Privacy

Privacy Policy

A clear account of what FraudReader handles, what stays on your device, and which optional features send data online.

Version 1.0 · Effective 22 August 2026

1. Who is responsible

FTTG Stockholm AB, organisation number 559592-1049, Dragonvägen 18, 194 33 Upplands Väsby, Sweden, is the controller responsible for FraudReader and the personal data described here. Contact support@fraudreader.com for privacy questions or requests.

2. What works locally

Core checks of pasted messages, email text, links and QR destinations run locally on your device and can be used without an account. FTTG does not receive that content unless you deliberately use an optional online feature or send it to support.

Local history contains a redacted, non-user-authored summary rather than the full content you checked. It remains on the device until you clear history, clear app data or uninstall the app.

3. Accounts and sign-in

If you create or use an account, FraudReader processes an account identifier, email address where supplied, authentication-provider information, sign-in timestamps, and security or session data. This is necessary to create, secure and provide the account service requested by you. Supabase provides the authentication infrastructure.

Google, Microsoft and Apple also process sign-in data under their own terms when you choose those methods. An account is optional for core local checks.

4. Optional online analysis

Online AI analysis is off until you consent to it. When you request it, the selected content and the minimum technical context needed for the request are sent through FraudReader's protected backend to OpenAI. FraudReader requests use store: false, and FraudReader does not save the raw request content in its user-data tables.

You may withdraw consent by disabling online analysis. Local analysis remains available when online analysis is disabled or unavailable.

5. Optional email protection

Gmail or Outlook access begins only after you consent to the in-app disclosure, sign in to the provider and grant the displayed read-only mailbox permission. FraudReader stores your connected mailbox identity, consent and connection status, last-scan time, and encrypted provider credentials until you disconnect, revoke access or delete your account.

Message content is processed transiently for the scan you request. FraudReader does not store raw email bodies, subjects or attachments in its database or scan history. You may withdraw consent by disconnecting the mailbox. Google and Microsoft process provider authorization under their own privacy terms.

6. Subscriptions

When subscriptions are enabled, FraudReader stores verified product, entitlement and lifecycle status together with hashed and encrypted store references. Apple or Google handles payment information, billing, refunds and store subscription history. FraudReader does not receive your full payment-card details.

7. Support, security and language choice

The support form processes the issue category, your reply email, your message, and any device or app-version context you choose to provide so FTTG can answer your request. Privacy-rights requests are handled to meet legal obligations. Information needed to prevent abuse or investigate security incidents is processed for FTTG's legitimate interest in protecting users and the service.

The message is emailed to FraudReader Support through Resend and held in the One.com support inbox; the website does not place it in its database. Ordinary support messages are normally deleted within 180 days after the case is closed. Records needed for a privacy request, security incident or legal claim may be restricted and kept for up to 24 months after closure, or longer only when law or an active claim requires it.

A rotating pseudonymous network hash and counter are used only to prevent support-form abuse. Raw network addresses are not stored in that counter, and the counter is automatically deleted within 24 hours. Do not send passwords, verification codes, BankID information, payment details or complete private messages.

When you manually choose a website language, FraudReader stores one first-party preference cookie named fraudreader_locale for up to 12 months. It is not used for analytics, advertising or tracking. You can delete or block it in your browser.

8. Device access and notifications

Camera access is requested only when you start QR scanning. Notifications are optional and are requested only after an explanation. FraudReader does not request microphone access for scam analysis and does not listen to, record or analyze live call audio.

9. Legal bases, sharing and transfers

FraudReader does not sell personal data, show third-party advertising or use data for cross-app tracking. FTTG relies on contract necessity for accounts and subscriptions; consent for optional AI and mailbox processing; legal obligation for privacy requests and consent accountability; and legitimate interests for proportionate service security, abuse prevention and ordinary support where those interests do not override your rights.

Data is shared only when needed to provide a feature you choose, protect the service, meet a legal obligation or respond to your request. Current providers include Supabase, OpenAI, Google, Microsoft, Apple, Google Play, OpenAI Sites and its hosting infrastructure, Resend, and One.com.

Providers may process data in the EEA and, where applicable, other countries. For transfers outside the EEA, FTTG requires an applicable safeguard such as an adequacy decision or contractual safeguards. Contact support for information about safeguards relevant to your data. Provider agreements, locations and deletion evidence remain release controls before the related app feature is publicly enabled.

10. Retention and deletion

Raw pasted content, optional AI request content and mailbox content are not retained in FraudReader user-data tables. Email authorization state becomes unusable after 10 minutes and is removed when authorization completes, restarts or the account is deleted. Encrypted mailbox credentials remain only while the connection is active.

Account, consent, connection, entitlement and service-limit records remain while the account is active and are removed from FraudReader's active database when the account is deleted. Store billing records remain controlled by Apple or Google. Provider backup or security logs are retained only under the applicable provider terms and legal requirements.

The support and website periods are described in section 7. FTTG reviews this schedule when a feature, provider or legal requirement changes.

11. Your choices and rights

You can use core local checks without an account, withdraw optional consent, disable notifications, disconnect mailbox access, clear local history, and delete your FraudReader account in the app.

Depending on applicable law, you may also have rights to access, correct, delete, restrict or object to processing, and receive portable data. Contact support to exercise a right. FTTG may ask for only the information reasonably needed to verify identity and normally responds within one month, subject to lawful extensions.

You may complain to the Swedish Authority for Privacy Protection (IMY) or the data-protection authority where you live or work. Contact details for IMY are available at imy.se.

12. Security, risk scoring, children and changes

FraudReader uses encrypted transport, owner-only access controls, encrypted provider credentials and data minimization. No service can guarantee absolute security.

Risk scores and explanations are advisory safety signals. FraudReader does not use them to make a decision about you that has legal or similarly significant effects.

FraudReader is a general-audience safety tool and is not directed to children under 13. A user who is below the age at which they may consent to an online service must use optional account, AI, mailbox and support features only with a parent or guardian's authorization where required by law. FraudReader does not ask for a date of birth or create advertising profiles.

Material policy changes will be versioned and dated. Where required, FTTG will provide additional notice or request renewed consent.