Protection with less data.
Routine checks do not retain message bodies. If you explicitly share a corrected example, Spamadin stores a minimized copy for up to 90 days solely to improve spam detection and reduce false positives. You can delete shared examples in your dashboard.
1. Who this policy covers
Brandify LLC operates Spamadin. This policy describes information processed through our website, customer accounts, and anti-spam API. If you submitted a form or comment on a customer’s website, that website determines how your original message is collected, moderated, and retained. Contact that website about its copy of your submission.
2. Information we process
- Website and form profiles: saved descriptions, categories, form purposes, illustrative requests, commercial preferences, and website-specific support settings. Public excerpts and field labels are processed to suggest form profiles; only the confirmed profile is saved.
- Account information: name, email address, verification records, password hashes, and sign-in sessions.
- Account activity: the most recent authenticated dashboard visit, used for account management and customer support. This does not include submission content.
- Service information: connected hostnames, hashed API-key secrets, subscription references, check identifiers, usage totals, verdicts, reason codes, response times, keyed input digests, and moderation corrections.
- Submission information: the message, submission type, optional page context, and optional behavioral signals supplied by your integration. Routine classification does not save message bodies. Optional training examples are described separately below.
- Billing information: Stripe processes payment details. We retain customer and subscription references, but do not receive or store complete card numbers.
3. AI processing and retention
Classification runs on our servers through OpenRouter using GLM 5.3 Flash, with an optional Jev 1.13 assessment. We require zero-data-retention provider routing and disallow provider data collection on every AI request. If a compliant route is unavailable or classification fails, the API returns a degraded review result rather than relaxing those requirements.
OpenRouter and the chosen inference providers necessarily receive the content needed to classify a submission. Common email and phone patterns are replaced in message text and optional page context before forwarding. This is data minimization, not complete anonymization. Visitor IP addresses, user agents, and the website URL are not forwarded to the models.
OpenRouter’s definition of zero retention permits some in-memory prompt caching. It does not mean that no processing occurs or that all account and billing metadata disappears. Review OpenRouter’s zero-retention policy for the provider-level definition.
4. Why we use information
We use information to authenticate customers, provide classification, enforce plan allowances, prevent abuse, handle payments, investigate service issues, and respond to support requests. Only explicitly shared corrected examples may be used for spam-detection evaluation and training. We do not sell submitted message content or use examples for advertising or unrelated purposes.
Repeat-submission fingerprints
When repeat recognition is enabled for a website, we keep a limited history of keyed fingerprints for up to 24 hours to recognize similar submissions. Fingerprints contain no saved message text, but they are derived data and are not treated as anonymous. You can turn repeat recognition off in your dashboard to clear this history and withdraw approved campaign signals. Patterns derived from explicitly shared examples remain linked to those examples and expire or are deleted with them. Similarity alone never determines that a message is spam.
Optional browser evidence
Integrations may send form tokens and limited interaction counts or flags to support spam classification. Our optional browser helper does not collect typed text, clipboard contents, mouse trails, or cookies. Tokens and interaction summaries are not retained in check history. Safe summaries can be sent to our zero-retention AI providers; tokens, visitor IPs, and user agents are not forwarded.
When an integration supplies a visitor IP with browser evidence, we use a keyed, website-scoped digest for short-term submission-rate counters. These are derived data, not anonymous data. Only aggregate counters are stored; they are removed by scheduled cleanup after the one-day retention cutoff. Missing browser activity or rapid submissions alone never establish spam.
Optional training examples
Sharing a corrected example is optional and separate from ordinary checks or metadata-only feedback. We retain the minimized message, relevant context, corrected label, check reference, and sharing record solely to improve spam detection and reduce false positives. Common email and phone patterns are removed, but names and other personal data may remain. Do not share passwords, payment details, sensitive personal information, or content you lack authority to share.
Examples are encrypted in our database, accessible only to authorized account users and restricted operations staff, and expire after 90 days unless deleted sooner. You can withdraw a stored example through your dashboard or API; visitors can contact the submitting website or [email protected] about a privacy request. Sharing does not immediately retrain a model. The training API does not send examples to third-party model-training services.
5. What remains and for how long
- Routine check message bodies: not persisted. Explicitly shared training examples: up to 90 days, removable sooner.
- Check metadata and corrections: 30 days.
- Monthly usage counters: 400 days.
- Security and billing audit metadata: 365 days.
- Webhook event identifiers: 30 days; short-term rate-limit records: up to one day.
- Account, API-key, and subscription records: retained while needed to provide the account, resolve disputes, and meet applicable recordkeeping obligations.
These periods are enforced by the scheduled maintenance job. Expired sessions and verification records are removed during cleanup. Deleting a live record does not necessarily immediately remove a backup copy.
6. Service providers and international processing
OpenRouter and its selected inference providers process classification requests. Stripe processes subscription payments. Cloudflare delivers verification, password-reset, and service emails. If you choose social sign-in, Google, GitHub, or LinkedIn provides your account identity. Infrastructure providers host the app and database. Access and processing may occur outside your country, including from Algeria. Contact us to discuss processing agreements and international transfers. Zero retention does not by itself determine a processing location.
7. Cookies and security
We use Rybbit to measure visits to public pages when analytics is enabled. Account, sign-in, and password-reset pages are excluded from pageview tracking. We do not send submitted messages or API keys to analytics.
We use the essential spamadin_locale cookie to remember your chosen website language for up to one year. You can change it using the language selector or remove it in your browser settings. We do not use it for advertising or tracking.
Essential cookies maintain sign-in and account security. Passwords and API-key secrets use Argon2id hashing. Account queries are scoped to their owner, and provider credentials stay server-side. No system can guarantee absolute security; report suspected exposure to our support address without including the exposed secret.
8. Your choices and requests
You can revoke API keys in your account and manage subscription renewal through the billing portal. To request access, correction, export, or deletion of account information, email [email protected]. We may verify your identity and retain information where required by law. Customers remain responsible for their own stored messages and privacy notices. Do not send credentials, payment-card details, or unnecessary sensitive information to the classification API.
9. Policy changes
We will update the date above when this policy changes and provide appropriate notice of material changes. Questions about this policy can be sent to the contact below.
Contact us
Spamadin is operated by Brandify LLC, a US registered company, with operations from Algeria. For service, billing, privacy, or security questions, email [email protected]. Please do not include passwords, API keys, or sensitive submission content.