Privacy Policy for PaisaSafeX
Effective Date: October 10, 2026 · Last Updated: October 10, 2026
This Privacy Policy explains how PaisaSafeX ("we," "our," "the App") collects, uses, stores, and protects information when you use our Android application. PaisaSafeX is a fraud-protection app designed to help Indian users identify and avoid scam calls, messages, and video calls.
We built this app around one core principle: collect the minimum necessary to protect you, keep it on your device wherever possible, and never sell your data.
1. Information We Collect
1.1 Information We Do NOT Collect
To be clear upfront about what this app deliberately avoids:
- We do not read your full SMS inbox or SMS database.
- We do not access your call log/call history database.
- We do not require you to create an account, and we do not collect your name, email, or any sign-up information. (The only exception is the optional Family Protection feature, where you type a nickname and the App creates an anonymous ID — see Section 1.8.)
- We do not collect your precise location.
- We do not sell your personal data to anyone, for any purpose.
1.2 Message Content (SMS, WhatsApp, Telegram)
PaisaSafeX uses Android's Notification Access permission to read the text of notifications from your messaging apps (SMS, WhatsApp, Telegram) at the moment they arrive. This is a different, narrower mechanism than reading your phone's SMS/message database directly — we only see the notification text itself, not your full message history.
This text is checked against a local list of known scam patterns. If a message is ambiguous, the (personally identifying information redacted — see Section 4) text may be sent to Google's Gemini AI service for a second-opinion analysis.
1.3 Call Information
Using Android's call-screening and call-state APIs, the App observes:
- The phone number of incoming calls (when your device configuration allows it — see "Full Protection vs. Companion Mode" below)
- Call direction (incoming, outgoing, missed), duration, and timestamp
- Whether the number is saved in your Contacts (for identification purposes only)
This information is stored locally on your device only, in the App's own private storage. It is not uploaded to any server, with the limited exception described in Section 1.5 below (AI fraud analysis).
Full Protection vs. Companion Mode: on Android 10 and above, if PaisaSafeX holds the Caller ID & Spam Protection role, it can see the calling number to check it for known fraud patterns. On older Android versions, or if another app (such as Truecaller) holds that role, PaisaSafeX operates in "Companion Mode" and may not have access to the caller's number at all — this is a limitation of the Android operating system, not a choice we make.
1.4 Contacts
The App queries your device's Contacts (name and phone number only) to determine whether a caller is someone you already know. This lookup happens entirely on your device using Android's standard Contacts API — your contact list is never uploaded, transmitted, or shared with us or any third party.
1.5 AI-Assisted Fraud Analysis (Google Gemini via Firebase)
When the App cannot determine with confidence whether a message or call situation is fraudulent using its local rules, it may send the relevant text to Google's Gemini AI model (via Google Firebase) for analysis. Before this happens:
- All personally identifying information is automatically removed from the text — this includes OTPs, bank account numbers, card numbers, and Aadhaar numbers.
- The redacted text is used only to generate a fraud risk assessment and is not stored by us after the analysis completes.
- This processing is subject to Google's own privacy practices for its Firebase and Gemini API services, since Google acts as our data processor for this specific function.
1.6 Advertising (Google AdMob)
The App displays ads through Google AdMob within certain screens (such as the call summary screen). Google AdMob may collect device identifiers and usage data to serve and measure ads, in accordance with Google's own privacy policy. We do not share any of your call, message, or contact data with AdMob — only what's needed for standard ad serving, handled directly by Google's SDK.
1.7 Device and Diagnostic Information
The App may access general device information (Android version, device manufacturer) solely to ensure compatibility and troubleshoot issues across the wide range of Android devices used in India. This information is not linked to your identity.
1.8 Family Protection (Optional Feature)
Family Protection lets you link your phone with a family member or friend you trust, so that they are notified if PaisaSafeX detects a serious scam attempt on your phone. It is optional and does nothing unless you choose to use it, by generating a pairing code ("I want to be protected") or by entering someone else's code ("I'm a guardian"). Both people are shown a consent notice before pairing.
If you use it, the following is created and stored with our service provider, Google Firebase (the pairing, link and device records are held in its Mumbai, India region):
- An anonymous ID — a random identifier created by Firebase Anonymous Authentication. It is not linked to your name, phone number or email address.
- A nickname — the name you type for yourself (for example "Mom"). The person you pair with sees it.
- A push-notification token for your phone, so that alerts can reach it.
- A pairing code record — the 6-digit code (valid for 10 minutes and usable once), with your anonymous ID, nickname and timestamps.
- A link record — the anonymous IDs and nicknames of both people, and when they were linked.
What an alert contains. When PaisaSafeX detects a high-risk scam on the protected person's phone, the guardian is told: the type of scam (for example "Digital Arrest Scam"), the risk level, where it was detected (for example WhatsApp, SMS or during a call), and the time.
What an alert never contains. The message text, the sender's phone number, your contacts, call audio, or your location.
How long it is kept.
- Alerts are deleted from our servers as soon as the notification has been sent. The guardian's phone keeps its own copy in its alert history, which is deleted when the link is removed.
- Pairing codes are deleted automatically, typically within a day or two after they expire.
- Link records, nicknames, your anonymous ID and your push token are kept until you remove the link and/or ask us to delete them (see our data deletion page).
