Digital Fraud Safety India Pvt. Ltd. ("Company", "we", "us") develops and operates Digital Guardian ("Digital Guardian", "the app", "the product") — free scam-checking tools and mobile applications for people in India. Our top goal is to protect everyone from digital and other scams — and help everyone stay digitally safe. This Privacy Policy describes how we handle information when you use our website, APIs, and Digital Guardian mobile apps (when available).
Our approach: The public website uses rule-based checks, minimal data collection, and no advertising. We do not sell personal data or use third-party analytics cookies for tracking. See our Disclaimer for service limits.
1. Introduction
We built Digital Guardian because scam messages, fake calls, and fraudulent payment requests are everyday problems — and people need fast, plain-language guidance without being asked for OTPs or banking passwords.
This policy applies to:
- Visitors who browse www.digitalfraudsafe.in and related pages at https://www.digitalfraudsafe.in
- Users who run free safety checks on the website
- People who contact us for support, feedback, or partnership inquiries
- Future registered users of Digital Guardian mobile apps (when launched)
By using our services, you acknowledge this policy. If you do not agree, please do not use the service. For terms of use, see our Terms of Service.
2. Scope & definitions
For clarity, these terms are used in this policy:
| Term | Meaning |
|---|---|
| Personal data | Information that identifies you or could reasonably be linked to you — for example an email address, phone number, or IP address combined with other data. |
| Check content | Text, URLs, phone numbers, UPI details, or payment context you paste into a safety tool. |
| Check result | Risk score, category, detected signals, recommended actions, and related output from our safety engine. |
| Anonymous user | Someone using free web tools without creating an account. |
| Essential cookies / local storage | Small files or browser storage needed for security, consent, or basic site operation — see our Cookie Policy. |
| Service providers | Companies that host infrastructure, deliver email, or provide security — under contract and only for specified purposes. |
We are an independent consumer safety product. We are not a government agency, bank, law-enforcement body, or payment network.
3. Information we collect
3.1 When you use free check tools
| Data | Examples | Why we collect it |
|---|---|---|
| Check content you submit | Message text, links, phone numbers, UPI ID, payment context | To run the scam-pattern analysis and return a result |
| Check result metadata | Risk score, signals, category, result ID | To show your result and allow share links |
| Technical data | IP address, browser user-agent, request timestamps | Rate limiting (5 free checks/day per IP), abuse prevention, security |
| Optional feedback | Thumbs up/down on a result (when submitted) | To improve detection rules when submitted |
Check results are stored with a content hash and result metadata so share links work. When Postgres is enabled, anonymous results are retained for 24 hours; registered-user history (when accounts launch) may be retained longer. Without Postgres, results are held in server memory until restart. Anyone with a result link may view that result while it remains available.
3.2 Visitor statistics (website)
We display aggregate visitor and check counts on the website. To avoid inflating numbers, we record a random session identifier in your browser's session storage and send it once per browser session. We store only the count of unique session IDs — not page browsing history. See also our Cookie Policy.
3.3 When you contact us
- Name, email address, and message content you choose to send
- Subject category you select on the contact form
- Technical metadata in email headers (handled by your email provider)
3.4 When you create an account (planned — mobile apps)
When accounts launch, we may additionally collect:
- Phone number or email for sign-in and verification
- Display name (optional)
- Check history linked to your account (retention configurable, up to 90 days planned)
- Push notification token (only if you enable alerts)
- Trusted contact details (only with your explicit consent, for family alert features)
- Device type and app version for support and security
We will update this policy and ask for any additional consents before enabling account features.
3.5 Information we do not intentionally collect
- Precise GPS location (unless you explicitly grant it in a future app feature)
- Contacts, photos, or files from your device without a clear in-app request
- Call recordings or continuous microphone access
- Full bank account numbers typed into our forms (our payment tools ask for UPI ID/context only)
4. What we never collect or ask for
We will never ask you for:
- UPI PIN, MPIN, or banking passwords
- OTP, one-time codes, or Aadhaar OTP
- Credit or debit card PINs or CVV
- Remote access to install software on your behalf
- Payment to "verify" your account on Digital Guardian (the service is free)
If someone contacts you claiming to be Digital Guardian and requests any of the above, that is a scam impersonating us. Do not share credentials. Report it via our Contact page and to cybercrime.gov.in.
5. How we use your information
We use collected information only for legitimate purposes connected to the service:
| Purpose | Description |
|---|---|
| Provide safety checks | Analyze submitted content with our rule-based engine and return risk guidance |
| Display results & share links | Show your check outcome and generate a shareable result URL if applicable |
| Rate limiting & abuse prevention | Enforce fair use (5 anonymous checks per day per IP) and protect infrastructure |
| Aggregate statistics | Count visitors and completed checks without selling individual profiles |
| Improve detection | Use anonymized or aggregated patterns to refine rules — not to build advertising profiles |
| Support & communication | Respond to emails, bug reports, and partnership inquiries |
| Legal compliance | Respond to valid legal requests or protect users' safety where required by law |
| Future account features | Authentication, history, family alerts, and notifications — only when you opt in |
We do not use your check content for targeted advertising, credit scoring, insurance underwriting, or selling lists to third parties.
