Privacy Policy
- We never store the messages you check, unless you choose to report one. There are no accounts, no ads and no tracking.
- When you tap Check message, only the text is sent. Your phone first hides details like phone numbers, codes and card numbers.
- The text is analysed by Anthropic's AI (Claude). Anthropic deletes it within 30 days and doesn't use it to train its AI.
- Web addresses (links) may be checked against Google's list of unsafe sites (Google Web Risk), without the part after “?”. The site itself is never visited.
- We keep a few anonymous numbers about each check (never the message) for 13 months, to improve the app.
- If you choose to report a message, we keep it (personal details hidden) to help spot new scams. Only when you agree.
Who we are
AortaShield is a free, personal, non-commercial project made by an independent developer to help people spot scam messages. It is not a company and has no revenue, ads or paid features. In this policy, "we" means AortaShield.
Questions about privacy: privacy@aortashield.com. For data protection laws, we are the "controller" of the data described below.
What happens when you check a message
1. On your phone, before anything is sent
- Nothing leaves your phone until you tap Check message.
- If you pick a screenshot or photo, your phone reads the text in it itself (Apple Vision on iPhone, Google ML Kit on Android). The image is never sent.
- Link and QR code checks start on your phone. The app reads the address or the code and explains what it contains. The link is never opened. If link checking with Google is switched on (see section 4), the address is also checked as described there.
- If you scan a QR code, the camera is used only while the scan screen is open, to read the code on your phone. Nothing is recorded, saved or sent.
- Your phone replaces personal details with labels such as
[phone]: email addresses, phone numbers, card, bank account and ID numbers, one-time codes, and on iPhone people's names. Web addresses and amounts are kept, because they help spot scams. This catches common formats, not everything, so please remove anything else private yourself.
2. On our server
The cleaned text is sent over an encrypted connection to our server (Google Cloud). The server looks for common warning signs, asks the AI for a verdict, sends you the answer, and forgets the message. We don't store the message and don't write it in our logs.
3. At Anthropic (the AI)
To give you a clear answer, the text is sent to Anthropic, the company that makes the Claude AI, through its API. Under Anthropic's terms for API customers, it deletes the text within 30 days, keeps it longer (up to 2 years) only if its safety systems flag it or the law requires it, and does not use it to train its AI.
4. At Google Web Risk (links only)
To spot links to known phishing and malware sites, web addresses in a message you check, or a link you paste into Check a link, may be sent from our server to Google Web Risk, a Google Cloud service that compares an address with Google's list of unsafe sites. We remove everything after “?” or “#” first (that part often contains personal or tracking details). Only the address is sent, never the rest of your message. Google doesn't visit the site for us. We don't store or log the addresses or Google's answers, and we don't pass Google's answers to anyone else, including Anthropic. Google's results come with Google's own notice: Google cannot guarantee that its information is complete and error-free.
What we keep
| What | Why | Where | How long |
|---|---|---|---|
| Anonymous check statistics: a random check ID, the hour of the check, the verdict, which common warning signs matched, the message length, how long the check took, AI usage counts, the AI model, the app version and platform (iPhone/Android). Never the message, the answer's text, your IP address or any device ID. | To see how well the app works and improve it | Neon (database service) | 13 months |
| Your feedback: if you answer "Was this right?", your yes/no and, if you choose, what the message really was, linked to that random check ID | To find and fix wrong verdicts | Neon | 13 months |
| Messages you choose to report (only if you tap Report this message and tick that you agree): the message as shown on the report screen, with personal details already hidden by your phone and again by our server (phone numbers, email addresses, long numbers), the verdict AortaShield gave, what you said it is (optional), a random report code, the day, the app version and platform. Not linked to you: no name, account, IP address or device ID. | To help AortaShield recognise new scams: the developer reviews reports, and good ones become examples that help the AI spot similar messages | Neon | Up to 12 months, unless chosen as an example (kept while useful). Ask for deletion any time with your report code. |
| Technical logs: errors and security events (e.g. a request refused), without message content. Google Cloud also keeps standard request logs, which include the IP address of the request. | To keep the service running and secure, and to stop abuse | Google Cloud | 30 days |
| Emails you send us (support@ or privacy@), including your email address | To answer you | Until the question is resolved, then deleted within 12 months |
Because the statistics and feedback aren't linked to you, we can't tell which records came from your phone. For a report, quote its report code (shown after you send it) to privacy@aortashield.com and we'll delete it.
What stays on your phone
- Your agreement to this policy (its version and date), so the app doesn't ask every time. On iPhone it's shared with the app's Share sheet.
- Nothing else: the app doesn't save your messages or results. They're cleared when you check another message, and the screen is covered in the app switcher.
Proving it's the real app (App Check)
To stop others from misusing our server, each request carries a short-lived token that proves it comes from the genuine AortaShield app. The token is provided by Google Firebase App Check, which asks Apple (App Attest / DeviceCheck) or Google (Play Integrity) to confirm the app and device are genuine. This involves technical information about the app and device, processed by Apple, Google and Firebase under their own privacy policies. It doesn't include your messages, your name or an account. Firebase's usage analytics are turned off.
Who we share data with
Only the service providers needed to run the app: Anthropic (AI analysis), Google Cloud and Firebase (server, logs, App Check, Web Risk link checks), Neon (anonymous statistics) and Apple / Google (app stores and app verification). We don't sell or rent data, don't use it for advertising, and don't share it with anyone else unless the law requires it.
Why we're allowed to use it (legal bases)
- Your consent (asked when you first open the app) for sending the text of messages you choose to check to our server and Anthropic, and the web addresses in them to Google Web Risk; and, separately each time, for keeping a message you choose to report.
- Legitimate interests for anonymous statistics, feedback, technical logs and App Check: keeping the app working, accurate and safe from abuse.
Your choices and rights
- Only check what you choose. Nothing is sent without tapping Check message, and you can edit the text first.
- Withdraw consent at any time in Settings → Withdraw consent. The app then won't send anything until you agree again.
- Access, correction, deletion, objection: wherever you live, you can ask us about the data we hold, and ask us to correct or delete it. Because we don't store messages and our statistics aren't linked to you, we usually hold nothing we can identify as yours, but write to privacy@aortashield.com and we'll help.
- You can also complain to the data protection authority where you live.
Processing in other countries
Our server, database and AI provider may be located in a different country from you, so your message text may be transferred to and processed in another country to be checked. We rely on our providers' contractual safeguards for these transfers.
Security
Connections are encrypted. Keys and passwords are kept in Google Secret Manager, not in the app. The server accepts requests only from the genuine app. Personal details are hidden on your phone before sending. No system is perfectly secure, which is one more reason we keep as little as possible.
Children
AortaShield is meant for adults (18 and over). It isn't designed for children and we don't knowingly collect information about them.
Changes to this policy
If we change what the app sends or keeps, we'll update this page and the app will ask you to agree again before your next check.