Privacy Policy
Last updated 27 August 2026. Operated by Scamlist.
This policy explains what data Scamlist does and doesn't process, why, how long we keep it, and the rights you have under the privacy laws that may apply to you.
1. Who we are
Scamlist is operated by Scamlist (“we”, “us”), which is the controller / data fiduciary responsible for the limited data described here. You can reach us using the details in section 17. The governing jurisdiction for the service is India.
2. Our approach: privacy by design
Scamlist is built to collect as little as possible about you:
- No accounts, ever. You do not register, log in, or give us your name to browse, search, or submit a report.
- No tracking cookies for visitors, and no third-party analytics or advertising of any kind.
- No profiling. We do not build a profile of you and do not track you across other sites.
3. What we process — and what we don't
To keep voting and reporting resistant to manipulation (automated bots, coordinated fake votes, abusive submissions), our anti-abuse systems process a small set of technical signals when you submit a report or cast a vote:
- A salted, hashed form of your IP address — computed with a secret key, stored as a one-way hash. We do not store your raw IP address.
- For report submissions, a coarse browser hash derived from your user-agent and language header (also salted and hashed) — used only to spot abnormal submission patterns. This is not a persistent, cross-site device fingerprint.
- Coarse technical metadata such as timing.
These signals are processed solely to detect and prevent abuse (including a per-visitor risk score used for review), are stored separately from the public report text, and are never used to advertise to you or to identify you in normal operation. The content you choose to put in a report (for example, a listing URL or your description) is published publicly — so please don't include your own sensitive personal information in it.
Location & Google Maps (optional). If you add a location to a report, or use “Scams near me,” that feature uses Google Maps. When the map picker or a map image loads, Google (as an independent processor) receives the request and the address/coordinates involved, subject to Google's own privacy policy. “Scams near me” reads your device location in your browser only to run the search — it is not sent to us or stored. Adding a location is always optional; if you never use these features, no data goes to Google.
4. Why we process it (our legal grounds)
Where the EU/UK GDPR applies, our legal basis for processing the anti-abuse signals is our legitimate interest in keeping the service trustworthy and free from manipulation — an interest we balance against your rights by using salted hashes (not raw IPs), strict purpose limitation, and short retention. Where India's DPDP Act applies, we rely on the corresponding legitimate-use / security grounds. We do not sell or share this data (see section 11).
6. How long we keep it
Report-derived anti-abuse signals (the salted IP and browser hashes attached to a report) are kept for up to 30 days and then automatically purged by a scheduled job, leaving the public report itself intact. We do not keep raw IP addresses, and we do not use these signals for anything other than abuse prevention.
One exception, for honesty: the salted hash attached to an upvote is the mechanism that enforces one-vote-per-person. Because it is inseparable from the vote it protects, it is retained for as long as that vote is counted. It is a salted hash (never a raw IP) and is not used for profiling.
7. Where your data is processed
Scamlist is self-hosted on infrastructure chosen by the operator. Depending on where that infrastructure and any backups are located, the limited data described here may be processed in India or other countries. Where a cross-border transfer is subject to law (for example, the GDPR's transfer rules or the DPDP Act), the operator is responsible for putting an appropriate safeguard in place.
8. Your rights (and how anonymity limits them)
Depending on where you live, you may have rights to access, correct, delete, or object to the processing of your personal data, and to complain to a regulator. We honour these rights wherever they apply — but one honest limitation follows directly from our design:
Because we hold no account and no data that identifies you — only salted, one-way hashes we cannot reverse — we usually cannot locate “your” data from your name or email, and so cannot action identity-based access or deletion requests for the anti-abuse signals. This is a consequence of collecting less, not a way to avoid your rights. Where you can point us to specific content (see section 13), we can act on that.
9. EU / EEA / UK (GDPR)
If you are in the European Economic Area or the United Kingdom, you have the rights under the GDPR / UK GDPR to access, rectify, erase, restrict, and object to processing, and to data portability, subject to the limits in section 8. Our basis for the anti-abuse processing is legitimate interest, and you may object to it on grounds relating to your situation. You also have the right to lodge a complaint with your local supervisory authority. To exercise any of these, contact us (section 17).
10. India (DPDP Act, 2023)
If you are in India, the Digital Personal Data Protection Act, 2023 gives you, as a Data Principal, rights to access a summary of your personal data, correct or erase it, a grievance-redressal route, and the ability to nominate another person to exercise your rights. We act as the Data Fiduciary for the limited data described here and rely on the Act's legitimate-use / security grounds. If we cannot resolve your concern, you may approach the Data Protection Board of India. The anonymity limitation in section 8 applies here too. Contact us via section 17.
11. United States (CCPA/CPRA and state laws)
If you are a resident of California or another US state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, or Utah), you may have rights to know what personal information is processed, to delete or correct it, and to opt out of sale, sharing, or targeted advertising.
We make this simple: we do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not use it for targeted advertising or profiling — so there is nothing to opt out of. We also do not discriminate against you for exercising any right. The anonymity limitation in section 8 applies to know/delete requests.
12. Other regions
If you are elsewhere (for example, Brazil under the LGPD, Canada under PIPEDA, or another jurisdiction with a privacy law), the same principles apply: we minimise what we process, use it only for abuse prevention, keep it briefly, and honour the rights your local law grants to the extent our anonymous design allows. Contact us with any request and we will respond as that law requires.
13. If a report concerns you
If a report or other content appears to be about you or your business — including if you believe it is false, defamatory, or discloses private information — contact us (section 17) with a link to the specific content and an explanation. Reports are unverified user claims, not findings of ours, and we will review genuine requests in good faith and remove or hide content that breaks our Terms of Use.
14. Children
Scamlist is not directed to children and is not intended for use by anyone below the age at which they can consent to processing under their local law. We do not knowingly process children's personal data; if you believe a child has, contact us and we will address it.
15. Legal requests and disclosures
If we receive a valid court order or lawful government request, we will respond as required by applicable law. Because the anti-abuse data is salted, hashed, and time-limited, in many cases we simply do not hold anything capable of identifying a specific person by the time such a request arrives.
16. Changes to this policy
We may update this policy from time to time. When we make material changes we will update the “Last updated” date at the top of this page. Your continued use of Scamlist after a change means you accept the revised policy.
17. How to contact us or exercise a right
For any privacy question, or to exercise a right described above, contact Scamlist at legal@scammer.fyi. Please tell us which right you want to exercise and include enough detail (such as a link to specific content) for us to act — remembering that, by design, we often hold nothing that identifies you.
This page is a plain-language template covering the minimum privacy-disclosure points identified in our research, across the EU/UK GDPR, India's DPDP Act, and US state privacy laws. It is not legal advice and should be reviewed by qualified legal counsel for your specific jurisdictions and processing before you rely on it in production.