ScamNemesis

Privacy Policy

This policy explains what personal data ScamNemesis processes, why we process it, who we share it with, and what you can do about it. It covers both the scamnemesis.com website and the ScamNemesis mobile app.

Last updated: 16 August 2026

Who is responsible for your data

ScamNemesis is operated by TODO: registered legal name, IČO TODO: IČO, with its registered seat at TODO: registered address, Slovak Republic. We are the controller of the personal data described in this policy.

For any question about this policy or about how we handle your data, write to info@scamnemesis.com. We answer data protection requests within one month.

What data we process

We only process what a scam-reporting service actually needs. The categories below are exhaustive.

Account data

  • Your email address, which is also your login.
  • Your password, stored only as a salted hash. We never see it.
  • Your display name and, if you choose to add one, your phone number.
  • Two-factor authentication settings and the list of devices you have marked as trusted.

Reports you submit

  • Your contact details as the reporter: name, email address and phone number. These are never published.
  • The details of the incident: what happened, when, the amount involved, and the fraud category.
  • The identifiers of the person or business you are reporting: phone number, email address, IBAN, website, cryptocurrency address, social media profile or name.
  • Any evidence you attach, such as screenshots, photographs or documents.

Call history and messages (mobile app only)

  • If you grant the call log or SMS permission and start a scan, the app reads the phone numbers involved and sends only those numbers to our servers to check them against the scam database.
  • The text of your messages is never uploaded, never stored and never published. Neither is the content of your calls, which the app cannot access at all.
  • Both permissions are optional. Every other feature works without them, and you can revoke them at any time in your device settings.
  • Automatic call and message screening runs on your device against a list of known scam numbers that the app downloads from us. Incoming calls and messages are not sent to us for screening.

Technical data

  • IP address, browser or app version, device model and operating system version.
  • Crash reports and diagnostic data, so we can fix what breaks.
  • A push notification token, if you allow notifications.
  • Server logs recording which pages and endpoints were accessed and when.

Payment data

  • Premium subscriptions are billed by Apple or Google, not by us. We never receive or store your card number.
  • We receive a purchase receipt or token confirming that a valid subscription exists, and we link it to your account.

Why we process it, and on what legal basis

Purpose Legal basis
Creating and running your account, and providing the features you ask for. Performance of a contract, Article 6(1)(b) GDPR.
Publishing verified reports so that other people can avoid the same fraud. Legitimate interest in preventing fraud and protecting the public, Article 6(1)(f) GDPR.
Checking numbers from your call history or inbox against the scam database. Performance of a contract, at your request, Article 6(1)(b) GDPR.
Moderating submissions, preventing abuse, and keeping the service secure. Legitimate interest in a safe and accurate service, Article 6(1)(f) GDPR.
Sending push notifications about cases you follow. Your consent, Article 6(1)(a) GDPR, which you can withdraw at any time.
Meeting accounting, tax and other statutory duties. Legal obligation, Article 6(1)(c) GDPR.
Responding to lawful requests from public authorities. Legal obligation, Article 6(1)(c) GDPR.

What becomes public, and what never does

A report is not published automatically. Every submission is reviewed by a moderator before any part of it becomes visible.

Published after moderation

  • The identifiers used to commit the alleged fraud: phone number, email address, IBAN, website, cryptocurrency address or profile.
  • A description of what happened, the fraud category and the approximate loss.
  • The date the report was filed and any moderator-approved updates.

Never published

  • Your name, email address and phone number as the reporter.
  • The content of your messages or your call history.
  • Your account details, payment information or device identifiers.
  • Evidence files, unless you explicitly ask for a specific file to be published and a moderator agrees.

If you have been named in a report

We publish allegations made by members of the public. An entry in the database is a report, not a court finding, and we say so on every case page.

If you believe an entry about you is inaccurate, outdated or unlawful, write to info@scamnemesis.com with the case reference and an explanation. We will review it, and we will tell you the outcome.

You have the right to have inaccurate data corrected and to have a statement of your own added to the case. Where a report turns out to be unfounded, malicious or unverifiable, we remove it.

Who else sees your data

We do not sell personal data, and we do not share it for anyone else's advertising. We use a small number of processors who act only on our instructions.

Our processors

  • Google Ireland Limited, for push notifications and crash reporting in the mobile app, and for spam protection on our forms.
  • Apple Inc. and Google Ireland Limited, for processing subscription payments made through their stores.
  • Our hosting provider, which stores the database and files on servers in the European Union.

Other recipients

  • Law enforcement and public authorities, where we are legally required to disclose data or where disclosure is necessary to prevent serious harm.
  • Our legal and accounting advisers, where necessary and under a duty of confidentiality.

Transfers outside the European Economic Area

Our servers and databases are in the European Union. Some of our processors are part of groups based in the United States. Where data reaches them, the transfer relies on the European Commission's adequacy decision for the EU-US Data Privacy Framework or on Standard Contractual Clauses.

How long we keep it

Data Retention period
Account data For as long as your account exists, then deleted within 30 days of closure.
Published reports For as long as they remain relevant to fraud prevention. We review them periodically and remove entries that are no longer justified.
Reporter contact details Three years from the report, so we can verify or follow up on the case.
Evidence files Three years from the report, unless needed longer for an ongoing investigation.
Numbers submitted for scanning Checked and discarded. We do not build a record of your call history or inbox.
Server and security logs Up to 12 months.
Accounting records Ten years, as required by Slovak law.

How we protect it

All traffic to the website and the app is encrypted in transit with TLS. Passwords are stored as salted hashes and are not recoverable. On mobile, your session token is held in the device keystore, and you can lock the app behind your fingerprint or face.

Access to the administration system is limited to named moderators, protected by two-factor authentication, and logged. Sensitive fields in the database are additionally protected against casual access.

No system is perfect. If a breach ever affects your rights, we will notify the Slovak Data Protection Authority within 72 hours and tell you directly where the law requires it.

Your rights

Under the GDPR you can exercise all of the following. Write to info@scamnemesis.com and we will respond within one month.

  • Access: get a copy of the personal data we hold about you.
  • Rectification: have inaccurate or incomplete data corrected.
  • Erasure: have your data deleted where there is no overriding reason to keep it.
  • Restriction: have us pause processing while a dispute is resolved.
  • Portability: receive the data you gave us in a machine-readable format.
  • Objection: object to processing based on our legitimate interests, including publication of a report about you.
  • Withdraw consent: turn off notifications or withdraw any other consent at any time, without affecting what happened before.

You can also complain to the Slovak Data Protection Authority, Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk.

Cookies and analytics

The website sets cookies that are strictly necessary to keep you logged in and to protect forms against abuse. These do not require consent.

If analytics are enabled, they run only with your consent, IP addresses are anonymised, and you can change your choice at any time. The mobile app does not use advertising identifiers and contains no advertising.

Children

ScamNemesis is not intended for children. You must be at least 18 to create an account or submit a report. If we learn that we hold data about a child, we delete it.

Changes to this policy

If we change how we handle personal data, we update this page and the date at the top. Where a change materially affects you, we tell you by email or in the app before it takes effect.

Questions about this document? Write to us at info@scamnemesis.com

Read the Terms of Use