Español · English · Galego · Català · Euskara
← Back to Shield404
Privacy Policy
Last updated: July 2026. Written to be understood at a glance, not to protect us with small print.
One-sentence summary: Shield404 analyses the text you paste to tell you if it's a scam, doesn't store your IP or identifying data, and only asks for your email if you choose to turn on an alert — you can unsubscribe in one click, no questions asked.
1. Who is responsible for your data
Shield404 is an independently operated project. The owner's identification details (name/company name and tax ID) are available in our terms of service and legal notice (ES), as required by Spanish Law 34/2002 (LSSI-CE). You can contact us about any privacy matter at contacto@shield404.com.
2. What legal basis do we use to process your data?
Under the GDPR (Article 6), we process your data under these legal bases, depending on the case:
- Your explicit consent (art. 6.1.a): when you voluntarily enter an email or phone number to turn on a watch, ticking the relevant consent box. You can withdraw this consent at any time by deleting your data at shield404.com/mis-datos.html.
- Legitimate interest (art. 6.1.f): for the technical analysis of links and text, the community's scam memory (with anonymous fingerprints, never personal data), and preventing automated abuse of the service.
3. What data we process, and what we NEVER process
When you analyse a link, message or phone number
- We store the content analysed (the link or text pattern) and the verdict, so the next person who asks the same thing gets an instant answer, and to feed the community scam radar.
- We don't store your IP address. To limit abuse we use an anonymous, irreversible fingerprint (a hash with a key that changes every time the server restarts) — not even we can trace it back to your real IP. The web server's own technical logs are kept for a maximum of 7 days and are only used to detect technical problems.
- Before storing any link, we strip parameters that might contain personal data (tokens, emails in the URL).
- Before storing any text report, we automatically remove any emails, bank account numbers and ID numbers that appear in it.
When we check a password
- Your password never leaves your device. It's turned into a cryptographic fingerprint in your own browser, and only the first 5 characters of that fingerprint are sent to a specialised external service (k-anonymity) — it's mathematically impossible to reconstruct your password from that information.
When you turn on a watch (email alerts)
- We store the email or phone number you provide, solely so we can notify you.
- You can unsubscribe at any time with a single click, no password or justification needed, from the link included in every email we send you.
When you check an attachment or photo
- The file is never uploaded to our servers. It's analysed inside your own browser. Only if you have the VirusTotal check enabled is the file's cryptographic fingerprint sent (never the file itself).
4. Who we share data with
To provide the service, some checks (never with your personal data, only with the content to analyse) are sent to specialised external services:
- Google Safe Browsing and VirusTotal: link and file reputation.
- Have I Been Pwned (password checks, only if it's not already in our own local list of very common passwords; via k-anonymity: only 5 characters of a fingerprint travel, never your password) and XposedOrNot (email breaches).
- AbuseIPDB: IP address reputation.
- URLhaus and OpenPhish: free, public sources of already-known malicious domains, which we download periodically to enrich our own Red List. This doesn't involve sending them any of your data: we only receive information from them.
- Google Custom Search: checking whether a piece of data (ID number, phone, name) appears published on the indexed web.
- ipwho.is: approximate geolocation of your internet provider, only if you use the "Is someone tampering with my connection?" tool.
- Groq (or whichever AI provider is active at the time): processes the text of your query to the advisor, after automatically removing emails, bank account numbers, ID numbers and phone numbers.
- Resend: sending confirmation emails and watch alerts, only to the email address you provided.
Each one has its own privacy policy, and only receives the minimum information necessary to respond (for example, a URL or a password fingerprint, never your identity).
International transfers: some of these providers (including Groq, Resend, AbuseIPDB and Google) have servers outside the European Economic Area, mainly in the United States. When this happens, the transfer is covered by the protection mechanisms the GDPR provides for these cases (such as the EU-US adequacy framework or other equivalent safeguards recognised by European regulations). You can ask us for more detail about a specific provider by writing to contacto@shield404.com.
We do not sell, rent or share data for advertising purposes. There are no ads on Shield404 and there never will be.
5. How long we keep the data
Link analyses are kept for as long as they're useful to the community memory (detecting repeated scams). You can request the deletion of any data associated with you by writing to contacto@shield404.com.
6. Your rights (GDPR)
You have the right to access, rectify, delete, restrict processing, object to, and request portability of any data we may hold about you. Since we don't use accounts or passwords, identification is done by verifying you know the exact data (your watched email or phone number).
🗑️ You can delete your data yourself, instantly: visit shield404.com/mis-datos.html, enter the email or phone number you set up for watching, and we'll send a link to that same inbox to confirm the complete deletion. No need to write to us or wait for a reply.
If you believe we haven't handled your request correctly, you can file a complaint with the Spanish Data Protection Agency (AEPD).
7. Minors
Shield404 is designed to protect people of all ages, including the most vulnerable. We don't ask for or verify the age of whoever uses the tool, because we don't require sign-up. If you're a minor's guardian and want more information on how to protect them, you can write to us.
8. Changes to this policy
If we make a significant update to this policy, we'll indicate it with the "last updated" date at the top of this page.
Any questions? Write to us at contacto@shield404.com. We always reply in plain language, with no unnecessary jargon. (Please note our team generally corresponds in Spanish.)