Privacy Policy
Last updated: October 1, 2026
Ingam is a browser extension and web service that checks a payment right before it is made. To do that it needs very little information, and this page lists all of it. Ingam is run by an independent developer. Contact: hello@ingam.dev.
The short version
- Ingam runs only when you press a pay button on a checkout page.
- It sends the store's domain and the total, not your card, name, address or the page contents.
- It never sells data and never uses it for advertising.
What the extension sends, and why
| Data | When | Why |
|---|---|---|
| The store's domain (e.g. example.com), the checkout page's domain | When you press a pay button, or "Check this site" | To check the seller's history and whether the payment goes where the seller says |
| The total and currency shown on the page | When you press a pay button | To spot unusual amounts |
| Your choice after a review or block (paid or cancelled) | When you choose | To remember stores you trust and to measure how often our checks are wrong |
| Reports you send ("this check was wrong", "Ingam didn't appear here") | Only when you send one | To fix mistakes |
| An anonymous install ID, extension version and mode | With each check | To apply the free daily limit and to see whether a new version works |
| Page text from the checkout | Only in AI agent mode, which is off by default | To find hidden instructions aimed at AI agents. Processed in memory and not stored |
What Ingam never collects
- Card numbers or anything typed into payment fields
- Your name, email, shipping or billing address
- Full web addresses (which can contain order numbers or tokens)
- Pages you visit outside a checkout
- Page contents in the default mode
Network address
When the extension is installed it asks our server for an anonymous key. To stop abuse we keep a one-way hash of the network (IP) address that asked, used only to limit how many keys one network can create per day. We do not store IP addresses themselves.
How long we keep it
- Check records (domain, amount, result, your choice): 12 months, then deleted or reduced to totals per store that contain no install ID.
- Reports you send: until the issue is resolved, at most 12 months.
- Page text in AI agent mode: not stored.
How we use it
- To answer each check.
- To improve our checks, for example by learning which stores many Ingam users pay without problems.
- To publish aggregate statistics that cannot identify you (for example "Ingam stopped N payments to look-alike stores this month").
We do not sell data, share it with advertisers, or use it to build profiles of people.
Services we rely on
- Cloudflare hosts our server and database.
- To check a domain we ask public domain registries (RDAP) and may fetch the store's public /.well-known/agent-payments.json file. These requests come from our server, not from you.
Your choices
- Turn checks off any time in the extension's menu, or remove the extension.
- Records are tied to an anonymous install ID, not to you. If you'd like the records from your install deleted, email us and we'll explain how to find your install ID.
Children
Ingam is not directed at children under 13 and does not knowingly collect their information.
Changes
If this policy changes in a way that affects what we collect, we will update the date above and note the change in the extension's release notes.