Digiscam ("we", "us") provides an AI-powered scam-detection service over WhatsApp. We are committed to processing as little personal data as technically possible.
What we collect
Phone number hash. When you forward a message to our WhatsApp bot, we receive your phone number from WhatsApp. We immediately convert it to a one-way SHA-256 hash and discard the original. We use the hash only to enforce rate limits (e.g. 20 scans/day).
Message content. The text or image you forward is sent to our AI provider (currently OpenAI) for analysis. We retain only the AI's verdict (risk score, flags, recommendation) and a short neutral description of the input — never the raw text or image you sent.
Technical logs. We log timestamps, anonymous request IDs, and the WhatsApp message ID for de-duplication and abuse prevention.
What we do not collect
Your name, contacts, profile picture, or any WhatsApp metadata beyond the inbound message.
Browsing data — we use no tracking cookies or analytics pixels on this site.
Account credentials — there is no account or login.
Who we share data with
OpenAI — for AI analysis. OpenAI does not use API data to train models by default.
Twilio (or our WhatsApp provider) — to deliver the reply to your phone.
We do not sell or share data with advertisers.
How long we keep it
Scan verdict records (without raw content) are retained for up to 90 days to support rate limiting and dedupe. Logs are rotated after 30 days. Phone-hash records are pruned once they are no longer needed for limits.
Your rights
If you are in the EU/EEA, UK, or Morocco, you have the right to access, correct, or delete your data. Because we hash your phone number and discard raw content, the practical scope of personal data is minimal. To exercise a right, email hello@digiscam.com from any address — or send "DELETE ME" via WhatsApp to the bot.