# 1. Introduction
itsflagged ("we", "our", or "us") operates itsflagged.app (the "Service"). We take your privacy seriously. This Privacy Policy explains what information we collect, how we use it, and what rights you have over it. By using itsflagged, you agree to the collection and use of information in accordance with this policy.
# 2. Information We Collect
2.1 Information You Provide
When you create an account, we collect your email address and password. When you submit content for analysis (URLs, phone numbers, email addresses, text messages, or images), we process that content solely to provide you with a scam detection verdict.
2.2 Information Collected Automatically
We collect standard log data including your IP address, browser type, pages visited, and the time and date of your visit. We use cookies and similar tracking technologies to maintain your session and remember your preferences.
2.3 Payment Information
We use Stripe to process payments. We do not store your credit card number, CVV, or full payment details on our servers. All payment data is handled directly by Stripe in accordance with their privacy policy and PCI DSS standards.
# 3. How We Use Your Information
To provide the Service: We use submitted content to run scam detection checks through our third-party APIs.
To maintain your account: We use your email to manage your account, send verification emails, and provide support.
To improve the Service: We analyse usage patterns in aggregate to improve detection accuracy and user experience.
To communicate with you: With your consent, we send weekly digest emails and breach alerts. You can opt out at any time in your account settings.
# 4. Third-Party Services
itsflagged uses the following third-party services to provide scam detection. By using our Service, you acknowledge that submitted content may be processed by these services:
Google Safe Browsing: For URL safety checks. Subject to Google's Privacy Policy.
VirusTotal: For deep URL and file scanning. Subject to VirusTotal's Privacy Policy.
URLScan.io: For phishing site detection. Subject to URLScan's Privacy Policy.
Twilio: For phone number verification. Subject to Twilio's Privacy Policy.
IPInfo: For domain and IP analysis. Subject to IPInfo's Privacy Policy.
OpenAI: For AI-powered content analysis. Subject to OpenAI's Privacy Policy.
Google Places: For business phone number verification. Subject to Google's Privacy Policy.
We strongly recommend you do not submit sensitive personal information (passwords, full social security numbers, bank account details) for analysis.
# 5. Data Retention
We retain your account information for as long as your account is active. Check history is retained for 12 months for Pro users and 30 days for free users. You may request deletion of your data at any time by contacting us.
# 6. Data Security
We implement industry-standard security measures including HTTPS encryption, secure password hashing, and protected API key storage. However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your data.
# 7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
Access: Request a copy of the personal data we hold about you.
Correction: Request correction of inaccurate personal data.
Deletion: Request deletion of your personal data.
Opt-out: Opt out of marketing communications at any time.
To exercise these rights, contact us at support@itsflagged.com.
# 8. Children's Privacy
itsflagged is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately.
# 9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on our website. Continued use of the Service after changes constitutes acceptance of the updated policy.
# 10. Contact Us
For privacy-related questions, contact us at: support@itsflagged.com