PRIVACY POLICY — AGRONOS PTY LTD · ACN [YOUR ACN] · LAST UPDATED APRIL 2026
Legal

Privacy Policy

This Privacy Policy explains how ScamShield AI, operated by Agronos Pty Ltd, collects, uses, stores and protects your personal information when you use our website, web scanner, Telegram bots and related services.

Effective: April 2026 Jurisdiction: Australia Operator: Agronos Pty Ltd

1. Overview

ScamShield AI is an AI-powered scam detection platform operated by Agronos Pty Ltd (ABN/ACN to be inserted), headquartered in Australia. We are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using our website at scamshieldai.com.au, our web scanner, our Telegram bots (@TheScamShieldAIBot and @ScamShieldProBot), or any related service, you agree to the collection and use of information as described in this policy.

We do not sell your personal information to third parties. We do not use your submitted content for advertising. ScamShield AI products are ad-free.

2. Information We Collect

Information you provide directly

  • Text messages, email content, URLs, phone numbers, crypto addresses and other content you paste or submit for scanning
  • Screenshots and images you upload for analysis
  • Email address if you subscribe to scam alerts or create an account
  • Payment information processed via Stripe (we do not store card details — Stripe handles this directly)
  • Support enquiries and communications sent to support@scamshieldai.com.au

Information collected automatically

  • Browser type, operating system and device information
  • IP address and approximate location (country/region level only)
  • Pages visited, scan types used and session duration
  • Telegram user ID when using our bots (no messages are stored beyond what is needed to deliver scan results)
  • Cookies and similar tracking technologies (see Section 6)

Information from third-party services

When you submit content for scanning, we may receive risk data, threat intelligence and analysis results from third-party APIs including VirusTotal, Google Safe Browsing, Have I Been Pwned, GoPlus Security, Chainabuse, and Anthropic Claude AI. We do not receive personal information from these providers about you — only analysis results relating to the content you submitted.

3. How We Use Your Information

We use the information we collect to:

  • Deliver scam detection results and analysis in response to your scan requests
  • Improve the accuracy and coverage of our scam detection models
  • Process payments and manage your subscription via Stripe
  • Send scam alert newsletters and product updates (only if you have opted in)
  • Respond to support requests and communications
  • Compile anonymised, aggregated scam intelligence reports submitted to ACMA, AFP ReportCyber and Australian banks
  • Monitor for abuse, fraud and security threats to our platform
  • Comply with legal obligations under Australian law

We do not use submitted content (messages, screenshots, links) for advertising, profiling, or sale to third parties. Scan content may be used in anonymised, aggregated form to improve detection accuracy.

4. Sharing Your Information

We share your information only in the following circumstances:

  • Third-party scan APIs: Content you submit for scanning is sent to VirusTotal, Google Safe Browsing, Have I Been Pwned, GoPlus Security, Chainabuse and Anthropic Claude AI to generate analysis results. Each provider's privacy policy applies to data processed by them.
  • Stripe: Payment details are processed directly by Stripe, Inc. We receive confirmation of payment status only. Stripe's privacy policy governs their handling of your payment data.
  • Supabase: User account data and scan logs are stored in Supabase (a US-based cloud database provider). Data is stored in compliance with Australian Privacy Principles.
  • Law enforcement and regulators: We may disclose information where required by Australian law, court order, or to comply with a request from a government authority including the Australian Federal Police, ACMA or ASIC.
  • Aggregated scam reports: Anonymised, non-identifying scam reports are submitted weekly to ACMA, ReportCyber (AFP), and major Australian banks as part of our community reporting program.

We do not sell, rent or trade your personal information to any third party for marketing or commercial purposes.

5. Data Storage & Security

Your data is stored on servers operated by Supabase and Railway, both of which maintain industry-standard security certifications. We implement the following security measures:

  • All data transmission encrypted via HTTPS/TLS
  • Database access restricted to authenticated services only
  • API keys and credentials stored as environment variables, never in code
  • Regular security reviews of third-party dependencies
  • Stripe handles all payment card data — we never store card numbers

We retain scan logs for up to 90 days for the purpose of improving detection accuracy, after which they are deleted or irreversibly anonymised. Account information is retained for the duration of your subscription and for a reasonable period thereafter as required by law.

While we take reasonable steps to protect your information, no system is completely secure. If you believe your data has been compromised, contact us immediately at support@scamshieldai.com.au.

6. Cookies

We use cookies and similar technologies to operate our website and improve your experience. Specifically:

  • Essential cookies: Required to maintain your login session and deliver core functionality
  • Analytics cookies: Used to understand how visitors use the site, helping us improve usability. Data is aggregated and anonymous.
  • Payment cookies: Set by Stripe to process transactions securely

You can control cookie settings through your browser. Disabling essential cookies may affect site functionality. We do not use advertising or tracking cookies for targeted advertising.

