Privacy Policy

A clear explanation of what we collect, why we collect it, how long we keep it, and the choices you have.

Last updated: 20 August 2026

Digital Fraud Safety India Pvt. Ltd. ("Company", "we", "us") develops and operates Digital Guardian ("Digital Guardian", "the app", "the product") — free scam-checking tools and mobile applications for people in India. Our top goal is to protect everyone from digital and other scams — and help everyone stay digitally safe. This Privacy Policy describes how we handle information when you use our website, APIs, and Digital Guardian mobile apps (when available).

Our approach: The public website uses rule-based checks, minimal data collection, and no advertising. We do not sell personal data or use third-party analytics cookies for tracking. See our Disclaimer for service limits.

1. Introduction

We built Digital Guardian because scam messages, fake calls, and fraudulent payment requests are everyday problems — and people need fast, plain-language guidance without being asked for OTPs or banking passwords.

This policy applies to:

  • Visitors who browse www.digitalfraudsafe.in and related pages at https://www.digitalfraudsafe.in
  • Users who run free safety checks on the website
  • People who contact us for support, feedback, or partnership inquiries
  • Future registered users of Digital Guardian mobile apps (when launched)

By using our services, you acknowledge this policy. If you do not agree, please do not use the service. For terms of use, see our Terms of Service.

2. Scope & definitions

For clarity, these terms are used in this policy:

TermMeaning
Personal dataInformation that identifies you or could reasonably be linked to you — for example an email address, phone number, or IP address combined with other data.
Check contentText, URLs, phone numbers, UPI details, or payment context you paste into a safety tool.
Check resultRisk score, category, detected signals, recommended actions, and related output from our safety engine.
Anonymous userSomeone using free web tools without creating an account.
Essential cookies / local storageSmall files or browser storage needed for security, consent, or basic site operation — see our Cookie Policy.
Service providersCompanies that host infrastructure, deliver email, or provide security — under contract and only for specified purposes.

We are an independent consumer safety product. We are not a government agency, bank, law-enforcement body, or payment network.

3. Information we collect

3.1 When you use free check tools

DataExamplesWhy we collect it
Check content you submitMessage text, links, phone numbers, UPI ID, payment contextTo run the scam-pattern analysis and return a result
Check result metadataRisk score, signals, category, result IDTo show your result and allow share links
Technical dataIP address, browser user-agent, request timestampsRate limiting (5 free checks/day per IP), abuse prevention, security
Optional feedbackThumbs up/down on a result (when submitted)To improve detection rules when submitted

Check results are stored with a content hash and result metadata so share links work. When Postgres is enabled, anonymous results are retained for 24 hours; registered-user history (when accounts launch) may be retained longer. Without Postgres, results are held in server memory until restart. Anyone with a result link may view that result while it remains available.

3.2 Visitor statistics (website)

We display aggregate visitor and check counts on the website. To avoid inflating numbers, we record a random session identifier in your browser's session storage and send it once per browser session. We store only the count of unique session IDs — not page browsing history. See also our Cookie Policy.

3.3 When you contact us

  • Name, email address, and message content you choose to send
  • Subject category you select on the contact form
  • Technical metadata in email headers (handled by your email provider)

3.4 When you create an account (planned — mobile apps)

When accounts launch, we may additionally collect:

  • Phone number or email for sign-in and verification
  • Display name (optional)
  • Check history linked to your account (retention configurable, up to 90 days planned)
  • Push notification token (only if you enable alerts)
  • Trusted contact details (only with your explicit consent, for family alert features)
  • Device type and app version for support and security

We will update this policy and ask for any additional consents before enabling account features.

3.5 Information we do not intentionally collect

  • Precise GPS location (unless you explicitly grant it in a future app feature)
  • Contacts, photos, or files from your device without a clear in-app request
  • Call recordings or continuous microphone access
  • Full bank account numbers typed into our forms (our payment tools ask for UPI ID/context only)

4. What we never collect or ask for

We will never ask you for:

  • UPI PIN, MPIN, or banking passwords
  • OTP, one-time codes, or Aadhaar OTP
  • Credit or debit card PINs or CVV
  • Remote access to install software on your behalf
  • Payment to "verify" your account on Digital Guardian (the service is free)

If someone contacts you claiming to be Digital Guardian and requests any of the above, that is a scam impersonating us. Do not share credentials. Report it via our Contact page and to cybercrime.gov.in.

5. How we use your information

We use collected information only for legitimate purposes connected to the service:

PurposeDescription
Provide safety checksAnalyze submitted content with our rule-based engine and return risk guidance
Display results & share linksShow your check outcome and generate a shareable result URL if applicable
Rate limiting & abuse preventionEnforce fair use (5 anonymous checks per day per IP) and protect infrastructure
Aggregate statisticsCount visitors and completed checks without selling individual profiles
Improve detectionUse anonymized or aggregated patterns to refine rules — not to build advertising profiles
Support & communicationRespond to emails, bug reports, and partnership inquiries
Legal complianceRespond to valid legal requests or protect users' safety where required by law
Future account featuresAuthentication, history, family alerts, and notifications — only when you opt in

We do not use your check content for targeted advertising, credit scoring, insurance underwriting, or selling lists to third parties.

7. Automated analysis & profiling

Our checks use automated analysis — primarily deterministic rule-based pattern matching tuned for Indian scams, with an optional structured secondary pass when scores fall in an ambiguous band. Results are generated without human review of every submission.

