Privacy Policy

Effective date: August 6, 2026

Scambook is operated by Webair AI LLC("Webair AI," "we," "us," or "our"), a limited liability company located in New York, United States. This Privacy Policy describes what information we collect through the Scambook website and the Scambook iOS application (together, the "Service"), how we collect it, how we use it, who we share it with, how long we keep it, and the choices and rights you have — including how to request deletion of your data or revoke consent at any time.

The short version: we designed Scambook so that checking a message requires as little personal information as possible. Content you submit for a check is shared with one third-party AI service — OpenAI — solely to generate your scam analysis, and only after you have given your permission (Section 6). Scambook itself does not store the messages and screenshots you check — they are analyzed and discarded, and they are never sold or used to build a profile of you. What we do retain — pseudonymized safety signals such as a scammer's phone number — is described in Section 4.

1. Information we collect and how we collect it

We collect only the information needed to operate the Service:

  • Content you submit for analysis.When you paste a message, phone number, email address, or link, or upload or share a screenshot, that content is transmitted to our servers so our AI can analyze it. This content may incidentally contain personal information (for example, a phone number inside a text message, or a photo of a person's face inside a screenshot — see Section 5). We treat all submitted content as sensitive. Content is collected only when you actively choose to submit it for a check; we never access your messages, photo library, or camera in the background. Before submitting, please redact or crop out sensitive information about other people that is not needed for the scam check — for example, unrelated faces, account numbers, ID documents, or health information belonging to third parties. By submitting content, you confirm that you have the right and authority to submit it, including any third-party information it contains.
  • Waitlist and contact information. If you join our waitlist or contact us, we collect your email address and any information you choose to include in your message.
  • Account information (app). If you create a Scambook account in the app, we collect your email address, your name if you provide it, a user ID we assign to your account, and basic account settings.
  • Subscription and purchase history. Purchases of Scambook Pro are processed by Apple through your Apple Account. We receive confirmation of your subscription status and purchase history (which plan you bought and when) from Apple, but we never receive or store your payment card details.
  • Usage, device, and product-interaction data. Standard technical information such as device type and device identifiers, operating system version, app version, crash logs, and product interaction events (for example, that a check was performed or a screen was viewed), used to keep the Service reliable and secure. This data is linked to your user ID when you have an account.
  • Pseudonymized safety signals (blocklist data).When a check identifies scam indicators, we retain safety signals — such as a sender's phone number or email address that was flagged, a malicious link or domain, or the structural pattern of a scam script. These signals are separated from you (the submitting user) and from the surrounding message content. Because a phone number, email address, or URL can identify the person or business that uses it, we treat these signals as pseudonymized personal information — not anonymous data — and handle them as described in Section 4.

These categories correspond to the data types disclosed on our App Store privacy label: contact information (name, email address), identifiers (user ID, device ID), purchase history, product interaction, and user content submitted for analysis. Data linked to your identity on the label (such as your user ID, device ID, email, name, purchase history, and product interaction) is limited to account, subscription, and diagnostic purposes — never the content of your checks.

2. How we use your information

  • To analyze the content you submit and return a scam verdict — the core function of the Service.
  • To maintain and improve our scam-detection database using pseudonymized safety signals (Section 4), which helps protect all users.
  • To operate, secure, debug, and improve the Service.
  • To manage your waitlist spot, account, and subscription, and to respond when you contact us.
  • To send you service communications (such as launch notifications you signed up for). Marketing emails always include an unsubscribe link.
  • To comply with legal obligations.

We do not sell your personal information, and we do not use the content of your checked messages for advertising. We do not use your submitted content to train third-party AI models.

3. What happens to messages and screenshots you check

Submitted content is processed in memory on Scambook's systems to produce your verdict and is then discarded — Scambook does not write it to a database or persistent storage, and we do not build a profile of you from the messages you check. (Our AI provider's own, separate API retention is described in Section 6.) What Scambook keeps is limited to the pseudonymized safety signals described in Section 4 — for example, that a particular phone number sent a known scam script — retained because they protect other users from the same scammer.

