Privacy
Hunch is built to know as little about you as possible. Here is exactly what we do and don't do, on this website and in the Hunch extension.
What Hunch does NOT do
No message storage. We don't keep the messages you read or paste. No accounts. There's no login, and we don't build a profile of you. No cross-web tracking, Hunch doesn't follow you around the web. No selling or sharing your data, ever. And no tracking cookies or third-party analytics on this website.
Detection runs on your device
Scam detection happens locally, in your browser on this site, and inside the extension. The extension runs only on five messaging views: LinkedIn, Facebook, Messenger, WhatsApp Web, and Gmail. On those sites it reads the text of messages shown on the page, on your device, to run the check and show you a card. It reads nothing on any other website. The content of your messages is not uploaded and not stored. Detection runs on your device only. Two Hunch features do reach a server, the Telegram bot and the email check, described next.
Where your message goes
The Chrome extension and the browser checker send nothing from your message. Nothing from your message leaves your device, on your computer or your phone. Two server doors exist: the Telegram bot and the email check (check@checkyourhunch.com). In each, the message you send is read on our server so we can check it and reply, then deleted. The text of your message is never stored or sent to any outside AI service. For abuse control we keep only short-lived counters keyed to a one-way hash of your Telegram id for the bot, or to a one-way hash of the sender address for the email check, together with the verdict, the locale and the message length, never the text itself. To avoid answering the same email twice, we keep a one-way fingerprint of the email's ID (not its content) for up to 7 days. Rate-limit counters expire within 24 hours. From version 3.8.13 the extension makes no network requests at all.
How this site's checker handles your message
When you paste a message into the checker on this site, it is analyzed in your browser. Detection runs on your device only. That is why it also works for a text on your phone. The share-card is created on your device. It shows only the kind of result and Hunch branding, and never any text from your message.
What we receive
In the extension and the browser checker, nothing from your message leaves your device. On Telegram, we receive what Telegram sends to any bot (your message and your Telegram account name) and delete it after the reply. Telegram itself keeps your chat history, as with any chat app. We do not.
What the extension keeps
The extension keeps a few things in your browser only: your settings, and small local records it uses to avoid checking the same message or contact twice. Those records are one-way hashes with a count and a time. They contain no message text and no sender identity, and nothing in them ever leaves your device.
Operator and processors
Hunch is run by an independent developer based in Israel; reach a human at support@checkyourhunch.com. A short list of service providers processes data on our behalf, and only for the purpose named: Cloudflare (hosts and serves this website and routes the email check), Railway (runs the server that checks a message from the Telegram bot or the email check, then deletes it), Resend (sends the email-check reply), and Telegram (delivers a message you send the bot). None of them receives your message from the extension or the on-device site checker, because those never leave your device.
Your rights
Because we keep no account and no messages, there is usually nothing stored about you to access or delete. You can still ask us what we hold, or ask us to correct or delete anything, by writing to privacy@checkyourhunch.com. We answer within 30 days. If you are not satisfied, you can contact the Israeli Privacy Protection Authority or, in the EU, your local data protection authority.
Honest limits
Hunch catches a lot, but not everything. A quiet result is not a promise that a message is fine, so always verify unexpected requests independently through a channel you choose.
If anything changes
If our data practices ever change, we will say so here, with a new date at the top, and in the extension's update notes before the change takes effect.
Questions: privacy@checkyourhunch.com