Menu
Legal

Privacy Policy

How ScamVerify™ collects, uses, and protects your information across all verification channels.

Effective: March 7, 2026 | Last Updated: June 16, 2026

ScamVerify™ LLC ("we," "us," or "our") operates the ScamVerify.ai website and service (the "Service"), including Ava, your AI security analyst. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use the Service. By using the Service, you consent to the data practices described in this policy.

1. Information We Collect

1.1 Information You Provide Directly

  • Account Information: When you create an account, we collect your email address and display name. If you sign in with Google, we receive your name, email, and profile picture from Google.
  • Conversations with Ava: When you chat with your analyst, we store your messages and Ava's responses so she can continue an investigation and recall useful context next time. See Section 3 for how Ava's memory works and how to delete it.
  • Phone Numbers: When you use our phone number verification service, you submit phone numbers for analysis.
  • Website URLs: When you use our website verification service, you submit URLs for analysis.
  • Text Messages: When you use our text message analysis service, you paste text message content for analysis. We extract phone numbers and URLs from the text for verification.
  • Email Content: When you use our email analysis service, you paste email headers or body content for analysis. We extract sender information, embedded links, and other indicators.
  • Forwarded Emails: When you forward a suspicious email to scan@scamverify.ai, we receive the full email including sender address, subject, body content, headers, and any attachments. We extract the forwarded email content, analyze it for scam indicators, and send you a reply with the analysis results. The forwarded content is hashed for caching (so re-forwarding the same email does not re-run the analysis). We log the sender address, analysis results, and processing metadata. We do not use forwarded email content for marketing purposes.
  • Secondary Email Addresses: If you add secondary email addresses in Settings for email forwarding recognition, we store these addresses and associate them with your account. Secondary emails are verified via a confirmation link and are used solely to identify you when you forward emails to scan@scamverify.ai.
  • Document Images: When you use our document analysis service, you upload photos of documents (court notices, invoices, letters) for scam analysis. We retain the uploaded images in secure private storage to improve scam pattern detection and help protect other users.
  • QR Code Images: When you use our QR code verification service, you upload QR code images for decoding. The images are processed for decoding only and are not retained after processing.
  • Community Reports: If you submit a report about a phone number or other threat, we collect the report type, any comments you provide, and whether you received the communication.
  • Watchlist Data: If you add phone numbers to your watchlist, we store these numbers along with the risk score at the time you added them.
  • Contact Information: If you contact us, we collect your name, email, and message content.

1.2 Information Collected Automatically

  • Device Information: Browser type, operating system, and device identifiers.
  • Usage Data: Pages visited, time spent, click patterns, and feature usage.
  • IP Address: We collect and hash your IP address for rate limiting and fraud prevention. We do not store your raw IP address.
  • Cookies: We use essential cookies for site functionality. We also use cookies from analytics partners (see Section 7).
  • Session Data: Session tokens to maintain your login state.
  • Lookup History: When you are logged in, we store your verification history including the items searched, risk scores, and timestamps.

1.3 Information from Third Parties

  • Government Databases: We query FTC Do Not Call complaints and FCC consumer complaints (publicly available federal data).
  • Carrier and Telecom Data: Phone number carrier, line type, and caller ID information from our carrier-data providers.
  • Threat Intelligence: Phone reputation scores, robocall detection flags, domain risk data, and malware database matches from our threat-intelligence providers.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the analyst and our verification services across all channels
  • Power your conversations with Ava and let her recall useful context across sessions
  • Generate AI-powered risk scores and analysis narratives
  • Provide the family and multi-seat protection you have consented to
  • Display aggregated community reports and risk assessments
  • Authenticate your account and maintain your session
  • Process payments and manage subscriptions via Stripe
  • Send email notifications about watchlist changes and account activity
  • Prevent fraud, abuse, and duplicate submissions
  • Monitor usage patterns and improve service quality
  • Respond to your questions and support requests
  • Comply with legal obligations

3. Ava, AI Processing, and Memory

ScamVerify™ is built around Ava, your AI security analyst. Ava reviews phone numbers, websites, text messages, emails, documents, voicemails, and QR codes across seven channels, explains the risk in plain English, and can take protective actions that you confirm. Ava is an automated AI system, not a person.

3.1 AI Analysis

When you submit content for verification or ask Ava a question, the relevant data (such as phone numbers, complaint summaries, carrier information, URLs, message content, voicemail audio, or document and QR-code images) is processed by our AI providers to generate your analysis. For document and image analysis, uploads are processed by vision AI to extract entities such as addresses, official names, legal citations, and dollar amounts. AI-generated analysis is informational only, may be incomplete or inaccurate, and is not legal, financial, or professional advice. See our Terms of Use.

