Privacy and safety
You share sensitive things with TrustShield. Here is exactly what we do with them, in plain language.
Detection is not verification
A TrustShield result is an estimate based on warning signs in what you submitted. It cannot prove that anything is safe, authentic, or fraudulent. Verification means confirming a request through a separate channel you already trust, such as calling a company on the number printed on your card, or asking the relative a message claims to come from. Our trusted-circle feature helps with that second step.
What we store
- Your result: risk level, warning signs, next steps, and when you checked.
- A redacted copy of what you submitted, with email addresses, phone numbers, codes, card and account numbers removed.
- The complete text only if you ask us to keep it, encrypted, for 24 hours so you can share it with a trusted contact. Then it is deleted automatically.
- Screenshots are processed in memory and not stored, unless you choose to keep one. Kept screenshots are stored privately with location and camera details removed, and deleted after 7 days.
- Free plan history is kept for 30 days. Paid plans keep history until you delete it.
What we never do
- Read your messages, email, or accounts. We only see what you choose to submit.
- Open the links you submit, or contact anyone on your behalf.
- Use your submissions to train AI models without your separate, explicit consent.
- Sell your submissions or your contact information.
- Put your submitted content in emails or web addresses.
Your control
- Delete any check at any time. Its stored evidence is removed immediately and any trusted contact loses access.
- Choose, for each verification request, whether a contact sees a redacted summary or the complete text.
- Download your data, or permanently delete your account, from Settings.
Services that may receive data
This list reflects how this TrustShield deployment is configured right now.
AI-assisted analysis: not enabled
When enabled, the text you submit (or text read from a screenshot) is sent to Anthropic for analysis. It is not used to train models.
Screenshot text reading: not enabled
When enabled, a metadata-free copy of your screenshot is sent to Anthropic to read the visible text.
Email delivery: not enabled
Recipient address and the message template only. Emails never include what you checked.
Payments: not enabled
Stripe receives your email and plan. TrustShield never sees or stores card details.
Hosting and database: enabled
Account data and results are stored in a managed Postgres database with row-level security.
If you have already acted on a scam
Contact your bank or payment provider immediately using the number on your card or their official website. Change passwords you may have shared and turn on two-step verification. TrustShield does not report incidents to authorities on your behalf.