Privacy Notice

Privacy should be understandable.

Effective: August 24, 2026 · Last updated: August 24, 2026

This notice explains how Scam Ba ’To? handles information when you use the public website and message checker. The project follows a data-minimization approach: do not submit secrets, and only information reasonably necessary to provide and protect the service should be processed.

1. Who operates this service

Scam Ba ’To? is an independently developed public-interest technology project operated by John Clement S. Escobañez. National University affiliation is used for professional identification and does not by itself make the University the operator or personal information controller of this service.

2. Information you provide

When you submit a message for checking, the server processes the text you provide to generate risk guidance. You should not submit an OTP, PIN, password, CVV/CVC, full payment-card number, government identification number, recovery phrase, or other secret credential.

3. Automated redaction

Before analysis, the application attempts to redact several obvious sensitive-value patterns, including OTP-like values, PINs, CVV/CVC values, passwords or passcodes, account numbers, and card-like numbers while preserving context needed for scam analysis. Automated redaction is a safeguard, not a guarantee that every sensitive value will be detected.

4. Purpose of processing

Submitted text is processed to provide the checker result, explain relevant risk signals, protect the service from abuse, maintain security, and diagnose technical failures. Processing is limited to purposes reasonably connected with operating and securing the service and providing the result requested by the user.

5. Network and technical data

The service may process limited technical information such as network address, request timing, browser or protocol information, and security events as necessary for rate limiting, security, delivery, and troubleshooting. The application rate limiter uses a salted identifier derived from the client network address rather than displaying that address as part of the analysis result. Hosting and infrastructure providers may process technical logs under their own service terms.

6. Message retention

The normal analysis flow is designed not to intentionally store the original submitted message in the application database after returning the result. Infrastructure, security, or error logs may temporarily contain technical request information depending on the production provider and configuration. The project does not use submitted messages for advertising profiles or sell them as personal data.

7. Cookies and browser storage

The current public build does not use advertising or behavioral-tracking cookies. Essential browser storage may be used to remember interface preferences such as language or privacy choices. If non-essential analytics, advertising, or materially different tracking is introduced, this notice and the relevant controls will be updated before that processing is relied upon.

8. Verified links and third-party services

Results may contain independently verified links to banks, e-wallets, government agencies, schools, utilities, couriers, platforms, or other organizations. Opening an external site leaves Scam Ba ’To? and makes that organization’s own privacy notice and terms applicable. A verified destination does not mean Scam Ba ’To? controls that external service.

9. Security

The project uses safeguards including input sanitization, sensitive-value redaction, request limits, security headers, and conservative handling of verified destinations. No internet service can guarantee absolute confidentiality, integrity, availability, or protection from every attack.

10. Data sharing

Scam Ba ’To? does not sell submitted personal data. Information may be processed by infrastructure providers to host, secure, and deliver the service, or disclosed when required by applicable law, lawful process, or when reasonably necessary to protect users, the service, or legal rights.

11. Your privacy rights

Subject to the Data Privacy Act of 2012 and other applicable rules, data subjects may have rights including being informed, access, correction, objection, erasure or blocking when warranted, data portability where applicable, and the right to lodge a complaint with the National Privacy Commission. Because the normal checker flow is designed not to maintain user accounts or intentionally retain original submitted messages, the project may not possess data that can later be retrieved by identity.

12. Children and sensitive information

The checker is not designed to collect sensitive personal information from children or to serve as a repository for identity documents, financial credentials, medical information, or other highly sensitive records. Users should remove unnecessary personal details before submitting a message.

13. Changes to this notice

This notice may be revised when the service’s hosting, analytics, security controls, retention practices, features, or legal obligations materially change. The effective or last-updated date on this page will be changed when a material revision is published.

14. Privacy contact

Privacy questions, requests, or concerns may be sent to jsescobanez@national-u.edu.ph. You may also contact the Philippine National Privacy Commission regarding rights and complaints under applicable privacy law.