Corrections Policy

Last updated: August 2026

This site publishes guidance that people act on when they have money at risk. Getting something wrong here is not a typo — it can send someone down the wrong path at the worst moment of their year. So we would rather be corrected than be consistent.

This page states what we do about errors. It is not aspirational: everything below is already how we work.

How to report an error

Email press@tuteladigitalis.com with the page and what is wrong. You do not need to prove it or explain it formally — pointing at it is enough, and we will do the checking.

We would particularly like to hear from an organisation that believes we have described its policy incorrectly, and from any researcher or journalist who finds a figure that does not hold up.

What we do when something is wrong

What counts as a source

Where we state what an organisation does, we take it from that organisation's own published guidance or a named regulator, and we link it so you can check rather than trust us. Where an organisation publishes an exact line, we quote it; otherwise we paraphrase and attribute. We do not invent quotes, and we do not attribute a figure to an agency that did not publish it.

Absence of evidence is not evidence of absence

Some of our reference data records that we could not find a published policy or scheme. That is a search result, not a proven absence — no authority publishes a statement that it has never created something. Where this distinction matters, our datasets record it explicitly rather than collapsing it into a failing grade, and we would rather look less decisive than overstate what we know.

Third-party information goes stale

Deadlines pass and official portals are not always updated by the bodies that run them. We have found a programme still advertising a deadline that had already expired on the administrator's own site. We check dates against the current date rather than against what a page says, and we would rather tell you a programme has closed than let you rush at a door that is already shut.

Corrections we have made

A corrections policy that never lists a correction is not worth reading. This is the running log. Each entry says what we published, what is actually true, and how the error was found.

1 September 2026 — we said we had checked five absence claims. Three of them were wrong.

Yesterday's correction to the Dating App Safety Index brought the count of apps publishing no retention period from seven down to six, and stated that the remaining five claims, for Match.com, eharmony, Duet, PURE and SCRUFF, "were checked and stand". Three of them did not stand. Duet, PURE and SCRUFF each publish a retention rule. In every case we had read the wrong document.

Duet's privacy policy has a section headed Retention and Deletion: verification photos and videos are "retained for the lifetime of your account", and the face geometry is "not retained as a persistent biometric template after processing". PURE's privacy policy states that biometric data is permanently deleted when the account is deleted, that nothing is retained if verification is cancelled before it completes, and that Veriff session data "may be retained for 7 days in active storage and then for up to 3 months in secure archive". SCRUFF's operator, Perry Street Software, publishes a dedicated Notice and Consent to Process Biometric Data with a section headed Retention.

The pattern is identical in all three, and identical to Tinder: retention lives in a privacy policy or a dedicated biometric notice, and all three rows cited only help and safety pages. PURE is the sharpest case. Its own entry said the data was handled "in accordance with Pure's Privacy Policy and Veriff's Privacy Notice" and then reported that no retention period was stated. It named both documents and read neither, which is the Tinder failure repeated a day later, inside the revision written to prevent it.

Found by us, during a sweep of every citation in every dataset. The count is now three of twelve. Of those three, eharmony was re-read against its privacy policy and stands. Match.com and Plenty of Fish could not be re-read at all: both sit behind blocks that refuse us, and Plenty of Fish's privacy policy defers the question to a help article we cannot open. Those two are recorded as an absence in the pages we could review, and are explicitly not confirmed. The dataset is version 2.2.0, and the archived copy has not yet been updated to match.

31 August 2026 — we recorded an app as publishing no retention period, on the page where we tell you an absence is not a finding

Our Dating App Safety Index said that seven of twelve dating apps "publish no retention period at all", and counted Tinder among them. Tinder in fact publishes one of the most detailed schedules in the whole index. Its Photo Check privacy page states that the video selfie is promptly deleted, that the FaceMap and FaceVector derived from it are retained for the lifetime of the account and deleted within 30 days of closure, and that two audit images and the verification result are kept until 90 days after the account closes, or a year if the account is banned.

The per-app row was hedged honestly: it said no retention period was stated "in the pages reviewed". The summary sentence dropped that hedge and asserted a proven absence. That distinction is the entire subject of the "Absence of evidence is not evidence of absence" section further up this page, which makes this the second time we have published the error that section exists to prevent. The first was a background-check programme in July. What makes this one worse rather than better is that the page carrying Tinder's schedule was already listed in that row's own sources. It was cited and not read.