4. Retained safety signals: legal basis, retention, and disputes

This section explains exactly how we handle the safety signals we retain from checks that identify scam indicators.

  • What is retained. Flagged sender identifiers (phone numbers, email addresses), flagged links and domains, the scam category and structural pattern detected, and the date of detection. These records identify the suspected scammer's contact points — they are stored separately from your account, are not linked to your user ID, and do not include the surrounding message content you submitted.
  • Why we call it pseudonymized, not anonymized. A phone number, email address, or URL may identify the person or business that uses it. We therefore treat these signals as personal information subject to this policy, with the protections described here — we do not claim they are anonymous.
  • Legal basis. We retain these signals on the basis of our legitimate interest — and the legitimate interest of all Scambook users — in preventing fraud and protecting people from scams (Article 6(1)(f) GDPR where it applies), and as permitted by applicable U.S. law for fraud-prevention and security purposes.
  • Access controls. Safety-signal data is stored in access-controlled systems. Access is restricted to authorized personnel who need it to operate the Service, and administrative access is authenticated and logged.
  • Retention rationale and review. Signals are retained for as long as they serve fraud prevention. We periodically review the database and remove signals that are stale, that no longer show scam activity, or that are contradicted by newer evidence.
  • Correction, appeal, and deletion. If you believe your phone number, email address, website, or business has been flagged in error, contact us at hello@webairai.com with the flagged identifier and any supporting information. We will review the record, respond within 30 days, and correct or delete signals that we cannot substantiate. If you disagree with our decision, you may appeal by replying to our response, and a different reviewer will re-examine the record.

5. Face data

Scambook does not perform facial recognition and does not collect biometric data. The app does not scan, detect, map, measure, or identify faces; it does not create faceprints, facial geometry, biometric templates, or any other biometric identifiers; and it does not use face data to identify you or anyone else. We do not access Face ID or any data derived from it — Face ID authentication, if you enable it on your device, is handled entirely by Apple on your device and is never available to us.

The only way an image of a face can reach the Service is incidentally: if a screenshot you choose to submit for a scam check happens to contain a photo of a person (for example, a screenshot of a dating-app profile used in a romance scam). Where a face or other sensitive third-party information is not needed for the scam check, please crop or redact it before submitting. Such images are treated exactly like all other submitted content:

  • Collection. We collect images only when you actively select and submit a screenshot for analysis. We never access your camera or photo library in the background.
  • Use. The image is analyzed solely to assess scam risk (for example, reading the text of a suspicious message shown in the screenshot). Faces appearing in an image are not analyzed, extracted, or processed as biometric data.
  • Sharing. With your permission (Section 6), the submitted image is sent to OpenAI to generate the scam analysis. It is not shared with any other third party, and OpenAI does not use it to train its models.
  • Storage. The image is processed in memory on our servers in the United States. It is never written to a database or persistent storage by Scambook.
  • Retention and deletion.Scambook discards the image immediately after the analysis completes — our retention is zero, so no separate deletion step is required on our side. OpenAI's own, separate API retention window is described in Section 6.

6. Sharing with a third-party AI service, and your permission

Scambook uses one third-party AI service to power its analysis: OpenAI (OpenAI, L.L.C., headquartered in San Francisco, California, USA).

  • What is sent.Only the content you submit for a check — the pasted message text, phone number, email address, or link, or the screenshot you selected — is sent to OpenAI's API to generate your scam analysis. We do not send your name, email address, account information, device identifiers, contacts, location, or any other data about you.
  • Who it is sent to. OpenAI, and only OpenAI. No other third-party AI service receives your content.
  • Your permission. The app asks for your explicit consent before any content is sent to OpenAI: you are shown a clear notice explaining what will be sent and to whom, and no content is transmitted unless you agree. Each check is also initiated by you — nothing is sent automatically or in the background. You can revoke consent at any time (Section 9), after which no further content will be shared.
  • OpenAI's own retention (separate from ours).Scambook's zero-retention practice (Section 3) describes our systems only. OpenAI processes submitted content under its API business terms, and under OpenAI's standard API data policy it may retain API inputs and outputs for up to 30 days to monitor for abuse and misuse, after which they are deleted unless OpenAI is legally required to keep them. OpenAI does not use content submitted through its API to train its models. We have confirmed that OpenAI provides the same or equal protection of your data as described in this policy.

