A careful defender.
Credentials stay on the server. Routine checks do not save message bodies. Explicitly shared training examples have separate encryption, access controls, and retention limits.
Credentials belong on the backend
Your browser never receives our OpenRouter or Stripe secret keys. Your reusable Spamadin account API key is shown once, stored as an Argon2id hash, and revocable. Keep it on your server. Website limits and blocks are enforced on the backend, and account operations require authentication and ownership checks.
Context before conclusions.
GLM 5.3 Flash assesses messages using website and form context. Where enabled, Jev adds an initial assessment with a short path for clear legitimate messages in evaluated languages. Conflicting assessments remain uncertain. Keywords, links, submission speed, honeypots, profanity, or language alone never establish spam.
Submitted text and page context are treated as untrusted data. Instruction-like content is routed to review, and malformed model output cannot become an allow or spam decision.
Less content retained
Routine classification does not persist message bodies. Common email and phone patterns are minimized before classification, and visitor IP addresses and user agents are not forwarded to models. Both AI requests require OpenRouter zero-retention routing and disallow provider data collection. Account and limited service metadata remain necessary; see the privacy policy for details and retention periods.
Optional training examples are minimized, compressed, and encrypted with AES-256-GCM using a separate server-held key. Account and platform storage caps, duplicate detection, and 90-day expiry limit retention. Corrected labels are unverified reports, not instructions that automatically change other customers’ protection.
Predictable failure behavior
Provider failures return a degraded review result without consuming a check. Requests have bounded deadlines, payload sizes, rate limits, and concurrency. Usage reservations and idempotency checks prevent double counting. Your integration must still handle network failures and non-success responses by preserving the submission.
Infrastructure boundaries
Encrypted connections protect requests in transit. Account data and API access are restricted to their owner. Website controls let you stop new checks immediately without deleting your previous check history.
Repeat-recognition fingerprints are keyed, scoped to each account and website, limited in number, and excluded after 24 hours. They do not contain message text and are never shared across customer accounts. Campaign patterns require a separately approved, explicitly shared example. Similarity does not automatically block messages.
Report a security issue
Email [email protected] with a description, affected endpoint, and steps to reproduce using synthetic data. Do not send live passwords or API keys, access other customers’ data, or disrupt the service. If a key is exposed, revoke it and issue a replacement.
Contact us
Spamadin is operated by Brandify LLC, a US registered company, with operations from Algeria. For service, billing, privacy, or security questions, email [email protected]. Please do not include passwords, API keys, or sensitive submission content.