3.2 We Never Train On or Sell Your Data

ScamVerify™ does not use your submitted data or your conversations with Ava to train AI models, and we do not permit our AI providers to use your data for training. We do not sell your personal information. Our AI providers process your data under their commercial API terms, which prohibit using it to train their models.

3.3 Ava's Memory

So she can act as a personal analyst, Ava remembers durable, useful facts from your conversations, such as the kinds of scams aimed at you, entities you have checked, verdicts you have received, and recurring patterns across your history. Ava's memory is:

  • Sanitized: Ava's memory stores short, summarized facts, not raw sensitive data. It is designed not to retain full card numbers, Social Security numbers, or similar sensitive identifiers.
  • Private to you: your memory is scoped to your account and is never shared with other users.
  • Retained while your account is active: we keep Ava's memory so she can help you over time. There is no fixed expiration; it is retained until you delete it or delete your account.

You stay in control. Your conversation history is visible to you in the console, and deleting your account permanently and completely removes everything Ava has remembered about you, along with your conversations, threat profile, and related records. You can also download a copy of your account data (your lookup history, usage, and subscription details) at any time from Settings > Privacy & Data.

3.4 Family and Multi-Seat Protection

If you are on a Duo or Family plan, protection is directional and consent-based, and is for adults only. Joining a plan does not by itself let anyone act for you or see your activity. Each protective relationship is something you grant to a specific person and can revoke at any time:

  • You can let another member's Ava take help-only protective actions for you, such as blocking or reporting a number. This is a capability you grant, not visibility into your activity.
  • Separately, and off by default, you can let a member see the threat outcomes handled on your behalf (scams stopped or flagged for you) - never your searches, questions, verdicts, messages, or settings.

A protector can never see your private activity or change your account, even with your consent - those actions are never permitted. The person who pays for a plan is not automatically a protector of anyone.

3.5 Reporting to the FTC on Your Behalf

Ava can help you report fraud to the FTC. Filing a report on your behalf is turned off by default. When it is available, Ava will file only after you explicitly confirm the facts are true and authorize the filing, will use only the facts you provide (never invented details), and will include your email so the FTC confirms the report to you. Otherwise, Ava gives you a prefilled summary and the link to file it yourself at reportfraud.ftc.gov.

4. How We Share Your Information

We share your information only with the following categories of recipients, each under contract to use it solely to provide their function and never for their own purposes:

  • AI Providers: We send verification data and your messages to our AI providers so Ava can generate your analysis. They process data under their commercial API terms and do not use it to train models.
  • Payment Processor: Stripe processes your payment information. ScamVerify™ does not store credit card numbers. See Stripe's Privacy Policy.
  • Authentication Provider: Our authentication provider handles account sign-in and data storage. If you choose to sign in with Google, data is exchanged with Google for authentication.
  • Service Providers: We use third-party providers for carrier and telecom data, identity and address verification, threat intelligence, product analytics, error monitoring, and transactional email delivery (such as account verification and alerts). They receive only the data needed for their function.
  • Bot Protection: Our bot-protection provider, Cloudflare Turnstile, processes client-side signals (such as a hashed IP address, TLS fingerprint, and user-agent) to tell humans from bots. It does not use this data for advertising. See the Cloudflare Turnstile Privacy Addendum.
  • Government Databases: We query publicly available FTC and FCC complaint data. This does not involve sharing your personal information with those agencies.
  • Aggregated Data: We display aggregated, anonymized community report data publicly to help other users identify potential scams.
  • Legal Requirements: We may disclose information if required by law, regulation, or legal process.
  • Protection of Rights: We may disclose information to protect the rights, property, or safety of ScamVerify™ LLC, our users, or others.

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.

5. Data Retention

  • Verification data and community reports: Retained indefinitely to maintain our threat database and help protect future users.
  • Account data: Retained until you delete your account.
  • Ava's memory and conversation history: Retained while your account is active so Ava can help you over time. There is no fixed expiration; removed when you delete your account, or sooner on request.
  • Watchlist and lookup history: Retained until you delete them or delete your account.
  • Rate limiting data: Retained for 24 hours.
  • Payment and billing records: Retained for 7 years as required by tax and accounting regulations.
  • Document images: Uploaded document images are retained in secure private storage to enable scam pattern detection and near-duplicate matching. You may request deletion of your uploaded images by contacting us. QR code images are not retained.
  • Analytics data: Retained per our analytics provider's default retention policies.
  • Error tracking data: Retained per our error-monitoring provider's default retention policies (typically 90 days).

You may request deletion of specific data by contacting us. To delete your account and all associated data, go to Settings > Privacy & Data.

6. Your Privacy Rights

6.1 California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act and the California Privacy Rights Act:

  • Right to Know: You can request what personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties we share it with.
  • Right to Delete: You can request deletion of your personal information, subject to certain exceptions (such as data needed to complete a transaction, comply with legal obligations, or maintain our threat database).
  • Right to Correct: You can request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising.
  • Right to Limit Sensitive Personal Information: We collect limited sensitive personal information (account credentials). You may request limits on how we use this data.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.

