Introduction
fraudly.app (“Fraudly”, “we”, “us”) helps you check websites and links for signs of fraud or low trust before you click, buy, or share personal details. We take privacy seriously and aim to be transparent about what we collect, why we use it, and what choices you have — including under the EU General Data Protection Regulation (“GDPR”).
This policy describes our current practices. The product may evolve; when it does, we will update this page and adjust the “Last updated” date above.
Data we collect
Depending on how you use Fraudly, we may process categories such as:
- User-provided data: for example, URLs you submit for analysis, optional feedback or messages you send us, and any other information you voluntarily provide. Please do not submit passwords, payment card numbers, government IDs, or other highly sensitive data.
- Technical data: such as IP address, approximate location derived from IP, browser type and version, device type, operating system, and timestamps. We use this for security, rate limiting, and troubleshooting.
- Usage data: such as pages or screens viewed, interactions with the interface, and events related to feature use (for example, starting or completing a check), where we collect this for analytics or product improvement.
- Cookies and similar technologies: we use strictly necessary cookies (or local storage) where needed for the site to function. Optional analytics or marketing cookies are only used if you allow them via our cookie banner and preferences — see the Cookies section below.
How we use data
We use personal data for purposes such as:
- Providing and improving the service: running checks, showing results, fixing bugs, and developing features.
- Fraud detection and prevention: scoring and explaining risk based on signals you ask us to evaluate (this is informational, not a guarantee of safety).
- Analytics and performance: understanding how the product is used, only where allowed by your cookie choices.
- Security and abuse prevention: detecting spam, misuse, or attacks, enforcing rate limits, and protecting our infrastructure.
Legal basis (GDPR)
Where GDPR applies, we rely on one or more of the following legal bases:
- Consent: for optional cookies and similar technologies (for example analytics or marketing), as set in our cookie preference centre. You can withdraw consent at any time via Cookie Settings in the site footer; that will not affect the lawfulness of processing before withdrawal.
- Legitimate interests: for example operating and securing the service, preventing abuse, understanding aggregate usage in a way that respects your rights, and improving Fraudly — balanced against your interests and rights.
- Contractual necessity: where we need certain data to perform our agreement with you (for example, delivering the check you request when that constitutes a contract under applicable law).
- Legal obligation: where we must retain or disclose data to comply with the law.
Data sharing
We may share data with:
- Service providers: such as hosting (e.g. Vercel), AI providers (e.g. OpenAI for explanations), maps/review APIs (e.g. Google), or analytics tools — only what they need to perform their services, under appropriate agreements.
- Legal and safety: regulators, courts, or law enforcement when required by law or to protect rights, safety, and security.
We do not sell your personal data as “sale” is commonly understood under privacy laws.
Data retention
We keep personal data only for as long as needed for the purposes above — for example, for the duration of a session, to enforce rate limits, to satisfy legal obligations, or to resolve disputes. Technical logs may be kept for shorter rolling periods. When data is no longer needed, we delete or anonymise it where feasible.
Exact retention windows may depend on infrastructure and backups; we will refine this policy as we mature.
Your rights (GDPR)
If GDPR applies to our processing of your personal data, you may have the right to: access your data; rectify inaccurate data; request erasure (“right to be forgotten”) in certain cases; request restriction of processing; data portability where processing is based on consent or contract and is automated; and object to processing based on legitimate interests. You may also withdraw consent for consent-based processing (such as optional cookies) at any time.
To exercise these rights, contact us at support@fraudly.app. You may also lodge a complaint with your local supervisory authority.
Security
We apply reasonable technical and organisational measures designed to protect personal data — for example access controls, encryption in transit where appropriate for our stack, and separation of environments. No method of transmission or storage is 100% secure; we encourage you to use strong devices and networks when handling sensitive decisions.
Third-party services
Fraudly relies on external providers (for example hosting, AI, or data APIs). Their use of data is governed by their own policies and our instructions. We encourage you to read their privacy notices if you want detail on how they process data on our behalf.
International transfers
Some providers may process data outside the European Economic Area (EEA), including in the United States. Where required, we rely on appropriate safeguards recognised under GDPR — for example the EU Commission’s standard contractual clauses (SCCs), plus supplementary measures where appropriate — or other lawful transfer mechanisms.
Changes to this policy
We may update this Privacy Policy from time to time. The latest version will always be published on this page with an updated “Last updated” date. If changes are material, we will take reasonable steps to inform you (for example via the site or email where we have your address).
Contact
Questions about this Privacy Policy or your personal data? Contact us at: support@fraudly.app.