Privacy Policy
Updated September 6, 2026
Information you provide
When you run a check, the words, image, or short audio recording you submit is processed to identify possible fraud. Do not submit passwords, security codes, full account numbers, Social Security numbers, or other secrets.
What stays on your iPhone
Your saved check summaries and trusted-person details are stored locally on your device. They are not uploaded to create an account. Temporary files are used to record and play audio. In the updated app, input recordings are removed after being read for sending, including failed reads; requests retry from memory. Playback audio files are removed when playback ends or is interrupted, when replaced, when the screen closes, or when the app goes into the background. Replaying a message may reuse audio held in memory for that screen. Selected-image cache copies are removed when image review closes; original photos are not deleted. Startup and Delete all data retry cleanup of leftover app-owned files, including those from older versions or interrupted sessions. An operating-system or storage failure can delay cleanup until a later attempt. Saved check summaries remain until you delete them or they leave the app's 30-check history limit.
Service providers
With your permission, OpenAI processes submitted text, audio, photos, and QR images to provide AI analysis and spoken answers. OpenAI does not use API inputs and outputs to train its models by default. It may retain content for up to 30 days for abuse monitoring, or longer when required by law or necessary for safety; some features have additional retention rules. We do not claim Zero Data Retention. Cloudflare hosts our service and processes network and security data such as IP addresses and request logs. Supabase stores the operational records described below. RevenueCat and Apple process a random app user identifier and purchase information to manage subscriptions.
What our service retains
Our application service processes raw recordings and submitted scam content for the request without writing that content to our database or application logs. This does not override OpenAI's retention. Content-free API-request and RevenueCat webhook-event records become eligible for deletion after 90 days. A daily cleanup normally removes eligible records at its next successful run. Installation records (random support identifier, one-way session-token hash) and related quota and cached subscription-access records remain while the installation is active and become eligible for cleanup after 180 days of inactivity. An authenticated Delete all data request removes the installation and its related service records earlier. Cleanup failures can delay removal until a successful retry.
Provider records and backups
Deleting data in ScamAlert does not cancel a subscription or automatically erase records retained by OpenAI, Apple, RevenueCat, Cloudflare, or provider backups. Those records follow the providers' retention, security, transaction, and legal requirements. Backup copies may remain until their normal expiration. Contact us for help with a data request; we will explain what we can remove and any required retention.
Sharing and selling
We do not sell personal information. We share information only with service providers needed to run the app, when you choose to share a result, or when required by law.
Your choices
The updated app asks for AI-sharing permission before any input method sends check content to OpenAI. You may decline, type instead of speaking, or skip adding a trusted person. Open Need help → Privacy and your data to turn off AI sharing or choose Delete all data, even with no saved checks. On the first setup screen, use Privacy. Turning off sharing stops new AI checks and cancels pending app requests; it cannot retract content already sent. You can still read saved results and local help. Older app versions may show deletion under Previous checks → See all; update the app for the new controls. Manage or cancel subscription renewal separately through Apple.
Contact
Questions or requests: support@getscamalert.com.