Ghotala.wtf
English

Choose your language

Report a new scam

Choose your language

All languages
Privacy

What we do with what you paste.

Short version: the check runs in your browser, and nothing you paste is ever written to our database. That is not the same as “we store nothing”, so here is the whole thing.

AI-assisted analysis

When enabled, the text you submit may be processed by OpenAI for AI-assisted scam analysis.

AI-assisted analysis

This preference is saved in this browser only. Clearing browser data, or using another browser or device, resets it.

Ghotala.wtf ("Ghotala", "we", "us" or "our") is operated by Piyush Chandra.

Ghotala helps people check suspicious messages, screenshots, images and documents, understand possible scam indicators, and find practical safety information.

This Privacy Policy explains what happens to information you submit when you use Ghotala.

1. The short version

Our privacy approach is simple:

  • you can use Ghotala without creating an account;
  • we do not sell your personal information;
  • we do not use the message or file you submit to build advertising profiles;
  • we do not permanently store the message or file you submit merely because you checked it;
  • AI-assisted analysis is disclosed before it is used, and you choose whether to allow it;
  • you may run a check without AI processing;
  • if you upload an image, you choose who reads the text out of it before it is uploaded;
  • choosing Google Cloud Vision sends the image itself to Google, which does not guarantee that it is handled in any particular country or region;
  • choosing Ghotala's own server means the image is not sent to Google to be read;
  • when you allow AI-assisted analysis, content needed for the check may be processed by OpenAI;
  • OpenAI states that API inputs and outputs are not used to train its models by default;
  • scam verdicts and AI outputs can be wrong. Ghotala is an assistance tool, not a guarantee.

2. Who is responsible for your information

Ghotala.wtf is operated by Piyush Chandra, Bengaluru, Karnataka, India. "Ghotala" and "ghotala.wtf" are the names of the service, not of a separate company.

Privacy enquiries: privacy@ghotala.wtf. Legal enquiries: legal@ghotala.wtf.

If applicable law gives you privacy rights or requires us to respond to a privacy request, you can contact us at the privacy address above.

3. Text that you check

You may paste text such as SMS or messaging-app messages, emails, payment or banking messages, social-media or marketplace messages, job or investment offers, or other text you want checked for scam indicators.

That text may contain personal information about you or another person, including names, phone numbers, email addresses, UPI IDs, account-related information, URLs or transaction details.

Please avoid including personal information that is not necessary for the check.

4. Images, screenshots and documents

Where supported, you may upload an image, screenshot, PDF or other supported document for scam analysis.

An image or document may contain visible text, names, phone numbers, account information, faces, locations, metadata or other personal information.

To analyse an upload, Ghotala validates the file type and structure, rejects unsupported or unsafe files, extracts readable text, inspects embedded images, and creates temporary processing copies. We do not intentionally execute macros, scripts or other active content contained in an uploaded file.

Reading the text out of an image can happen in one of two places, and you choose which before anything is uploaded. Ghotala can read it with Google Cloud Vision, which is faster and better at difficult images; or Ghotala can read it with its own software on its own server in Bengaluru, which is slower and fails more often on hard images.

If you choose Google, the image itself — not a description of it, not text taken out of it — is sent to Google Cloud Vision to be read. Ghotala uses Google’s global service endpoint, and Google does not guarantee that the request stays within any particular country or region. Section 9 says what is and is not sent; Section 15 says what Google states it does with it.

If you choose Ghotala’s own server, the image is not sent to Google for text reading at all. It is read by Ghotala’s own software, on Ghotala’s own server, and for that step the image does not leave India. This reader is slower than Google’s and gives up more often on a blurred, angled or low-contrast image.

Choosing Ghotala’s own server decides one thing: that the raw image is not sent to Google to be read. It is not a decision about everything that happens afterwards. Text taken out of the image is then handled as Sections 9, 10 and 11 describe, including any AI-assisted analysis you have separately allowed, and those remain separate choices with their own notices.

Neither choice is remembered for you unless you ask for it to be, and either can be changed at any time. If the terms of the choice change, you are asked again rather than assumed to still agree.

Uploading is not an on-device operation. The file itself leaves your device before anything can be extracted from it, and Section 9 explains where it goes and how long it lives.

