Hunch — Privacy Policy

Last updated: 2026-07-29

Hunch is a browser extension that warns you about scams and phishing in your messages. It is built to work with as little data leaving your device as possible. This policy describes exactly what is read, what leaves your device and when, and what is stored.

What Hunch reads (on-device)

Hunch reads the text of messages visible on your screen on supported platforms (LinkedIn, Gmail, Facebook Messenger, WhatsApp Web). Reading happens only while that tab is open. All scam classification runs locally in your browser using a built-in rule engine — no message text is sent anywhere to produce the on-page warning.

What leaves your device, and exactly when

WhenWhat is sentTo whomDefault
A message contains a shortened link (bit.ly, t.co, lnkd.in, …)The URL only — never the message textHunch server (to resolve the destination and check it against phishing lists)On
You click “Extended explanation” on a flagged messageUp to 300 characters of the messageHunch server → Anthropic Claude APIOn (manual click)
Automatic AI checks (opt-in)Up to 300 characters of the message + a few labels (e.g. “first message”, “has link”)Hunch server → Anthropic Claude APIOff until you enable it
Phishing-domain list refreshNothing about you — a plain list downloadHunch server (server-side aggregation)On

No message text leaves your device automatically. AI features that send text are off until you turn them on and have accepted the in-product data notice.

Message text is not stored or logged

The Hunch server does not store or log the content of messages or the text that is sent. Server logs record only a short one-way hash prefix and the character length of a request (for abuse-rate visibility) — never the text itself, and never anything that identifies you. The sent text is used to answer your request and then discarded; it is not retained by Hunch or by Anthropic beyond the request lifetime.

What is stored locally (never transmitted)

The following live only in your browser’s chrome.storage.local:

You can erase all of it at any time from Settings → Delete all my data.

Third-party services

ServicePurposeData sent
Hunch serverURL unshortening, optional AI checks, phishing-list aggregationURL or ≤300 characters of a message on the events above; nothing stored
Anthropic Claude APIAI explanation / risk scoring≤300 characters of a message, only on click or if you enabled automatic AI checks
OpenPhish / URLhausPhishing & malware domain listsNone — fetched by the Hunch server, not your browser

What Hunch never does

Limits of protection

Hunch catches many scams but not all. The absence of a warning does not mean a message is safe. Always verify unexpected requests for money, codes, or personal details independently.

Contact

Privacy questions: privacy@askhunch.app.