JagaShieldBahasa Malaysia

Privacy

In force from 30 August 2026 · version 2026-08-v3

This notice explains what JagaShield does with personal data, as required by the Personal Data Protection Act 2010. JagaShield is operated by Livorare, which is the data controller for that purpose.

What we do with what you paste into the checker

Text you submit to the checker is processed in memory to generate a result and is never written to disk or to our database. We keep only a one-way hash of the submission, the verdict, and coarse metadata — never the text itself. See methodology for what a result can and cannot tell you. If you rate a result as helpful or wrong, that rating is stored against the same record, so we can tell how often the checker gets it right.

Part of each check is performed by OpenAI, a third-party AI provider in the United States: the text you submit is sent to OpenAI’s API to be analysed, and its assessment comes back to our server. This is a cross-border data transfer under the Personal Data Protection Act. What is sent is the submission text itself — nothing that identifies you travels with it: no account, no IP address, no cookie.

What happens to it there is governed by OpenAI’s own terms, not ours. When we last checked, on 30 August 2026, those terms said that data sent through the API is not used to train OpenAI’s models, and is kept for up to 30 days for abuse monitoring before being deleted. Because those terms are OpenAI’s and can change, we link to them rather than restate them as though they were fixed — read OpenAI’s current data controls.

On our side, the rule-based half of the check runs on our own server, and if the AI provider is unavailable the checker completes with rules alone and labels the result accordingly. If we change or remove the provider, this section will be updated before the change takes effect — the provider named here is the provider in use.

Information about other people

A message you paste in usually contains details about someone else — the number that contacted you, an account number, sometimes a name. Please include only what is needed to check the thing you are checking. You do not need to add your own identity card number, your full account number, or anything about people who are not involved.

We never publish what you send us, and we never publish a report as an accusation against a named person. Names are matched only against the alert lists published by Bank Negara Malaysia and the Securities Commission — a match tells you a regulator has listed that name, and is not a finding by us about anyone. If you believe something on this site is wrong about you, please tell us using the contact form.

IP addresses

We only ever store a salted hash of your IP address, never the address itself. It is used for one thing: counting how many checks have come from one place today, so that a script cannot exhaust the service for everyone else. The hash cannot be turned back into an address, and we never store the address itself at any point.

Uploads

The checker accepts PDF files up to 2 MB. An uploaded PDF is read in memory to extract its text and is never written to disk, never logged, and never stored — not the file, and not the text taken from it. What we keep is the same as for pasted text: a keyed fingerprint, the verdict, and the reason codes.

Only the text layer is read. Embedded images are not extracted, and no metadata from the file is retained. Screenshots and other image formats are not accepted.

Waitlist

If you join the JagaShield Pro waitlist, we store your email address, the segment you selected, and where you heard about us, to contact you about the paid tier only.

Tip form

The tip form is anonymous: we collect no name, email address, or any other identity with it. Only the text you write is stored — so anything personal it contains is there because you chose to include it. Tips are deleted after 12 months and are never published or used for marketing. Because tips are anonymous, we cannot reply to them.

Visits to our pages

When a page here is requested, we record which page it was and the family of browser or crawler that asked for it — Chrome, Safari, or an AI assistant fetching the page on someone’s behalf. The full browser identification string is shortened before it is stored, so it cannot be used as a fingerprint, and no IP address, cookie or identifier is kept with it. We use this to understand how people find the site.

Where this runs, and where your data is kept

JagaShield runs on Replit, which hosts both the site and the database behind it. Everything this page describes as stored — including your email address, if you join the waitlist — is held in that database.

Replit’s data centres are outside Malaysia, so keeping your data there is a cross-border transfer under the Personal Data Protection Act. We will name the region we publish in here once the service is live. Replit is independently audited to the SOC 2 Type II standard, publishes the list of suppliers it relies on in turn, and publishes the data-protection terms it offers its customers — you can read that supplier list and those terms yourself.

As our host, Replit necessarily handles every request to this site, and reports back to us a summary of that traffic: which pages were visited, which sites people arrived from, the country a visit came from, and the family of browser and device used. We see it as counts and totals, not as individuals.

We use no other analytics service. Nothing in your browser reports anything to anyone — there is no tracking script on this site, from us or from anybody else.

Beyond the parties named on this page, we disclose personal data only where Malaysian law, the police, or a court validly requires it. If we ever add another service that handles your data, this page will name it before it starts.

Cookies

We set two small cookies, and neither is used for advertising or cross-site tracking. One counts how many free checks you have used today and resets after 24 hours; the other remembers that you joined the waitlist, so we stop asking. Both hold nothing but a count and a date, and both are signed so they cannot be edited to award extra checks.

There is no analytics cookie, because we run no analytics service in your browser. That is also why this site shows you no cookie banner — there is nothing to ask you to consent to.

How long we keep things

WhatHow long
Check records — verdict, reason codes, fingerprint, hashed IP90 days
Daily free-use counters7 days
Messages sent through the contact form12 months
Visits to our pages180 days
Waitlist — if you joined and we never wrote to you12 months from signing up
Waitlist — if you unsubscribeWe keep only your email address, so that we do not add you back by mistake

A job runs every day to enforce these. One thing worth being precise about: when we delete something, it stops being visible to us immediately, but our host keeps backups for up to seven days, so a deleted record is fully gone within a week rather than instantly.

Keeping it safe

The text you submit is never written to disk or to our database — not the message, and not an uploaded file. We never store your IP address, only a scrambled version of it that cannot be turned back. The fingerprint we keep of a submission is scrambled with a secret key, so that even a short message like a phone number cannot be worked backwards out of it. There is no tracking script on this site and no session recording, so there is nothing in your browser that could leak what you typed. Everything is served over an encrypted connection.

No system is completely secure and we will not claim otherwise, but the design principle here is simple: the safest way to protect what you paste in is not to keep it.

Your rights, and how to use them

Under the Personal Data Protection Act you may ask us to:

Use the contact form to ask. Two honest warnings about that form, because it was built to be anonymous: it does not ask who you are, and it gives us no way to reply. So if you want an answer, include a way to reach you in the message itself — and please include only what you are willing to have stored, since messages are kept for 12 months.

What we can find depends on what you gave us. If you joined the waitlist, we can look you up by email address. Check records are not linked to a name or an account, and messages sent through the contact form carry no identity at all — so for those, there is usually nothing we can retrieve that is identifiably yours, which is a consequence of collecting as little as possible rather than an evasion.

If you are unhappy with how we have handled your personal data, you may complain to the Department of Personal Data Protection (JPDP) Malaysia.

Age

Anyone can use the checker. There is no account, no age question, and nothing identifying is collected, so there is nothing here to check an age against — and we would far rather a teenager checked a suspicious message than was turned away from it. The waitlist is the one place we ask for an email address, and that is for adults: please do not join it if you are under 18.

If this service changes hands

JagaShield is run by an individual business and we intend to move it to a company in due course. If that happens, or if the service is transferred to anyone else, your personal data moves with it and the new operator takes on every obligation in this notice. Your rights above are unaffected. We will say so here when it happens.

Changes to this notice

We may update this notice. The version at the top changes whenever the wording does, and the date tells you when the version you are reading came into force.