Privacy Policy
Last updated: January 1, 2026
Our Privacy Commitment
At SpamShield, we are committed to protecting your privacy and ensuring the security of your personal information. This privacy policy explains how we handle data when you use our SMS scam detection service.
Legal Basis for Processing (GDPR)
Legitimate Interest — To provide scam detection services
Performance of Contract — To deliver the Service you requested
Legal Obligation — To comply with applicable laws
Consent — For optional features and marketing
Information We Process
Messages You Submit
- •Text content of SMS messages you choose to analyze
- •Images of SMS messages you upload (text extraction only)
- •Basic metadata (timestamp, processing time)
- •Extracted elements: URLs, phone numbers, brand names (threat detection only)
Message content is automatically deleted within 24 hours.
Technical Information
- •Browser type, version, and user agent
- •Device type and operating system
- •IP address (for rate limiting, deleted after 7 days)
- •General location (country/region level only)
Information We Do Not Collect
- •Your name, email address, or phone number
- •Personal account information or precise location data
- •Contact lists or address books
How We Use Information
Analysis & Protection
- Detect spam and scam patterns
- Provide safety recommendations
- Improve detection accuracy
Service Improvement
- Enhance user experience
- Fix bugs and errors
- Develop new features
Data Retention & Security
Message content is processed temporarily and deleted within 24 hours. We do not build permanent databases of user messages.
- •All data encrypted using HTTPS/TLS
- •Server access restricted and monitored
- •Regular security audits
- •No third-party access to message content
Your Privacy Rights
GDPR (EU/EEA/UK)
- Access, rectification, erasure
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent
CCPA/CPRA (California)
- Know what data is collected
- Delete personal information
- Opt-out of sale/sharing
- Limit sensitive data use
- Non-discrimination
Contact privacy@spamshield.tech to exercise your rights. We respond within 30 days.
Third-Party Services
We do not sell or share your personal information for marketing.
Infrastructure
Vercel (hosting), Supabase (database), Cloudflare (CDN/security)
Analysis
OpenAI (LLM analysis), Tesseract.js (OCR, runs locally in browser)
Analytics
Vercel Analytics (privacy-focused, no cookies, GDPR compliant)
Children's Privacy
Not directed to children under 16. Contact privacy@spamshield.tech with concerns.
Contact Us
Privacy — privacy@spamshield.tech
DPO — dpo@spamshield.tech
We typically respond within 2-3 business days.