  • Automated outputs include risk scores, signal lists, and suggested actions
  • These outputs are guidance only — not legal, financial, or police decisions
  • We do not make solely automated decisions that produce legal or similarly significant effects
  • Secondary analysis supplements rules — it is not presented as guaranteed fact
  • You may contact us if you believe a result is materially wrong (see feedback on result pages)

8. Data retention

Data typeCurrent retentionPlanned retention
Anonymous check content & resultsPostgres: result JSON + content hash up to 24 hours, then deleted. In-memory fallback: until server restart.Registered accounts: up to 90 days check history (user-deletable) when accounts launch
Rate-limit counters (IP-based)Daily counters in Redis or server memory; reset per dayPer-account fair use when accounts launch
Visitor session IDs (stats)Session ID in browser; server stores ID list for unique counts onlySame approach or anonymized aggregation
Cookie consent choiceUp to 1 year in browser local storageSame — see Cookie Policy
Feedback (helpful / not helpful)Stored with check ID when Postgres enabledSame
Contact form / emailAs long as needed to resolve inquiry, then deleted or archived per policySame
Registered account dataNot applicable until accounts launchUp to 90 days check history (user-deletable); account deleted within 72 hours of request
Server logsShort operational retention; IP addresses hashed where logged for rate limits — raw message content not loggedDocumented retention schedule at launch

Expired anonymous checks are purged automatically when Postgres is enabled. We store a content hash for checks rather than using message content for advertising profiles.

9. Sharing & disclosure

We do not sell your personal data. We do not share check content with advertisers or data brokers.

We may share information only in these situations:

  • Service providers — hosting, CDN, email delivery, or security vendors under contracts that limit use to providing services to us
  • Legal requirements — court orders, lawful requests from authorities, or to protect the rights, safety, or property of users and the public
  • Business transfers — if Digital Guardian is merged or acquired, data may transfer subject to this policy or notice to you
  • Aggregated research — anonymized scam trend statistics with no personal identifiers (e.g. "UPI collect scams increased this quarter")
  • With your direction — when you share a result link, anyone with the link can view that result

10. Cross-border transfers

Digital Guardian is built for users in India. Our primary aim is to process and host data in India where feasible.

Some infrastructure providers (e.g. global CDNs or cloud regions) may process technical data outside India. When that occurs, we use appropriate safeguards such as contractual protections and minimization of personal data transferred. We will document major subprocessors in an updated annex before large-scale launch.

11. Your rights & choices

Depending on applicable law, you may have the right to:

  • Access — request a copy of personal data we hold about you
  • Correction — ask us to fix inaccurate account information
  • Deletion — request deletion of account data (when accounts exist)
  • Withdraw consent — for optional features such as marketing or analytics
  • Grievance redressal — under Indian law, contact us and escalate if unresolved
  • Nominate — in certain cases under Indian law, nominate another person to exercise rights on your behalf

To exercise rights, email support@digitalfraudsafe.in or use our Contact page. We may need to verify your identity before responding. We aim to respond within timelines required by applicable law.

Anonymous checks are not linked to an identity unless you contact us about a specific result ID. Include the result link or ID in support requests if relevant.

12. Security measures

We apply reasonable technical and organizational measures, including:

  • Encryption in transit (HTTPS/TLS) for website and API communication
  • Rate limiting and abuse detection on public check endpoints
  • Access controls on production systems (least-privilege for team members)
  • No storage of OTPs, PINs, or passwords in our forms or logs by design
  • Planned encryption at rest when persistent databases are introduced

No online service is completely secure. Do not submit information you would not share with a trusted person. If you believe your interaction with us was compromised, contact support@digitalfraudsafe.in promptly.

13. Cookies & local storage

We use essential cookies and browser local storage for consent preferences and session statistics. We do not use third-party advertising or analytics cookies.

Full details: Cookie Policy.

14. Third-party websites & services

Our results may link to official resources (e.g. cybercrime.gov.in, bank helplines). We are not responsible for third-party privacy practices. Read their policies before submitting data on external sites.

App store billing (future paid features) is handled by Google Play or Apple — subject to their privacy policies.

15. Children & family use

Digital Guardian is a family-oriented safety tool, but it is not directed at children under 13 to use independently without parental involvement.

  • Parents and guardians may use the service to help protect children and seniors
  • Future family-alert features will require adult account holders and explicit consent
  • If you believe a child under 13 submitted personal data without consent, contact us for deletion

16. Sensitive personal data

You may paste content that incidentally mentions health, financial hardship, or other sensitive topics while describing a scam message. We process this only to provide the check you requested.

Do not deliberately submit Aadhaar numbers, full bank account numbers, or medical records unless necessary to describe a scam — and never submit OTPs or PINs. Minimize personal identifiers in pasted text when possible.

17. Data breach notification

If we become aware of a personal data breach that is likely to affect your rights, we will investigate promptly and notify affected users and regulators as required by applicable law, including reasonable steps to mitigate harm.

18. Changes to this policy

We may update this Privacy Policy when we add features, change data practices, or respond to legal requirements. Material changes will be posted on this page with an updated "Last updated" date. Continued use after changes constitutes acceptance where permitted by law.

For significant changes (e.g. new analytics or AI processing), we will provide prominent notice on the website and, where required, request fresh consent.

19. Contact & grievance

For privacy inquiries, data requests, or general support, email support@digitalfraudsafe.in or use our Contact page.

If you are not satisfied with our response, you may have the right to lodge a complaint with the relevant data protection authority in India as applicable law comes into full effect.