Privacy policy
This page says what ScamSam stores, why, for how long, and who else gets to see it. It describes the service as it actually works.
The main thing first: submitted content is never stored
What you paste or forward — the suspicious message itself — is never persisted. It is handled in memory, shown to the language model, and discarded.
- For a check made in the browser, the result (verdict, reasons, advice — the reasons may quote the message) stays retrievable for 24 hours and is then purged. What remains is the verdict word and metadata.
- For a check made by mail the result is not stored at all — it exists only in the reply. The forwarded mail is deleted from the service's mailbox after the answer goes out.
- IP addresses are never written down — only a SHA-256 hash salted with a secret value, for the guests' daily cap.
Controller
The controller under the GDPR is the operator named in the legal notice. Data protection questions go to scamsam@grgmyr.com.
What is stored
| Data | What for | How long |
|---|---|---|
| Account: email address, password as a salted hash, language, default model, account type | Login, defaults, limits | Until the account is deleted |
| Two-factor secret, if enabled | Second factor at login | Until switched off or the account is deleted |
| Sessions: a hash of the session token, timestamps | Staying logged in; the token itself is never stored | Until expiry or sign-out |
| Check data: time, route (web or mail), model, verdict word, character count, token counts, cost | Your history, the limits, the cost budget | While the account exists; for guests anonymously via the IP hash |
| The full result of a web check (reasons and advice, possibly quoting the message) | Being able to reopen the result page | 24 hours, then purged |
| Salted hash of a guest's IP address | The daily cap for guests | As part of the check rows |
| Salted hash of the sender address of an unknown mail submission | So the "please register" pointer is sent exactly once; the address itself is never stored | Kept, as a hash |
| Rate-limit counters | Protection against overload and abuse | Hours |
Legal bases: contract or terms of use (Art. 6(1)(b) GDPR) for account, sessions and checks; legitimate interest (Art. 6(1)(f) GDPR, abuse prevention and cost control) for the hashes, limits and the cost log.
Where the checked content is sent
- Free model. Runs on a machine the operator owns; the content does not leave that network.
- Claude models. If a signed-in account picks a Claude model, the submitted content is transmitted to Anthropic PBC in the United States and processed there. That model cannot work without it. If you would rather not, choose the free model.
- Mail. Verification and reply mail goes through the operator's own mail server, not a sending service.
There are no analytics, no advertising networks, no external fonts and no embedded third-party content.
Cookies
Three cookies, all strictly necessary: one keeps you logged in
(HttpOnly, SameSite=Lax, Secure in
operation), one remembers the language, one the chosen appearance (light or
dark). No tracking cookie, so no consent banner.
Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection. A message to scamsam@grgmyr.com is enough. When an account is deleted, the account, its sessions and open verification links are removed; the check rows lose their link to the account and remain only as anonymous cost entries.
Complaints can be made to the Austrian data protection authority (www.dsb.gv.at).
Changes
When the service changes, this page changes with it. The version in force is always the one shown here.