Privacy Policy

Last Updated: December 31, 2025

1. Introduction

The Fraud Codex ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our scam detection service.

This policy complies with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

2. Information We Collect

2.1 Information You Provide

  • Email Address: When you sign up for updates via our newsletter
  • Scan Inputs: URLs, phone numbers, email addresses, crypto addresses, and files you submit for scanning
  • Contact Information: If you email us with stories or questions

2.2 Automatically Collected Information

  • Usage Data: IP address, browser type, device information, pages visited
  • Cookies: Small data files stored on your device (see Cookie Policy below)
  • Scan Metadata: Timestamp, scan results, API responses

3. How We Use Your Information

  • To provide and improve our scam detection service
  • To send you updates about new features (if you subscribed)
  • To analyze usage patterns and improve accuracy
  • To comply with legal obligations
  • To prevent fraud and abuse of our service
  • To respond to your inquiries and support requests

4. Legal Basis for Processing (GDPR)

We process your personal data based on:

  • Consent: When you sign up for our newsletter
  • Legitimate Interest: To provide and improve our service
  • Legal Obligation: To comply with applicable laws
  • Performance of Contract: To deliver the scam detection service you requested

5. Data Sharing and Disclosure

We share your information with:

  • Service Providers: Anthropic (AI), VirusTotal, URLScan.io, Google Safe Browsing, Ahmia.fi
  • Hosting Providers: Vercel for website hosting
  • Analytics: To understand usage patterns (anonymized)
  • Law Enforcement: When required by law or to prevent fraud

We do NOT sell your personal data to third parties.

6. Your Rights

6.1 GDPR Rights (EU Users)

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate data
  • Right to Erasure: Request deletion of your data
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to processing based on legitimate interest
  • Right to Withdraw Consent: Unsubscribe from newsletters anytime

6.2 CCPA Rights (California Users)

  • Right to Know: What personal information we collect and how we use it
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt-out of sale of personal information (we don't sell data)
  • Right to Non-Discrimination: Equal service regardless of privacy choices

To exercise these rights, contact us at: privacy@fraudcodex.com

7. Cookies

We use cookies for:

  • Essential Cookies: Required for the website to function
  • Analytics Cookies: To understand how visitors use our site
  • Preference Cookies: To remember your settings

You can control cookies through our cookie consent banner and your browser settings.

8. Data Retention

  • Newsletter Emails: Until you unsubscribe
  • Scan Data: Temporarily cached, typically deleted within 24 hours
  • Analytics: Aggregated data retained for up to 2 years
  • Support Emails: Retained for 3 years for customer service

9. Data Security

We implement industry-standard security measures:

  • HTTPS encryption for all data transmission
  • Secure API connections to third-party services
  • Regular security audits and updates
  • Limited access to personal data by authorized personnel only

However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

10. International Data Transfers

Your data may be transferred to and processed in countries outside your jurisdiction, including the United States. We ensure appropriate safeguards are in place, including:

  • Standard contractual clauses approved by the European Commission
  • Privacy Shield frameworks where applicable
  • Adequacy decisions by relevant authorities

11. Children's Privacy

Our service is not intended for children under 13 (or 16 in the EU). We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us immediately.

12. Third-Party Services

Our service uses the following third-party APIs:

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last Updated" date.

14. Contact Us

For privacy-related questions or to exercise your rights:

Email: privacy@fraudcodex.com

Data Protection Officer: [Your Name/Company]

Address: [Your Business Address]

15. Supervisory Authority

If you are in the EU/EEA and believe we have not addressed your concerns, you have the right to lodge a complaint with your local data protection authority.