How to exercise your rights: Submit a request through our contact form with the subject "Privacy & Data Deletion Request." We will verify your identity by confirming your email address. We will respond within 45 days. If we need additional time, we will notify you of the extension (up to an additional 45 days). You may also designate an authorized agent to submit requests on your behalf.

6.2 European Residents (GDPR)

If you are a resident of the European Economic Area or the United Kingdom, you have the right to:

  • Access your personal data
  • Correct inaccurate personal data
  • Request erasure of your personal data
  • Object to processing of your personal data
  • Data portability
  • Withdraw consent at any time
  • Lodge a complaint with a supervisory authority

Our legal basis for processing personal data includes: performance of a contract (providing the Service), legitimate interests (improving the Service, preventing fraud), consent (where applicable), and compliance with legal obligations.

6.3 Automated Decision-Making

ScamVerify™ uses automated systems, including AI models and algorithmic scoring, to generate risk scores and safety assessments. These automated decisions are informational only and do not produce legal or similarly significant effects. You have the right to request information about the logic involved in automated decision-making and to request human review of any automated assessment by contacting us.

6.4 Account Data Management

You can manage your data directly through your account:

  • View and edit your profile information in Settings
  • Clear your lookup history in Settings > Privacy & Data
  • Remove numbers from your watchlist
  • Delete your account and all associated data in Settings > Privacy & Data

7. Analytics

We use a privacy-focused product analytics provider to understand how visitors use our site and to improve the Service. For logged-in users, our analytics provider receives a pseudonymous user identifier to measure feature usage across sessions. For anonymous visitors, it collects aggregated data including page views, referral sources, browser type, and general location. We do not use this data for advertising. You can opt out of analytics cookies in Section 11 below, and we honor Global Privacy Control signals (Section 12).

8. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including encryption in transit (TLS/HTTPS), hashed IP addresses, secure session management, and access controls. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

9. Data Breach Notification

In the event of a data breach involving your personal information, we will notify affected users within 30 days of discovery as required by California Civil Code Section 1798.82. If more than 500 California residents are affected, we will also notify the California Attorney General within 15 days of notifying consumers. Notifications will include a description of what happened, what information was involved, what we are doing about it, what you can do, and how to contact us for more information.

10. International Data Transfers

Your data is stored and processed in the United States. If you are accessing the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer. Where required by applicable law (such as GDPR), we rely on standard contractual clauses or other appropriate legal mechanisms for international data transfers.

11. Cookies and Tracking Technologies

We use the following types of cookies:

  • Essential cookies: Required for authentication, session management, and core functionality. These cannot be disabled.
  • Analytics cookies: Our analytics provider uses cookies to measure usage patterns and help us improve the Service.

You can manage cookies through your browser settings. Disabling essential cookies may prevent the Service from functioning correctly.

12. Do Not Track and Global Privacy Control

We do not track users across third-party websites ourselves. We do not use advertising cookies or serve advertisements on our website.

We honor Global Privacy Control (GPC) signals. If your browser sends a GPC signal, we automatically disable analytics cookies. You can also manage analytics cookies manually in Section 12 above. For more information about GPC, visit globalprivacycontrol.org.

13. Children's Privacy

Our Service is not directed to individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If we learn we have collected personal information from a child under 16, we will delete that information promptly. If you believe a child under 16 has provided us with personal information, please contact us.

14. Third-Party Services

Our Service relies on third-party providers in the following categories, each governed by its own privacy policy:

  • AI providers - generating Ava's analysis (under terms that prohibit training on your data)
  • Payment processing - Stripe ( Privacy Policy)
  • Carrier and telecom data - carrier, line type, and caller ID verification
  • Identity and address verification - validating entities extracted from documents
  • Threat intelligence - phone, domain, and malicious-URL reputation data
  • Authentication and sign-in - account authentication, including Google OAuth if you choose it ( Google Privacy Policy)
  • Bot protection - Cloudflare Turnstile ( Privacy Addendum)
  • Product analytics and error monitoring
  • Transactional email delivery

We also access publicly available government databases:

  • FTC Do Not Call Complaints: Public consumer complaint data from the Federal Trade Commission
  • FCC Consumer Complaints: Public complaint data from the Federal Communications Commission

Accessing these databases does not involve sharing your personal information with these organizations. We query their public data to enhance threat detection.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last Updated" date at the top of this page and, for significant changes, by sending a notice to the email address associated with your account. We encourage you to review this Privacy Policy periodically.

16. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how your data is handled, please contact us.

ScamVerify™ LLC
115 W. California Blvd #9300
Pasadena, CA 91105
United States