5. The Ghotala browser extension: the page you are looking at

The Ghotala browser extension is a separate way to run a check, and what it collects is a separate matter from the two above. Pasted text is something you typed or copied deliberately; a web page is not. So this section describes the extension on its own terms rather than folding it into the sections about pasted text or uploaded files.

The extension does nothing until you ask it to. It has no background monitoring, no periodic checking, and no code that runs on a page you have not asked about. There is no browsing history, no reading of cookies, no interception of network requests, and no persistent script sitting on the pages you visit. Every check happens because you clicked Ghotala or chose a Ghotala item from the right-click menu.

When you run a check, the extension reads the address of the page, the page title, and the text that is visible on the page, and sends those to Ghotala for analysis. It does not read values you have typed into the page: the contents of text boxes, password fields, dropdowns and text areas are excluded before any text is collected, rather than removed afterwards. It does not read the page’s underlying code, its attributes, or anything you have stored in the browser.

You can also check a piece of text you have selected, or a link address you have right-clicked. A link check reads the address only. Ghotala does not open, fetch, load or otherwise visit the link on your behalf, so a link check tells you about the address and not about what the destination would show you.

What is sent for a page check is used to run that check and is not stored. As with pasted text, Ghotala records the resulting signals and verdict, never the page content itself.

6. The Ghotala browser extension: what is visible on your screen

When image checking is available, pressing Check in the extension also captures a picture of what is currently visible in the browser tab, and sends it to Ghotala to be read. This is a third distinct thing the extension may collect, and it is the most sensitive, which is why it is described separately from the page text above and from the uploads in Section 4.

A picture of your screen can contain considerably more than the thing you wanted checked. It can include an account balance shown above a message, a notification, another person’s name, or a document open in the same view. Because of that, the extension shows a notice explaining this before the first check that could capture one, and no capture happens until you have seen it.

The picture is only ever taken at the moment you ask for a check. There is no capture on page load, on navigation, on a timer, or in the background, and the extension holds no permission that would allow one.

The picture covers what is visible in the tab at that moment. It is not a picture of the whole website, not of content further down the page, and not of any other tab or window. Where a check could not include the picture — because image checking is switched off, because the capture failed, or because you stopped it — the extension says so and does not describe the result as a complete visual check.

The picture is uploaded from your browser directly into private storage operated by DigitalOcean on Ghotala’s behalf, read once, and deleted. It is not publicly enumerable, is excluded from backups, and is subject to the same deletion rules as an upload under Section 9. DigitalOcean stores the file; it does not analyse it or use it for its own purposes.

Neither the page text nor anything read out of the picture is sent to OpenAI or any other AI provider. The extension’s checking path does not include AI-assisted analysis at all, and no path exists by which page content or screenshot content could reach one. If that ever changes, it would require its own notice and your separate agreement, exactly as AI analysis of pasted text does today.

Ghotala keeps the signals and the verdict. It does not keep the picture, and it does not keep any text read out of it.

7. What happens when you press "Check it"

Ghotala uses more than one layer of analysis.

Ghotala’s own analysis uses deterministic rules, signals, canonical scam patterns and other Ghotala-controlled logic to assess scam indicators. For pasted text this begins in your browser, and a server check then adds infrastructure evidence such as how old a linked domain is and where a shortened link actually goes.

AI-assisted analysis is separate, and it is the only processing that involves a third party.

8. AI-assisted analysis of pasted text

Before Ghotala first sends pasted text to an external AI provider from your browser, we show a notice explaining that AI-assisted scam analysis may send that text to OpenAI.

If you choose "Proceed & Check", you authorise the disclosed AI-assisted processing for the current notice version. Your choice is stored locally in your browser so that we do not show the same notice before every check.

If you choose "Check without AI", Ghotala performs the check without making an OpenAI call for AI-assisted classification. If you close the notice without choosing, no check runs and nothing is sent.

We will not treat an acceptance of an older notice as permission for materially different AI processing. If the notice version changes, you will be asked again.