Re-reading all seven absence claims against the platforms' own pages corrected three more entries. Hinge was described only through Selfie Verification, which deletes within 24 hours, and was called the tightest deletion window in the index; Hinge also runs Face Check, which keeps the FaceMap for the life of the account. OkCupid's 24-hour purge is real but was attributed to "the Match Group family standard", which does not exist: inside Match Group, OkCupid purges within 24 hours while Tinder and Hinge retain for the account lifetime. Plenty of Fish rested on that same invented standard. The remaining five absence claims, for Match.com, eharmony, Duet, PURE and SCRUFF, were checked and stand. The count is now six of twelve.

Found by us, while researching an article that would have quoted the figure. The fix that matters is structural rather than textual: the retention field now carries its own citation list, the way our background-check field already did. A field that asserts an absence has to show the pages that absence was read from, or nobody can check it, ourselves included. The dataset is now version 2.1.0, and the archived copy is being updated to match.

12 August 2026 — we told UK victims to report to a body that no longer exists, on a page where we claimed we had fixed exactly that

The UK replaced Action Fraud with Report Fraud (reportfraud.police.uk) in December 2025, and we did a pass to update our pages. Three places were missed, and all three were instructions rather than background: a step in our UK refund guide, the UK escalation advice inside our refund checker, and a step in that checker listing each country's reporting body. Anyone following them would have been sent to a service that had shut.

What makes this worth logging is where else it appears. Our about page uses this very rename as its worked example of how we handle a superseded source, and says we "corrected every page that referenced it". We had corrected forty of the forty-three places it appears, which is not the same claim. The three instructions now name Report Fraud, and note that it replaced Action Fraud in December 2025 so the change is not confusing to anyone who remembers the old name.

Found by us, while clearing an old to-do that we expected to already be closed. The forty we left alone were left alone deliberately: most of them say "replaced Action Fraud" or "formerly Action Fraud", which is correct, and four cite Action Fraud reports as the source of a 2022 to 2023 dataset, where renaming the body would misattribute the data. The lesson is that a rename is not one edit, and the sentences most likely to be missed are the ones telling somebody what to do.

11 August 2026 — we put a precise fraction on a qualitative FBI statement, and cited a page that predates the real numbers

Our flagship essay published "3 in 4" FBI-contacted victims did not know they were being scammed, and our recovery-scams guide published "3,780 of them in 2025" and 78%. All of it was credited to the FBI's February 2025 news story on Operation Level Up. That story contains none of those numbers. It says only that "most of the victims contacted by the FBI are unaware they are being scammed" — a qualitative statement, to which we had attached a precise-sounding fraction.

The FBI does publish the figures, on its own Operation Level Up victim-services page. As of December 2025: 8,103 victims notified, and 77% of them did not know they were being scammed. Both pages now carry those numbers, and both source links point at the page that actually holds them rather than at the older story. The summary file we publish for AI systems was carrying the same wrong fraction and has been corrected too.

Found by us, because we were about to use the figure somewhere public and checked it at source first. The general lesson we take from it: a rounded fraction reads like a summary and invites nobody to verify it, where a percentage invites a look. The number that was hardest to check was the one that turned out to be wrong.

2 August 2026 — Our phishing guide asserted a mechanism instead of citing it, and framed it as casework.

A note on the phishing page claimed personal review of hundreds of phishing emails from victim cases, and explained that the successful ones land at a moment of distraction. The underlying mechanism is real and documented, but we asserted it rather than sourcing it, and the framing implied direct casework we had not evidenced. The section now quotes Frank Stajano and Paul Wilson (University of Cambridge, Communications of the ACM) for what they actually wrote, the distraction and time principles, and marks the phishing conclusion as our inference rather than theirs. It also carries a link to the paper, which it previously did not. The same first-person framing was removed from five other guide pages in the same pass.

A reader raised it publicly. We changed it the same day. An unverifiable claim to authority is precisely the thing this site tells people to distrust, so it had no business being on ours.

28 July 2026 — Finland was listed as having no scam-text protection. It has one of the strictest.

Our Scam-Text Protection Index placed Finland in the "none identified" tier: no mandatory scheme found to block or label a text wearing a company's name. That was wrong, and it was already wrong when we published on 14 July. The Finnish regulator Traficom issued Order 28 L/2025, in force 4 May 2026, requiring organisations to obtain approval for every SMS sender ID in advance — either authorised through their messaging provider or reserved exclusively with Traficom — and Traficom's own guide states that traffic using a reserved sender name outside the agreed routes "will be blocked". Finland now sits in the Blocked tier alongside Ireland, Spain, India and Italy. The counts, the table, the alt text and the graphic have all moved with it.

