Effective October 4, 2026
The short version
- Danger Stamp looks at the pages, emails and messages you see so it can warn you about scams. That is the only thing we use it for.
- The first checks run on your computer. On the Free plan, nothing you read ever leaves it.
- On Pro, only things that already show scam warning signs are sent for an AI check, with card, account and ID numbers blanked out first, and only after you agree.
- We don't store or log what was checked. We don't sell data, show ads, or use it to train AI.
Who we are
Danger Stamp is a Google Chrome extension and this website, dangerstamp.com. It warns people about scams on websites, in webmail, in chats, and in comments and ads. In this policy, "we" and "us" means Danger Stamp. Questions about privacy go to hello@dangerstamp.com.
What the extension reads
To spot a scam, the extension has to see what you see. While you browse, it reads, on your computer:
- Web pages: the site's name, the page title, the visible text, the labels of form boxes (like "Password" or "Card number"), logos, and where buttons and links go.
- Webmail: the email you have open in Gmail, Outlook.com, Yahoo, AOL and other webmail: sender, subject, body, where its links go, and any QR code in it.
- Chats: the conversation you have open in supported chat and messaging sites.
- Comments, posts and ads: on sites like YouTube, Facebook, X, LinkedIn and Reddit.
The first checks run right there, on your computer: warning signs, simple rules, and a list of real brands and banks and their official websites. Most pages stop there. Passwords and what you type into forms are never sent anywhere.
An email or chat can only ever be sent for an AI check (on a paid plan, see below) if it contains words that often mean a scam, like a payment request, a code or a link. Ordinary messages never leave your computer.
On the Free plan
The Free plan never uses the AI, ever. Nothing you read leaves your computer. Only these things go between the extension and our server:
- Rule downloads. The extension downloads our rules and the list of brands and banks every few hours, when they change. These are the same for everyone and say nothing about you.
- A one-time registration. When you install it, the extension asks our server for a random ID for this browser. It isn't linked to your name, email or anything you do.
- Your plan. From time to time the extension asks which plan this browser is on, using that random ID.
- A count. About once an hour the extension sends how many checks it ran on your computer since the last time. Just the number, nothing about what was checked. It's used for the "checks this month" count. It also includes counts of whether each site reader (like the Gmail or Amazon reader) found what it looks for, numbers only, so we can fix a reader when a site changes its layout. They say which kinds of site were read (Gmail, Amazon), never which page or what was on it, and our server only keeps them added up across everyone, never per browser. Email and chat readers aren't counted when you switch email and chat checks off.
On Pro and Pro Family: AI checks
Some scams can only be told apart from the real thing by reading the whole page or message. On a paid plan, when something on your screen already shows scam warning signs, the extension sends a copy of what's needed to our server, which asks our AI provider, TypeSafe, and sends back a verdict. This only starts after you turn on AI checks in the extension, on a screen that explains what is sent. Every browser asks for itself, including each one on a family plan. Until you say yes, a paid browser checks only on your computer, like Free.
What is sent, depending on what you're looking at:
- For a page: the site's name (never the full web address, so never anything after it like reset links or codes), the title, the visible text (up to a few thousand characters), words from its logo, the labels of its form boxes, and the website names its form and links go to.
- For an email: the sender's name and address, the subject, the text, and the website names its links and QR codes point to.
- For a chat: the recent messages in the conversation.
- For a comment, post or ad: its text and the name it was posted under.
Before anything leaves your computer, the extension blanks out card numbers, account and routing numbers, social security and other ID numbers, and other people's email addresses. Our server blanks them again, in case anything slipped through.
The verdict comes back and the check is gone. We don't store or log what was checked. Our server's only record is a count: this browser used one AI check this month, and, if the AI found a scam, that it did and on which day (not the time, and never what it was). The payer of a plan sees those counts for each browser on the plan.
TypeSafe. TypeSafe runs the AI that does these checks. Under its privacy policy, it doesn't train its AI on what we send or share it with anyone except the services it runs on, and keeps data only as long as it needs to run the service. We have asked TypeSafe to confirm that it keeps nothing we send, and will update this page when it does.
How old a website is
Brand-new websites are a common scam sign. On a paid plan, when a page has already set off a warning sign, our server may look up the date the website's name was registered in the public domain records (RDAP, through rdap.org). Only the website's name is looked up, never the full address, and never from a Free browser. We keep the registration date of that website name for up to a week, so we don't look it up again, but never who asked.
"Check this"
You can ask Danger Stamp to check a message: select text and right-click "Check this with Danger Stamp", paste it into the extension's toolbar button, or paste it on our website.
- In the extension on Free, it is checked on your computer only.
- In the extension on Pro, the text you chose goes for an AI check like above.
- On our website, the text you paste is sent to our server and checked by the AI, free, because you asked.
Card, account and ID numbers and other people's email addresses are blanked out first. Only the text you chose is checked, and nothing is kept.
