Our Privacy Philosophy
At TenCore Digital Labs, we build security software designed for India's digital resilience. Our flagship safety app, Safety Setu, is designed with a fundamental rule: your privacy is absolute. We believe that to protect you from digital fraud, we must never compromise your personal information.
🛡️ Zero Cloud Dependency: Safety Setu performs 100% of its scans, keyword matching, and security evaluations locally on your device. We do not host your personal chats, SMS messages, phone logs, or screen telemetry on external cloud servers, nor do we sell or share them with any third parties.
1. Information We Access & Analyze
To detect real-time fraud threats (like remote screen-sharing, phishing links, and vishing calls), Safety Setu accesses specific system inputs locally on your Android device:
- Incoming Notifications: We inspect notification text from messaging applications (like WhatsApp or Telegram) strictly to identify phishing links or known scam signatures.
- Text Messages (SMS): We scan SMS contents locally to catch OTP phishing templates and scam links.
- Running App Status: We monitor when financial apps (e.g., UPI, banking portals) are launched, helping us warn you if screen sharing is active at the same time.
- System Warnings & Overlays: We draw instant alert panels over financial apps during high-risk events (like an active scam call) to prevent fraudulent transfers.
2. Sensitive Permissions & Declarations
To function effectively, Safety Setu requests the following high-risk system permissions. These are essential for core protection and operate with complete local privacy:
🔔 Notification Scanner BIND_NOTIFICATION_LISTENER_SERVICE
Required to intercept and analyze messaging notifications (WhatsApp, Telegram, etc.) in real-time. This allows Safety Setu to scan incoming message content for high-risk phishing URLs before you tap them, protecting you from remote installation threats.
💬 SMS Intercept & Delivery RECEIVE_SMS / SEND_SMS
RECEIVE_SMS: Used as a critical fallback scan method to intercept incoming text messages and parse them locally for scam links or OTP-stealing attempts if system notification access is turned off.
SEND_SMS: Used exclusively for the Trusted Contacts safety feature, allowing the application to dispatch an automated offline SMS alert to your designated emergency contact when a high-risk fraud attempt is blocked.
🖥️ Draw Over Other Apps SYSTEM_ALERT_WINDOW
Required to display instant, full-screen red warning blocks over payment screens. Under high-stress vishing (call-based) scam scenarios, this overlay immediate cuts off user interactions with payment apps to block transfers before they are authorized.
📊 Usage Statistics Access PACKAGE_USAGE_STATS
Required to check the package identity of active foreground applications. This helps Safety Setu identify if a financial app (like Paytm, PhonePe, or Google Pay) has been opened while screen-sharing software is running, triggering a remote access warning.
3. Local Data Retention & Pruning
All scanned messages, alert flags, and timeline events are recorded in an encrypted, local SQLite (Room) database on your device. We implement a strict data retention and pruning policy:
- Threat Logs: In the Free Tier, non-critical logs (low and medium severity) are automatically deleted after 7 days, and critical/high-severity scan logs are deleted after 30 days to optimize local storage, or they can be cleared manually at any time. Premium Tier accounts support indefinite retention of threat logs.
- No Analytics Leakage: Analytics and performance logs collected (if allowed by the user) are strictly limited to anonymized application crashes and navigation paths, with zero containing user names, messages, or phone numbers.
4. User Control & Consent Revocation
You remain in complete control of the permissions you grant to Safety Setu. At any time, you can:
- Disable notification listener, draw-over-apps, or SMS permissions within your Android system settings. Disabling these will cause the respective protection shield to go offline.
- Clear all scan histories, detected threats, and settings databases permanently using the "Clear Log History" button located inside the application dashboard.
5. Contact & Inquiries
If you have any questions or feedback regarding this Privacy Policy or our safety engineering, please contact us:
- Developer Email: tencorelabs@gmail.com
- Company Address: TenCore Digital Labs, India