9. AI-assisted analysis of an upload, and where the file goes

An uploaded file is handled differently from pasted text, and more cautiously, because a screenshot commonly carries far more than the message you meant to check — the sender’s name, an account balance above the message, a one-time code in the notification shade.

An uploaded file is sent from your browser straight into private storage in Bengaluru, India, operated for Ghotala. It is not publicly browsable and is excluded from backups.

It is deleted as soon as it is no longer needed for the check — on success, on validation failure, on extraction failure, on timeout and on cancellation.

During normal operation, Ghotala also removes stale uploads automatically within about an hour, in case one is ever left behind by a failure we have not seen.

If the service itself is unavailable for an extended period, that automatic cleanup does not run. The storage provider has a separate lifecycle rule configured to expire any remaining upload after one day.

There is one exception, and it exists so that a failed check does not make you upload the same screenshot twice. If the reader you chose cannot read your image for a reason that is not the image’s fault — it was unavailable, too busy, or ran out of time — Ghotala offers you the other reader, and keeps the image briefly while you decide. Declining, closing the offer, cancelling, or simply doing nothing all end it and delete the image. Accepting starts one more attempt, and the image is deleted when that attempt ends, exactly as any other.

None of that depends on you staying on the page. Closing the tab, losing your connection or putting the phone down all count as doing nothing, and Ghotala’s own servers end the offer and delete the image without needing to hear from you again. As everywhere else in this section, a prolonged failure of the service itself falls back to the storage rules described above.

The uploaded image or document itself is not sent to OpenAI, and no path exists by which it could be. That is unchanged. It is a different question from who reads the text out of an image, and a different question again from what happens to that text afterwards — which is described immediately below.

If you chose Google Cloud Vision to read the image, the image is transmitted to Google for that purpose only. Google returns the text it read and Ghotala does the scam analysis itself. Ghotala does not send Google the verdict, the rest of your check, or anything identifying you, and does not receive from Google any judgement about the content.

If you chose to have the image read on Ghotala’s own server, no part of the image reaches Google.

AI-assisted analysis of an uploaded image is part of the check rather than a later optional step: you are not asked again for each image. It follows the same AI-analysis setting as the rest of Ghotala, which is on by default. While it is on, Ghotala extracts the text, redacts the identifiers it can detect, and sends only the redacted extracted text to OpenAI. If you have turned AI-assisted analysis off, no text from your image is sent to OpenAI and the check finishes on Ghotala’s own analysis alone. The image itself is never part of what is sent, either way.

Automated redaction is imperfect. The deterministic redactor Ghotala uses elsewhere covers phone numbers, email addresses, UPI IDs, account numbers, payment-card numbers, one-time codes and credentials embedded in URLs. It does not cover names, physical addresses or transaction IDs. Text recovered from an image can also be broken in ways typed text is not — split digits, misread characters, lost line breaks — and we have not measured how well redaction performs on it. We therefore would not claim that identifiers are reliably removed from text extracted out of an image. Redaction should be understood as reducing what is sent, not as a guarantee that every identifier has been removed.

10. Checking links and domains

A scam usually points somewhere. To judge a link or a sender domain, Ghotala performs technical network lookups: domain-registration (RDAP) checks to see how recently a domain was registered, DNS checks to see whether it resolves and what mail records it has, certificate checks to see who issued its TLS certificate, and — for recognised URL shorteners only — a request that reads where the short link points.

These lookups send the relevant domain or hostname to the service handling them, and nothing else. They do not send the uploaded screenshot, the text read out of it, the message you pasted, or anything identifying you. A lookup service sees a domain name; it does not see who asked or why.

Ghotala does not visit the destination of an ordinary link. Only a recognised shortener is requested, and only so that the address it hides can be read; the page it eventually points to is not fetched.

Some checks involve nobody outside Ghotala at all. The list of known-bad domains, for example, is held inside Ghotala’s own software and consulted locally, so checking against it sends nothing anywhere.

11. What we send to OpenAI

When you have allowed AI-assisted analysis, we send only what the enabled purpose needs. Depending on what you checked, that may include:

We aim to avoid sending unnecessary identifiers or metadata, and you should avoid submitting personal information the check does not need.

