Privacy
Last updated: September 25, 2026. This policy covers the ScamShield website, the Scam Shield Alexa skill ("Escudo Antiestafas" in Spanish), and the ScamShield MCP server.
ScamShield is built for people who may be worried, rushed, or older. It is designed to learn as little about you as possible.
What we store
Nothing about you. There are no accounts, no database, no message history, no cookies, and no analytics or advertising trackers. Each check is handled in memory and forgotten as soon as the answer is sent.
What we log
Only operational errors, recorded as an error type and code location. The text of your message is never written to our logs.
What leaves our server
- Official-website checks. When a message claims to be from a known company (like USPS or Amazon), we send a short search made of the company name and the scam's topic (for example, "USPS scam alert redelivery fee") to our search provider, Tavily, and read only that company's official website. We also look up recent official scam alerts (FTC, FBI, Social Security) this way. Your full message is never sent.
- AI assistants. If you use ScamShield through an AI assistant that supports "sampling", the message and our findings are sent back to that same assistant's AI model, which you are already using, for a second opinion. ScamShield has no AI model or API key of its own.
- Alexa. Amazon processes your voice under Amazon's privacy notice. Our skill accepts only requests signed by Amazon. It keeps the current conversation (for example, the last message you checked, so "warn my family" can refer to it) only until the conversation ends. It does not receive or store your name, email, address, or contacts.
Links are never opened
Suspicious links are analyzed as text. ScamShield never visits, clicks, or previews them.
On this website
"Read it to me" uses your browser's built-in voice. "Warn my family" writes a message on your device, and you choose whether and how to share it. If you install ScamShield on your phone and share a text to it, that text is checked the same way and not stored.
Screenshots and QR codes are read entirely on your device: the picture is never uploaded. Only the text read from it (or the QR code's link, which is not opened) is checked, like a pasted message. To do this, your browser downloads the free open-source reading tools (Tesseract.js and jsQR) from the jsDelivr network the first time you use it; the picture is not sent to them.
Hosting
The service runs on Render. Render may keep standard request logs (such as IP address and time) under its own policies. We use them only to keep the service running and to block abuse (for example, too many requests per minute).
Children
ScamShield is a general-audience safety tool and does not knowingly collect information from anyone, including children.
Changes and contact
If this policy changes, we will update this page and its date. Questions or requests: open an issue on GitHub.