What we collect
- Account data: Name, email address, phone number, company name, and GSTIN (if provided) for account creation and GST-compliant invoicing.
- Gmail metadata: Sender addresses, subject lines, and header fields. During scanning, message body text is analysed in memory and discarded immediately after classification; it is not collected or stored, and attachments are not accessed — neither their contents nor their file names. If you choose to report a message, we re-fetch the complete message, including its body and attachments, to build a cybercrime evidence pack.
- Universal Scanner submissions: Text, URLs, UPI IDs/VPAs, payment screenshots, and voice/audio clips you submit for analysis.
- WhatsApp submissions: Messages and media forwarded to our scan number.
- Threat detection output: Detected threat categories, confidence scores, indicator-of-compromise (IOC) URLs, and timestamps, stored per-customer in an encrypted database.
- Usage data: Login events, dashboard actions, and feature usage for product improvement (anonymised).
Email data handling
We connect to Gmail via secure sign-in using a single read-only scope, gmail.readonly, which does not allow us to send, change, or delete your email. We use the Gmail History API for incremental synchronisation, accessing only what has changed since the last scan rather than your full inbox history.
The email body is processed in memory at scan time to detect fraud indicators and is discarded immediately after classification; scanning never writes it to disk or database. The only exception is a message you choose to report, which is re-fetched for a cybercrime evidence pack as described below. The subject line and a masked version of the sender's email address are retained for up to 90 days so you can locate and verify a flagged message in your own mailbox.
Cybercrime Evidence Pack
When you choose to report a fraudulent email, we will re-fetch that message from your connected Gmail mailbox at that time to generate a cybercrime evidence pack. We do not retain the raw email content except inside the finished pack. The pack includes full email headers, sender authentication results (SPF/DKIM/DMARC), a rendered copy of the message, attachments, and the original .eml file. We retain the finished evidence pack for up to 12 months from creation (with an optional one-time extension to 24 months if you indicate an ongoing case), after which it is deleted.
If you request a Section 63 certificate, a designated ScamShield reviewer will read the contents of your evidence pack, including the original email, before approving or rejecting the certificate. This human review occurs only when you request a certificate and provide explicit consent in the portal. No additional retention applies — the same 12-month (with optional one-time extension to 24 months) window applies to the finished pack.
Vendor payment fraud detection
ScamShield AI helps our customers detect a common fraud pattern in which a criminal impersonates a known supplier and requests payment to a new, unfamiliar bank account. To provide this service, we process bank account and UPI identifiers that appear in correspondence our customers choose to route through our platform, in their capacity as the party responsible for that business relationship.
How this data reaches us: This data reaches us automatically, when our email scanner detects a low-risk message referencing a vendor's payment details, as part of correspondence our customer has authorised us to scan.
How this data is processed: The account number or UPI ID is converted immediately into a one-way cryptographic hash, a scrambled fingerprint that cannot be reversed into the original number. The actual account number is not stored, logged, or retained anywhere in our systems, in any form, at any point. We store and compare only the hash.
What this feature does and does not do: This tool indicates whether an account has been associated with a specific vendor in the customer's own prior activity through our platform. It does not verify with any bank, the NPCI, or any government registry that the account belongs to a real or legitimate business. A result of no prior record does not indicate an account is unsafe, and a result showing a prior record does not guarantee safety. It is one signal for the customer to weigh alongside their own verification, not a substitute for it.
IFSC codes, where provided, are used only for the customer's own reference and are not included in the stored fingerprint.
Our role and our customer's role: ScamShield AI processes this data on the instructions of, and as a service to, the business customer using our platform. Our customer is responsible for ensuring they have an appropriate basis for processing their own vendor's payment information as part of their ordinary business correspondence, in the same way they would when using accounting, invoicing, or email software. Where a vendor's bank account belongs to an individual rather than a registered business, we extend the same hashing, non-retention, and access safeguards described in this section as a matter of our own data handling standard, regardless of whether that data falls within the technical scope of applicable law.
Screenshot, UPI, and voice data handling
- Payment screenshots: Submitted images are processed for forensic analysis (Error Level Analysis, OCR, metadata checks). The image and the extracted OCR text are retained as part of your account data for as long as your account remains active, and are permanently deleted (including the underlying image file) if you delete your account via Settings, or by emailing us to request deletion (see “Your rights under DPDP Act 2023” below).
- UPI IDs / VPAs: When a scan produces a fraud verdict, the submitted VPA is added to our shared fraud-reputation database, which benefits all customers by improving detection across the network. If you submit a data deletion request, the link between your account and any VPA you submitted is permanently removed; the VPA and its fraud signal remain in the shared reputation database in anonymised form, no longer traceable to you.
