Last updated · August 2026

Privacy Policy

A precise map of what each tool processes, what a report retains, and which data never leaves your browser.

09 chaptersPublic reference

The short version

  • We do not sell or rent personal data.
  • Scanner reports are cached. Some are public and indexed; Email and SMS reports are accessible by their hash but excluded from search engines.
  • Do not submit passwords, private tokens, confidential messages, or personal data you do not have permission to process.
  • Raw Email and SMS upload bytes are discarded after analysis, but extracted and derived report evidence can be retained.
  • The Password Generator and QR decoder work locally in your browser unless you choose to send a decoded URL to another scanner.

What each scanner retains

URL and phishing scans

The URL scanner stores the submitted URL, hostname, verdict, screenshot, and the security signals used to build the report. Those reports can appear in the public URL report index. The dedicated phishing scanner uses a stricter public form: credentials, paths, query parameters, and fragments are removed before its public report is persisted.

Email scans

Email reports retain the normalized sender components, display name when available, verdict, score, and derived evidence such as header, domain, URL, message-pattern, OCR, and AI analysis. The public report URL contains a SHA-256 hash instead of the sender address and is markednoindex, but anyone with that URL may be able to view the report. Raw .eml files and raw screenshot bytes are not written to persistent storage.

SMS scans

SMS reports retain the normalized sender when provided, a message snippet of up to 500 characters, verdict, score, campaign fingerprint, and derived or AI evidence. Reports are addressed by a SHA-256 hash and marked noindex, but they are not private vaults. Raw screenshot bytes are discarded after extraction.

File scans

File reports retain cryptographic hashes, verdicts, metadata, and the forensic evidence produced by the scan. Uploaded files are processed for analysis; the report is the retained artifact, not a downloadable copy of the original file. File reports may be publicly accessible, so do not upload files containing confidential data.

Local-only utilities

The Password Generator creates values in your browser. The QR decoder reads the selected image in your browser. A decoded destination leaves the local tool only if you explicitly choose to open it or send it to the URL scanner.

Abuse prevention and attribution

Requests include technical metadata such as IP address, user agent, and timestamp. We use this information for rate limiting, fraud prevention, incident investigation, and moderation. Scanner records can retain the IP address and, when you are signed in, the MalwareTips forum user ID that first submitted a report. Attribution fields are not displayed in public reports.

Accounts and community activity

Accounts are provided by the MalwareTips forum through XenForo SSO. On sign-in we receive your forum username, user ID, avatar URL, and staff role; we do not receive your forum password. Comments, ratings, and tags posted on reports are public and associated with the displayed forum identity. Guest contributions are also subject to moderation, abuse controls, and edit or deletion records.

Analytics and advertising

We use Google Analytics 4 for aggregate traffic and product-usage measurement. We do not connect analytics events to your displayed forum identity or create MalwareTips remarketing audiences. Where advertising is enabled, guest pages may load clearly separated Google AdSense placements. Signed-in members do not load AdSense. Google services may process device, browser, network, and storage identifiers according to their own policies and your browser or consent settings.

Cookies and local storage

First-party storage supports session authentication, CSRF protection, rate limiting, theme, and interface preferences. Optional analytics, anti-abuse, or advertising services may use their own cookies or local storage when enabled. Browser privacy controls and content blockers may limit those services, although essential security checks can require a challenge before a guest scan is accepted.

What we do not do

  • We do not sell or rent scanner submissions or account data.
  • We do not read unrelated tabs or browser history.
  • We do not read your clipboard unless you activate a paste action provided by the browser.
  • We do not use raw Email or SMS uploads as a persistent file archive.
  • We do not receive your MalwareTips forum password.

Your choices and rights

You can ask us to:

  • Explain or export data associated with your account
  • Delete your account and eligible associated contributions
  • Review, correct, hide, or remove a specific scan report when appropriate

Contact staff through the MalwareTips forum with the report URL and enough information to verify the request. Some records may need to be retained for security, legal, or abuse-prevention reasons.

Changes and contact

We update the date above when this policy changes materially. Questions or data requests can be sent to staff through the MalwareTips forum.