  • the normalised text you pasted;
  • a short structured summary of entities found in it, such as link hostnames;
  • limited technical context from Ghotala’s own infrastructure checks, such as how old a linked domain is;
  • for an upload, the redacted text read out of your image — never the image or document itself.

12. Turning AI-assisted analysis off

You can turn AI-assisted analysis off at any time using the control on this page. When it is off, later checks do not make an OpenAI call for that purpose, and the deterministic check remains fully available.

Because Ghotala has no accounts, this preference is stored in the browser you are using. Clearing browser data, or using a different browser or device, resets it. Turning AI off also discards your stored acknowledgement, so if you later turn it back on you will see the notice again before anything is sent.

Withdrawing permission does not undo processing that already happened before you withdrew it.

This control covers AI-assisted analysis and nothing else. It does not decide who reads the text out of an image you upload — that is the separate choice described in Section 4, made before each upload or remembered if you asked for it to be, and changed in the same place.

13. What Ghotala keeps

We do not keep the text you check or the file you upload as a permanent content record merely because you performed a check. There is no column for submitted content anywhere in our database, which is a property of the schema rather than a policy we intend to follow.

We may temporarily cache the structured result of an AI classification so that identical work is not repeated. The cache is keyed by cryptographic digest rather than by the message, holds the structured result rather than your content, and its current maximum lifetime is 7 days.

For each server check we keep one row of content-free operational telemetry: which signals fired with their severity and confidence, the verdict tier and score, the number of characters submitted, the detector version, latency, a random analysis identifier, a hash of the feature vector, and the hour it happened in. None of it can be turned back into your message and none of it is attached to you.

Our application is designed not to log submitted message bodies, uploaded-file contents, extracted text, filenames, or identifiers such as phone numbers, email addresses, UPI IDs or one-time codes. Infrastructure and hosting providers process ordinary network and security information required to run and protect the service.

14. Feedback, corrections and scam reports

Choosing to submit feedback, a correction or a scam sample is a separate action from checking content. Where we ask to retain a sample, we tell you before submission and we may redact or minimise it before storing it.

Simply checking a message or file does not mean you have agreed to donate that content to a scam database.

15. Service providers

We use service providers for cloud infrastructure, databases and caching, temporary file storage, security and networking, reading text out of images, and AI processing.

Temporary storage of an uploaded file, or of a screenshot taken by the browser extension, is provided by DigitalOcean. They hold the file while it is being read and until it is deleted. They do not analyse it, do not read its contents for their own purposes, and are not an AI provider. Naming them here is deliberate: it would be inaccurate to say that no third party is involved in handling a screenshot. Since image reading became a choice, the accurate statement is longer than it used to be — one third party stores the file, and a second one reads text out of it if, and only if, you chose Google Cloud Vision. Neither renders a judgement about what the image says; the scam analysis is Ghotala's own.

Ghotala uses Google Cloud Vision to read text out of an image, when and only when you chose it for that image. Google states that it does not use the content sent to Cloud Vision to train or improve Cloud Vision, that it does not share that content with any third party, and that it claims no ownership of it. Google also states that for the kind of request Ghotala makes — a single image, answered immediately — the image data is processed in memory and not written to disk, and that it temporarily logs some metadata about the request, such as when it arrived and how large it was. Google does not publish how long that metadata is kept, so we do not tell you a number for it. These are Google’s statements about Google’s handling, not undertakings Ghotala can verify or give on Google’s behalf.

What Ghotala sends Google is the image and nothing else: no verdict, no other part of your check, no account or identifier, and nothing about you. What Google returns is the text it read. Google is not asked for, and does not give, any opinion about whether the content is a scam — the scam analysis is Ghotala’s own.

Ghotala uses the OpenAI API for AI-assisted analysis when you have allowed it. OpenAI states that data sent to its API is not used to train or improve its models by default. Under standard API data controls, OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring, unless longer retention is required by law. Ghotala is on OpenAI’s standard API terms; we have not entered a zero-retention or modified-abuse-monitoring arrangement, and we do not claim one.

We may change providers or provider configurations. If a change materially affects how your submitted content is processed, we will update this Policy and, where appropriate, require a new notice version.

16. Where processing happens

Ghotala’s own infrastructure — the API and the database that serve a check — runs in Bengaluru, India.

