Last updated July 26, 2026
Privacy notice
ShareToCheck is designed to help adults evaluate suspicious content while collecting as little personal information as practical.
ShareToCheck does not currently sell paid subscriptions. The legal operator name, postal address, and a monitored privacy contact must be added to this notice before a general public beta or paid launch.
Scope and our role
This notice explains how ShareToCheck processes information through its website, account access, message checker, link checker, image and sampled-video-frame text extraction, device Share intake, voluntary result feedback, and the subscription foundation if paid access is enabled. It does not govern a third-party website you choose to visit.
ShareToCheck acts as the controller of the limited account, entitlement, rate-limit, and feedback information described below. Submitted scan content is processed only to provide the check you request and is not kept in ShareToCheck's application database.
Information we process and why
| Category | Purpose and disclosures | Application retention |
|---|---|---|
| Messages, emails, and approved media text | Detect scam patterns. Bounded content may be sent to the configured AI provider when AI assistance is available. | Not written to the application database. |
| Images and sampled video frames | Extract text after you select an image or video. Images are prepared in the browser. Videos remain on the device while three frames are sampled into a derived image. Only the image or derived frame sheet is sent to the configured AI provider; you review and approve redacted text before scam analysis. | Not written to the application database. |
| Items received from a device Share menu | Move the selected text, link, image, video, or email/text file into the checker on supported installed devices. | Held in device-local browser Cache Storage for no more than 15 minutes and deleted after the page consumes it. It is not written to the application database. |
| Links and public page evidence | Check reputation, registration, redirects, and suspicious page features. This may involve Google Web Risk, DNS and registration services, the target host, and the AI provider. | Links, tokens, raw HTML, and extracted page text are not written to the application database. |
| Account and plan data | Apply access limits. The authenticated email received during sign-in is converted to a one-way account key. | The database keeps the key, plan, status, and expiration. Inactive or expired pilot records are deleted on a rolling basis after 90 days. |
| Subscription and billing records | If paid enrollment opens, Stripe-hosted Checkout processes billing contact, payment, invoice, tax, and subscription information. ShareToCheck receives subscription status and opaque customer, subscription, price, and event references. Stripe receives the signed-in email so it can associate and service the billing account. | ShareToCheck keeps the minimum provider references, plan, billing interval, status, period end, cancellation flag, and accepted terms version needed to provide and audit paid access. It does not receive or store complete card numbers. Final billing-record retention must be approved before paid enrollment opens. |
| Rate-limit data | Prevent abuse and control provider costs using a keyed, rotating pseudonym derived from the account or network address. | The raw network address is not stored in the rate-limit table. Buckets expire after the applicable usage window plus one hour and are removed during later requests. |
| Optional result feedback | Measure possible missed threats and false alarms. Stored fields are a random result ID, scan type, risk category, signal IDs, engine version, AI-use flag, feedback label, review status, reviewer, and timestamps. | No submitted content or link is included. Feedback is deleted on a rolling basis after 24 months. |
| Service and security data | Hosting and security providers may process request headers, timestamps, device/browser data, and network addresses to deliver and protect the service. | Controlled by the applicable provider's security and retention settings. ShareToCheck does not intentionally log submitted request bodies. |
How checks work
A message, email, link, image, or sampled video frame is processed only when you submit it for a check. Message text is analyzed in memory. Media OCR sends an image or a locally derived three-frame contact sheet to the configured AI provider, returns redacted extracted text for your review, and does not analyze that text until you approve it. Video audio, identity, deepfakes, unsampled frames, and motion-only behavior are not analyzed. Link checks may send the hostname to DNS and registration services, send the normalized address to Google Web Risk, and retrieve a small, bounded portion of public page content to identify redirects or suspicious forms. Remote scripts are not executed.
AI-assisted analysis
When AI assistance is enabled, message text, approved media text, an image, or a locally derived video-frame contact sheet may be sent to OpenAI to provide the requested analysis. The original video and its audio are not sent. Link review sends only bounded evidence and does not send the complete link, query string, fragment, redirect token, or raw HTML. ShareToCheck sends a request not to store the model response, but that setting is not a promise that a provider has zero retention in every legal, safety, or account context. Provider processing is governed by its applicable business terms and data controls.
AI output can be inaccurate, incomplete, or inconsistent. AI evidence may raise a warning but cannot reduce a deterministic warning. ShareToCheck does not use submitted content to train its own models or permit voluntary feedback to change live results without human review and regression testing.
Accounts, authentication, and cookies
Anonymous checks use a keyed network pseudonym for short-lived request limits. When you sign in, ShareToCheck converts the authenticated email to a non-reversible account key. The account database stores only that key, access plan, status, and expiration date. It does not store the email address, submitted content, or check history.
The subscription foundation is currently disabled. If paid access is activated, ShareToCheck sends the signed-in email and selected plan to Stripe-hosted Checkout. Stripe processes payment methods, billing contact details, invoices, taxes, and cancellation. ShareToCheck stores only the pseudonymous account relationship and bounded billing references and statuses needed to provide access, prevent duplicate processing, and honor account management requests.
ShareToCheck does not currently use advertising cookies, behavioral advertising pixels, or third-party analytics. The hosting and sign-in platforms may use strictly necessary cookies or similar technologies for authentication, security, and service delivery.
Sale, targeted advertising, and sensitive data
ShareToCheck does not sell personal data, share it for cross-context behavioral advertising, or process it for targeted advertising. ShareToCheck does not knowingly monetize sensitive personal data. Because those activities are not performed, there is currently no sale or targeted-advertising opt-out to apply. If this changes, ShareToCheck will update this notice and honor legally required browser-based preference signals, including Global Privacy Control where applicable.
Your choices and privacy rights
Remove names, account numbers, faces, or other personal details before submitting content when they are not needed. Do not submit passwords, authentication codes, full payment-card data, medical records, government identification numbers, intimate images, or content involving child sexual exploitation. Feedback is optional.
Depending on where you live and whether the applicable law covers ShareToCheck, you may have rights to know, access, correct, delete, or obtain a copy of personal data; opt out of certain processing; appeal a denied request; and receive equal service without unlawful discrimination. ShareToCheck may take proportionate steps to verify the requester and an authorized agent. A privacy-request and appeal channel must be configured and published before a general public beta.
Children
ShareToCheck is intended only for adults age 18 or older and is not directed to children. ShareToCheck does not knowingly collect personal information from children under 13. If the operator learns that a child submitted personal information, it will take reasonable steps to delete it and address the submission.
Security and incidents
ShareToCheck uses encryption in transit, data minimization, pseudonymous rate limits, bounded remote retrieval, private-network blocking, access controls, and secret-based integrity protections. No service can guarantee absolute security. If a security incident affects personal information, ShareToCheck will investigate and provide legally required notices.
Changes to this notice
ShareToCheck will post an updated date and explain material changes through the service when required. It will not use previously collected personal information for a materially different purpose without notice and any consent required by law.
Contact and operator information
Before a general public beta or paid launch, this section must identify the legal entity or individual operating ShareToCheck, a postal address, a monitored privacy email, a support contact, and any legally required jurisdiction-specific disclosures. This evaluation preview is not launch-ready until those details are published and tested.
