Privacy Policy
Version 1.0
Effective date: 08 July 2026 Last updated: 08 July 2026
This Privacy Policy explains how XZero Labs Private Limited (“XZero Labs”, “we”, “our” or “us”) handles information in connection with the SayNo mobile application (the “App”) on Android and iOS. We built the App to help people in India detect scams, fraud, phishing, malicious QR codes and unsafe files, while collecting as little personal data as possible.
For the purposes of India's Digital Personal Data Protection Act, 2023 and the rules under it (together, the “DPDP Act”), XZero Labs is the Data Fiduciary responsible for personal data processed through the App. By using the App and giving the consents it requests, you agree to this Policy. If you do not agree, please do not use the App.
1. Who we are and how to reach us
The App is provided by XZero Labs Private Limited, a company incorporated in India with its registered office at Bengaluru, Karnataka, India · CIN: U72900KA2022PTC164384.
For any privacy question, to exercise your rights, or to raise a complaint, contact our grievance contact:
Grievance contact: Chief Executive Officer, XZero Labs Private Limited
Email: hello@xzerolabs.com
Website: https://www.xzerolabs.com/
We aim to acknowledge requests promptly and to resolve grievances within 90 days.
2. What this Policy covers
This Policy covers the App and its features. It does not cover third-party services, websites, senders or apps you may reach through content the App analyses (for example, a link inside a message); those are governed by their own policies.
3. Information we do not collect
Unless you voluntarily provide it for a specific feature, the App does not collect:
Your name, email address or phone number
Your contact list, photos or media library
Your GPS or precise location
Banking passwords, card numbers, UPI PINs or OTPs
Government identity documents
Please never enter passwords, PINs or OTPs into the App. No genuine service needs them, and the App does not ask for them.
4. What we process, feature by feature
4.1 SMS scam detection
On Android, with your permission the App reads incoming SMS messages to detect “smishing” (SMS phishing) and other scam messages. A message being analysed may be sent over an encrypted connection to our analysis service hosted in India, classified (for example as likely scam, likely genuine, or uncertain), and then discarded. We access SMS only for this scam-detection purpose.
On iPhone, the App uses Apple's Message Filter extension to classify messages from Known and unknown senders (senders not in your contacts) directly on your device. Message content is not uploaded for this feature.
Retention: message content is processed in memory and is not retained after analysis (see Section 9).
4.2 QR code scanner
What we process: the data encoded in a QR code you scan (for example a UPI ID, payment request or URL).
Why: to warn you about malicious QR codes, fraudulent payment requests, phishing links and fake-merchant codes.
Camera: used only to read the code in the moment; we do not take or keep photographs.
Retention: the scanned content is checked and then discarded; it is not retained.
4.3 Screen-sharing / recording detection
What we process: a device signal indicating whether your screen is being shared or recorded during a sensitive action.
Why: scammers often ask victims to share their screen; we warn you. This runs on your device and does not capture or transmit your screen contents.
4.4 Chat / OTT message analysis (WhatsApp, Telegram, and similar)
What we process: only the message text you deliberately copy, paste or share into the App.
What we do not do: we do not monitor, read or access your private conversations in any messaging app. Nothing is analysed unless you submit it.
Retention: processed like a message submission and discarded after analysis.
4.5 Malicious file detection
What we process: a file you select for analysis (for example PDF, Office documents, APK, ZIP or images).
Why: to check it for malware and scam indicators before you open or install it.
Retention: files are analysed for security purposes only and are not retained after analysis. Please avoid submitting files containing your own sensitive personal information.
4.6 Analytics dashboard (financial and security insights)
The dashboard shows you personal insights — such as spending summaries, subscription tracking and security-related activity — generated solely from the SMS content you have already allowed the App to analyse for scam detection. It does not request any additional permission, does not collect any new information, and does not obtain financial information from banks or other institutions.
Where it is stored: these insights are generated and stored locally on your device only. The underlying messages are not retained, and your insights are not sent to us or to any third-party analytics provider. They are removed when you uninstall the App.
5. Permissions the App uses
The App requests only the permissions its current features need. You can grant or deny each one and change your choice at any time in your device settings. Denying a permission disables the feature that relies on it but does not stop the rest of the App working.