7. Other service providers and disclosures

Beyond OpenAI, we share data only with service providers that help us operate the Service, and only to the extent necessary. We confirm that these providers offer the same or equal protection of user data as described in this policy, and we require this contractually:

  • Vercel (hosting). Our website and API are hosted on Vercel infrastructure in the United States.
  • Apple (payments).In-app purchases and subscriptions are processed by Apple. Apple's handling of your payment information is governed by Apple's own privacy policy.

We may also disclose information if required by law, to protect the rights and safety of our users, or as part of a corporate transaction (in which case this policy will continue to apply to previously collected data).

8. Data retention

  • Checked messages and screenshots(including any images of faces incidentally contained in them — see Section 5): processed and discarded by Scambook; not retained by us after analysis completes. OpenAI's separate API retention window is described in Section 6.
  • Pseudonymized safety signals: retained for as long as they serve fraud prevention, subject to the periodic review, correction, and deletion process described in Section 4.
  • Waitlist and account data: retained until you delete your account or ask us to remove you, after which it is deleted within 30 days.
  • Usage and crash data: retained for up to 12 months, then deleted or aggregated.

9. Your rights: deletion, access, and revoking consent

You are in control of your data. At any time, you may:

  • Delete your account. If the app supports account creation, it also supports account deletion from within the app (Settings → Account → Delete Account). Deleting your account removes your personal information from our systems within 30 days.
  • Request deletion or a copy of your data. Email us at hello@webairai.com and we will respond within 30 days.
  • Dispute a flagged number, address, or website. If you believe an identifier associated with you was flagged in error, use the correction and appeal process in Section 4.
  • Revoke consent.You may withdraw consent to processing — including consent to sharing submitted content with OpenAI (Section 6) — at any time in the app's settings, by deleting your account, or by contacting us. Revoking consent does not affect processing that occurred before revocation.
  • Unsubscribe. Every marketing email includes a one-click unsubscribe link.

Depending on where you live (including under the New York SHIELD Act, the California Consumer Privacy Act, and the EU/UK GDPR where applicable), you may have additional rights such as access, correction, portability, objection to processing based on legitimate interest, and non-discrimination for exercising your rights. We honor these requests regardless of where you live.

10. Tracking and advertising

Scambook does not track you across apps and websites owned by other companies, does not serve third-party advertising, and does not use your data for targeted advertising. Because we do not track, the iOS app does not need to request App Tracking Transparency permission.

11. Security

All data is encrypted in transit using TLS. Access to production systems is restricted and logged. No method of transmission or storage is 100% secure, but we design for the minimum possible data footprint — the most sensitive thing you give us, the message you check, is not stored at all.

12. Children's privacy and age requirement

You must be at least 13 years old to use the Service, and the app asks you to confirm this during onboarding. The App Store content rating (such as 4+) describes the app's content only — it is not an age gate and does not change the 13+ eligibility requirement. The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us at hello@webairai.com and we will delete it promptly.

13. International users

The Service is operated from the United States. If you use it from outside the U.S., your information will be processed in the U.S. under this policy.

14. Changes to this policy

We may update this policy from time to time. Material changes will be announced on this page with an updated effective date, and — where required — through the app or by email. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

15. Contact us

Webair AI LLC
New York, United States
Email: hello@webairai.com

See also our Terms & Conditions.

Scambook
ANALYZE. DETECT. STAY SAFE.

The easiest way to answer one question: is this a scam?

© 2026 Scambook. All rights reserved.Scambook gives guidance, not legal or financial advice.