Uninstalling or clearing the App's data: this gives you a new anonymous ID, and any existing link stops working. To avoid leftover records, remove the link on the Family Protection screen first, or ask us to delete them. "Clear All My Data" in Settings clears what is stored on your phone only; it does not remove Family Protection records held on our servers.
Use and sharing. Family Protection data is used only to run this feature. It is not used for advertising and is not shared with Google AdMob. It is processed on our behalf by Google Firebase (Authentication, Firestore, Cloud Functions and Cloud Messaging). The person you pair with can see your nickname and the alert details above — nothing else.
2. How We Use Information
We use the information described above only to:
- Detect and warn you about potential scam calls, messages, and video calls
- Show you a risk assessment for calls and numbers
- Let you mark numbers as spam or safe, based on your own judgment
- Maintain your local call and alert history within the App
- Display advertisements to support the App's free availability
- Improve the App's fraud-detection accuracy over time
- If you choose to use the optional Family Protection feature, let a person you trust be notified when a serious scam attempt is detected on your phone (Section 1.8)
We do not use your data for any purpose beyond these — no profiling for unrelated purposes, no resale, no sharing with data brokers.
3. Where Your Data Is Stored
The overwhelming majority of data this App handles — your call history, spam/safe marks, personal notes on numbers, and settings — is stored locally on your device only, using Android's private app storage. This data is not accessible to us, is not uploaded to any server we control, and is deleted if you uninstall the App or clear its data.
The only data that leaves your device is the narrow, redacted text sent to Google's Gemini AI for fraud analysis (Section 1.5), standard ad-serving data collected by Google AdMob (Section 1.6), and, only if you choose to use the optional Family Protection feature, the limited records described in Section 1.8.
4. Data Sharing
We do not sell your personal data. We share information only with:
- Google Firebase / Gemini AI — as our AI processing service for fraud detection (redacted text only, as described above)
- Google AdMob — for displaying advertisements
- Google Firebase (Family Protection) — only if you use that optional feature: our service provider that stores the pairing and link records and delivers alert notifications (Section 1.8)
- The person you pair with — only if you use Family Protection: they see your nickname and the alert details described in Section 1.8, never your message content
- Law enforcement or regulators — only if legally required to do so under Indian law
We do not currently participate in any community or crowd-sourced spam-reporting network. If we introduce such a feature in the future, this policy will be updated in advance, and it will only involve information you explicitly choose to share.
5. Permissions We Request, and Why
| Permission | Why we need it |
|---|---|
| Notification Access | To read message notifications (SMS/WhatsApp/Telegram) for fraud scanning, without needing broader SMS database access |
| Phone / Call State | To detect call events (ringing, active, ended) for real-time fraud warnings during calls |
| Contacts (read-only) | To recognize whether a caller is already in your contacts |
| Display Over Other Apps | To show warning banners during an active call or video call |
| Usage Access | To detect if a banking app is opened during a suspicious call |
| Camera | Only used for the in-app QR code scanner feature, to verify payment QR codes |
| Post Notifications | To show you fraud alerts and the call summary screen |
We deliberately do not request SMS or Call Log permissions, as these would give us access to far more data than is necessary for fraud protection.
6. Data Security
We take reasonable technical measures to protect your information, including:
- Automatic redaction of sensitive personal identifiers before any AI analysis
- Secure, encrypted communication with Google's servers for AI analysis and app integrity checks
- No hardcoded credentials or API keys shipped inside the App
- Verification that requests to our AI and Family Protection services come only from a genuine, unmodified copy of the App (via Google Play Integrity)
No method of electronic storage or transmission is 100% secure, but we design the App to minimize what could ever be exposed in the first place.
7. Children's Privacy
PaisaSafeX is not directed at children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us using the details below so we can address it.
8. Your Rights
Under India's Digital Personal Data Protection Act, 2023, and general good practice, you have the right to:
- Access — most of your data (call history, notes, marks) is visible to you directly within the App at any time
- Correct or Delete — you can edit or remove notes, spam/safe marks, and clear your call history directly within the App's settings. For Family Protection, you can remove a link at any time on the Family Protection screen, and ask us to delete the remaining records (see our data deletion page)
- Withdraw consent — you can revoke any Android permission at any time via your device's Settings, though this may reduce the App's protective features
- Grievance redressal — you may contact our Grievance Officer (see Section 11) with any concerns about how your data is handled
9. International Data Transfer
Because our AI analysis (Section 1.5) and advertising (Section 1.6) are powered by Google's global infrastructure, the limited data sent for these purposes may be processed on servers located outside India. Google maintains its own data protection safeguards for these services. The Family Protection pairing, link and device records (Section 1.8) are held in Google's Mumbai, India region, but the anonymous sign-in record and push-notification delivery run on Google's global infrastructure.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the App's features or legal requirements. We will update the "Last Updated" date at the top of this page when changes are made. Continued use of the App after changes take effect constitutes acceptance of the updated policy.
11. Grievance Officer & Contact Us
In accordance with Indian data protection regulations, you may direct questions, concerns, or complaints about this Privacy Policy or your data to:
Grievance Officer: PaisaSafeX Support Team
Email: paisasafex@gmail.com
Website: https://paisasafex.com/
We aim to acknowledge and address all privacy-related concerns promptly.