Privacy
Privacy Policy
LEGITTAP analyzes text, phone numbers, links, and images for scam and fraud indicators. This policy explains what information is processed, what is retained, and which service providers may receive data.
1. Information we process
Account information
When you create an account, LEGITTAP uses Supabase Authentication. We process your account identifier, email address, authentication information handled by Supabase, and an optional display name.
Scan content
Depending on the scan you start, LEGITTAP may process:
- text you paste or share into the app;
- a phone number you submit for verification clues, plus an optional claimed sender name;
- a URL you submit for analysis;
- a screenshot or image you intentionally upload or share to LEGITTAP.
Do not submit information you do not want processed for fraud analysis. Avoid uploading passwords, full payment-card numbers, government identifiers, or other unnecessary highly sensitive information.
2. What is stored in scan history
LEGITTAP stores the scan record and analysis result so you can review history. Stored data can include a redacted preview, classification, risk score when applicable, confidence, summary, evidence signals, uncertainties, recommended actions, timestamps, and technical analysis metadata.
For text scans, history records a privacy-safe preview rather than the full submitted message. For phone checks, history is designed to retain only a masked preview ending in the final four digits rather than the full submitted phone number. For URL scans, history is designed to retain the hostname preview rather than reconstruct the full submitted URL. Raw screenshots are not intended to remain in history after analysis.
3. Phone-number processing
During a phone check, LEGITTAP processes the submitted phone number to evaluate supported structural clues. The current beta does not claim to verify subscriber identity, ownership, live carrier, line type, or complaint reputation. Caller ID may be spoofed. If you provide an optional claimed sender name, it may be used during that active analysis.
LEGITTAP is designed so the full submitted phone number is not preserved in scan history. The stored preview keeps only the final four digits.
4. Image retention
Images are uploaded to a private Supabase Storage bucket for analysis. After a successful image analysis, LEGITTAP attempts to delete the raw uploaded image immediately and records that deletion. Terminal image-analysis failures also attempt to purge the evidence.
If an image is uploaded but analysis is abandoned, its artifact record expires after 24 hours. An automated cleanup job removes expired evidence. Temporary provider-side processing may still occur as described below.
5. Service providers
Supabase
Authentication, PostgreSQL database, private object storage, and Edge Functions.
OpenAI
When configured, submitted text or image content may be sent to OpenAI for structured fraud-risk analysis. LEGITTAP requests API processing with store: false. OpenAI's handling is also governed by its own applicable policies and service terms.
Google Web Risk
When configured, submitted URLs may be checked against Google Web Risk threat intelligence. A “no match” is not treated as proof that a URL is safe.
RevenueCat
If paid subscriptions are enabled, RevenueCat may process app-user identifiers, entitlement state, purchase/restore information, and related subscription metadata.
6. Why we use information
- provide and secure LEGITTAP accounts;
- analyze submitted content and phone-number clues for scam, phishing, impersonation, payment fraud, credential theft, and related risk indicators;
- show explainable scan results and privacy-safe history;
- enforce usage limits and subscription entitlements when enabled;
- debug failures, protect the service, and measure server-side analysis performance.
7. Security
LEGITTAP uses account-scoped access controls, Row Level Security, private storage, server-side secrets, payload limits, image signature verification, and automated cleanup. No online service can guarantee absolute security, so use care when choosing what to submit.
8. Data sharing and sale
LEGITTAP shares data with service providers only as needed to operate the functions described above, or when required by law. LEGITTAP does not operate an advertising network and does not use scan content to serve targeted advertising.
9. Your choices
You may stop using the service at any time. To request deletion of your LEGITTAP account and associated application data, follow the instructions at Delete account.
10. Children
LEGITTAP is not directed to children under 13. If you believe a child has provided personal information through LEGITTAP, contact beta support so the issue can be reviewed.
11. Changes to this policy
We may update this policy as the beta evolves, service providers change, or legal requirements change. The date at the top will identify the current version.
12. Contact
Privacy questions may be sent to LEGITTAP beta support. This is the verified beta contact address until a dedicated @legittap.com support mailbox is activated.