Privacy policy
What SecureOne sees, sends and keeps
Last updated 10 September 2026 · applies to SecureOne for Android 1.0.4
The short version
- Most checks run on your phone. Online checks send the smallest thing that answers the question — a link, a file's fingerprint, the start of a password hash — never the message, file or password itself.
- The text of your messages and notifications is never stored and never uploaded.
- Your contacts, call history and files never leave your phone.
- There are no ads and no advertising or analytics trackers in the app.
- Signing out erases the scan results stored on your phone.
What stays on your phone
SecureOne reads the following on your device to scan it. None of it is uploaded unless listed in the next section.
- Installed apps — names, permissions, install source, signing certificate and app code, for the app, tracker and adware checks. Trackers are matched on your phone against a signature list downloaded to it.
- Device settings — screen lock, root signs, developer options, device administrators, security patch level.
- Wi-Fi — the network name and its security type, when location access is granted (Android requires it to read the name).
- Incoming SMS and notifications — searched in memory for links; the text is then discarded.
- Recent calls — the last 50 entries, judged and discarded; nothing about who called is saved.
- Files you choose to scan, and new downloads — read to compute a fingerprint and to compare their real type with their name.
Results, alerts and your score history are stored in the app's private storage on your phone. Signing out, or Settings › Clear scan data, deletes them.
What is sent, and to whom
| What | When | Sent to |
|---|---|---|
| Your email address, and a name if you give one | Signing in | SecureOne's server; Google (Gmail), which delivers the one-time code by email |
| A link | You scan it; it arrives by SMS; or it appears in a notification while you are signed in with “Check every link online” switched on | SecureOne's server, which asks Google Safe Browsing, VirusTotal and URLhaus (abuse.ch). Redirects are followed by the server, not your phone. |
| A website's domain name | You check a link | SecureOne's server, which inspects the site's certificate and asks Google Safe Browsing |
| App and file fingerprints (SHA-256) and app package names | A device scan, or a file you scan | SecureOne's server, which asks VirusTotal and MalwareBazaar (abuse.ch) |
| Your email address | You run a breach check, and weekly for the email saved for breach alerts | XposedOrNot, directly from your phone. XposedOrNot also sees your phone's IP address. |
| The first 5 characters of a password's SHA-1 hash | You check a password | SecureOne's server, which asks Have I Been Pwned's Pwned Passwords range service. The comparison happens on your phone. |
| A phone number | Only a number Call protection has already flagged on your phone | SecureOne's server, to look up fraud reports from other users |
| A fraud report: the number or link, a category and any description you type | You report fraud | SecureOne's server. Other users see only how many reports a number or link has. |
| A “disagree with verdict” report: the item, a fixed reason and the verdict | You send one | SecureOne's server |
| A push-notification token and a random device ID | You are signed in | SecureOne's server and Firebase Cloud Messaging, to deliver alerts |
| Your name, email, mobile number, the plan and its price | You buy a plan on this website | SecureOne's server, and Razorpay, which processes the payment |
| Card, UPI or bank details | You pay for a plan | Razorpay only. SecureOne never receives them. |
| Your location, battery, network and SIM status | Only in reply to an anti-theft command you send, or when the SIM changes | By SMS to the trusted numbers you set up. Not to SecureOne's server. |
What SecureOne's server keeps
- Your account — email address, optional name, and when you signed up and last signed in.
- Plans and payments — your plan and its start and end dates; for each payment, the Razorpay order and payment IDs, the amount and the date, with the name and mobile number given at checkout. Payment records are kept for as long as tax and accounting law requires.
- Sign-in codes — stored only as a salted hash, used once, and expire.
- Sessions — which device a sign-in belongs to, and whether it has been signed out.
- Check results — verdicts for links, domains and fingerprints are cached for between minutes and 30 days, so the same item is not looked up again and again.
- Reports — fraud and “disagree” reports you send, with your account ID.
The database is Google Cloud Firestore in the asia-south1 (Mumbai) region. The server itself runs on Render.
Permissions, and why
- SMS (receive, read, send) — to check links in incoming SMS, and to receive and answer anti-theft commands.
- Call log — for Call protection. Only the last 50 calls are read, and none are stored.
- Location — to read the Wi-Fi network name, and to answer a LOCATE command.
- Notification access — to find links in notifications. Off until you switch it on.
- Device administrator — for the anti-theft LOCK command.
Every permission is optional. A feature that lacks its permission says so, and the rest of the app keeps working.
Your choices
- Use on-device scans without an account.
- Switch off “Check every link online” in the Privacy Center, so only suspicious-looking links are looked up.
- Clear scan data, or sign out, to erase results on your phone.
- Deny or revoke any permission in Android settings.
Contact
SecureOne is run by Aman Gupta, trading as AGC One, Nashik, Maharashtra, India. For privacy questions or to delete your account, write to oneagc.1@gmail.com from the email your account uses. See also the Contact page.