Privacy Policy
Last updated: 18 September 2026 (version 1.1.0, which adds subscriptions)
- The pages you visit never leave your device. ShieldScam scans page text inside your browser and discards it.
- To run your subscription we keep your email address and your subscription status. Stripe handles all payments; we never see your card.
- We don't sell or share your data. No ads, no analytics, no tracking.
What stays on your device
To warn you about scams, ShieldScam reads the visible text of the pages you visit, in your browser's memory. It matches that text against a catalogue of scam patterns that ships inside the extension, scores it locally, and then discards it. Page text, the addresses of pages you visit, and scan results are never sent to us or anyone else.
ShieldScam doesn't read passwords, form fields or anything you type: input and text boxes are excluded from scanning.
This is enforced in the code, not just promised. The only part of the extension that can make network requests is its license module, which is never loaded into web pages and can reach only our license server. An automated check blocks any release that breaks either rule.
Stored on your device, in the browser's local extension storage: your settings (on/off, sensitivity, disabled categories, muted sites), and your sign-in token with the last subscription status we received. Uninstalling ShieldScam deletes all of it.
What we collect, and why
| Data | Why | Where it lives |
|---|---|---|
| Email address | Your account: sending sign-in codes, and matching you to your Stripe subscription | our license server |
| Subscription status and dates (trial end, renewal, cancellation) | Deciding whether ShieldScam should be active | our license server (copied from Stripe) |
| Stripe customer ID | Linking your account to Stripe | our license server |
| Device sign-ins (a hashed token, a label such as "Chrome on Windows", sign-in and last-seen times) | Keeping you signed in; limiting an account to 3 devices | our license server |
| IP address in request logs | Security and abuse prevention (rate limiting sign-in attempts) | rotating server logs; the oldest entries are overwritten automatically |
Sign-in codes and device tokens are stored only as one-way hashes.
Payments
Payments are processed by Stripe. Your card details go straight to Stripe and never reach ShieldScam. Stripe handles your subscription, renewals, receipts and invoices under its own privacy policy.
Sharing
We share data only with the services needed to run ShieldScam: Stripe, for payments and subscription management, and our email provider, to deliver your sign-in codes. We don't sell your data, and we don't use it for advertising, profiling, or anything unrelated to providing ShieldScam.
How long we keep it
We keep your account while you have a subscription, and for up to 12 months after it ends so you can resubscribe and sign in again. After that it's deleted automatically, apart from records Stripe or the law requires to be kept (such as invoices). You can ask us to delete your account at any time.
Your choices
- Manage or cancel your subscription: the popup's Manage subscription button opens Stripe's secure customer portal.
- Sign out a device: the popup's Sign out button.
- Access or delete your data: email us at the address below.
Children
ShieldScam isn't directed at children under 13, and we don't knowingly collect their data.
Changes
If this policy changes, we'll update it here and change the "last updated" date. Significant changes will also be announced on the extension's welcome page.
Contact
Privacy questions and data requests: razaqnadim04@gmail.com.