Last updated 29 July 2026
SecureScan checks whether a web link is dangerous before you open it. This page explains exactly what happens to a link when you check it, in plain language.
The short version. Most links are checked entirely on your phone and never leave it. When a link does need a second opinion, we send the address to our server, get an answer, and do not keep the address. We do not sell data, we do not show ads, and there are no advertising or analytics trackers in the app.
| Data | Why | Where it goes |
|---|---|---|
| The link you check | To tell you whether it is dangerous | Checked on your phone first. Only if your phone cannot decide is the address sent to our server and to VirusTotal. |
| Your scan history | So you can look back at what you checked | Stored on your phone. Deleted when you delete it, or when you uninstall the app. |
| Email and password (only if you create an account) | To sign you in | Our server. The password is stored only as a one-way hash — we cannot read it. An account is optional; the scanner works without one. |
| Camera (only when you scan a QR code) | To read the code | Processed on your phone. No image is stored or uploaded. |
We do not keep them. The address is used to produce your answer and is then discarded. Our web server records that a check happened and which page of our API was called, but not the address you checked — the query is stripped before anything is written to disk. Our application log records only the domain name, never the full address, so a link containing a password-reset token or an invoice number is never written down.
Operational records that contain no scanned addresses are kept for 14 days and then deleted automatically.
If you leave Help improve SecureScan switched on (Settings → Security), the app sends us a small count after each check. The whole message is:
The address you checked is not in that list, and neither is its domain, nor any code made from it. These counters tell us how often our on-device checks are enough and how often we have to answer “we don’t know”. They cannot tell us, or anyone else, which sites you looked at.
Switching the setting off stops the sending and throws away the random number, so nothing sent before can be connected to anything sent afterwards.
When a link needs a second opinion, we send the address to:
We send only the address. We do not send your name, your email, your device identifier, or anything else that identifies you. These services therefore receive a link without knowing who checked it.
SecureScan is not directed at children under 13, and we do not knowingly collect personal information from them.
If you are in the UK, EU or another region with similar laws, you have the right to ask what personal data we hold about you, to have it corrected, to have it deleted, and to object to how we use it. In practice, if you never created an account we hold no personal data about you at all.
If you did create an account, you can ask us to delete it and everything attached to it by emailing the address below. We will action it within 30 days.
Traffic between the app and our server is encrypted with HTTPS. Passwords are stored as one-way hashes. Our database is not reachable from the internet.
If we change how we handle data, we will update this page and change the date at the top. Material changes will be announced in the app.
Questions, or a request about your data: ahmdberro50@gmail.com