Scam SafeGuard's email scanner extracts hyperlink URLs only. It does not read, store, or transmit the content, subject line, sender, or attachments of any email. We don't sell your data, ever. We check the links you encounter against trusted threat databases, and we keep only what we need to help keep you safe. The detail below explains exactly how.
What's in here
1. Who we are
Scam SafeGuard ("we", "us", "our") is a browser extension and related service that helps protect you from scam and phishing websites. The service is operated by SCAM SAFEGUARD PTY LTD, an independent developer based in Australia (ABN 51 698 899 795). We are not affiliated with any bank, telco, or government agency.
This policy applies to the Scam SafeGuard browser extension, the website at scamsafeguard.com, and our backend scanning service.
2. What information we process
Web addresses (URLs) of pages and links checked
To protect you, Scam SafeGuard checks web addresses against threat databases. Depending on your settings, this includes addresses of pages you visit, links you click from social media, and links you ask us to check. These checks are matched by website address, not tied to a personal profile of your browsing history. Results are briefly cached by website address so we don't re-check the same site repeatedly.
Page content — only for borderline sites
If a site looks suspicious but isn't a confirmed match, we may send the visible text content of that page to an AI service for a closer look (see section 5). This only happens for the small number of sites that fall into a "needs a closer look" category — not for normal browsing on sites already known to be safe.
Messages you choose to check
When you paste a message into the "Check a Message" tool — whether inside the extension or the free message checker on this website — we process that text to find and check any links inside it. If the message shows signs of a scam, its text may be analysed by our AI service to help judge the risk.
Email and message links
Scam SafeGuard checks links you click from webmail and messaging services (Gmail, Outlook, WhatsApp Web, and Google Messages) before they open. It does this in two ways:
Automatic checking (Email & Message Guard): When you click a link inside one of these services, Scam SafeGuard checks the destination web address before the page opens. Only the destination URL is sent for checking — we do not read, access, or transmit the content, subject line, sender, or any other part of your emails or messages — only the destination web address is checked.
Manual checking ("Check Links" button): When you click "Check Links" inside Gmail or Outlook, our code extracts only the web addresses (the href of links) from the email and checks them. Again, no email content, subject line, or sender information is ever accessed or transmitted.
Many common websites (such as your bank, government services, and major retailers) are recognised on your device without any network request at all — these pass through instantly with no data sent anywhere. See section 3 for what this feature explicitly excludes.
A random installation ID
When you install the extension, it creates a random identifier (a string of characters) stored on your device. It is sent with scan requests to help us apply fair-use limits and prevent abuse. It is not your name, email, or anything that identifies you personally, and we do not link it to your identity.
Your settings
Your preferences — such as notification level and your list of trusted sites — are stored locally on your own device using your browser's storage. They are not sent to us.
Payment information
If you subscribe to a paid plan, payments are handled by our payment provider, Paddle, acting as Merchant of Record. We never see or store your full card details. We receive limited information such as your subscription status and country (for tax purposes).
2a. Trusted Contact feature (optional)
The Trusted Contact feature is entirely optional. It lets someone using Scam SafeGuard designate a trusted person — typically an adult child — to receive a weekly summary of their protection activity. If you choose to use this feature, the following applies.
What is collected
The email address of the designated Trusted Contact is collected when you enrol them. This is the only personal information collected specifically for this feature. The weekly summary sent to that address contains only aggregate counts (how many links were checked, how many dangerous sites were flagged) and a coarse category description (for example, "a fake login page"). It never contains URLs, domain names, page titles, or any information that could reveal browsing activity.
Consent and verification
When you enrol a Trusted Contact, you confirm that you have that person’s permission to provide their email address to us for this purpose. Before any summary is sent, the designated Trusted Contact receives a single first-contact verification email that explains who enrolled them, what they will receive, and how to opt out — and they must click a confirmation link. No summaries are sent until they confirm. The Trusted Contact is never added to any marketing. The protected person sees the consent explanation — including exactly what the Trusted Contact will and won't receive — before any enrolment is submitted.
How the email address is stored
The Trusted Contact's email address is encrypted at rest using industry-standard symmetric encryption. It is stored against a hashed (scrambled) identifier — never against your name, account, or any directly identifying information.
How to remove it
Every summary email includes a one-click unsubscribe link. Clicking it permanently deletes the email address and all associated data immediately, with no login required. The protected person can also remove the Trusted Contact at any time from the extension settings. Either action deletes all stored data for that enrolment.
Retention
The email address and weekly counters are retained for as long as the enrolment is active. Weekly counter data expires automatically after 21 days. When an enrolment is removed (by either party), all associated data is deleted immediately.
2b. Email subscriptions (Scam Watch & checklist)
You can choose to sign up for our weekly "Scam Watch" email, our free scam checklist, or both — from the website, the extension's welcome page, or after using the free link checker. This is entirely optional and separate from using the extension.
What is collected
Your email address, and optionally your first name if you choose to give it. We don't ask for anything else to send you these emails.
Why we collect it
To send you the weekly Scam Watch email (one Australian scam explained in plain English), to deliver the scam checklist if you requested it, and to occasionally let you know about product updates.
Who processes it
We use Resend, a third-party email provider, to send these emails and to hold the subscriber list. Resend processes your email address on our behalf to deliver messages and manage unsubscribes.
Consent and unsubscribing
Signing up is opt-in — you must tick a consent checkbox before submitting the form; it's never pre-ticked or bundled with anything else. Every email we send has a one-click unsubscribe link, and you can opt out at any time. Once you unsubscribe, we no longer send you these emails.
