ScamWarning Privacy Policy
Last updated: April 25, 2026
ScamWarning is a free, open-source Chrome extension by MCPCIO (EffinSoftware.com, Inc.). This policy explains exactly what data ScamWarning collects, how it is used, and what it does not collect.
The short version: ScamWarning analyzes web pages for scam indicators. Most analysis happens locally in your browser. When our API is used, only the minimum data needed for threat assessment is transmitted. We never collect personal information, browsing history, or tracking data. The extension is fully open source for verification.
1. What Data We Collect
When ScamWarning sends data to our assessment API, the following information may be transmitted:
| Data | When Sent | Purpose |
|---|---|---|
| Domain name (e.g., "example.com") | When API assessment is triggered | Look up cached threat assessment |
| Page title and meta description | When API assessment is triggered | Context for threat analysis |
| Extracted threat signal counts | When API assessment is triggered | Structured indicators (not raw text) |
| Page content (first 2,000 characters) | Only when local analysis detects threats AND no cached result exists | AI-powered threat assessment for novel pages |
| Anonymous install ID | With every API request | Rate limiting only (not linked to identity) |
2. What We Do NOT Collect
- Browsing history — We do not record, store, or transmit which pages you visit or when
- Personal information — No names, email addresses, phone numbers, or account information
- Credentials — No passwords, authentication tokens, cookies, or session data
- Form data — We never read or transmit data you enter into forms on any website
- IP addresses — Our servers do not log IP addresses beyond in-memory rate limiting
- Location data — No geographic or physical location information
- Financial data — No payment, banking, or credit card information
3. How Data Is Used
Data transmitted to our API is used exclusively for:
- Threat assessment — Determining if a web page contains scam, phishing, or fraud indicators
- Knowledge base improvement — Assessed pages contribute to our anonymous threat database, improving future assessments for all users
- Rate limiting — The anonymous install ID prevents abuse of our free API
Data is never used for advertising, user profiling, data brokerage, credit assessment, or any purpose unrelated to scam detection.
4. Local-First Architecture
The majority of ScamWarning's analysis happens locally in your browser:
- Local pattern matching runs on every page without any network call
- Pages with no suspicious patterns are marked safe without contacting our servers
- Assessment results are cached locally for 1 hour — repeat visits use the cache with zero network calls
- In "Click to Scan" mode (the default), no data is sent until you explicitly click the ScamWarning icon
5. Data Retention
- Local cache: 1 hour, stored in your browser via Chrome's storage API
- Server-side cache: 1 hour per domain assessment (Cloudflare KV)
- Threat database: Anonymized assessment results are stored indefinitely to improve the knowledge base. These contain no user-identifying information.
- Rate limit counters: Reset daily (24-hour TTL)
6. Third-Party Services
ScamWarning uses the following third-party services:
- Cloudflare Workers — Hosts our assessment API at the edge for fast response times. Subject to Cloudflare's Privacy Policy.
- Anthropic (Claude AI) — Provides AI-powered threat assessment for novel pages. Page content sent for assessment is not used by Anthropic for model training. Subject to Anthropic's Privacy Policy.
No other third-party services, analytics, telemetry, or tracking tools are used.
7. User Corrections
When you submit a correction ("This assessment is wrong"), the following is stored:
- The domain name
- The corrected risk level
- Your optional note (if provided)
Corrections are anonymous — they are not linked to your install ID, identity, or browsing history.
8. Your Rights
- Transparency: ScamWarning is open source. You can read every line of code to verify these claims.
- Control: You choose between Click-to-Scan (default, no automatic data transmission) and Always-On mode.
- Whitelist: Add any domain to your trusted list to skip assessment entirely.
- Uninstall: Removing the extension deletes all locally stored data immediately. No server-side data is linked to your identity.
9. Children's Privacy
ScamWarning does not knowingly collect any personal information from anyone, including children under 13. The extension does not require an account, login, or any personal information to use.
10. Changes to This Policy
We will update this page if our practices change. The "Last updated" date at the top reflects the most recent revision. Material changes will be noted in the extension's changelog.
ScamWarning's use and transfer to any other app of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
11. Contact
For questions about this privacy policy or ScamWarning:
EffinSoftware.com, Inc. (MCPCIO)
2232 Dell Range Blvd, Suite 245-3069
Cheyenne, WY 82801
[email protected]