The instant check
When you press Check it, the detection engine runs in your browser. Your text is not uploaded for that verdict. If you close the tab there, nothing about what you checked has left your device.
The server check
If the server check is switched on, your text is then sent to our API so it can add the things a browser cannot do: how old the linked domain is, where a shortened link actually goes, whether the certificate is trustworthy, and an AI read of what the message is asking you to do.
That AI read means the text is sent to OpenAI, who process it on our behalf and return a classification. We name them because you should be able to decide about that, not discover it. If you would rather nothing left your device at all, the browser verdict on the page is already complete without it — everything the server adds is marked server or AI read in the signal list.
Once scored, your text is discarded. There is no column for it anywhere in our database, which is a schema-level guarantee rather than a policy we intend to follow.
What we do keep from a check
For every server check we keep one row of structured, non-content telemetry:
That is what lets us tell whether the detector is getting better or worse. None of it can be turned back into your message, and none of it is attached to you.
- which signals fired, with their severity and confidence
- the tier and score we returned
- how many characters the input was — the length, not the text
- which version of the detector produced it, and how long it took
- the hour it happened in, rounded — not the minute, not the second
- a random ID for that analysis, so that if you tell us the verdict was wrong we know which verdict you mean
What we never keep
Because we set no visitor ID, we can count how often something happens but cannot follow one person from one page to the next. That is a deliberate trade and it costs us analytics we would otherwise find useful.
- the message, link, UPI ID or number you pasted
- your name, email, or phone number — we never ask for any of them
- an account, because there are no accounts
- a login, a visitor ID, or a device fingerprint
- your IP address, the region it suggests, or any record of where you were
- a session recording or replay of anything you typed
The language you read this in
Choosing a language stores one cookie, ghotala_locale, containing one of thirteen language codes and nothing else. It holds no identifier, no location and no record of what you checked, and every visitor who picks the same language stores the same value — so it can remember a preference and cannot recognise a person.
On a first visit, before you have chosen, we may open the menu on the language most common where the request appears to come from. That inference uses a country and state code your network provider’s edge has already worked out; we never see, store or log your IP address, we never send it to our API or to OpenAI, and we do not call any outside location service. The result is used once, to pick a default, and is never written down. If it is unavailable the site simply starts in English.
"Did we get this right?"
If you answer that, we store your answer, which verdict it was about, and the detector version — and nothing else. The form cannot take free text and the endpoint refuses any field it does not recognise, so there is no way to attach the message to it even if you wanted to.
The recovery page
Every question on the recovery page is a choice from a fixed list, and we keep only those choices: roughly what happened, roughly how long ago, which payment rail, who you have already contacted, and where things stand. We do not ask and cannot store how much money it was, who it went to, a transaction reference, a bank, a phone number, or a screenshot.
Those choices are stored as fixed codes, the same ones in every language — so answering in Kannada and answering in English produce identical records. The optional outcome form is not linked to the pages you visited on the way to it. We can say "this many people reported this outcome". We cannot say who.
There is one exception, and it only exists if you choose it: if you pick "Something else", an optional box lets you describe what happened in your own words. That description is sent to us, stored, and read by a person, because it is how we learn scam types we do not cover yet. It is stored with nothing that identifies you — no address, no session, no link to anything else you did here — and it never changes the guidance you see. If you leave the box empty, nothing is sent.
Counting how the site is used
We keep coarse counts — page views, checks started and finished, which verdict tier came back, whether the feedback prompt was used. They are stored as totals per hour on our own servers. There is no third-party analytics script on this site and no session replay.
Official guidance
When a verdict shows advisories from I4C, RBI, SEBI or CERT-In, your browser has already downloaded the whole short list and matched it locally. We are not told which tactics your message tripped. No authority has seen what you checked, and none of those advisories is a statement about your message or about whoever sent it.
The business API
Companies who call the API with their own key are on a different footing: we record which key made which call for billing. That is metering, and it still stores no submitted content.
What Ghotala is not
It is not a bank, the police, a regulator, or a court. It reads text for patterns scammers reuse. It cannot tell you who owns a number, and it never says that a named person or a specific phone number is a fraudster — it describes patterns, links and domains, and nothing else.
Changes
If what we do changes, this page changes with it. Questions: privacy@ghotala.wtf.