro is not intended for under-18s and accounts are for adults only.
Changes
If we change this policy, the date at the top will change and we will tell account holders about anything significant. Our terms of use explain what the service does and does not promise.