Introduction
fraudly.app (“Fraudly”, “we”, “us”) helps you check websites and links for signs of fraud or low trust before you click, buy, or share personal details. We take privacy seriously and explain clearly what we collect, why we use it, and what choices you have—including under the EU General Data Protection Regulation (GDPR).
This policy describes our current practices. The product may evolve; when it does, we update this page and change the date above.
Fraudly does not track you across apps or websites for advertising, and we do not share data with data brokers or ad networks.
Data we collect
Depending on how you use Fraudly, we may process categories such as:
- What you provide: URLs you submit for checks; optional Premium uploads such as screenshots or photos for screenshot analysis or QR code checks; optional feedback or messages; and other information you choose to share. Please do not submit passwords, payment card numbers, government IDs, or other highly sensitive data.
- Technical data: IP address, approximate location from IP, browser and device type, operating system, and timestamps—for security, rate limiting, and troubleshooting.
- Usage data: pages viewed, interactions with the interface, and events related to feature use (for example starting or completing a check), where we collect this for analytics or product improvement.
- Cookies and similar technologies: strictly necessary cookies or local storage where needed for the site to work. Optional privacy-friendly analytics only run if you allow them via our cookie banner—see the Cookies section below. We do not use advertising or cross-app tracking cookies.
How we use data
We use personal data for purposes such as:
- Providing and improving the service: running checks, showing results, fixing bugs, and developing features.
- Fraud detection and prevention: scoring and explaining risk based on signals you ask us to evaluate (informational only—not a guarantee of safety).
- Premium screenshot analysis and QR code checks: analysing images or QR codes you upload when you use those Premium features.
- Analytics and performance: understanding how the product is used, only where allowed by your cookie choices.
- Security and abuse prevention: detecting spam, misuse, or attacks, enforcing rate limits, and protecting our infrastructure.
Legal basis (GDPR)
Where GDPR applies, we rely on one or more of the following legal bases:
- Consent: for optional privacy-friendly analytics cookies, as set in our cookie preference centre. You can withdraw consent anytime via Cookie Settings in the site footer; that does not affect processing before withdrawal.
- Legitimate interests: operating and securing the service, preventing abuse, understanding aggregate usage in a way that respects your rights, and improving Fraudly—balanced against your interests.
- Contractual necessity: where we need certain data to perform our agreement with you (for example delivering the check or Premium analysis you request when that constitutes a contract under applicable law).
- Legal obligation: where we must retain or disclose data to comply with the law.
Data sharing
We may share data with:
- Service providers: such as hosting (e.g. Vercel), AI providers (e.g. OpenAI for explanations and optional Premium image analysis), maps or review APIs (e.g. Google), or analytics tools—only what they need to perform their services, under appropriate agreements.
- Legal and safety: regulators, courts, or law enforcement when required by law or to protect rights, safety, and security.
We do not sell your personal data as “sale” is commonly understood under privacy laws.
We do not share personal data with data brokers or advertising networks for cross-app or cross-website tracking.
Data retention
We keep personal data only as long as needed for the purposes above—for example for the duration of a session, to enforce rate limits, to satisfy legal obligations, or to resolve disputes. Technical logs may be kept for shorter rolling periods. When data is no longer needed, we delete or anonymise it where feasible.
Uploaded image files used for Premium screenshot analysis or QR code checks are processed for your request and are not permanently stored by Fraudly as image files. Limited analysis metadata (for example a content hash or short summary) may be retained if you attach results to a website check, under the same retention approach as other check data.
Exact retention windows may depend on infrastructure and backups; we will refine this policy as we mature.
Your rights (GDPR)
If GDPR applies to our processing of your personal data, you may have the right to: access your data; rectify inaccurate data; request erasure (“right to be forgotten”) in certain cases; request restriction of processing; data portability where processing is based on consent or contract and is automated; and object to processing based on legitimate interests. You may also withdraw consent for consent-based processing (such as optional cookies) at any time.
To exercise these rights, contact us at support@fraudly.app. You may also lodge a complaint with your local supervisory authority.
Security
We apply reasonable technical and organisational measures designed to protect personal data—for example access controls, encryption in transit where appropriate, and separation of environments. No method of transmission or storage is 100% secure; we encourage you to use strong devices and networks when handling sensitive decisions.
Third-party services
Fraudly relies on external providers (for example hosting, AI, or data APIs). Their use of data is governed by their own policies and our instructions. You can read their privacy notices if you want more detail on how they process data on our behalf.
International transfers
Some providers may process data outside the European Economic Area (EEA), including in the United States. Where required, we rely on appropriate safeguards recognised under GDPR—for example the EU Commission’s standard contractual clauses (SCCs), plus supplementary measures where appropriate—or other lawful transfer mechanisms.
Browser extension (Chrome and Edge)
If you install the Fraudly browser extension, it checks the website in your active tab when you open the extension or when you enable optional Live Protection (Premium). The extension is designed not to build a browsing history.
When you run a check, the extension sends the active tab’s URL to Fraudly’s servers over HTTPS. This is required for real-time security analysis, including path-specific phishing detection (for example, whether a particular page on a domain shows suspicious signals). We do not use this to reconstruct where you have browsed over time.
On your device, the extension does not store a history of safe websites. Results that Fraudly treats as generally safe (trust score 65 or higher) are kept only in short-lived memory for the current browsing session and are not written to extension storage. When you leave a site, that transient result is not saved on disk.
The extension may store limited Protection Events locally when there is meaningful security value—for example high-risk warnings, suspicious indicators, or threats you asked us to analyse with Deep Scan. These events record the hostname and warning context, not a timeline of your browsing.
Privacy-sensitive destinations (such as banking, healthcare, government, or email login pages) may be analysed for live protection when you check or enable Live Protection. They are not saved locally unless Fraudly identifies a confirmed public threat (for example phishing or malware signals).
The extension does not read page content, passwords, or form fields. It does not include third-party advertising or analytics SDKs. It may send privacy-safe product analytics to Fraudly (for example whether Premium education was shown or a Premium CTA was clicked) without browsing history, scanned URLs, or domain names. Optional Premium account status may be cached briefly on your device after you sign in on Fraudly.app.
You can remove extension data by uninstalling the extension or clearing its data in your browser settings.
Changes to this policy
We may update this Privacy Policy from time to time. The latest version will always be published on this page with an updated date. If changes are material, we will take reasonable steps to inform you (for example via the site or email where we have your address).
Contact
Questions about this Privacy Policy or your personal data? Contact us at: support@fraudly.app.
- Chamber of Commerce (KVK) number
- 42105805
- Establishment number (vestigingsnummer)
- 000066091004
- VAT ID
- NL005497525B11
- Registered office
- Houtrustweg 353, 2583 LL 's-Gravenhage, The Netherlands
Fraudly is an online service. The address above is our registered business location, not a walk-in shop or visitor office.