False alarms and scam reports
False alarms. When you press FALSE ALARM, the choices to unlock the page or always trust a site are saved on your computer only. Telling us it got it wrong is a separate box, unticked unless you tick it. If you tick it, we receive the page's address without anything after a "?" and the name of the warning, so we can fix it.
Scam reports. When you send a report on our report page, we keep what you wrote: where you saw the scam, what it said, what you gave them (if you tick any), anything else you tell us, and your email address only if you choose to give it so we can reply. Links in reports are never opened automatically. Reports are kept privately and used only to learn new scams and to test Danger Stamp.
Screenshots in a report. You can add up to 3 screenshots. Before they leave your computer or phone, your browser shrinks each one and saves it again as a new picture, which leaves behind the hidden details a photo can carry, such as where and when it was taken. Only the pictures you add are sent, and only when you press Send report. We keep them on our server with the report, and only the Danger Stamp team looks at them, to understand the scam. They are never shared, sold or used to train AI, and they are deleted automatically 90 days after you send them. Please crop or cover your own name, address, card and account numbers first.
The extension never sends a report by itself. Its "Report this scam" link only opens this report page with where you saw it filled in; nothing is sent until you press Send report.
Accounts and payments
There are no passwords and no sign-up form. All our server keeps about people is:
- for each browser: a scrambled (hashed) copy of its random ID, so the file can't be used to act as anyone; when it was set up; a name if you give it one (like "Mom"); and this month's counts of checks, AI checks and AI warnings, plus the date of the last AI warning;
- for each paid plan: which plan it is and its billing status, the payer's email address and customer number from Stripe, and which browsers belong to it.
On Pro Family, everyone on the plan sees each browser's name and counts, and family members also see the payer's email address, so they know who to ask for help.
Payments are handled by Stripe. Your card details go to Stripe, never to us.
Using your plan on a new browser. If you ask, we email a 6-digit code to the payer's email through our email service, Resend. The code is kept scrambled, in memory only, for 15 minutes.
To stop abuse, our server keeps a short-term count of requests per internet connection, in memory only, for an hour at most. It is never written down.
Other companies we use
- TypeSafe: the AI for paid checks and website "Check this" (privacy policy).
- Stripe: payments and receipts.
- Resend: the plan code email.
- Railway runs our server, and Vercel runs this website. Like any host, they handle the internet connections and may keep standard technical records, such as connection addresses, for a short time under their own policies.
- rdap.org: public website registration dates.
This website has no ads, no tracking, no analytics and no third-party scripts, and it doesn't set cookies. It only remembers whether you turned the demo sound off, in your own browser.
What we never do
We use what Danger Stamp reads only to warn you about scams, the feature you installed it for. We never:
- sell or rent data to anyone;
- use it for advertising, or to build a profile of you;
- use it to train AI;
- store or log pages, emails, chats or anything else that was checked;
- let a person read it.
This follows the Chrome Web Store User Data Policy, including its Limited Use requirements.
Your settings
Click the Danger Stamp button in your toolbar to change these at any time:
- Check emails and chats. Switch it off and the extension stops checking webmail and chats altogether.
- AI checks (paid plans). Off until you turn them on. Switch them off any time and nothing more is sent.
- Low-quality content warning. Off unless you turn it on. When it is on and AI checks are on (Pro), social posts on X, LinkedIn, Reddit and Facebook that show several signs of AI-written filler are checked the same way as other items: the post's text, redacted, with nothing kept.
- Child mode. Adds warnings for grooming and gambling sites and a 10-second wait before unlocking. The only extra thing an AI check learns is that child mode is on.
- Trusted sites. The sites you told it to trust, kept on your computer. You can remove them.
Uninstalling removes the extension and everything it saved on your computer, including its random ID. What's left on our server is that browser's scrambled ID and counts, which can no longer be linked to you.
How long we keep things, and deleting them
- What was checked: not kept at all.
- Browser records and plan details: while the browser or plan is in use. Counts start again each month.
- Plan codes: 15 minutes, in memory.
- Scam and false-alarm reports: as long as they help us catch scams. Ask, and we'll delete yours.
- Screenshots in a scam report: 90 days, then deleted automatically.
- Our running-cost totals (requests and AI checks per day, nothing about anyone): about a year.
To see or delete what we have about you, email hello@dangerstamp.com from the address your plan uses (or tell us which report). We'll delete your account record and reply within 30 days. Stripe keeps its own payment records as the law requires; cancel your plan with Manage billing in the extension first.
Children
Danger Stamp is set up and paid for by adults. A parent can turn on child mode for a child's browser. We don't knowingly collect personal information from children, and a child's browser sends nothing more than any other browser on the same plan. If you think we have a child's personal information, email hello@dangerstamp.com and we'll delete it.
Changes to this policy
If what Danger Stamp collects or sends changes, we'll update this page and its date first. For a big change, such as sending something new, the extension will tell you and ask again before it does.
Using Danger Stamp is also covered by our terms of service.
Contact us
Email hello@dangerstamp.com with any question about privacy.