Legal
Privacy policy
What is collected from reporters, what gets published, what is redacted, and how to have your details removed.
01The short version
We collect as little as possible. Reporters appear under a first name or initials only, or anonymously on request. Your email address, phone number, home address, banking details, wallet addresses you personally control, and payment records are never published. Nothing is sold or rented to anyone.
02What is collected when you file a report
Nothing in the form is required beyond the domain and a description of what happened. If you would rather we have no way to contact you, leave the email field blank and submit anyway.
- The incident details you describe: the domain or platform, the brand name, amounts, payment rail, identifiers, and dates.
- Any name or initials you choose to give, and an email address if you want an analyst to be able to follow up.
- Files you email voluntarily, such as screenshots, chat exports, invoices, or transaction records.
03What appears in a published alert
A published alert contains the domain and trading identity of the reported operation, open-source records about that domain, the operation's own wallet addresses and handles, the reported loss, the payment rail, the dates, and a narrative of the mechanics. Where a reporter is credited it is by first name or initials only.
Personal information about the reporter — contact details, exact address, employer, and full account or card numbers — is removed before publication. Where a document or screenshot is reproduced, identifying details in it are masked.
04Information about reported operations
Alerts also process information about the people running reported sites. This is limited to what the public-interest purpose requires: trading identities, domains, publicly filed registration records, the payment destinations used to receive funds, and the contact details the operation itself published or used to solicit targets. Home addresses and family details of individuals are not published.
05Analytics and server logs
We use privacy-respecting aggregate analytics to see which alerts are being found and to detect bulk scraping. There are no advertising trackers and no audience data is sold. Our hosting provider retains standard server logs, including IP addresses, for a limited period for security and abuse prevention.
07Retention
Published alerts are retained indefinitely, because their entire value is that they remain findable years later when the same identifiers resurface under a new brand. Unpublished submissions, correspondence, and evidence files are retained while a record remains open and for a reasonable period afterwards to support law enforcement requests.
08Your requests
Send requests to alerts@scamalerted.com, from the address you originally wrote from where possible.
- You can ask what we hold about you, ask for your name to be removed from a published alert, or ask for your contact details to be deleted from our records.
- You can withdraw a report before publication and it will not be published.
- We cannot always unpublish the underlying factual record of a documented fraud, because that record concerns the reported operation rather than you — but your role in it can be fully anonymised.
09Security
Submissions are transmitted over encrypted connections and evidence files are stored with restricted access. No system is perfect, so please never send full account numbers, government identity numbers, passwords, or wallet seed phrases. They are never needed here, and any request for them is itself a scam.
10Children
This site is intended for adults and is not directed at children under 13. We do not knowingly collect their information.
11Changes
Material changes to this policy are reflected in the date shown at the top of this page. Continued use of the site after a change indicates acceptance of the updated policy.
Privacy questions and data requests go to alerts@scamalerted.com.