Legal

Privacy Policy

Last updated: 20 August 2026

ScamFendr helps UK fraud victims build reimbursement claims, and helps anyone check a business against the regulatory registers before sending money. You can use it through this website or through our Telegram bot. Because our users have often just been through something distressing, we hold ourselves to a simple standard: collect the minimum, explain everything, sell nothing.

Who we are

ScamFendr ("we", "us") operates scamfendr.uk. We are the data controller for the personal data described in this policy. Contact: hello@scamfendr.uk.

What we collect, and why

Your email address — stored only as a keyed one-way hash. When you sign in we send a 6-digit code to your email. We store a keyed hash of your address (HMAC-SHA256), not the address itself, and the key is held outside the database. Someone who obtained a copy of our database could not work out which email addresses are in it. We never use your address for marketing.

To be precise, because the distinction matters: this is not the same as us having no record of you. If someone held both the database and the key, the hash would identify you — a plain hash of an email is guessable, which is why the key exists. We treat these hashes as personal data and they are covered by your right to erasure below.

Your case details. When you build a case we store what you tell us: the timeline of the scam, amounts lost, payment methods, and contact details of the scammer (phone numbers, emails, websites, names they used). This is the entire point of the product — we use it to generate your Report Fraud report, bank complaint letter, and Financial Ombudsman referral.

Evidence you upload. Screenshots and documents you attach to your case are stored encrypted at rest and linked only to your case.

Firm checks. When you search on our Check a business page, we check the name against the FCA register and warning list, Companies House, and HMRC's supervised business register. The Companies House check sends your search term to Companies House in real time; the other two are checked against data we already hold. We cache the result (the business name and its register status) so the next person's check is faster. Searches are not attached to your account or used to build a profile of you. Two things do happen that we want to be precise about: if a check fails, the search term appears in our server error logs, and we hold caller IP addresses briefly in memory to stop the page being abused.

Telegram bot. If you use our Telegram bot, the messages and images you send are processed to classify the scam risk. Personal identifiers are stripped from the text before we store it, and we store the stripped text together with the classifier's output against your session. Use /private in the bot to have nothing stored at all. Note that Telegram is a separate company and receives your messages under its own privacy policy — if you would rather not use Telegram, the web app does the same job.

Saved on your device, not ours. While you are building a case, the web app keeps a copy of what you have typed in your browser's local storage, so a refresh, a closed tab or an expired sign-in does not wipe out work you may have found difficult to write. That draft never leaves your device — we cannot read it. It is deleted as soon as your case is created, when you sign out, or whenever you press Discard and start over. If you are using a shared or public computer, signing out is what clears it.

What we do not collect: we use no advertising trackers, no analytics cookies, and no third-party ad networks. We do not sell or share your data for marketing — ever. The web app does store a sign-in token in your browser; that is essential to keep you logged in and is not used for tracking.

Visitor numbers: we count visits to our public pages using Plausible, a privacy-focused analytics service hosted in the EU. It sets no cookies, stores nothing on your device, and does not identify you or follow you to other websites. We receive counts — how many people opened a page, and which site sent them — never individuals.

Two limits we have put on it deliberately. It records the page address only, never anything you type, so when you check a business the name you searched for is not sent. And it does not run at all once you are signed in — not on your dashboard, your case, or your documents.

Counting how the service is used: separately from Plausible, we keep a small tally on our own servers of how many checks were run each day, how those checks came back, and how many documents were generated. This is how we know whether the service is being used at all.

It is a tally and nothing more. Each entry is a date, a label from a short fixed list, and a number — for example 2026-08-05 · check · unknown · 14. There is no entry for you, no record of which checks were yours, no IP address, and no record of the business you searched for. Those numbers cannot be traced back to a person because nothing linking them to a person is ever written down.

Who processes your data

We use a small number of service providers to run ScamFendr:

ProviderWhat they do
RailwayHosts our application and database
CloudflareStores uploaded evidence files (R2 object storage)
AnthropicAI processing that turns your answers into your documents, and classifies scam risk for messages sent to our Telegram bot. Content is processed under our data processing agreement and is not used to train AI models.
SendGridSends your 6-digit sign-in codes
PlausibleCounts visits to our public pages. Receives the page address, the site that referred you, and your country, browser and device type. It sets no cookies and does not identify you. Hosted in the EU. Not used on any page you see once signed in.
SerpAPIReverse image search. If you send a photo to our Telegram bot, we pass a copy to SerpAPI to find out whether the same picture already appears elsewhere online — a common sign of a stolen listing photo. SerpAPI passes it to Google Lens. We delete our copy as soon as the check finishes.
Companies HouseReceives the business name you search on the Check a business page, so we can return its registration details. A public register operated by the UK government.
TelegramDelivers messages to and from our bot, if you choose to use it. Telegram is an independent controller of the messages you send it.

Each provider we instruct processes data only on our instructions and under a data processing agreement. Companies House and Telegram are not our processors — they handle data under their own terms, which is why we name them separately above.

Where your data goes

Some of these providers are based outside the UK, mainly in the United States. Where data leaves the UK we rely on the UK's international data transfer safeguards, and we are completing that documentation with each provider. If you would like to know the current position for a specific provider before you use the service, email us and we will tell you plainly.

Legal bases

How long we keep things

Your rights (UK GDPR)

You have the right to access, correct, delete, or export your data, and to object to or restrict our processing of it. Email hello@scamfendr.uk and we'll respond within one month. You can also complain to the Information Commissioner's Office, though we'd appreciate the chance to fix things first.

Security

All traffic is encrypted in transit (TLS). Evidence files are stored in Cloudflare R2, which encrypts them at rest. Email addresses are stored as keyed hashes, with the key held outside the database. Access to production systems is restricted and authenticated.

One exception is worth stating plainly. To run the reverse image search described above, the photo you send our Telegram bot has to be readable by SerpAPI over the internet, so for up to five minutes it sits behind a long, unguessable web address that does not ask for a password. Anyone who obtained that address within those five minutes could open the picture. We delete the copy as soon as the check finishes. If you would rather not accept that, send the listing text instead of a screenshot — the text check never leaves our own systems and Anthropic's.

Changes

If we change this policy in a way that matters, we'll update the date at the top and, where the change is significant, tell you when you next sign in.