We don't sell it
We never sell or trade your email address or name to anyone.
3. What we never collect
Scam SafeGuard’s email feature checks the web addresses (links) in a message. By design, it does not access the following, and we do not collect or transmit them:
- The body or text content of your emails
- Email subject lines
- Sender or recipient names and addresses
- Attachments
We also do not:
- Sell, rent, or trade your personal information to anyone
- Build or sell an advertising profile of you
- Log your browsing history against your identity
- Read the contents of messages you haven't chosen to check
4. How we use information
We use the information we process only to:
- Check links and warn you about dangerous sites in real time
- Improve the accuracy of our scam detection
- Apply fair-use limits and protect the service from abuse
- Provide customer support when you contact us
- Process payments and manage subscriptions (via Paddle)
- Meet our legal obligations
5. How AI analysis works
For sites and messages that can't be judged by threat-database matching alone, we use Google's Gemini AI service to assess scam indicators. In these cases:
- The visible page text (or the message text you pasted) is sent to Google for analysis.
- This is limited to borderline cases — not your everyday browsing.
- Google processes this text to return a risk assessment to us.
Google's handling of this data is governed by Google's own terms and privacy practices for its AI services. We send only what's needed for the assessment and never include your installation ID or any account details in that request.
6. Who we share data with
We don't sell your data. We rely on a small number of trusted service providers to run the service:
| Provider | Purpose | What they receive |
|---|---|---|
| Google (Web Risk) | Checks addresses against Google's threat database | The web address being checked |
| Google (Gemini AI) | Analyses borderline sites and messages | Page text or pasted message text (borderline cases only) |
| Google Cloud | Hosts our scanning service | Data processed in transit as above |
| Upstash (Redis) | Temporarily caches scan results | Website addresses and their risk results |
| Paddle | Processes payments (Merchant of Record) | Your payment and billing details |
| Resend | Sends the weekly Trusted Contact summary and verification emails; sends the weekly Scam Watch email and scam checklist, and holds that subscriber list | The Trusted Contact's email address and the summary counts; and, for subscribers, the email address (and optional first name) you sign up with |
| Cloudflare | Hosts our website (scamsafeguard.com) | Standard web-server logs (such as IP address and pages requested) for website visitors |
We use public scam blocklists (such as global phishing and malware feeds) by downloading their lists to our own servers. Your data is never sent to those providers.
We may also disclose information if required by law, or to protect the rights, safety, and security of our users and the service.
7. How long we keep it
- Scan results are cached by website address for a short period (typically between 12 hours and 7 days) and then expire automatically.
- Fair-use and abuse-prevention records tied to your random installation ID are kept in a hashed (scrambled) form for up to 30 days.
- Your settings stay on your device until you change them or uninstall the extension.
- Support correspondence is kept only as long as needed to help you and for our records.
8. How we protect it
We use encryption in transit (HTTPS), access controls, and data-minimisation by design — we simply don't collect most of the data that would be sensitive. We do not sell or share your personal information, and we do not disclose browsing-related data for advertising or marketing purposes. No method of transmission or storage is ever 100% secure, but we take reasonable steps — including technical and organisational measures — to protect your information.
If something goes wrong (data breaches)
If a data breach occurs that is likely to result in serious harm, we will assess it and notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme, and any other regulator where the law requires.
9. Your rights and choices
Depending on where you live (including under the Australian Privacy Act 1988, the EU/UK GDPR, and the California CCPA/CPRA), you may have rights to access, correct, delete, or restrict the use of your personal information, and to object to certain processing.
Because we deliberately collect very little personal information, much of your control is direct:
- You can turn off scanning, change notification levels, or manage your trusted-sites list at any time in the extension settings.
- You can uninstall the extension at any time, which removes the locally stored data on your device.
- You can contact us to make a privacy request, and we will respond as required by the laws that apply to you.
To exercise any right, contact us at privacy@scamsafeguard.com. You also have the right to complain to your local privacy regulator — in Australia, the Office of the Australian Information Commissioner (OAIC).
10. Overseas disclosure and international users
We are based in Australia. To run the service, we disclose limited information to service providers that process data overseas, including in the United States. The main overseas recipient is Google LLC (Web Risk threat checks, Gemini AI analysis of borderline cases, and Google Cloud hosting), and our payment provider Paddle and email provider may also process data outside Australia. The specific data each receives is listed in section 6.
Under Australian Privacy Principle 8, we remain accountable for how these overseas recipients handle your personal information, except where an exception applies. By using the service, and as set out in this policy, you acknowledge that your information may be processed in these countries, where privacy protections may differ from those in your own country. Where we transfer personal information internationally, we take reasonable steps to ensure it remains protected in line with applicable law, including using appropriate contractual protections (such as Standard Contractual Clauses) where required.
EU, UK and other regions
If you are in the EU, the UK, California, or another region with its own data-protection laws, those laws may give you additional rights (for example, under the EU/UK GDPR or the California CCPA/CPRA). We honour those rights where they apply to you. Our legal basis for processing is generally our legitimate interest in detecting scams and providing the service you have asked for, and your consent where required (for example, for AI analysis of borderline pages). You can object to processing, or withdraw consent, at any time using the controls in the extension or by contacting us.
11. Children
Scam SafeGuard is intended for adults and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, please contact us and we will delete it.
12. Changes to this policy
We may update this policy as the product or the law evolves. When we make material changes, we'll update the date at the top and, where appropriate, notify you. Continuing to use Scam SafeGuard after changes take effect means you accept the updated policy.
13. Contact us
Questions about your privacy, or want to make a request? Email us at privacy@scamsafeguard.com. We read every message.