Hunch — Privacy Policy
Hunch is a browser extension that warns you about scams and phishing in your messages. It is built to work with as little data leaving your device as possible. This policy describes exactly what is read, what leaves your device and when, and what is stored.
What Hunch reads (on-device)
Hunch reads the text of messages visible on your screen on supported platforms (LinkedIn, Gmail, Facebook Messenger, WhatsApp Web). Reading happens only while that tab is open. All scam classification runs locally in your browser using a built-in rule engine — no message text is sent anywhere to produce the on-page warning.
What leaves your device, and exactly when
| When | What is sent | To whom | Default |
|---|---|---|---|
| A message contains a shortened link (bit.ly, t.co, lnkd.in, …) | The URL only — never the message text | Hunch server (to resolve the destination and check it against phishing lists) | On |
| You click “Extended explanation” on a flagged message | Up to 300 characters of the message | Hunch server → Anthropic Claude API | On (manual click) |
| Automatic AI checks (opt-in) | Up to 300 characters of the message + a few labels (e.g. “first message”, “has link”) | Hunch server → Anthropic Claude API | Off until you enable it |
| Phishing-domain list refresh | Nothing about you — a plain list download | Hunch server (server-side aggregation) | On |
No message text leaves your device automatically. AI features that send text are off until you turn them on and have accepted the in-product data notice.
Message text is not stored or logged
The Hunch server does not store or log the content of messages or the text that is sent. Server logs record only a short one-way hash prefix and the character length of a request (for abuse-rate visibility) — never the text itself, and never anything that identifies you. The sent text is used to answer your request and then discarded; it is not retained by Hunch or by Anthropic beyond the request lifetime.
What is stored locally (never transmitted)
The following live only in your browser’s chrome.storage.local:
- Your settings (
hunch_options) and consent flag - Scan statistics and category breakdown (
hunch_stats,hunch_breakdown) - Local caches: phishing-domain list, resolved-URL cache, AI-verdict cache
- Muted contacts and the false-positive learning counters, plus contact profiles — one-way hashes only, never raw thread ids, names, or message text
- A “recent warnings” log — the last 20 warnings as date + platform + warning-type only, never message text
- Missed-scam reports you create (
hunch_missed) — stays on your device unless you copy it out
You can erase all of it at any time from Settings → Delete all my data.
Third-party services
| Service | Purpose | Data sent |
|---|---|---|
| Hunch server | URL unshortening, optional AI checks, phishing-list aggregation | URL or ≤300 characters of a message on the events above; nothing stored |
| Anthropic Claude API | AI explanation / risk scoring | ≤300 characters of a message, only on click or if you enabled automatic AI checks |
| OpenPhish / URLhaus | Phishing & malware domain lists | None — fetched by the Hunch server, not your browser |
What Hunch never does
- Store or log your messages
- Sell or share your data
- Track you across sites, or require an account or login
- Read messages in background tabs or when the browser is closed
Limits of protection
Hunch catches many scams but not all. The absence of a warning does not mean a message is safe. Always verify unexpected requests for money, codes, or personal details independently.
Contact
Privacy questions: privacy@askhunch.app.