AI processing by OpenAI occurs outside India. OpenAI does not currently offer regional processing in India, and we do not claim that all Ghotala processing or storage happens in India.

If you choose Google Cloud Vision to read an uploaded image, that reading also occurs outside Ghotala’s own infrastructure. Ghotala calls Google’s global Cloud Vision endpoint, and Google’s own documentation states that resources at the global endpoint are stored and processed in a global location and are not guaranteed to remain within any particular location or region. We therefore make no promise about which country reads your image on that path, and you should not read one into the fact that Ghotala is operated from India.

If you choose to have the image read on Ghotala’s own server, that step happens on the same Bengaluru infrastructure as the rest of a check.

Where applicable law imposes requirements on cross-border processing, we will apply the required measures.

17. Cookies, local storage and browser preferences

Ghotala uses cookies and browser storage for a small number of purposes: remembering your language, remembering your versioned AI-processing choice, remembering — only if you ask us to — which reader you want for uploaded images, remembering interface settings, and security and abuse prevention. We do not require an account to store any of these.

The image-reader preference is stored only if you tick the box asking us to remember it, and it records the choice and the version of the disclosure you were shown — nothing about the image and nothing about you. If the terms of that choice change, the stored answer stops being used and you are asked again. You can see the current setting and change it wherever you upload an image.

Your local acknowledgement record contains the notice version you accepted, the date you accepted it, and which processing purposes it covers. The date is never transmitted to us. This record is not intended to identify you, and is not used to recognise you across other websites.

18. Future AI features, including related reading

Ghotala may in future suggest scam guides automatically — "related reading" — chosen by comparing what you checked against guides we wrote ourselves. That feature is not enabled today and no such processing occurs.

If it is introduced, it would be informational only and would form no part of your scam verdict. Because it would be a materially new AI-processing purpose, it would require a new notice version and a fresh acknowledgement. We will not treat an old acceptance as permission for it.

19. Your choices and rights

You may decline AI-assisted processing, turn it off for future checks, choose who reads the text out of an image and change that choice at any time, decline to upload an image at all, clear locally stored preferences through your browser, and avoid uploading unnecessary personal information.

Depending on the law applicable to you and the commencement dates of those rights, you may have rights concerning personal data, including access, correction, deletion, grievance handling or withdrawal of consent.

To make a request, contact privacy@ghotala.wtf. Because Ghotala ordinarily maintains no accounts and retains no submitted content, we may have little or no user-specific information to retrieve or delete. We will not ask you for more personal information than is reasonably necessary to handle a legitimate request.

20. Children

Ghotala is intended for users aged 18 or older. If you are under 18, use Ghotala only with the involvement of a parent or legal guardian.

Do not knowingly submit a child’s personal information unless it is necessary for a legitimate scam-safety purpose and you are authorised to do so.

21. Security

We use technical and organisational safeguards intended to protect information, including encrypted network connections, access controls, private storage, input and file validation, content-minimised application logging, rate limiting, and separation between temporary user uploads and canonical scam content.

No internet service can guarantee absolute security.

22. Information about other people

A suspicious message or screenshot often contains information about someone else. Only submit content you are reasonably entitled to submit for the purpose of checking whether it may be fraudulent or unsafe.

Do not use Ghotala to collect, expose or investigate another person’s private information for unrelated purposes. Ghotala describes patterns, links and domains; it does not and will not assert that a named person or a specific phone number is a fraudster.

23. Changes to this Policy

We may update this Policy as Ghotala changes, and we will update the effective date when we do.

If we materially change the purposes for which submitted content is sent to an AI or other external provider, we will not rely on an old browser acknowledgement. We will use a new notice version.

24. Language

This Policy is published in English, and English is its source version. Ghotala’s interface is available in thirteen languages, but this document is not currently translated, and no translation of it should be treated as authoritative.

A translated version must not be represented as professionally or legally reviewed unless that review has actually taken place.

25. Contact

Privacy questions or requests: privacy@ghotala.wtf.

Legal enquiries: legal@ghotala.wtf.

Operator: Piyush Chandra, Bengaluru, Karnataka, India.

Privacy - ghotala.wtf