ScamShield Privacy Policy

Last updated: 2026-08-08

ScamShield analyzes web pages on your device to warn you about scams and phishing. We designed it so your browsing stays private.

What we collect

Nothing. ScamShield does not transmit your browsing history, the pages you visit, URLs, form contents, messages you check, or any personal data to us or any third party. All scam/phishing analysis runs locally inside the extension.

Local storage

ScamShield stores your settings, your list of trusted sites, and a protection history (site names and event types only — never full addresses) in your browser's local extension storage. This never leaves your device, can be cleared in Settings, and is removed when you uninstall the extension.

Optional anonymous reporting

Settings includes an opt-in "Send anonymous threat reports" toggle (off by default). In this version it is a stored preference only — no reports are transmitted. If a future version activates it, reports would contain only anonymized, non-identifying risk features about a flagged page, never full URLs, page content, your IP-based identity, cookies, or anything that identifies you or the specific page.

Threat-list download

ScamShield periodically downloads an updated blocklist of known scam domains — a static JSON file, by default from ScamShield's public open-source feed. It is the same file for every user; nothing about you or your browsing is sent with the request beyond what any file download implies (your IP address reaching GitHub's servers). You can point the URL at your own feed or clear it to disable updates entirely in Settings. It never uploads your browsing or any other data.

Permissions

See the permissions justification in the store listing. We request the minimum needed to read the current page for analysis and to block known-bad sites.

Contact

Questions: jojostev@gmail.com