This is the second time the same source class has failed in the same direction. On 17 July we moved Italy out of that tier for exactly the same reason: it was sourced to a commercial messaging aggregator's country-requirements page rather than to a regulator, and AGCOM was in fact running a mandatory register. An aggregator's matrix records what that company needs in order to route a customer's traffic, which is a different question from whether a regulator has mandated consumer-facing protection — and it can be silent on a rule that exists. So rather than only fix the row, we have added the weakness to the limits section on the index itself, naming the remaining rows in that tier as the weakest claims on the page.

Found by us, while checking a lead for something else entirely. Three further defects surfaced in the same audit and were fixed: the headline read "In five countries, it doesn't" when the blocked tier held four — a hardcoded number on a page where every other count is derived, so it is now derived too; the image alt text still named Italy among the countries with no scheme, ten days after Italy was moved; and a stray character in the page source rendered one sentence as "the $6 countries". The archived dataset on Zenodo still carries the pre-correction table and is noted as such on the page until it is re-deposited.

26 July 2026 — Verification of Payee is already in force, not arriving in 2027

Our Scam-Refund Index said that mandatory "Verification of Payee" — the name-and-IBAN check before a transfer — was coming with the EU's Payment Services Regulation (PSD3), with realistic application around 2027. That was wrong on both the instrument and the date. Verification of Payee comes from the Instant Payments Regulation (EU) 2024/886, and Article 5c(9) requires banks in euro-area countries to comply since 9 October 2025, free of charge. The 2027 date we published is real but belongs to EU countries outside the euro, which have until 9 July 2027. Both dates exist and apply to different countries, which is how they came to be merged into one wrong sentence. PSD3 is a separate, later package; what it would actually add is a refund right for bank-impersonation fraud.

Found by us, by noticing that our own guide to reporting scams in Europe already said the opposite — correctly. That page needed no change. The error was confined to the index, and it was corrected against the text of the regulation rather than by making the two pages agree with each other.

22 July 2026 — the Impersonation Index counts entries, not organisations

We described the Impersonation Index as covering "27 organisations". It holds 27 entries covering roughly thirty organisations: one row is generic (your bank, any bank) and five bundle several bodies together — Zoll, Finanzamt and Österreichische Post are a single row spanning two countries. The count therefore overstated and understated at the same time. Corrected on the page, in the structured data, and on the archived dataset record, and the page now explains what counts as an entry.

26 July 2026 — a "60% recovery rate" we could not source, on the page for people who have just been scammed

Our recovery guide stated that roughly 60% of money is recovered by banks if you act fast. We could not trace that figure to any source, and it contradicted our own guide to getting money back, which correctly says the odds depend on the payment rail you used. It was the worst error we have found on this site, because it sat on the page people read in the hours after losing money — the moment when false hope is most expensive.

Removed. The page now carries a figure we can source and that says something narrower: the FBI reports a 58% success rate for its Recovery Asset Team in freezing funds on fast-reported wire fraud, and $679 million frozen for victims in 2025. That is the FBI freezing a transfer, not a bank refunding a loss — a different thing from what we had published, and we would rather say the narrower true thing.

26 July 2026 — we cited a report that disagreed with our own figure

Our phishing guide published a statistic and credited it to Verizon's Data Breach Investigations Report. The report does not support that number. We were citing a source that contradicted us, which is worse than citing none. The figure now shown — that 62% of breaches involve a human element — is the one the report actually publishes.

26 July 2026 — arithmetic that contradicted itself on the same line

Our glossary gave a loss total and a complaint count for business email compromise and then concluded the average exceeded $160,000. Its own two numbers divided to about $129,000. The error was checkable by anyone reading the sentence. The entry now uses current FBI figures — $3,046,598,558 across 24,768 complaints — and states the average they actually produce, about $123,000.

26 July 2026 — three wrong figures in one identity-theft guide

The page said 48% of adults had experienced identity theft; that number came from an unrelated survey question about cases still unresolved after twelve months, not lifetime prevalence. It said victims spend 300 hours resolving it; that traces to a survey from the early 2000s which reported roughly 300 million hours in aggregate across all victims, not 300 hours each. And it gave 1.4 million reports for 2024, which is the 2021 figure. All three are removed; the page now states that more than 1.1 million Americans reported identity theft in 2024.

Three errors of the same kind: a real number from a real source, attached to the wrong claim. That is harder to catch than an invented statistic, because every part of it looks checkable until you open the source.

What we will not do

Reuse

Our reference datasets are published under CC BY 4.0 and are free to cite. If you are relying on one for research or a story and want to confirm a row before you publish, write to us — we would rather answer the question first than correct the record afterwards.

One person researches, writes and checks this site. That makes an outside correction more valuable here, not less.