Independent education & support
Privacy notice
Read every guide without telling us who you are. If you choose to write to us, we keep it private, protect it, and delete it on a schedule—or sooner, when you ask.
Effective October 4, 2026 · Version 2026-10-04.2
The short version
- Forms are optional. You can use the whole site without giving us personal information.
- What you send goes to a private review inbox, is encrypted before storage, and is never published automatically.
- You can withdraw a submission yourself at any time with the code you receive after submitting.
- Analytics is aggregated, does not use cookies to identify you, and you can turn it off on this page.
- We do not sell personal information, share it for advertising, or show ads.
Who runs this site
ZelleFraud is an independent educational project founded and run by Navendu Chandra in the United States. It is not affiliated with Zelle, Early Warning Services, or any bank. “We” means the project and the reviewers it authorizes to read submissions.
What we collect
When you send a form
Feedback, experience stories, and mission messages contain:
- your message;
- an email address—optional for feedback and stories, required for mission messages so we can reply;
- an optional name, for stories and mission messages;
- for stories, the situation and outcome you choose and whether you are open to publication;
- for page feedback, the public page path, without any query string or fragment;
- a reference, the time, the review status, and the version of this notice you agreed to.
Please leave out account and card numbers, Social Security numbers, passwords, verification codes, addresses, and other people’s details. The form checks for common patterns before sending and our server checks again; anything flagged is returned for you to edit, never silently stored. These checks can miss information written in unusual ways and can occasionally flag an ordinary number.
Images, screenshots, documents, and other attachments are not accepted. We do not run OCR or send your text to an AI model or any other outside scanning service.
Analytics and performance
When analytics is allowed in your browser, Vercel Web Analytics records page views and a short list of interactions: links followed (the destination page or website domain), reading milestones, 30 seconds of engagement, “Was this guide useful?” votes, opening the feedback form or dismissing the feedback button, form stages (started, sent, or error), withdrawal outcomes, and the length and result count of searches. These events never include what you type—no messages, names, email addresses, or search text. Query strings and fragments are removed before anything is sent.
Vercel also records the referring page, approximate location (country, region, and city), browser, operating system, and device type. It does not use cookies to identify visitors; it tells visits apart with a hash of the request that it discards after 24 hours. Vercel Speed Insights reports page-load timings with the page address, browser, operating system, device type, network speed, and country.
Analytics stays off if your browser sends a Do Not Track or Global Privacy Control signal, or if you turn it off here. Staff review pages never load analytics.
Bot protection and abuse limits
When you send a form or a withdrawal request, Vercel BotID runs an invisible check in your browser to confirm a person is using it. We use the free Basic level, not the paid Deep Analysis mode. To limit repeated attempts, we store keyed one-way hashes of your IP address for each minute of activity; they expire after two minutes and are deleted within about a day. A separate in-memory counter resets within minutes and is never stored.
Hosting and security logs
To deliver the site and defend it against attacks, our host, Vercel, processes your IP address, browser user agent, and the pages you request, and keeps request logs for a limited period. Our own application logs record events such as “a submission was received” without submission content, email addresses, or IP addresses.
AI assistants and public data
Our public JSON resources serve published guides only. Requests to the search and guide endpoints record the guide requested, or the search length and result count, with a coarse label based on the self-declared user agent. Private submissions are never available through these endpoints. The search box on our pages runs in your browser and sends nothing; the AI-assistant search endpoint receives search text in the request address, so that text can appear in Vercel’s request logs.
Browser storage
- Closing the feedback button stores a flag in session storage that keeps it closed for that tab.
- Turning analytics off stores your choice in this browser’s local storage.
- Our code sets no cookies for visitors. Staff who sign in receive secure session cookies; staff sign-in attempts and sessions record the IP address and browser and are deleted within about a day after they expire.
How submissions are protected
- Messages, names, and email addresses are encrypted by our application (AES-256-GCM) before they reach the database. The submission type, times, review status, chosen story situation and outcome, publication preference, feedback page, and notice version are stored unencrypted so the inbox can sort them. A keyed fingerprint of each submission detects accidental duplicates.
- Only invited reviewers with individual accounts and multi-factor authentication can open the inbox, and each sees only the submission types their role covers. Among reviewers, only the owner can delete records. Review actions are logged with the reviewer, action, reference, and time.
- New-submission email alerts, when enabled, contain only the type, reference, and a sign-in link—never your message or contact details.
- No system is perfectly secure. If a breach affects your information, we will notify you where the law requires.
Who we share information with
We do not sell or rent personal information or share it for advertising. These providers run parts of the service for us and process information under their own terms:
- Vercel: hosting, request logs, BotID, Web Analytics, and Speed Insights.
- Neon: database storage for encrypted submissions.
- Resend: delivery of content-free alerts to our reviewers, once enabled.
- Our email provider: any messages we exchange with you, such as replies to mission messages or confirmation before publication.
We may disclose information when the law requires it, such as in response to a valid subpoena or court order, or to protect someone from imminent harm. We do not otherwise share submissions with banks, Zelle, Early Warning Services, law enforcement, or regulators. Writing to us is not a bank claim or an official fraud report.
Publication and consent
Agreeing to this notice lets us review what you send; it is not permission to publish. Stories are published only after review, redaction, and your confirmation, so include an email if you are open to publication. You can change your mind at any point before publication.
How long we keep it
- Open submissions: deleted 180 days after we receive them.
- Resolved or declined submissions: deleted 90 days after closure. Reopening restarts the 180-day period.
- Withdrawn or owner-deleted submissions: deleted immediately, with any queued alert.
- Review audit log: one year. It holds references, actions, and times, not submission content.
- Abuse-limit hashes: expire after two minutes and are deleted within about a day.
- Analytics: Vercel discards the visit hash after 24 hours. Page-view and event records (page, referrer, location, browser, device) remain in our Vercel account for our plan’s retention period.
- Email we exchange with you: kept in our email account until we delete it. Withdrawal and the schedule above do not reach it, so email privacy@zellefraud.com if you want it deleted.
- Database recovery history: Neon keeps a short history of database changes so we can recover from a failure. A withdrawn or deleted submission stays in that history until it expires. If we ever restore the database, we will delete again every submission our audit log records as withdrawn or deleted.
Scheduled deletion runs daily, so a record can outlast its date by up to a day, longer if a service is briefly unavailable.
Your choices
- Withdraw a submission: after you submit, we show a reference, a withdrawal code, and a private link. Use them on the withdrawal page to delete the submission immediately.
- Lost your code, or want a copy: email privacy@zellefraud.com with your reference, or send a feedback message starting with “Privacy request.” If the original submission had a follow-up email, we may write to it to confirm. To correct a submission, withdraw it and send a new one.
- Analytics: use the control above, or turn on Global Privacy Control or Do Not Track in your browser.
- Publication: nothing is published without your confirmation.
Children
This site is written for adults and is not directed to children under 13. We do not knowingly collect their information. If a child has sent us something, withdraw it or email privacy@zellefraud.com and we will delete it.
Changes to this notice
Each submission records the version of this notice in effect when it was sent. If we change how we handle information, we will update this page and its effective date before the change applies to new submissions.
Contact
For privacy questions or requests, email privacy@zellefraud.com. Include your submission reference if you have one, and leave out account numbers, passwords, and other sensitive details. Email you send us is kept as described under How long we keep it.