Privacy Policy
Last updated: June 11, 2026
At Scam Snap, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and process your personal data in accordance with the Personal Data Protection Act (PDPA) 2012 of Singapore. Please read this policy carefully to understand our privacy practices.
1. Data Controller
Scam Snap is operated from Singapore and is responsible for the data described in this policy. When a corporate entity is incorporated for the service, this section will be updated with its registered name and number.
2. Information We Collect
Gameplay Progress (stored on your device)
Scenarios completed, scores, XP, streaks, unlocked content, and your training preferences are saved in your browser's local storage on your own device. This data never needs to leave your device for the game to work, and clearing your browser storage removes it.
Anonymous Gameplay Telemetry
To understand which scams fool people and make the training sharper for everyone, the app sends a small set of anonymous events to our database: a random device identifier (generated on your device, linked to no account or person), gameplay outcomes (e.g. session accuracy, which scenario types were answered correctly), and coarse, optional onboarding answers chosen from on-screen buttons (your self-selected persona, and — only if you choose to share it — whether a scam has affected you or someone close, by category). No names, contact details, free text, or message content are ever collected, and these events cannot be linked back to you.
No Accounts Today
Scam Snap currently requires no account: we do not collect names, email addresses, or phone numbers. If optional accounts or paid plans launch in the future, we will update this policy before collecting any such data, and will collect only what that feature requires.
3. How We Use Your Data
- •Improving scenario realism and effectiveness based on user interactions
- •Personalizing your training path and difficulty progression
- •Analyzing app performance and technical metrics
- •Producing aggregated, anonymized research insights about scam vulnerability and awareness (e.g. which scam types are hardest to spot) — never individual profiles
4. Data Storage and Security
Your gameplay progress lives on your own device. The anonymous telemetry described above is stored with Supabase, an open-source backend provider, in their Singapore region. All data is encrypted in transit (TLS) and at rest.
We use industry-standard security measures to protect your data from unauthorized access, alteration, or disclosure. However, no method of transmission over the internet is completely secure.
5. Third-Party Services
Supabase (Database)
Stores the anonymous telemetry events described above, in its Singapore region. Supabase is SOC 2 compliant and operates under strict data protection agreements.
Cloudflare (Hosting & Delivery)
Serves the website and app worldwide. Like any web host, Cloudflare processes IP addresses and request metadata transiently to deliver and protect the service. Cloudflare is ISO 27001 certified.
Anthropic Claude API (AI-Assisted Content)
Training scenarios may be drafted with the help of Claude, Anthropic's AI model, during content production. These are content-generation prompts only — no player data of any kind is sent to Anthropic.
6. Your Rights Under PDPA
Under Singapore's Personal Data Protection Act, you have the right to:
- •Access your personal data held by us
- •Correct inaccurate personal data
- •Withdraw consent for us to collect, use, or disclose your data
- •Request deletion of your personal data
To exercise any of these rights, contact our Data Protection Officer at contact@scam-snap.com.
7. Data Breach Notification
In the event of a confirmed data breach affecting your personal data, we will notify you and the Personal Data Protection Commission (PDPC) within three (3) days of discovery, or as soon as practicable, in accordance with PDPA requirements. We will provide information about the nature of the breach, the data affected, and recommended protective measures.
8. Cookies and Tracking
Scam Snap currently sets no cookies at all. The app uses your browser's local storage and a service worker cache for offline play and preferences — these stay on your device and are not used to track you. We use no advertising cookies, no behavioral tracking, and no third-party analytics that build user profiles. See our Cookie Policy for details.
9. Children's Privacy
Scam Snap is designed for users aged 13 and older. We do not knowingly collect personal data from children under 13. If we discover we have collected data from a child under 13 without parental consent, we will delete it immediately. Parents or guardians who believe we have collected data from a child under 13 should contact contact@scam-snap.com.
10. Data Retention
Gameplay progress on your device stays there until you clear your browser storage or uninstall the app — it is under your control. Anonymous telemetry events are retained to support long-term research into scam awareness; because they carry no identity, they cannot be traced back to any person. If you want the events associated with your device's random identifier deleted, contact contact@scam-snap.com from the device in question and we will remove them.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be announced on this page and, where feasible, with an in-app notice. Your continued use of Scam Snap after changes constitutes acceptance of the updated policy.
Contact Information
Data Protection Officer
Email: contact@scam-snap.com
We aim to respond to data requests within 14 days.
General Inquiries
Email: support@scam-snap.com
If you have concerns about our privacy practices or believe we have violated your rights under PDPA, you may lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore.