Strike Cyber Shield is built privacy-first. The app audits your device's security,
scans for scams, protects your photos, and teaches you to spot threats. Almost everything happens
entirely on your device. This policy explains, in plain language, exactly what data the
app handles and what — in the rare cases it does — leaves your phone.
No accountOn-device analysisEncrypted at restEncrypted in transit
What stays on your device
The following never leave your phone. They are processed locally and, where stored, encrypted with
device-only keys:
Your photos and any image you scan, plus your encrypted photo vault
Your Guardian Score, security checks, and their results
Passwords you check (see k-anonymity below) and any PINs or codes
Location data read from photo metadata (EXIF/GPS)
Your learning progress, streaks, badges, and app settings
What the app may send — and why
Only these specific, minimal requests ever go out, always over encrypted connections:
Push registration. On first launch, a random install identifier and a push
(FCM) token are sent to our notification service so we can deliver security alerts. No personal
information is included.
Password exposure checks. When you choose to check a password, it is hashed on
your device and only the first five characters of that hash are sent (a technique called
k-anonymity). Your password — and its full hash — never leave your phone.
Email breach checks. When you add an email to monitor, that email is sent — over
encrypted, certificate-pinned connections — to a public breach-lookup service solely to run the
check. It is not stored by us.
Known-breach catalogue. The app fetches a public list of known breaches to power
its encyclopedia. This request contains nothing about you.
Security content updates. The app may check whether newer educational content is
available and download it. This carries no personal data.
Permissions
Every permission is requested only when you use the feature that needs it, with an explanation:
Camera — to scan QR codes, read suspicious letters or messages, and capture
photos directly into your encrypted vault.
Photos — to scan your library on-device for sensitive content and location
leaks. Limited access is requested first; full access only if you ask for a full sweep.
Notifications — to send daily briefs, audit reminders, and breach alerts.
Face ID / Touch ID — to unlock your private vault.
Notifications
With your permission, the app sends local reminders (daily brief, weekly audit, streak nudges) and,
via Firebase Cloud Messaging, timely security alerts such as new breach exposures. You can turn these
off at any time in the app or in your device Settings.
Data security
Sensitive data stored on your device — the photo vault, cached breach results, and monitored emails —
is encrypted using industry-standard AES-GCM with keys held in the device Keychain and
excluded from backups. Network traffic uses TLS with public-key pinning on our stable
endpoints. The app also includes tamper-detection safeguards and will refuse sensitive operations if the
device appears compromised.
Children's privacy
Strike Cyber Shield is a general-audience security tool and is not directed at children under 13. We
do not knowingly collect personal information from children.
Your choices
Because there is no account, you stay in control: remove a monitored email at any time, empty your
vault, disable notifications, or simply delete the app to remove all locally stored data from your
device.
Changes to this policy
We may update this policy to reflect improvements or new features. Material changes will be surfaced
in the app. Continued use after an update means you accept the revised policy.