ScamCatchr

Privacy Policy

How ScamCatchr collects, uses, and protects your data

Terms of Service Privacy Policy

Effective date: June 14, 2026  ·  Last updated: June 14, 2026

Short version: ScamCatchr never reads your email body content. We only analyse email headers. Any data we store locally stays on your device unless you explicitly submit a report or subscribe to the digest.
Contents
  1. Who We Are
  2. What Data We Collect
  3. How We Use Your Data
  4. Local Storage
  5. Cloud Storage (Firestore)
  6. Gmail API & OAuth
  7. Weekly Digest
  8. Third-Party Services
  9. Data Sharing
  10. Data Retention
  11. Security
  12. Your Rights
  13. Children's Privacy
  14. Changes to This Policy
  15. Contact

1. Who We Are

ScamCatchr is a Chrome browser extension built to help individuals and businesses identify scam, phishing, and fraud emails in Gmail. The Service is operated at scamcatchr.com and can be reached at info@scamcatchr.com.

This Privacy Policy explains what personal data ScamCatchr collects, why we collect it, and what choices you have. It applies to the extension, the website, and the weekly digest email service.

2. What Data We Collect

2.1 Data we never collect

2.2 Data collected automatically (when you use the extension)

DataWhyWhere stored
Sender domain of emails you view in GmailTo check against known scam domain listsYour device only (memory, not persisted)
Email display name and sender addressTo detect brand impersonation and display-name spoofingYour device only (memory)
Authentication-Results email headerTo check SPF, DKIM, and DMARC verification statusYour device only (memory)
Risk level and warning reasons for flagged emailsTo power the popup stats and recent threats viewchrome.storage.local on your device

2.3 Data you provide when submitting a phishing report

DataWhyWhere stored
Sender domain (not the full email address)To add to community flagging databaseFirestore (anonymised)
Email subject lineTo categorise the scam patternFirestore (anonymised)
Scam type (chosen from dropdown)For digest statisticsFirestore
Risk level (warning / danger)For digest statisticsFirestore
Detection reasons (which checks triggered)For pattern analysisFirestore
TimestampFor trend analysisFirestore
Your personal email address is never included in phishing reports. We store only the sender domain (e.g., evil-shipping.com), not your full sender address or your own address.

2.4 Data collected when you subscribe to the weekly digest

3. How We Use Your Data

We use collected data only for the following purposes:

We do not use your data for advertising, profiling, or any purpose unrelated to scam detection.

4. Local Storage

ScamCatchr stores the following data in chrome.storage.local on your own device. This data never leaves your device except where explicitly described:

You can clear all local storage at any time: chrome://extensions → ScamCatchr → Clear data.

5. Cloud Storage (Firestore)

When you submit a phishing report, anonymised fields are written to Google Cloud Firestore, a secure cloud database operated by Google. The following Firestore collections are used:

6. Gmail API & OAuth

ScamCatchr's Gmail API integration is governed by the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

You can revoke Gmail access at any time from Google Account → Third-party apps & services or from the extension popup.

7. Weekly Digest

The weekly digest is an entirely optional service. If you subscribe:

8. Third-Party Services

ServicePurposeData sharedPrivacy policy
Google Cloud Firestore Cloud database for anonymised reports and digest subscriptions Anonymised report data; Gmail address (digest subscribers only) google.com/privacy
Google Cloud Functions Backend processing: report storage, community flags, digest sending Same as Firestore above google.com/privacy
Google Firebase Authentication Pseudonymous user identity for digest subscription management Firebase UID only (no personal data) google.com/privacy
SendGrid (Twilio) Transactional email delivery for the weekly digest Gmail address at send time only sendgrid.com/policies/privacy
Google Fonts Roboto typeface on the website Your IP address (standard web request) google.com/privacy

We do not use any analytics, advertising, or tracking services on this website or in the extension.

9. Data Sharing

We do not sell, rent, or trade your personal data. We do not share your data with advertisers. The only circumstances under which we share data are:

10. Data Retention

11. Security

We take the following measures to protect your data:

No method of transmission over the internet or electronic storage is 100% secure. While we implement strong safeguards, we cannot guarantee absolute security.

12. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, email info@scamcatchr.com. We will respond within 30 days. Most data subject rights can be exercised immediately via the extension popup (disconnect Gmail, unsubscribe from digest, clear local data).

If you are located in the European Economic Area, United Kingdom, or California, additional rights may apply under GDPR, UK GDPR, or CCPA respectively.

13. Children's Privacy

ScamCatchr is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided personal data to us, please contact us at info@scamcatchr.com and we will delete it promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page. For material changes, we will display a notice in the extension popup. Your continued use of the Service after any change constitutes acceptance of the revised policy.

15. Contact

For privacy questions, data subject requests, or any concerns about this policy:

See also our Terms of Service for the rules governing use of the extension.