- Voice/audio clips: Submitted for synthetic-voice and digital-arrest-scam detection. The audio file exists only temporarily during processing and is deleted immediately after a result is returned, whether the scan succeeds or fails. As a safeguard, an automated hourly process also removes any temporary audio file that may remain due to an unexpected error. No audio recording is stored as part of your account data.
You can delete your account and all associated data at any time from Settings → Profile → Danger zone, or by emailing privacy@scamshieldai.in. Self-serve deletion is processed immediately; email requests are processed within 30 days. See “Your rights under DPDP Act 2023” below.
WhatsApp data handling
Messages and media forwarded to our WhatsApp scan number are processed to detect fraud. Message content (text and media) is not persisted after scanning. Sender phone numbers are stored in hashed form only, never in plaintext. We connect directly to Meta's WhatsApp Business Platform API. No third-party Business Solution Provider is used.
By forwarding a message to our WhatsApp number, you consent to that message being processed as described here and in accordance with WhatsApp's own Business Terms.
Vendor payment fraud detection, described above, currently applies to correspondence processed through our email scanning service. Payment identifiers in messages forwarded via WhatsApp are not currently included in this vendor-matching process.
Google API Services User Data Policy
ScamShield AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, do not transfer it to third parties except as necessary to provide and improve the service (see Sub-processors below), and do not allow humans to read it except in the narrow circumstances Google's policy permits (e.g. with your consent, for security purposes, or to comply with law). When you ask us to create a cybercrime evidence pack, the message is re-fetched from Gmail and kept only inside that pack, for you to download and use in your complaint; it is not used for any other purpose, and it is deleted when the pack's retention period ends.
How we use data
- To provide real-time fraud detection and threat alerts
- To generate GST-compliant invoices for paid accounts
- To improve our machine-learning models using anonymised, aggregated threat patterns only, and never personal data or raw content
- To send transactional emails and WhatsApp alerts (threat alerts, invoices, account notifications)
- We never sell, share, or license your data to third parties for their own purposes
Sub-processors and data sharing
We use the following third parties to operate the service. None of them are permitted to use your data for any purpose other than providing their service to us.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure (Central India) | Hosting, database, compute | Mumbai, India |
| Resend | Transactional email delivery (alerts, invoices, account notifications) | Resend maintains a published Data Processing Addendum and is certified under the EU-US Data Privacy Framework |
| Meta (WhatsApp Business Platform, direct API, no third-party BSP) | WhatsApp message delivery | Per Meta's infrastructure |
| Anthropic (Claude API) | Second-opinion AI fraud review of message content during scanning | United States, Europe, Asia and Australia |
| Razorpay | Payment processing | India |
| GST Network (Government of India) | GSTIN verification | India |
AI model providers, as of 14 August 2026: most of our fraud detection runs on our own models, on our own infrastructure. In addition, message content submitted for scanning may be sent to Anthropic (Claude API) for a second-opinion fraud review in cases where our primary models call for one; the content being scanned is sent as part of that review — with direct identifiers automatically masked first (see “Third-party AI processing” below) — and is processed outside India. We do not send customer scan content to any other AI model provider. If this changes, we will update this policy and notify active customers before enabling it, and only after completing a data protection impact assessment and DPA review.
Third-party AI processing
As of 14 August 2026. When our primary detection engine cannot confidently classify a message, and when it confirms a message is fraudulent but cannot determine its type, the message content is sent to Anthropic PBC's Claude API for an additional automated review. Before anything is sent, direct identifiers in the text are automatically masked: email addresses, phone numbers, UPI IDs, GSTIN and PAN values, bank-account-length digit runs, exact monetary amounts, personal names where detected, and the path portion of web links are all replaced with placeholders. What remains is the message text needed to judge the scam pattern — for email, the subject line and message body; for WhatsApp, the forwarded message; for the scanner, the text you paste or the text extracted from an image or PDF you upload. Sender email addresses, your account identity, and your company details are not included. This content is processed in memory for the duration of the review and is not stored by us as part of it.
We use Anthropic's standard commercial API. Under Anthropic's published commercial terms, content sent for this review is not used to train their models, and inputs and outputs are automatically deleted from their systems within 30 days, except where longer retention is required by law or by Anthropic's own trust-and-safety processes. We have not entered into a zero-data-retention arrangement with Anthropic; if we do, we will update this policy to say so.
