Privacy Policy
Last updated: 2026-09-12
Summary
ScanLens helps you check links and suspicious content for common phishing, scam and malware indicators. Scan inputs and technical information are used to provide the service and protect it from abuse. Website analytics and marketing choices are separate from mobile-app data handling. Android version differences and the limits of disabling Analytics are explained below.
What we collect
- Scan inputs: we process the URL you submit to generate a security verdict. In the Android app, you may also choose to submit message text. Submitted content is sent to the ScanLens service for analysis; screenshot text is reviewed on the device before you choose to submit an extracted link.
When ScanLens checks a submitted link, the ScanLens service may request that link and follow redirects in order to analyse it. The operators of the submitted or redirect-destination websites may receive the requested URL, including its path and query string. If a link is extracted from a submitted message, this destination request uses the extracted link, not the full message body. Those website operators are independent recipients and may process request records under their own policies.
- Security and service logs: we may collect IP address, user-agent, timestamp, requested URL or API path, HTTP status code, CDN/security request identifiers, rate-limit events, abuse signals, and error events. We use these logs for API protection, fraud and abuse prevention, rate limiting, debugging, and service reliability.
- Model training / improvement data: we store hashed identifiers (for example URL hash) and derived features (such as URL length and structure) together with verdict and reason codes. Hashing alone does not make a record anonymous; a hashed identifier may remain pseudonymous.
- Necessary cookies / local storage (website): we use essential browser storage for cookie choices, scanner operation, service limits, and security controls. These are not used for advertising.
- Website analytics, only after consent: if you accept analytics, we may collect page views, referrer, campaign parameters, approximate device/browser information, and product events such as scan activity to improve the service.
- Website marketing and ads tracking, only after consent: if you accept marketing, we may use Google Ads / Google tag conversion tracking for app-store clicks, advertising performance, and campaign measurement.
- Mobile app data: in mobile apps, similar technologies may be used to support app functionality, analytics, and advertising, subject to platform permissions and consent where required.
Business enquiries
If you submit the ScanLens Business form, we collect the full name, company name, website URL, email domain, contact email, selected package, main concern and message that you provide. The form also uses a honeypot and Cloudflare Turnstile security token to help reject automated abuse.
We use these details to respond to the enquiry, confirm the requested service scope and prepare or discuss a quote. We do not use a consent checkbox as the default lawful basis for this processing.
Lawful bases
We use Business enquiry information:
- under Article 6(1)(b) UK GDPR where processing is necessary to take steps at your request before entering a contract with you; and
- under Article 6(1)(f) UK GDPR where you contact us on behalf of a company or organisation, based on our legitimate interests in responding to genuine Business enquiries, confirming service scope and administering potential customer relationships.
We do not rely on consent as the default lawful basis for responding to a Business enquiry.
Email delivery, storage and use
Business enquiry emails are sent and stored using Namecheap Private Email. Namecheap acts as an email service provider and processor on our behalf.
Namecheap may process personal information outside the United Kingdom, including in the United States. Where a restricted international transfer occurs, we rely on the contractual safeguards contained in Namecheap's Data Processing Addendum and the applicable UK transfer mechanism.
You may contact [email protected] for more information about these safeguards.
- Email provider: the validated enquiry is sent as a plain-text email through Namecheap Private Email to the monitored [email protected] mailbox. Version 1 sends no automatic response and accepts no attachments.
- Application storage: the ScanLens application does not store the enquiry in an application database.
- Analytics: enquiry contents are not sent to analytics.
- Application logs: the message body and contact details are not written to ordinary application logs. Limited security and delivery metadata may be recorded to prevent abuse and diagnose delivery failures.
- Marketing: enquiry details are not used for marketing by default. A separate lawful basis or valid opt-in would be required for any future marketing use.
- Unsuccessful genuine enquiries: retained for 12 months from the last contact.
- Spam, failed honeypot submissions and rejected abuse: deleted as soon as reasonably practical, retaining only minimal rate-limit or security records where necessary.
- Accepted orders and customer records: accepted orders, contracts, accepted Terms versions, reports and material customer correspondence are retained for six years after the end of the contract.
