ScamSift
Privacy Policy
Last updated 7 September 2026
ScamSift cannot listen to your calls, access your microphone, view video chats, or read your inbox, contacts, call logs, email, or notifications. It processes only text, screenshots, or images that you deliberately paste, select, or share for a check.
1. Content you submit
Submitted text or image content is sent over an encrypted connection to our analysis service and Google Gemini after you confirm processing. Our app and API are designed not to write the original submitted content to our database, application logs, or analytics.
Google's Gemini API documentation states that prompts and responses may be retained for up to 55 days for abuse monitoring. Google states that paid-service prompts and responses are not used to improve its products. An approved Zero Data Retention request sanitizes content and identifiable metadata before abuse-monitoring logs are written.
ScamSift's active Gemini key is on Paid Tier 1 and optional project logging is disabled. ScamSift does not use Gemini Search or Maps grounding, the stateful Interactions API, the Live API, File API storage, explicit context caching, saved datasets, or feedback sharing. We do not claim Zero Data Retention because project approval has not been verified. See Google's Zero Data Retention documentation, abuse-monitoring policy, logging and dataset documentation, and Gemini API terms.
2. Account and service data
We process account, installation, and service records needed to operate sign-in, quotas, account deletion, Circle sharing you choose to initiate, and analysis-output reporting. We also retain usage counts, purchase and entitlement information supplied by RevenueCat and the stores, and user-submitted analysis-output reports. A report includes verdict, threat level, and the reason you provide—not the original content you submitted for a check.
Private scan history contains at most 12 compact result summaries encrypted on your device, not the submitted message or screenshot. Circle phone numbers used to address a message remain in encrypted device storage and are not uploaded to our service.
3. Optional Safety Alerts and Community Signals
These features apply when available in your app version. They are optional; you can use the scam checker without enabling notifications or submitting a community report.
Safety Alerts
If you turn on Safety Alerts, we store an installation-linked push token, your selected alert region and device language/locale in Supabase. Expo and Google Firebase Cloud Messaging deliver source-linked educational updates. Notification content contains a reviewed title, summary and alert identifier, never the suspicious messages or screenshots you submit for analysis. The region is selected by you; we do not collect GPS location.
Turn alerts off in Scam safety alerts to delete this installation's push subscription. It is also removed with the associated installation/account deletion or when the notification provider reports an unregistered token. Alerts are not real-time monitoring and are not a guarantee that a communication is safe.
Community Signals
You may share an enumerated scam pattern, contact channel and broad region. The report is linked to your random installation ID for abuse prevention and deletion, so it is not anonymous. This form accepts no message content, personal story, names, phone numbers, account details or links.
Reports require moderation. Only combined totals from the last 30 days with at least five approved matching reports are shown; no individual report is published. Rejected reports are removed after 30 days and all reports after 90 days. You can remove linked reports through Settings → Delete my data or the verified external deletion process.
4. Providers
| Provider | Purpose | Data involved |
|---|---|---|
| Google Gemini | Analysis | Submitted content and request metadata under Google's terms |
| RevenueCat and Google Play / Apple | Subscriptions and billing | Account, installation, purchase identifiers, and store transaction data |
| Expo and Google Firebase Cloud Messaging | Optional Safety Alert delivery | Push token, reviewed notification title/body, alert identifier and delivery metadata; no submitted scam messages or Community Signal reports |
| Supabase and hosting | Service operation | Account, installation, usage, deletion, Circle, analysis-output reports, opted-in push subscriptions, curated alerts and structured Community Signal records |
5. What ScamSift cannot access or collect
ScamSift cannot listen to calls, access your microphone, view video chats, monitor conversations in real time, or read your SMS or email inbox, contacts, call logs, other apps' notifications, or unselected device files. Permission to deliver our optional alerts does not let us read other apps' notifications. We do not collect GPS location, advertising identifiers, or payment-card details, and we do not sell submitted data.
6. Deletion and contact
You can delete your account and associated service data in the app after confirmation. For an authenticated account, this removes linked installation records and associated ScamSift service records, including push subscriptions and Community Signal reports. This does not cancel an app-store subscription. For support or an external deletion request, use the account-deletion page or email support@limocontech.com.