The Root Access Network — UbuntuScamBank
Privacy Policy
Last updated: July 2026
Who we are
UbuntuScamBank is operated by The Root Access Network (“TRAN”, “we”, “us”, “our”), a cybersecurity education organisation and the parent body of the Ubuntu Bridge Initiative. We are based in the United Kingdom.
If you have questions about this policy, contact us at therootaccessnetwork@africybercore.com.
Who this policy applies to
This policy applies to anyone who uses UbuntuScamBank at scambank.ubuntubridgeinitiatives.org — whether you submit reports, browse the public feed, use the researcher API, or simply visit the site.
You must be at least 16 years old to create an account. By registering, you confirm that you meet this requirement.
What information we collect
Information you give us directly
When you create an account, we collect your email address and a username. You may optionally provide a display name, biography, and country. If you apply for researcher API access, we collect your name, organisation, role, and intended use case.
When you submit a scam report, we collect the content of the report — which may include text you paste, files you upload, and contextual notes you provide. We also collect the scam type, severity rating, and country you select.
When you use the feedback form, we collect your name, email, role, and message.
Information collected automatically
When you sign in with Google, we receive your name and email address from Google as part of the authentication process. We do not receive your Google password.
We collect information about how you interact with the platform, including which reports you view and vote on. We do not use third-party analytics or advertising trackers.
Information in submitted reports
Scam reports often contain information about scammers — phone numbers, email addresses, domain names, URLs, and sender names. Our AI triage system is designed to extract this threat intelligence and strip personal information about the victim before storing the report. However, automated stripping is not perfect. If you include your own personal information in a submission (for example, your name in a message you paste), it may be stored.
We recommend reviewing what you submit before sending. You can use the optional context note field to describe what happened in your own words rather than pasting content verbatim.
How we use your information
We use your information to:
- Operate and improve the platform
- Authenticate your account and maintain your session
- Calculate and display your points and badge tier
- Process and publish scam reports
- Respond to feedback and researcher applications
- Send the fortnightly community digest email (you can unsubscribe at any time)
- Deliver your researcher API key if your application is approved
- Take moderation actions where necessary (including suspending or removing accounts that violate our terms)
We do not sell your data. We do not use your data for advertising. We do not share your data with third parties except as described below.
Who we share your information with
Supabase— our database and authentication provider. Your account data and submitted reports are stored on Supabase‘s infrastructure. Supabase is SOC 2 Type II certified and stores data in the European Union.
Anthropic— when you submit a report, the content is sent to Anthropic‘s Claude API for AI triage analysis. Anthropic processes this data as a service provider and does not use it to train their models by default. See Anthropic‘s privacy policy at anthropic.com/privacy.
Resend — we use Resend to send transactional emails (API key delivery, account notifications) and the community digest. Resend stores your email address as part of the mailing list. You can unsubscribe from the digest at any time using the link in any digest email.
Vercel— the platform is hosted on Vercel‘s infrastructure. Vercel may process request metadata (IP addresses, request logs) as part of serving the application.
We do not share your data with any other third parties. We do not sell or rent your information.
Your rights
Under UK data protection law (UK GDPR), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data — you can update your display name, bio, and country from your profile page at any time
- Delete your account and associated personal data — contact us at therootaccessnetwork@africybercore.com and we will process your request within 30 days. Note that scam reports you have submitted will remain in the platform anonymised (your name and account will be removed, but the threat intelligence data remains to protect others)
- Object to or restrict processing of your data in certain circumstances
- Withdraw consent for the digest email by unsubscribing at any time
To exercise any of these rights, contact us at therootaccessnetwork@africybercore.com. We will respond within 30 days.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the UK Information Commissioner‘s Office (ICO) at ico.org.uk.
How long we keep your data
We keep your account data for as long as your account is active. If you request deletion, we will remove your personal data within 30 days.
Submitted scam reports are retained indefinitely as threat intelligence data. When an account is deleted, the reports are anonymised — the link between the report and your identity is removed.
Feedback form submissions are retained for 12 months and then deleted.
Cookies and storage
We use cookies only for authentication — to maintain your signed-in session. We do not use advertising cookies, tracking pixels, or any third-party analytics cookies. You can clear cookies at any time through your browser settings, which will sign you out of the platform.
Changes to this policy
We may update this policy from time to time. When we make significant changes, we will update the “Last updated” date at the top of this page. Continued use of the platform after changes constitutes acceptance of the updated policy.
Contact
The Root Access Network