- Accounting and payment records: retained for six years from the end of the financial year to which they relate, or longer where legally required.
- Data protection complaints: retained for three years after the complaint is closed, unless longer retention is necessary for an active dispute or legal obligation.
- Operational email: reviewed and deleted according to the categories above rather than retaining every mailbox message indefinitely.
Your rights, deletion requests and complaints
- Privacy rights request: depending on the circumstances, you may have rights to access, correct or erase personal information, restrict its use, object to processing, or receive portable information. Email [email protected] with the subject "Privacy request".
- Request to delete information: use the same privacy request route and identify the information you want us to consider deleting. These rights are not absolute and may depend on the lawful basis and context.
- Data protection complaint: if your concern is about how ScanLens has handled personal information, follow our Data Protection Complaints Procedure or email [email protected] with the subject "Data protection complaint".
- General customer-service complaint: for a service, purchase, report or support issue that is not about personal information, email [email protected] with the subject "Service complaint" or use the Support page.
You may complain to the UK Information Commissioner's Office if you are dissatisfied with how we handle a data protection complaint. Using our internal procedure does not prevent you from contacting the ICO before it is complete. See the ICO's data protection complaint guidance.
Send only information that is necessary for the enquiry. Do not submit passwords, payment-card data, licence keys, health information, private client documents or other sensitive information through the Business form.
What we do not collect
- We do not store full raw URLs in training datasets.
- The statement about excluding raw URLs from training datasets does not describe operational caches. Operational link-result cache records may contain the submitted URL, including query parameter values, and its result. URL normalization does not itself remove query values. Expiry for cache reuse is not proof that the stored record has been physically deleted.
- We do not ask for a name, email address, or phone number to use the public website scanner.
- We do not operate user accounts.
Note: infrastructure providers such as CDN and security services may temporarily process IP addresses to protect the service. We do not use IP addresses in our training datasets.
How we use information
- To provide scan results and security verdicts.
- To maintain system stability and prevent abuse.
- To improve detection quality and train internal models using derived features and hashed identifiers as described above.
- To understand website usage and improve product flows, only where analytics consent has been given.
- To measure advertising and app-install campaigns, only where marketing consent has been given.
Website cookies, analytics and marketing consent
On the ScanLens website, non-essential analytics and marketing technologies are off by default. The cookie banner lets you choose Accept all, Reject non-essential, or Manage choices.
- Necessary: security, consent storage, scanner operation, rate limiting, and service reliability. These are required for the service and do not require analytics or marketing consent.
- Analytics: page views, referrers, campaign parameters, device/browser type, and product events. These run only after analytics consent.
- Marketing: Google Ads / Google tag conversion tracking, remarketing or advertising measurement. These run only after marketing consent.
You can change your website choices at any time by using the Cookie choices button in the page footer.
Advertising and third-party services
ScanLens uses third-party services to support its functionality:
- Google AdMob (mobile apps, depending on platform and version) — used by the iOS app and earlier Android versions, including Android 9.7. Android 9.8.8 contains no Google Mobile Ads or UMP SDK and has no Watch ad action. Earlier versions may remain installed or available during a staged transition.
- Google Ads / Google tag (website) - used only after marketing consent for conversion tracking and advertising performance measurement.
- Cloudflare — used for CDN, security, and human verification (Turnstile).
AdMob may collect and process device identifiers, usage data, and advertising interaction data to provide and improve advertising services. This may include the use of cookies or similar technologies where applicable.
Android 9.8.8: Analytics and other services
Android 9.8.8 disables new Google Analytics event collection and Advertising ID collection in the application. This is not a user-selectable Analytics switch. It does not remove the Analytics measurement components or erase information saved by an earlier version. We have not established that every old local Analytics queue is empty or that all previously queued uploads are prevented. We do not guarantee cancellation of an upload that was already in progress or deletion of data already received by Google or other recipients.
Firebase Crashlytics, Sessions, Installations, Cloud Messaging, Firestore, App Check with Play Integrity, and Google Play Billing remain in use. Depending on the service, these handle crash and diagnostic information, app/device and installation/session identifiers, notification registration, integrity information or purchase-related information. Disabling new Analytics collection does not disable these separate services. Website cookie choices do not control every mobile SDK.
