Policies
AI policy
Last updated: June 1, 2026
Introduction
Scamhound uses artificial intelligence (AI) to analyze emails and detect scams, phishing attempts, and fraudulent communications. This statement explains how we use AI, our commitment to responsible AI practices, and our compliance with the European Union's Artificial Intelligence Act ("EU AI Act").
We believe in transparency, accountability, and putting users in control. This statement is designed to help you understand the role AI plays in our service and your rights as a user.
Our approach to AI
Scamhound's AI system is built on these foundational principles:
Transparency
We clearly disclose when and how AI is used in our service. Users always know when they're interacting with AI-generated analysis.
User empowerment
Users maintain ultimate decision-making authority. Our AI provides information and recommendations, but you decide how to act.
Fairness and non-discrimination
Our AI is designed to analyze emails objectively based on technical indicators, without bias toward or against any individual or group.
Accountability
We take responsibility for our AI's outputs and maintain human oversight of the system.
Privacy and security
We protect your data and use AI in ways that respect your privacy. See our Privacy Policy for full details.
Continuous improvement
We regularly monitor, evaluate, and improve our AI to maintain accuracy and fairness.
How we use AI
Primary use: email scam detection
Our core service uses AI (specifically, Anthropic's Claude AI) to:
- Examine sender information and email headers
- Evaluate email body content for scam indicators
- Identify suspicious links and URLs
- Detect social engineering tactics
- Recognise impersonation attempts
- Assess urgency and pressure tactics
The AI generates a verdict (scam, legitimate, or uncertain), a confidence score (0-100%), specific red flags and warning signs, positive indicators of legitimacy, and recommended actions, all explained in plain language.
What our AI does not do
Our AI does not:
- Make binding decisions about your actions
- Automatically delete, block, or filter your emails
- Access your email inbox without your explicit forwarding
- Profile you for marketing or advertising purposes
- Sell your data or AI insights to third parties
- Make decisions that significantly affect your legal rights
- Use your personal information for training without removing PII
EU AI Act compliance
Risk classification
We have assessed Scamhound and classified it as a limited-risk AI system under the EU AI Act. It provides advisory information and recommendations, does not make binding or automated decisions about users, does not determine access to essential services, and users retain full control over their actions.
Scamhound is not a high-risk system: we do not operate in critical infrastructure, evaluate individuals for employment, determine access to essential services, perform law enforcement functions, or assess creditworthiness.
Transparency obligations
As a limited-risk AI system, we fulfil transparency requirements by:
- Prominently displaying this AI statement on our website
- Informing users about AI use at the point of interaction
- Clearly indicating that email responses are AI-generated
- Explaining how the AI works, what it can and cannot do, and how to interpret confidence scores
- Providing all information in plain language without technical jargon
Ethical design
Scamhound has been designed to avoid manipulation or dark patterns, respect user autonomy (you decide whether to use the service and how to act on our analysis), and promote understanding by explaining how AI reaches conclusions.
Accountability and governance
We maintain formal oversight processes including documented AI policies and procedures, regular review of our AI provider (Anthropic), change control for prompts and model updates, incident escalation and response procedures, and regular AI performance reviews.
Human oversight
Emails with less than 70% confidence are flagged for human review. Trained reviewers assess edge cases and their feedback improves AI performance. Users can request human review of any result. Our system can be paused if issues are detected, and rollback capability exists for problematic updates.
Quality management
We regularly evaluate accuracy against test datasets, monitor false positive/negative rates, test against adversarial examples, and validate with edge cases. We only integrate AI providers where safeguards are in place, including Anthropic's Constitutional AI approach and contractual data protection requirements.
Documentation and record-keeping
We maintain documentation including technical specifications, risk assessments and mitigation strategies, testing and validation procedures, incident logs and responses, performance metrics, and change logs. This documentation is stored securely, available to regulators upon request, and reviewed regularly.
Limitations and disclaimers
AI is not perfect
False positives may occur: Legitimate emails may be incorrectly flagged as scams. Unusual but genuine communications may trigger warnings. New or unfamiliar senders may be flagged cautiously.
False negatives may occur: Sophisticated scams may evade detection. Novel tactics not yet seen by the AI may be missed. Very convincing impersonations may not be caught.
Confidence scores are estimates: A 95% confidence score is not a guarantee. Confidence represents the AI's assessment, not certainty. Lower scores indicate genuine uncertainty. Always use your own judgement.
What AI cannot replace
Our AI is a tool, not a substitute for:
- Professional legal advice
- Financial planning or advice
- Cybersecurity consulting
- Law enforcement investigation
- Your own critical thinking and judgement
You should always verify important information through official channels, contact organizations directly if unsure about requests, and consult professionals for significant decisions.
Disclaimer
AI-generated content and analysis are provided strictly on an "as is" basis. We do not make any warranties, express or implied, as to the accuracy, completeness, or correctness of AI analysis, its suitability for your specific situation, the timeliness of scam pattern recognition, or the absence of errors or false results.
Our AI-generated analysis is provided for general information purposes only and is not intended to constitute legal advice, financial advice, professional cybersecurity consulting, or professional verification services.
To the fullest extent permitted by law, we disclaim all warranties, express or implied, relating to Scamhound and AI-generated content.
Your rights and controls
Right to transparency
You have the right to understand how our AI works, know when AI is being used, receive clear explanations of AI outputs, and access this AI statement at any time.
Right to human review
You have the right to request human review of uncertain analyses, challenge AI classifications you believe are incorrect, receive human explanation of complex cases, and escalate concerns about AI performance.
To request human review, email [email protected] with the analysis ID or email subject, why you believe the analysis is incorrect, and any additional context. We respond within 48 hours for standard requests, 24 hours for urgent matters.
Right to explanation
You have the right to understand why the AI reached a particular verdict, know which factors contributed to the confidence score, and receive explanations in plain language. Our AI responses automatically include the verdict, confidence percentage, red flags identified, positive indicators found, reasoning, and recommended actions.
Right to opt-out
While our core service is AI-based, you can choose not to use the service at any time, delete your account and data, or provide feedback on AI performance.
Feedback and complaints
We welcome your feedback about our AI system:
- General feedback: [email protected] — we review all feedback and use it to improve
- Complaints: [email protected] — we investigate all complaints thoroughly, with a response within 14 days
- False positives/negatives: [email protected] — include the analysis ID and your assessment; helps us improve AI performance
EU users who believe we are not complying with the EU AI Act may contact [email protected] or lodge a complaint with their national AI authority or data protection authority.
Changes to this statement
This AI statement may be updated to reflect changes in our AI system, new regulatory requirements, best practice developments, or user feedback. When we update, we revise the "Last Updated" date and notify you via email for material changes. Continued use constitutes acceptance.
Contact information
- General inquiries: [email protected]
- EU AI Act compliance: [email protected]
- Data protection officer: [email protected]
Mailing address:
Timbrespark Studios
1675 Route 228 #1075
Cranberry Township, PA 16066
United States
We aim to respond within 5 business days.