Privacy Policy for Cyber Kavach
Effective Date: July 06, 2026
At Cyber Kavach, your privacy is our core value. This Privacy Policy describes how your information is handled, processed, and protected by the Cyber Kavach mobile application.
Local-First Privacy Guarantee: Cyber Kavach operates under a strict "local-first" architecture. All scanning, heuristics analysis, notification auditing, and link filtering run entirely on your local device. We do not upload or share your private chats, notification logs, or file contents to any external servers.
1. Information We Collect & How We Use It
A. Account Information (Cloud Sync)
When you register an account or subscribe to premium licenses inside Cyber Kavach:
- Data Type: Email address.
- Usage: Used exclusively to authorize your subscription, verify premium status, and manage security session tokens via Google Firebase Authentication.
- Sharing: We do not share, lease, or sell your email address to third parties.
B. Chat & Phishing Link Interception (Local Processing)
Our Omni Guard Chat Shield scans incoming text messages and notifications to intercept malicious phishing URLs:
- Data Type: Notification layouts and message texts.
- Usage: Scanned on-device using heuristic algorithms and local signature checks to flag threat actors.
- Bypass/Cloud Lookup: High-priority API checks are optionally queried against URLhaus and PhishStats APIs to catch fresh zero-day threats. These checks transmit only the target URL for query purposes; no sender identification or conversation metadata is ever shared.
C. Installed Applications Auditing (Local Processing)
Our Permission Audit module scans installed applications to list their granted risk factors:
- Data Type: List of installed third-party packages and permissions.
- Usage: Analyzed locally to present security threat levels. This package data never leaves your device.
D. DNS Tracking & Ad Filtering (Local Processing)
Our VPN Tracker Blocker routes DNS requests through a local loopback VPN adapter:
- Data Type: Outbound DNS domains.
- Usage: Checked locally against JNI Bloom Filters to block track domains. No network traffic is decrypted, modified, or directed to any cloud proxy servers.
2. Data Security Practices
We implement industry-standard security measures to safeguard your credentials:
- All connections between the application and Google Firebase use HTTPS/TLS encrypted transit channels.
- Vault files are protected locally using hardware-backed AES-256-GCM encryption key stores.
3. Data Retention and Deletion
Your account credentials and subscription metadata are retained as long as your profile remains active. You can request the absolute deletion of your account and associated registration data at any time directly through the app's Profile configuration console or by reaching out to our developer support email.
4. Contact Us
If you have any questions or feedback regarding our privacy practices, please contact us at:
Email: support@cyberkavach.com