On 10 September 2026, the shared Analytics property was configured with advertising personalization off, granular location/device collection off and Google Signals off. User and event retention are set to two months, with reset on new activity off. These are configuration values, not confirmation that historical data has already been erased; provider processing and aggregated reports have separate limits. The specified Analytics–Google Ads link and Android AdMob–Firebase link were removed. The Firebase–Analytics connection and iOS AdMob link remain. No claim of zero data collection or deletion of all Google-held copies is made.
Tracking and advertising (iOS)
On iOS devices, ScanLens may request permission to track users using Apple's App Tracking Transparency (ATT) framework.
If permission is granted, advertising partners such as Google AdMob may use the device identifier (IDFA) to deliver personalized ads and measure their effectiveness.
If permission is denied, ads may still be shown, but they may be less personalized. You can change your tracking preference at any time in your device settings.
iOS version 1.7 contains no Google Mobile Ads or User Messaging Platform SDK, has no banner, interstitial, rewarded or Watch ad flow, and does not include Firebase Analytics. Earlier iOS versions, including version 1.6, may remain installed until users update and may have different advertising or tracking behavior. iOS 1.7 continues to use Firebase Crashlytics, Firestore and App Check with DeviceCheck, and Apple StoreKit, for reliability, trial/product state, integrity and purchases. Submitted links and messages are sent to the ScanLens service only after an explicit scan action. Images selected for link OCR are processed on the device; only a reviewed link is sent if the user chooses to scan it.
User consent (UK GDPR / PECR)
On the website, users in the United Kingdom, the European Economic Area (EEA), and Switzerland are shown consent controls for non-essential analytics and advertising technologies. Mobile controls depend on platform and version. Android 9.8.8 disables new Google Analytics event collection and has no advertising-consent form because it contains no ads; this does not erase earlier data or establish a lawful basis for earlier processing. The iOS tracking section above is separate.
- Users can accept, reject, or manage their preferences.
- Website preferences can be changed using Cookie choices in the footer.
- Mobile app preferences can be changed in the app or device settings, where available.
Data retention
Website server access logs are normally rotated after around 14 days. ScanLens application security and abuse-prevention logs are normally rotated after around 30 days. Logs may be kept longer only where needed to investigate abuse, security incidents, fraud, or legal requests. Aggregated, anonymized statistics may be kept longer for performance monitoring and service improvement.
Business enquiry and customer records use the category-specific periods in the Business enquiries section: 12 months for unsuccessful genuine enquiries, prompt deletion of spam and rejected abuse, six years for accepted customer records after the contract ends, six years from the relevant financial-year end for accounting and payment records, and three years after closure for data protection complaints unless a longer period is required.
Android storage and deletion boundaries
Local History and Guard Inbox are separate stores, with separate clear actions and limits of 200 and 100 entries respectively. Clearing either one is not deletion of remote ScanLens records, Analytics SDK storage or provider copies. OCR can misread text: compare the extracted address with the original image before submitting it. Reviewing or cancelling an extraction does not itself send that candidate for a scan.
Operational scan caches, usage-limit records, credits, purchase-related records, security logs and provider data have different purposes. Physical cleanup of the server's SQLite scan_results cache has not been deployed. We do not currently guarantee physical deletion of those cache records within 24 or 25 hours. Missing or invalid historical timestamps are not treated as new records or invented retrospectively.
A request to delete data is assessed by category. We distinguish verified actions, unresolved links, justified retention and pending provider or backup work. Deleting an active record does not itself erase journals, logs, backups or copies held by recipients. We will not report all data as deleted when those actions or links remain unresolved.
Your choices
- You can accept all, reject non-essential technologies, or separately manage analytics and marketing choices on the website.
- You can change website choices using Cookie choices in the footer.
- You can change privacy settings in the app, where available.
- You can control tracking permissions in iOS settings.
Contact
If you have questions about this policy, please use the Support page or email [email protected].