On iPhone, SMS scam detection uses Apple's Message Filter feature, which you enable in your iOS Settings; the App does not request permission to read your inbox. Not requested on any platform: access to your contacts, location or photo library.
6. How analysis works
When analysis happens in our cloud (for example, Android message or file checks), your submission travels over an encrypted connection to our analysis service hosted in India, an AI model evaluates it in memory, a result is returned to your device, and the submitted content is discarded. When analysis happens on your device (for example, iOS message filtering and the analytics dashboard), the content does not leave your phone. We do not use your content to train our models.
7. Consent and your choices
We rely on your consent to process the content you submit for scam detection and related insights. Before you first use a feature that processes your content, we show a clear, specific notice describing what is processed and why. You can withdraw consent at any time from within the App — withdrawing is as easy as giving consent. Withdrawal stops future processing but does not affect processing already carried out. On request, we can provide this notice in any of the languages listed in the Eighth Schedule to the Constitution of India.
8. Sharing and service providers
We do not sell your data, and we do not share the content you submit with third parties for their own purposes. We use one category of service provider (a “Data Processor”) strictly to run the App:
Cloud hosting / AI inference (India region) — to run our analysis service under a written agreement that requires the provider to protect data and use it only to provide the service to us.
We do not use third-party crash-reporting or analytics SDKs (such as Firebase, Crashlytics, Sentry, Mixpanel or Amplitude). We may disclose information only if required by law, or to detect, prevent or address fraud, security or technical issues, in line with applicable law. We remain responsible for any processing done by our provider on our behalf.
9. Data retention and erasure
We are built around not keeping your content.
We do not retain the content you submit. We keep limited security and access logs that do not contain your message content, only for as long as needed to keep the service secure and to meet legal requirements, after which they are deleted. We erase personal data once the purpose it was collected for is served or when you withdraw consent, unless the law requires us to keep it.
10. How we protect your data
Encryption in transit: connections use TLS 1.2/1.3 with strong ciphers (such as AES-256-GCM).
Encryption at rest: where data is temporarily held during processing, it is protected with AES-256.
In-memory processing: submitted content is analysed in memory and discarded; it is not persisted.
Access controls: access to systems is restricted by role and logged; submitted content is not retained and is not made available for review.
India-based infrastructure: our analysis runs on reputable cloud infrastructure in the India region, bound by security obligations.
No method of transmission or storage is completely secure, so while we work hard to protect your information we cannot guarantee absolute security.
11. If a data breach occurs
If a personal-data breach affecting you occurs, we will notify you and the Data Protection Board of India without undue delay, and provide the Board with a detailed report within the timeline required by the DPDP Act. Our notice will describe, in plain language, what happened, the likely impact, the steps we are taking, and how to reach us.
12. Your rights
Subject to the DPDP Act, you have the right to:
Access a summary of the personal data we process about you and how we process it.
Correct or update inaccurate or outdated personal data.
Erase personal data we hold, where the law allows.
Grievance redressal — raise a concern and have it addressed within 90 days.
Nominate another person to exercise your rights if you die or become incapacitated.
Withdraw consent at any time.
To exercise any right, contact us at hello@xzerolabs.com. Because we hold very little personal data about you, we may ask for information to verify your request. We will respond within the time the law requires.
13. Age requirement
The App is intended only for users aged 18 and above and is not directed to children. Under the DPDP Act, a child is a person under 18. We do not knowingly process the personal data of anyone under 18. If we learn that we have, we will delete it. If you believe a child has used the App, please contact us.
14. Where data is processed
We process and host data in the India region. If any processing ever occurs outside India, we will do so only in line with applicable law and any Government restrictions on cross-border transfers, and we will apply appropriate safeguards.
15. Changes to this Policy
We may update this Policy from time to time. When we do, we will change the “Effective date” above and, for significant changes, provide a more prominent notice in the App. Continued use after an update means you accept the revised Policy.
16. Grievance redressal and contact
XZero Labs Private Limited
Grievance contact: Chief Executive Officer
Email: hello@xzerolabs.com · Website: https://www.xzerolabs.com/
Registered office: Bengaluru, Karnataka, India.







