What we collect
- Account data: Name, email address, phone number, company name, and GSTIN (if provided) for account creation and GST-compliant invoicing.
- Gmail metadata: Sender addresses, subject lines, header fields, and attachment file names. Never email body text or attachment contents.
- Universal Scanner submissions: Text, URLs, UPI IDs/VPAs, payment screenshots, and voice/audio clips you submit for analysis.
- WhatsApp submissions: Messages and media forwarded to our scan number.
- Threat detection output: Detected threat categories, confidence scores, indicator-of-compromise (IOC) URLs, and timestamps, stored per-customer in an encrypted database.
- Usage data: Login events, dashboard actions, and feature usage for product improvement (anonymised).
Email data handling
We connect to Gmail via secure sign-in using the minimum required scopes: gmail.readonly and gmail.metadata. We use the Gmail History API for incremental synchronisation, accessing only what has changed since the last scan rather than your full inbox history.
The email body is processed in memory at scan time to detect fraud indicators and is discarded immediately after classification; it is never written to disk or database. The subject line and a masked version of the sender's email address are retained for up to 90 days so you can locate and verify a flagged message in your own mailbox.
Screenshot, UPI, and voice data handling
- Payment screenshots: Submitted images are processed for forensic analysis (Error Level Analysis, OCR, metadata checks). The image and the extracted OCR text are retained as part of your account data for as long as your account remains active, and are permanently deleted (including the underlying image file) if you delete your account via Settings, or by emailing us to request deletion (see “Your rights under DPDP Act 2023” below).
- UPI IDs / VPAs: When a scan produces a fraud verdict, the submitted VPA is added to our shared fraud-reputation database, which benefits all customers by improving detection across the network. If you submit a data deletion request, the link between your account and any VPA you submitted is permanently removed; the VPA and its fraud signal remain in the shared reputation database in anonymised form, no longer traceable to you.
- Voice/audio clips: Submitted for synthetic-voice and digital-arrest-scam detection. The audio file exists only temporarily during processing and is deleted immediately after a result is returned, whether the scan succeeds or fails. As a safeguard, an automated hourly process also removes any temporary audio file that may remain due to an unexpected error. No audio recording is stored as part of your account data.
You can delete your account and all associated data at any time from Settings → Profile → Danger zone, or by emailing privacy@scamshieldai.in. Self-serve deletion is processed immediately; email requests are processed within 30 days. See “Your rights under DPDP Act 2023” below.
WhatsApp data handling
Messages and media forwarded to our WhatsApp scan number are processed to detect fraud. Message content (text and media) is not persisted after scanning. Sender phone numbers are stored in hashed form only, never in plaintext. We connect directly to Meta's WhatsApp Business Platform API. No third-party Business Solution Provider is used.
By forwarding a message to our WhatsApp number, you consent to that message being processed as described here and in accordance with WhatsApp's own Business Terms.
Google API Services User Data Policy
ScamShield AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, do not transfer it to third parties except as necessary to provide and improve the service (see Sub-processors below), and do not allow humans to read it except in the narrow circumstances Google's policy permits (e.g. with your consent, for security purposes, or to comply with law).
How we use data
- To provide real-time fraud detection and threat alerts
- To generate GST-compliant invoices for paid accounts
- To improve our machine-learning models using anonymised, aggregated threat patterns only, and never personal data or raw content
- To send transactional emails and WhatsApp alerts (threat alerts, invoices, account notifications)
- We never sell, share, or license your data to third parties for their own purposes
Sub-processors and data sharing
We use the following third parties to operate the service. None of them are permitted to use your data for any purpose other than providing their service to us.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure (Central India) | Hosting, database, compute | Mumbai, India |
| Resend | Transactional email delivery (alerts, invoices, account notifications) | Resend maintains a published Data Processing Addendum and is certified under the EU-US Data Privacy Framework |
| Meta (WhatsApp Business Platform, direct API, no third-party BSP) | WhatsApp message delivery | Per Meta's infrastructure |
| Razorpay | Payment processing | India |
| GST Network (Government of India) | GSTIN verification | India |
We do not currently send customer scan content to any AI model provider outside our own infrastructure. If this changes (for example, to add a large-language-model-based review layer), we will update this policy and notify active customers before enabling it, and only after completing a data protection impact assessment and DPA review.
Storage & data residency
All production data is stored on Azure Central India (Mumbai). We do not transfer personal data outside India except where explicitly required for transactional email delivery via Resend, which maintains a published Data Processing Addendum (resend.com/legal/dpa) and is certified under the EU-US Data Privacy Framework.
Your rights under DPDP Act 2023
You have the right to:
- Access: Request a copy of all personal data we hold about you
- Correction: Correct inaccurate personal data
- Erasure: Request deletion of your account and all associated data
- Nomination: Nominate a person to exercise your rights in case of death or incapacity
- Grievance: File a complaint with our Data Protection Officer / Grievance Officer
To exercise these rights, use the account deletion option in Settings, or email privacy@scamshieldai.in for any other request. We will acknowledge grievances within 48 hours and resolve them within 30 days as required under the DPDP Act 2023.
Retention periods
- Account data: duration of subscription plus 90 days after cancellation
- Threat detection records: 12 months
- Audit logs: 24 months, for security purposes
- Gmail-sourced threat metadata (subject line, masked sender, message ID): 90 days, then automatically and permanently deleted
- Screenshot images, OCR text, and UPI/VPA records: retained for the duration of your active account; deleted (or anonymised, for VPAs, to preserve shared fraud-detection value) upon a verified data deletion request
- Voice/audio clips: temporary only, deleted immediately after processing; never persisted as part of your account data
- WhatsApp message content: not retained. WhatsApp enrollment metadata (name, email): currently retained indefinitely; a defined retention schedule for this is planned
You may delete your account and associated data at any time from Settings, or by emailing the contact below. Deletion requests are processed across all systems, including the Universal Scanner, immediately for self-serve requests or within 30 days for email requests.
What we keep even after you request deletion, and why
The DPDP Act 2023 does not require us to delete data where retention is necessary to comply with another law, or to establish, exercise, or defend a legal claim. Consistent with this, the following records survive a deletion request:
- Invoices and GST-related financial records, retained as required under the Companies Act 2013 and applicable GST law
- A record of your consent at signup (timestamp and IP address), retained for the duration of the relevant contractual/limitation period, so that either party can establish what was agreed if a dispute arises
- Correspondence directly tied to an active or resolved legal or billing dispute, retained until the applicable limitation period for that claim has passed
- A record that a deletion request was made and processed (who, when, what was purged), so we can demonstrate compliance with this policy and the DPDP Act if required
Everything else, including screenshots, OCR text, voice recordings, WhatsApp content, and Gmail-derived metadata, is deleted in full, not merely marked inactive. UPI/VPA records are anonymised rather than deleted outright, as described above.
Data breach notification
In the event of a personal data breach that is likely to result in harm, we will notify affected customers and, where required, the Data Protection Board of India, without undue delay and in accordance with the DPDP Act 2023 and applicable rules.
Contact our Data Protection Officer / Grievance Officer
Darshil Thummar, Co-Founder & CTO
ScamShield AI Private Limited, 32, Bhaktinandan Shopping, Bapasitaram Chowk, Krishnanagar, Ahmedabad 382345, Gujarat
Email: privacy@scamshieldai.in · Phone: +91 87587 32525