Privacy Notice
Version 3.1 — August 31, 2026
No learner account or direct identity is required. The service processes limited technical and training data as described below.
What stays on your device
Your practice progress, accessibility preferences, and partner-path assessment answers are stored in your browser's local storage on this device. A protected local copy of the public intake, completion, and optional feedback record is also kept so an interrupted secure submission can be retried. “Start over,” “Clear this device,” or clearing browser data removes these local copies.
Public-practice evaluation
Before Story 1, three categorical answers are sent to The End Scams Project for program evaluation: country category, broad age range, and whether a scam or fraud has ever caused a financial loss. The selected practice language and submission time are also included. Every question includes a privacy-safe answer.
The same anonymous record is updated when all four stories are mastered and, only if you choose to answer it, with Yes, No, or Not sure to the helpfulness question beneath the certificate. It does not contain your name, email, exact age, state, loss amount, assessment answers, story choices, IP-derived geography, browser details, or the local learner session identifier.
Results are reported only in aggregate. Demographic and prior-loss distributions remain hidden until at least 20 intake responses exist. Clearing this device removes only the browser copy, not a response already submitted to the program database.
Historical Final Check-In records
Before version 3.0, a separate post-training Final Check-In collected additional categorical fields. Those historical version 2.0 records remain under their original retention, access, and aggregate-only reporting controls. The current public flow no longer collects U.S. state or any actual or hypothetical loss range.
What is never stored anywhere, even on your device
Personal safety-plan entries (trusted contacts, bank fraud number, family verification phrase, computer helper) are kept only in the page's memory while you are on the safety-plan screen. They are never written to local storage, cookies, web addresses, logs, or any server, and they are cleared after printing, completion, or exit.
We never ask for and never collect passwords, one-time security codes, bank or card details, Social Security numbers, government IDs, full birth dates, medical information, exact home addresses, or uploads of real scam messages.
Technical data from hosting
Like nearly every website, the selected hosting and database providers process standard technical information — such as IP address, browser type, requested pages, and connection logs — to deliver the service and protect it from abuse. The application does not copy IP addresses or browser details into public evaluation records. Provider logs follow the provider retention configuration. This is why we do not describe the service as fully anonymous.
Site analytics
We use Google Analytics to understand general site use, such as the pages visited and broad device, browser, and location information. Google Analytics may set first-party measurement cookies, including cookies whose names begin with _ga. Google Signals and advertising-personalization features are disabled in the site tag.
We do not send assessment answers, story choices, public-evaluation answers, safety-plan entries, or the local learner session identifier to Google Analytics.
What we do not use
- No ad personalization, remarketing, or Google Signals.
- No browser fingerprinting.
- No learner answers or safety-plan contents in site analytics.
- No assessment answers or identifiers in web addresses.
Organizational inquiries
The community pilot form opens an email in your own mail app; contact details you send are used only to respond and are kept entirely separate from learner practice data.
Contact the privacy team
Questions or deletion requests: [email protected]