Skip to content
Back to CloudTrunk

Privacy Policy

ScamKavach by CloudTrunk Technologies

Last Updated: March 2026

Our Privacy Promise

Privacy-first scam protection. SMS and call analysis stays on your device. DPDP Act 2023 compliant.

ScamKavach is built by CloudTrunk Technologies Private Limited, an Indian company that believes privacy is a fundamental right. This policy complies with the Digital Personal Data Protection (DPDP) Act, 2023.

How ScamKavach Works

ScamKavach scans URLs, UPI IDs, phone numbers, SMS messages, and QR codes for fraud indicators using a hybrid approach:

On-Device Analysis

SMS content, call patterns, and QR codes are analyzed entirely on your device. This data is never transmitted to any server.

Cloud API Checks

URLs, phone numbers, and UPI IDs are checked against our secure cloud threat intelligence API for real-time protection. If the API is unavailable, the app falls back to its offline database of 360+ known scam entries.

What We Collect

On-Device Only

Scan history, threat alerts, and your preferences are stored locally on your device using an encrypted database. This data never leaves your phone.

Cloud API Checks

When you scan a URL, phone number, or UPI ID, that specific item may be sent to our secure API for a real-time threat check. These queries are processed ephemerally and not stored beyond what is needed to return a result. No personal information, device identifiers, or message content is sent with these requests.

What We Don't Do

We don't upload your SMS messages to any server
We don't upload your call logs or contacts
We don't track your location
We don't use advertising SDKs or tracking pixels
We don't serve advertisements
We don't sell or share your data with third parties
We don't create user profiles for marketing

Permissions We Request

ScamKavach requests certain Android permissions to provide its protection features. Each permission is optional and you control what to grant:

Camera

To scan QR codes for fraudulent UPI payment requests.

Internet

To check URLs, phone numbers, and UPI IDs against our cloud threat intelligence API.

Notifications

To alert you when a scam is detected.

DPDP Act 2023 Compliance

ScamKavach is designed to comply with India's Digital Personal Data Protection Act, 2023:

Consent: You control all permissions via granular toggles in the Privacy Center
Purpose limitation: Data is only used for scam detection, nothing else
Data minimization: We process the minimum data needed for each scan
Right to erasure: Delete all your data anytime from Settings > Privacy Center
Right to access: Export all your local data as JSON from the Privacy Center
Data retention: Scan history auto-deletes after 90 days, alerts after 30 days
Age verification: Users must confirm they are 18 or older during onboarding

Data Retention

Scan History:Automatically deleted after 90 days
Threat Alerts:Automatically deleted after 30 days
Manual Deletion:Delete all data anytime from Settings > Privacy Center > Delete My Data

Deleting Your Data

Option 1:Go to Settings > Privacy Center > Delete My Data (removes all local data and server records)
Option 2:Uninstall the app (all local data is deleted with the app)

Third-Party Services

ScamKavach uses Google ML Kit for on-device QR code scanning. ML Kit processes images entirely on your device and does not send camera data to Google servers. We do not integrate any analytics, advertising, or social media SDKs.

Children's Privacy

ScamKavach is intended for users aged 18 and above. We do not knowingly collect data from children. An age verification gate is presented during onboarding.

Contact

Privacy questions or data requests? Contact our Data Protection Officer: hello@cloudtrunk.tech

CloudTrunk Technologies Private Limited
Hyderabad, Telangana, India

Changes to This Policy

If we update this policy, we will update this page and notify users via the app. Continued use of the app after changes constitutes acceptance of the revised policy.