Website & In-App Privacy Content

Website trust content + in-app notices and consent dialogs

1. Website privacy content

1.1 Our privacy commitments

  • We analyse content only to protect you from scams and threats — and only when you ask us to.

  • We collect as little as possible: no name, email, phone number, contacts, location, passwords, PINs or OTPs.

  • We don't keep the content you submit. We analyse it and discard it.

  • We never sell your data or build advertising profiles.

  • On iPhone, message filtering happens on your device. On Android, message analysis runs on our secure servers in India, and content is discarded after analysis.

1.2 Our security commitments

  • Encryption in transit (TLS 1.2/1.3) and at rest (AES-256).

  • Processing in memory, then discarded — no content retention.

  • Infrastructure hosted in the India region.

  • No third-party advertising or analytics trackers in the app.

  • Role-based access controls and security monitoring.

1.3 How we protect your data

When you check a message, code or file, here's what happens: your content is analysed either on your device or, for some features, on our secure servers in India over an encrypted connection. Our AI decides whether it looks like a scam, tells you the result, and then the content is discarded. We don't store it, we don't read it later, and we don't use it to train our models. Insights in your dashboard are built on your device and stay on your device.

1.4 Frequently asked questions

Does the app read all my messages?

On Android, with your permission, it checks incoming SMS to spot scams; content is analysed and discarded, not stored. On iPhone, it only sees messages from unknown senders (not your contacts) and checks them on your device. You can turn message checking off at any time.

Do you store my messages or files?

No. We analyse them and discard them. We keep only limited security logs that do not contain your message content.

Do you sell my data or show ads?

No. We don't sell data, and there are no advertising trackers in the app.

Where is my data processed?

In the India region. Some features run entirely on your device.

Is the financial dashboard sending my data anywhere?

No. Those insights are built from messages you already allowed us to check, and they stay on your device.

Can I get my data deleted?

Yes. Because we hold very little, most data lives on your device and is removed when you uninstall. For anything else, contact hello@xzerolabs.com.

How old do I have to be?

The app is for users aged 18 and above.

1.5 Trust statements (for headers / cards)

  • “Built privacy-first.” Your safety shouldn't cost your privacy.

  • “We analyse, we don't keep.” Content is checked and discarded.

  • “No trackers. No data sales. Ever.”

  • “On-device where we can, encrypted where we can't.”

2. In-app notices & consent dialogs

Concise copy for the moments that matter. Keep buttons clear and never pre-tick consent.

2.1 First-launch notice

Welcome screen

Title: “Welcome to [App Name]

Body: “We help you spot scams, fraud and unsafe links, QR codes and files. We check only what you ask us to, we don't keep your content, and we never sell your data. You can review our Privacy Policy anytime.”

Buttons: [ Get started ][ Read Privacy Policy ]

2.2 Consent notice (DPDP — before processing content)

Consent dialog

Title: “Your consent to check content for scams”

Body: “To detect scams, [App Name] will analyse the messages, codes or files you submit. Content is analysed and then discarded — not stored, not shared, not used for ads. You can withdraw consent anytime in Settings.”

Controls: [ I agree ][ Not now ] · link: “How we handle your data”

2.3 Permission rationales (shown before the OS prompt)

SMS (Android)

“To detect scam and phishing messages, we need permission to read incoming SMS. A message being checked is analysed securely and isn't stored or shared. You can turn this off anytime.” (Full disclosure sequence is in the App Store Disclosures document.)

Camera

“We use your camera only to scan QR codes and check them for fraud. We don't take or keep photos.”

Notifications

“Turn on notifications so we can alert you the moment we detect a threat.”

2.4 Feature disclosures

QR scanner

“We'll check this code for fraud, phishing and fake-merchant tricks. The code's content is checked and then discarded.”

Chat / OTT message check

“Paste a suspicious message here. We only analyse what you paste — we never read your chats.”

File check

“We'll scan this file for malware and scam signs in a secure sandbox, then discard it. A ‘safe’ result isn't a guarantee — stay cautious.”

Screen-share alert

“Scammers often ask you to share your screen. We'll warn you if screen sharing or recording is on during sensitive actions. This check runs on your device.”

Analytics dashboard

“These insights are built on your device from messages you've already let us check. They stay on your device and are never sent to us.”

2.5 Settings / privacy controls

  • Withdraw consent: “Stop scam analysis — you can turn this back on anytime.”

  • Manage permissions: “Review SMS, Camera and Notifications access.”

  • Your data & rights: “Request access, correction or deletion, or raise a grievance — contact hello@xzerolabs.com.”

  • Privacy Policy / Terms: quick links.

Location

Bengaluru,
India