7. Third-Party Services

Our service integrates with the following third-party providers. Their privacy practices are governed by their own policies:

  • Anthropic (Claude AI) — anthropic.com/privacy
  • VirusTotal (Google LLC) — virustotal.com/privacy
  • Google Safe Browsing — policies.google.com/privacy
  • Have I Been Pwned — haveibeenpwned.com/Privacy
  • GoPlus Security — gopluslabs.io
  • Chainabuse — chainabuse.com/privacy
  • Stripe — stripe.com/au/privacy
  • Supabase — supabase.com/privacy
  • Telegram — telegram.org/privacy

We are not responsible for the privacy practices of these third parties. We encourage you to review their policies.

8. Your Rights

Under the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Request deletion of your personal information (subject to legal retention requirements)
  • Opt out of marketing communications at any time via the unsubscribe link in any email
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have mishandled your information

To exercise any of these rights, contact us at support@scamshieldai.com.au. We will respond within 30 days.

9. Children's Privacy

ScamShield AI is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at support@scamshieldai.com.au and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify registered users by email.

Your continued use of ScamShield AI after any changes to this policy constitutes your acceptance of the updated terms.

12. International Users

ScamShield AI is operated by Agronos Pty Ltd, an Australian company. If you access our Service from outside Australia, additional rights and obligations may apply to you under your local laws. The following provisions apply to users in specific countries.

🇬🇧 United Kingdom

If you are located in the United Kingdom, your use of ScamShield AI is subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Under UK GDPR, you have the following rights in addition to those listed in Section 8:

  • The right to data portability — to receive your personal data in a structured, machine-readable format
  • The right to object to processing based on legitimate interests
  • The right not to be subject to solely automated decision-making that produces legal or similarly significant effects
  • The right to withdraw consent at any time where processing is based on consent

Our lawful basis for processing your personal data is: (a) performance of a contract when providing scan services you have requested; (b) legitimate interests in improving our scam detection capabilities; and (c) your consent for marketing communications. We do not transfer your personal data outside the UK/EEA except to service providers with appropriate safeguards in place. To exercise your UK GDPR rights or lodge a complaint, contact us at support@scamshieldai.com.au. You may also complain to the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113.

🇺🇸 United States

If you are located in the United States, the following applies. ScamShield AI does not sell personal information as defined under US state privacy laws. If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including:

  • The right to know what personal information we collect, use, disclose or sell
  • The right to delete personal information we hold about you (subject to exceptions)
  • The right to opt out of the sale or sharing of personal information — we do not sell your data
  • The right to non-discrimination for exercising your privacy rights
  • The right to correct inaccurate personal information
  • The right to limit use of sensitive personal information

If you are a resident of Virginia, Colorado, Connecticut, Texas, Utah or another state with a comprehensive privacy law, similar rights may apply. To submit a privacy request, contact support@scamshieldai.com.au with the subject line "US Privacy Request" and include your state of residence. We will respond within 45 days as required under applicable state law.

ScamShield AI is not directed at children under 13. We comply with the Children's Online Privacy Protection Act (COPPA) and do not knowingly collect data from children.

🇨🇦 Canada

If you are located in Canada, your personal information is handled in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including Quebec's Law 25 (Act 25) where applicable.

  • We collect, use and disclose personal information only with your knowledge and consent, or as permitted by law
  • You have the right to access your personal information and request corrections
  • You may withdraw consent at any time, subject to legal or contractual restrictions
  • We retain personal information only as long as necessary to fulfil the purposes for which it was collected

Quebec residents have additional rights under Law 25, including the right to data portability and the right to be informed of any automated decision-making. To exercise your rights under Canadian privacy law, contact support@scamshieldai.com.au. Unresolved complaints may be directed to the Office of the Privacy Commissioner of Canada at priv.gc.ca.

🇳🇿 New Zealand

If you are located in New Zealand, your personal information is handled in accordance with the Privacy Act 2020 (NZ) and the New Zealand Privacy Principles (NZPPs). Under the Privacy Act 2020, you have the right to:

  • Access personal information we hold about you
  • Request correction of inaccurate information
  • Be informed of how your information is being used
  • Make a complaint if you believe we have breached the Privacy Act 2020

We are required to notify you and the New Zealand Privacy Commissioner of any privacy breach that is likely to cause serious harm. To exercise your rights, contact support@scamshieldai.com.au. Complaints may be directed to the Office of the Privacy Commissioner of New Zealand at privacy.org.nz or on 0800 803 909.

13. Contact Us

For privacy-related questions, access requests or complaints, contact us at:

Agronos Pty Ltd — ScamShield AI

Email: support@scamshieldai.com.au

Website: www.scamshieldai.com.au

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.