Privacy Policy
Last updated: September 2026
1. What NoScam does and how it runs
NoScam is open-source security software consisting of a local daemon running on your computer and a companion browser extension. Its single purpose is to stop Authorised-Push-Payment (APP) fraud by checking whether an irreversible action (sending money, entering a one-time passcode, or installing remote-control software) was prompted by an unsolicited message.
2. What information is processed locally
All safety decisions are made locally on your own machine:
-
Navigation Provenance: The extension observes navigation transitions (whether a page was
typed, opened from bookmarks, or clicked from a webmail or messaging tab) using the browser's
webNavigationAPI. This is stored temporarily in your browser's private session memory (chrome.storage.session) and decays after 15 minutes. - Payment & Form Action Gating: When you click a payment button or submit a transfer, the extension inspects the recipient name and amount locally to check if it exceeds your household limits or is a newly contacted payee.
- Downloads Interception: The extension monitors download file names to cancel known remote-desktop installers (such as AnyDesk, TeamViewer, or deceptive APKs) commonly pushed during phone scams.
-
Tamper-Evident Audit Log: Actions and decisions are logged in a local SHA-256 chained
log on your hard drive (
data/audit.jsonl) so you and your family have a clear record of what was held or approved. -
Update check: Once a day the desktop program asks GitHub
(
api.github.com) for the newest release number, so it can tell you when a newer version exists. The request contains nothing about you or your household, and nothing is downloaded or installed automatically. SetNOSCAM_NO_UPDATE_CHECK=1to turn it off.
3. Third-party network communications
By default, NoScam operates entirely on your local machine (127.0.0.1). There are three
external communications, and none of them carries your payment details in readable form:
-
End-to-End Encrypted (E2EE) Remote Pairing — off by default: NoScam makes no
connection to the relay until you press “Turn on” in the phone page, and stops when you press
“Turn off”. If you choose to pair a second device
(such as an adult child's phone in another city), notification payloads are encrypted client-side
with AES-256-GCM before being dispatched through a stateless blind pub/sub relay (such as
ntfy.sh). The relay operator sees only ciphertext blobs and has no access to transaction details, payees, or amounts. - Optional AI Coaching: If you explicitly configure a Google Gemini API key, NoScam sends the decision's reason code, the website's address, the payee name as shown on the page (truncated), the amount and any file name to generate a single sentence of plain advice. Account numbers, card numbers, passwords and one-time codes are never sent. Without an API key, this feature is off and deterministic explanations are used.
4. What we never do
- We never track or log which websites you visit outside of scam detection moments.
- We never collect bank account numbers, PINs, or credit card numbers.
- We never use analytics trackers, cookies, or telemetry beacons.
- We never sell, rent, or trade any user information.
5. Your control and data deletion
Because all household configuration (limits, known payees, audit log) resides locally on your
device in the data/ folder, you have complete control over your data. You can erase all
household records at any time by clicking "Reset" in the app or by deleting the local folder.
Uninstalling the extension immediately ceases all browser interception.
6. Open source and auditability
NoScam is open source under the MIT License. Anyone can inspect, build, and verify our code at:
github.com/Aditya-galaxy/noscam