Privacy Policy

Plain-language summary of how we handle data when you look up or report identifiers.

Last updated: September 24, 2025

What we collect

When you look up a phone number or email address, we process that identifier to return a status. We do not require an account for basic lookups. If you sign in to submit a report, we store your Firebase account identifier and the information you provide in the report (description, scam category, evidence link). When dispute filing is available, we will collect contact details from the reported party so we can respond — those details are encrypted and never shown publicly. We do not sell your personal data.

Hashing, logs, and analytics

Identifiers are normalized (for example, lowercase email and E.164 phone format) and stored using a one-way HMAC hash — not as plain text in our primary database. We do not write raw email addresses or phone numbers to application logs, error reports, or marketing analytics. Site usage analytics (Google Tag Manager / GA4) run only if you choose Accept on our consent banner; those tools are configured not to receive identifiers from lookups or reports.

What is public vs private

Public lookup results show only a cautious status (such as reported count, under review, or unknown) — never report narratives, evidence, or who filed a report. Report details and reporter identities are visible only to administrators with a legitimate need. Dispute evidence and contact information are treated as sensitive and are never included in public search results.

Retention and your rights

Community flags can expire after a configurable period unless renewed by new qualifying reports. Dispute records and moderation audit logs are kept for accountability and legal defense. You may ask us to access or delete reports you submitted; deleting a report does not erase the immutable audit record of what happened. To make a request, email us at the address below.

Service providers

We use Google Firebase (authentication, database, hosting), Upstash (rate limiting and caching), and Google reCAPTCHA v3 through Firebase App Check to reduce abuse on lookups and reports. App Check may load a third-party script even when you decline marketing analytics — it is a security measure, not advertising. Google's handling of data from reCAPTCHA is described in Google's Privacy Policy. We choose providers that help us run the service securely; we do not authorize them to use your lookup data for their own marketing.

When data is unavailable

If we cannot reach our data stores or complete a lookup safely, we return “Unknown” rather than implying that an identifier has no reports. That fail-safe protects you from acting on a false negative.

Contact us

Questions about this policy or your data: [email protected]