6. Legal basis for processing
Depending on applicable law (including India's Digital Personal Data Protection Act, 2023 and related rules, as they apply to us), we rely on one or more of the following:
- Consent — for example when you submit a check, accept cookies, enable notifications, or add trusted contacts (future features)
- Legitimate interests — operating a free safety service, preventing abuse, securing our systems, and improving scam detection in a privacy-conscious way
- Legal obligation — when we must retain or disclose information under applicable law
Where consent is required, you may withdraw it at any time for future processing (this will not affect processing already performed). Some features may not work if you withdraw essential consent.
7. Automated analysis & profiling
Our checks use automated analysis — primarily deterministic rule-based pattern matching tuned for Indian scams, with an optional structured secondary pass when scores fall in an ambiguous band. Results are generated without human review of every submission.
- Automated outputs include risk scores, signal lists, and suggested actions
- These outputs are guidance only — not legal, financial, or police decisions
- We do not make solely automated decisions that produce legal or similarly significant effects
- Secondary analysis supplements rules — it is not presented as guaranteed fact
- You may contact us if you believe a result is materially wrong (see feedback on result pages)
8. Data retention
| Data type | Current retention | Planned retention |
|---|---|---|
| Anonymous check content & results | Postgres: result JSON + content hash up to 24 hours, then deleted. In-memory fallback: until server restart. | Registered accounts: up to 90 days check history (user-deletable) when accounts launch |
| Rate-limit counters (IP-based) | Daily counters in Redis or server memory; reset per day | Per-account fair use when accounts launch |
| Visitor session IDs (stats) | Session ID in browser; server stores ID list for unique counts only | Same approach or anonymized aggregation |
| Cookie consent choice | Up to 1 year in browser local storage | Same — see Cookie Policy |
| Feedback (helpful / not helpful) | Stored with check ID when Postgres enabled | Same |
| Contact form / email | As long as needed to resolve inquiry, then deleted or archived per policy | Same |
| Registered account data | Not applicable until accounts launch | Up to 90 days check history (user-deletable); account deleted within 72 hours of request |
| Server logs | Short operational retention; IP addresses hashed where logged for rate limits — raw message content not logged | Documented retention schedule at launch |
Expired anonymous checks are purged automatically when Postgres is enabled. We store a content hash for checks rather than using message content for advertising profiles.
10. Cross-border transfers
Digital Guardian is built for users in India. Our primary aim is to process and host data in India where feasible.
Some infrastructure providers (e.g. global CDNs or cloud regions) may process technical data outside India. When that occurs, we use appropriate safeguards such as contractual protections and minimization of personal data transferred. We will document major subprocessors in an updated annex before large-scale launch.
11. Your rights & choices
Depending on applicable law, you may have the right to:
- Access — request a copy of personal data we hold about you
- Correction — ask us to fix inaccurate account information
- Deletion — request deletion of account data (when accounts exist)
- Withdraw consent — for optional features such as marketing or analytics
- Grievance redressal — under Indian law, contact us and escalate if unresolved
- Nominate — in certain cases under Indian law, nominate another person to exercise rights on your behalf
To exercise rights, email support@digitalfraudsafe.in or use our Contact page. We may need to verify your identity before responding. We aim to respond within timelines required by applicable law.
Anonymous checks are not linked to an identity unless you contact us about a specific result ID. Include the result link or ID in support requests if relevant.
12. Security measures
We apply reasonable technical and organizational measures, including:
- Encryption in transit (HTTPS/TLS) for website and API communication
- Rate limiting and abuse detection on public check endpoints
- Access controls on production systems (least-privilege for team members)
- No storage of OTPs, PINs, or passwords in our forms or logs by design
- Planned encryption at rest when persistent databases are introduced
No online service is completely secure. Do not submit information you would not share with a trusted person. If you believe your interaction with us was compromised, contact support@digitalfraudsafe.in promptly.
14. Third-party websites & services
Our results may link to official resources (e.g. cybercrime.gov.in, bank helplines). We are not responsible for third-party privacy practices. Read their policies before submitting data on external sites.
App store billing (future paid features) is handled by Google Play or Apple — subject to their privacy policies.
15. Children & family use
Digital Guardian is a family-oriented safety tool, but it is not directed at children under 13 to use independently without parental involvement.
- Parents and guardians may use the service to help protect children and seniors
- Future family-alert features will require adult account holders and explicit consent
- If you believe a child under 13 submitted personal data without consent, contact us for deletion
16. Sensitive personal data
You may paste content that incidentally mentions health, financial hardship, or other sensitive topics while describing a scam message. We process this only to provide the check you requested.
Do not deliberately submit Aadhaar numbers, full bank account numbers, or medical records unless necessary to describe a scam — and never submit OTPs or PINs. Minimize personal identifiers in pasted text when possible.
17. Data breach notification
If we become aware of a personal data breach that is likely to affect your rights, we will investigate promptly and notify affected users and regulators as required by applicable law, including reasonable steps to mitigate harm.
18. Changes to this policy
We may update this Privacy Policy when we add features, change data practices, or respond to legal requirements. Material changes will be posted on this page with an updated "Last updated" date. Continued use after changes constitutes acceptance where permitted by law.
For significant changes (e.g. new analytics or AI processing), we will provide prominent notice on the website and, where required, request fresh consent.
19. Contact & grievance
For privacy inquiries, data requests, or general support, email support@digitalfraudsafe.in or use our Contact page.
If you are not satisfied with our response, you may have the right to lodge a complaint with the relevant data protection authority in India as applicable law comes into full effect.