Skip to main content
TrustShield

Privacy and safety

You share sensitive things with TrustShield. Here is exactly what we do with them, in plain language.

Detection is not verification

A TrustShield result is an estimate based on warning signs in what you submitted. It cannot prove that anything is safe, authentic, or fraudulent. Verification means confirming a request through a separate channel you already trust, such as calling a company on the number printed on your card, or asking the relative a message claims to come from. Our trusted-circle feature helps with that second step.

What we store

  • Your result: risk level, warning signs, next steps, and when you checked.
  • A redacted copy of what you submitted, with email addresses, phone numbers, codes, card and account numbers removed.
  • The complete text only if you ask us to keep it, encrypted, for 24 hours so you can share it with a trusted contact. Then it is deleted automatically.
  • Screenshots are processed in memory and not stored, unless you choose to keep one. Kept screenshots are stored privately with location and camera details removed, and deleted after 7 days.
  • Free plan history is kept for 30 days. Paid plans keep history until you delete it.

What we never do

  • Read your messages, email, or accounts. We only see what you choose to submit.
  • Open the links you submit, or contact anyone on your behalf.
  • Use your submissions to train AI models without your separate, explicit consent.
  • Sell your submissions or your contact information.
  • Put your submitted content in emails or web addresses.

Your control

  • Delete any check at any time. Its stored evidence is removed immediately and any trusted contact loses access.
  • Choose, for each verification request, whether a contact sees a redacted summary or the complete text.
  • Download your data, or permanently delete your account, from Settings.

Services that may receive data

This list reflects how this TrustShield deployment is configured right now.

  • AI-assisted analysis: not enabled

    When enabled, the text you submit (or text read from a screenshot) is sent to Anthropic for analysis. It is not used to train models.

  • Screenshot text reading: not enabled

    When enabled, a metadata-free copy of your screenshot is sent to Anthropic to read the visible text.

  • Email delivery: not enabled

    Recipient address and the message template only. Emails never include what you checked.

  • Payments: not enabled

    Stripe receives your email and plan. TrustShield never sees or stores card details.

  • Hosting and database: enabled

    Account data and results are stored in a managed Postgres database with row-level security.

If you have already acted on a scam

Contact your bank or payment provider immediately using the number on your card or their official website. Change passwords you may have shared and turn on two-step verification. TrustShield does not report incidents to authorities on your behalf.