Privacy & Data Protection

Privacy Policy

Effective date: 2 September 2026

SecWarn Privacy Architecture: Message content is analyzed on-device and is not uploaded. Only specific normalized indicators (such as URLs and email addresses) are queried against threat databases when eligible.

App: SecWarn (com.eappsec.app)
Operator: D K Ellusha ("we", "us", "our")
Contact: support@secwarn.app
Website: https://secwarn.app

This policy describes the behavior implemented in the SecWarn Android application and associated SecWarn services.


1. What SecWarn does

SecWarn helps identify potential scam indicators in content you choose to check, notifications Android exposes after you grant access, and visible on-screen content processed through optional Accessibility access. SecWarn provides warnings and guidance; it does not guarantee detection, block websites, cancel browser navigation, stop calls, inspect all network traffic or establish that a device is secure.

2. Permissions and optional access

Internet

Used for account authentication, account/device/family management, security reputation lookups for eligible indicators, voluntary reports, privacy-minimal security telemetry, entitlement and billing verification, and links you choose to open.

Notifications

POST_NOTIFICATIONS is used to show scam warnings. Notification Access is a separate Android setting. If enabled, SecWarn can read notification fields exposed by Android and analyze them on-device for links, UPI IDs, phone numbers, email addresses and scam patterns. SecWarn does not read the SMS inbox.

Notification text is never uploaded by checking, and never uploaded by telemetry. For authenticated users, a suspicious notification detection may send only event type, severity, category, a random client event ID and app version. There is one exception that requires your action: when a notification is flagged, a bounded copy of its text (up to 2,000 characters) is saved on this device so the alert can show what was found, and if you choose Report on that item, the saved text is uploaded to SecWarn after you confirm.

Accessibility Service (optional Screen warnings)

If enabled, SecWarn receives window state and window content events only from an explicit package allowlist: selected browsers (to read the address bar after navigation) and selected messaging apps (to inspect scam content when a chat is already open). Banking, payment, password-manager, health and dating apps are not on the allowlist.

SecWarn processes visible text transiently to extract potential scam indicators such as URLs, UPI IDs, phone numbers and email addresses. Unrelated text is discarded. Before text is collected, SecWarn drops frames from password fields (isPassword) and editable input fields (isEditable) so typed credentials and in-progress typing are not read. Browser destination URLs are read through a separate address-bar path.

In supported browsers, when you navigate, SecWarn may send the normalized URL to SecWarn for an online reputation lookup. Warnings appear after the page has opened; SecWarn cannot stop the page from loading. You can revoke Accessibility at any time in Android Settings.

Camera

Used only when you choose to scan a QR code. Camera images are decoded on the device and are not stored or uploaded by SecWarn.

Google Play Billing

Google Play processes purchases. SecWarn sends purchase tokens and relevant product/account context to its backend to verify subscription entitlement. Deleting a SecWarn account does not cancel a Google Play subscription.

3. Account and device information

In the V1 Android app, sign-in is Google Sign-In only. The shipped sign-in screen offers Continue with Google and does not collect a phone number or run an SMS/email OTP sign-in flow. SecWarn exchanges a Google ID token with its backend to create or resume your account.

In-app account deletion uses your existing signed-in session and does not ask for a phone number.

Website account deletion: the browser page at https://secwarn.app/delete-account is designed for Google Account verification consistent with Android V1 sign-in. You can also delete from inside the Android app. Deleting a SecWarn account does not cancel a Google Play subscription.

Depending on the method and features you use, we may process Google account identity (Android V1); optional profile email, display name and avatar; an opaque device UUID derived on-device from an app-scoped Android identifier; device name/model, platform and app version; and session, device, subscription and family data. The raw Android ID is not transmitted. Session tokens are encrypted with an Android Keystore key before local storage.

4. Checks, reports and threat intelligence

Manual checks and online reputation

When you run a check, full message text is analyzed on the device and is not sent as lookup content.

From the Android app, only URL/domain and email indicators are eligible for an online reputation lookup to SecWarn's backend. Phone numbers and UPI IDs are evaluated locally (and against on-device/community intelligence where applicable) and are not automatically uploaded for cloud reputation by the current Android client. Background browser protection may upload a normalized URL only.

The backend may forward a looked-up URL/domain to Google Web Risk, or a looked-up email to IPQS, when those provider credentials are configured on the deployed service. Those providers receive only the indicator required for the lookup, not message or notification text. Phone and UPI have no third-party reputation provider in the current backend.

Voluntary reports

When you choose Report, SecWarn may receive the reported content you confirm (up to 2,000 characters — a URL, email, phone number, UPI ID, or other text such as a message excerpt), a type (LINK, MESSAGE, PHONE, UPI, or EMAIL), risk level, category, and an allowlisted report source. Reports are stored linked to your account (default 90-day retention), removed on account deletion, and are not automatically treated as confirmed threats. Report content is not forwarded to Google Web Risk or IPQS.

5. Information stored on the device

SecWarn stores app preferences, encrypted session state, cached account/entitlement data, reputation cache entries, and a bounded Activity history. Each Activity entry may include a bounded copy of source text (up to 2,000 characters) for alert display and optional reporting. Activity is local only. Clearing activity, clearing app storage, or uninstalling removes SecWarn's local app data (subject to Google account and provider records outside the app).

6. Retention and deletion

In-app account deletion, or https://secwarn.app/delete-account, removes server-side account data associated with the account. Contact support@secwarn.app for access or deletion requests. Deleting a SecWarn account does not cancel a Google Play subscription.

7. Sharing

We do not sell personal information or use advertising SDKs in the current app. We share data only as needed with Google (Sign-In / Play Billing), Google Sign-In for authentication, hosting/database infrastructure, configured threat-intelligence providers (Google Web Risk for URL/domain; IPQS for email) for eligible URL/email lookups when those provider credentials are configured on the deployed service, and authorities when required by law or necessary to protect users and the service.

8. Information SecWarn does not intentionally collect

SecWarn does not intentionally collect contacts, precise location, microphone recordings, advertising IDs, full chat transcripts or camera images. Accessibility and notification access can expose text transiently as described above.

9. Security

We use HTTPS for app API traffic, bounded network timeouts, server-side entitlement checks and encrypted local session-token storage. No method of storage, transmission or detection is completely secure.

10. Children

SecWarn is not directed to children under 13 or the minimum age required in the user's country. We do not knowingly collect children's personal information.

11. Choices and rights

You can decline or revoke Notification Access and Accessibility; deny notification or camera permission; use manual checks without background access; sign out and manage devices; delete the SecWarn account in the app or via the website; clear app storage or uninstall; manage subscriptions in Google Play; and contact support@secwarn.app about applicable privacy rights.

12. International processing

SecWarn and its service providers may process data in countries other than yours. Applicable contractual, legal and provider safeguards are used where required.

13. Independent services

SecWarn is independent of banks, government agencies, messaging platforms and browser vendors except where a named provider supplies authentication, billing, infrastructure or threat-intelligence services. Those services have their own terms and privacy policies.

14. Changes

We may update this policy as implementation, providers or legal requirements change. The effective date will be updated, and material changes will be communicated as required.

15. Contact

Questions or requests: support@secwarn.app

D K Ellusha

Get SecWarn on Google Play (Free Trial)