Privacy Policy
Effective 26 September 2026
In short: SafeHop checks links to protect you from scams. Most checks happen inside your browser. For unfamiliar websites, only the site name (for example example.shop) is sent to our server to be checked against scam lists. We do not store those names, we do not track you, and we never sell data.
1. Who we are
SafeHop is a browser extension ("the extension") and a web service at api.safehop.app ("the API") that detect scam links, phishing pages and malicious redirects. This policy covers both, and this website.
2. What stays on your device
The extension watches the addresses your browser tab loads, including each redirect, only to decide whether the destination is dangerous. This analysis runs locally. The following is stored in your browser and never sent to us:
- the redirect path of pages you visit and their risk results (kept only for the current browser session);
- your settings, the sites you choose to trust, and sites you choose to block;
- simple counters (pages checked, warnings, blocks).
Removing the extension deletes all of this.
3. What is sent to our server
| When | What is sent | What is not sent |
|---|---|---|
| Cloud checks (on by default, can be turned off in the popup) | The host name of unfamiliar websites in a link's path, e.g. zsmedia-tracker.shop. |
Full addresses, paths, search terms, page content, form data, cookies, and anything about you. Large well-known sites (Google, Amazon, Microsoft and similar) and private network names (like printer.local or IP addresses) are never sent. |
| Community blocklist (about once an hour) | A request to download the current list of confirmed scam sites. Nothing about your browsing is included. | — |
| When you click "Report this scam" | The reported address, a short reason and the risk score shown to you. | Anything else about your browsing. |
Like any web server, the API sees the IP address a request comes from. We use it only for rate limiting, to stop abuse. For reports, we store a one-way hash of the IP combined with a secret that changes whenever the server restarts, so it cannot be turned back into your IP address. We never store raw IP addresses, and checked host names are not logged or saved.
4. How the API checks a site
To answer a check, the API compares the host name with public threat lists (URLhaus, OpenPhish, Phishing.Database) that it downloads in advance, and looks up the domain's public registration record (age, registrar and status) from the official registry for that domain ending. Those registry lookups contain only the domain name, never information about you. Registration records are cached for up to seven days.
5. What we never do
- We do not sell, rent or share personal data.
- We do not use data for advertising, profiling or credit decisions.
- We do not build a history of the sites you visit.
- This website uses no cookies, analytics or third-party scripts.
6. Where data is processed and how long it is kept
The API runs on servers operated by Hetzner Online GmbH in Germany (European Union).
- Checked host names: not stored.
- Scam reports: kept while needed to review them and maintain the blocklist, and deleted within 12 months if not confirmed.
- Domain registration cache: public information about domains, kept up to 7 days.
7. Your choices
- Turn off Cloud checks in the extension popup to keep all checking on your device.
- Turn off protection entirely with the switch in the popup.
- Remove the extension at any time; its local data is deleted with it.
- You can ask us about, or to delete, any report you sent (see contact below).
8. Children
SafeHop does not knowingly collect personal information from anyone, including children.
9. Chrome Web Store Limited Use
SafeHop's use of information received from the browser complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide and improve SafeHop's single purpose, protecting you from dangerous links, and is not transferred, sold or used for any other purpose.
10. Changes
If this policy changes, we will update the date at the top of this page. Significant changes will also be noted in the extension's release notes.
11. Contact
Questions or requests: support@safehop.app