Crypto Scam Shield logo Crypto Scam Shield
  • Features
  • FAQ
  • Terms
Add to Chrome — Free
Home Features Terms Add to Chrome — Free
Legal

Privacy Policy

Effective Date: August 21, 2026 · Built on a foundation of data sovereignty.

Welcome to Crypto Scam Shield ("we," "our," or "us"). We provide a Web3 cybersecurity browser extension designed to protect users from phishing sites, malicious smart contracts, and wallet drainers.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Chrome extension. We built this tool on a foundational commitment to user privacy, data sovereignty, and the principle of Zero Data Collection for personally identifiable information (PII). We comply with global privacy standards, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

1. Zero Data Collection Guarantee

Our primary philosophy is that your security tools should not spy on you.

  • No Analytics or Telemetry: We do not use Google Analytics, Mixpanel, Segment, tracking pixels, or any telemetry scripts. We do not track your clicks, usage habits, or personal information.
  • No Browsing History Collection: Your browsing history is evaluated locally on your device or via anonymous API queries. It is never transmitted to, or stored on, our own servers.
  • No Private Keys or Seed Phrases: Crypto Scam Shield will NEVER ask for, access, request, or transmit your private keys, recovery seed phrases, wallet passwords, or hardware wallet PINs.

2. Data We Process (Deep Scan Disclosures)

To provide real-time threat detection, the extension must process certain data. Here is exactly what is processed and how:

A. Browsing Data (Domain Evaluation)

  • What is processed: The extension reads the URL (window.location.href) of the active tab.
  • How it is used: The URL is first checked locally on your device against a cached database of known threats.
  • External Processing: If a live check is required, only the hostname (e.g., example.com) is sent to the GoPlus Labs Phishing API. No path data, query parameters, or personal identifiers are sent.

B. Web3 Transactions (Transaction Analysis & Simulation)

  • What is processed: When you initiate a Web3 transaction, the extension intercepts the transaction payload (From address, To address, Value, and Data/Input).
  • How it is used:
    • The "To" address (recipient/contract) is sent to GoPlus Labs APIs for security scoring.
    • The payload is proxied through a custom Cloudflare Worker (crypto-shield-proxy.shubhamjainmail2.workers.dev) to blockchain RPC providers (like Alchemy or Tenderly) to simulate the transaction (Dry-Run) and predict asset changes.
    • No private keys or signatures are ever sent to these services.

C. Social Media Link Scanning

  • What is processed: When browsing supported social platforms (e.g., Twitter/X, Discord), the extension extracts outbound HTTP links from the page DOM.
  • How it is used: These links are sent to the GoPlus Labs Phishing API to visually flag malicious links directly in your feed.

D. AI Security Assistant (Bring-Your-Own-Key)

  • What is processed: Security questions you type and the API Key you provide.
  • How it is used: If you use the AI Assistant, your queries and your locally stored Groq API Key are sent directly to the Groq API endpoint. We do not intermediate this request or see your API key.

3. Local Storage

The extension uses your browser's local storage (chrome.storage.local) to save data directly on your device. This data never leaves your machine. We store:

  • Custom Whitelists: Domains you have manually marked as safe.
  • Threat Feeds: A cached copy of the threat blocklist and keywords.
  • User Settings: Preferences like shielding enabled/disabled.
  • Metrics: A local count of blocked threats and a history of recent alerts.
  • API Keys: Your personal Groq API key for the AI Assistant.

4. How Data is Shared / Third-Party Services (Processors)

Because we operate with a decentralized architecture, we do not have central backend servers that store your data. However, the extension communicates directly with the following third-party services to function:

  • GitHub (Raw Content): To fetch open-source blocklist updates. No user data is sent.
  • GoPlus Labs: Receives hostnames, contract addresses, and token addresses for real-time risk scoring.
  • Cloudflare Workers: Acts as a proxy to route unsigned transaction payloads to blockchain RPC nodes for simulation.
  • Groq: Receives your AI prompts and API key if you use the AI Assistant.
  • Gumroad: Receives an encrypted license key (via API) to verify PRO subscriptions. No payment or billing data touches the extension.

5. Chrome Web Store Compliance & Limited Use Policy

Crypto Scam Shield strictly adheres to the Chrome Web Store Single Purpose and User Data Policies. We request only the minimum required permissions (storage, alarms, activeTab, declarativeNetRequest, contextMenus, scripting, and specific host permissions) strictly necessary for real-time threat detection.

Limited Use Disclosure:

The use and transfer of information received from Google APIs to any other app will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically, we affirm that:

  • Not Sold: We do not sell user data to third parties.
  • Not Used for Unrelated Purposes: We do not use or transfer user data for purposes that are unrelated to the item's core functionality (security threat detection).
  • Not Used for Credit/Lending: We do not use or transfer user data to determine creditworthiness or for lending purposes.

6. User Rights (GDPR & CCPA Compliance)

Depending on your location, you may have rights regarding your personal data.

  • Right to Access, Rectification, Erasure, and Data Portability: Because we do not store your data on our servers, you have full control over it. You can exercise all of these rights by clearing the extension's local storage in your browser settings or by uninstalling the extension.
  • Do Not Sell My Personal Information (CCPA): We categorically do not sell your personal information.

7. Data Retention & Security

All external data processing (like transaction simulation or URL checks) occurs in transit. The third-party services we utilize are instructed to process requests statelessly. We retain zero user data on developer-controlled servers. Data stored locally on your device is retained until you clear your browser data or uninstall the extension.

8. Security Disclaimer

Crypto Scam Shield is a cybersecurity and threat-detection tool. It does not guarantee the detection, prevention, or elimination of all security threats or cryptocurrency losses. Automated analysis can produce false positives and false negatives. Users remain solely responsible for reviewing and approving transactions, wallet permissions, websites, and tokens before signing or approving them. We do not provide financial, legal, or tax advice.

9. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your data privacy, please contact us via our official support channels on our Gumroad product page.

© 2026 Crypto Scam Shield. All rights reserved.

Home Privacy Terms