Component D — Anthropic (Claude)
For fraud detection, we may use AI/ML tools, including Anthropic's Claude, to analyze scan content (message text and metadata). Anthropic may process this data in the United States, Europe, Asia or Australia, and stores it in the United States. If content is flagged for safety review, Anthropic may retain it for up to two years, and in rare cases longer where required for legal, safety, or enforcement purposes. Anthropic's commercial terms do not allow it to train its models on this content. We rely on contractual and technical safeguards with Anthropic to protect this data. For details, see Anthropic's Commercial Terms of Service and Data Processing Addendum.
While message content sent to Anthropic for analysis is not stored by us, we retain the resulting fraud assessment for up to 90 days. A short explanation derived from it may be kept with the related threat alert or scan result for as long as that record is retained. (Demo/test accounts may retain masked message text for up to 90 days for internal testing and demonstration purposes.)
Gemini (Google) — India-only processing
For fraud detection, we may also use Google's Gemini AI. When enabled, Gemini processing is restricted to Google's Mumbai (India) data centres. Message text and metadata are processed only in India for this feature. For details, see the Google Cloud Privacy Notice and Vertex AI data residency documentation.
Storage & data residency
All production data is stored on Azure Central India (Mumbai). Personal data is transferred outside India in two cases only: transactional email delivery via Resend, which maintains a published Data Processing Addendum (resend.com/legal/dpa) and is certified under the EU-US Data Privacy Framework; and the second-opinion AI fraud review described under Sub-processors, where the message content being scanned — with direct identifiers automatically masked — is sent to Anthropic (Claude API) for processing in the United States, Europe, Asia or Australia.
Your rights under DPDP Act 2023
You have the right to:
- Access: Request a copy of all personal data we hold about you
- Correction: Correct inaccurate personal data
- Erasure: Request deletion of your account and all associated data
- Nomination: Nominate a person to exercise your rights in case of death or incapacity
- Grievance: File a complaint with our Data Protection Officer / Grievance Officer
To exercise these rights, use the account deletion option in Settings, or email privacy@scamshieldai.in for any other request. We will acknowledge grievances within 48 hours and resolve them within 30 days as required under the DPDP Act 2023.
Retention periods
- Account data: duration of subscription plus 90 days after cancellation
- Threat detection records: 12 months
- Audit logs: 24 months, for security purposes
- Gmail-sourced threat metadata (subject line, masked sender, message ID): 90 days, then automatically and permanently deleted
- Cybercrime evidence packs (including the re-fetched message, its .eml file, and any transaction details you enter): 12 months from creation, or 24 months if you extend it for an ongoing case; then automatically and permanently deleted
- Screenshot images, OCR text, and UPI/VPA records: retained for the duration of your active account; deleted (or anonymised, for VPAs, to preserve shared fraud-detection value) upon a verified data deletion request
- Voice/audio clips: temporary only, deleted immediately after processing; never persisted as part of your account data
- WhatsApp message content: not retained. WhatsApp enrollment metadata (name, email): currently retained indefinitely; a defined retention schedule for this is planned
Vendor payment fingerprints (hashed, non-reversible) are retained for 12 months per vendor relationship, in line with our threat detection record retention, and are deleted earlier upon request.
You may delete your account and associated data at any time from Settings, or by emailing the contact below. Deletion requests are processed across all systems, including the Universal Scanner, immediately for self-serve requests or within 30 days for email requests.
What we keep even after you request deletion, and why
The DPDP Act 2023 does not require us to delete data where retention is necessary to comply with another law, or to establish, exercise, or defend a legal claim. Consistent with this, the following records survive a deletion request:
- Invoices and GST-related financial records, retained as required under the Companies Act 2013 and applicable GST law
- A record of your consent at signup (timestamp and IP address), retained for the duration of the relevant contractual/limitation period, so that either party can establish what was agreed if a dispute arises
- Correspondence directly tied to an active or resolved legal or billing dispute, retained until the applicable limitation period for that claim has passed
- A record that a deletion request was made and processed (who, when, what was purged), so we can demonstrate compliance with this policy and the DPDP Act if required
Everything else, including screenshots, OCR text, voice recordings, WhatsApp content, Gmail-derived metadata, and cybercrime evidence packs, is deleted in full, not merely marked inactive. UPI/VPA records are anonymised rather than deleted outright, as described above.
Data breach notification
In the event of a personal data breach that is likely to result in harm, we will notify affected customers and, where required, the Data Protection Board of India, without undue delay and in accordance with the DPDP Act 2023 and applicable rules.
Contact our Data Protection Officer / Grievance Officer
Darshil Thummar, Co-Founder & CTO
ScamShield AI Private Limited, 32, Bhaktinandan Shopping, Bapasitaram Chowk, Krishnanagar, Ahmedabad 382345, Gujarat
Email: privacy@scamshieldai.in · Phone: +91 87587 32525