Privacy Policy
Sently is a consumer scam & privacy companion for iOS. It helps you check whether a suspicious message, link, QR code, or voicemail might be a scam, watch your email for data breaches, filter scam texts, and keep a friendly eye on your digital safety. Because privacy is the whole point of the product, we try to collect as little about you as we can, and to be honest about what we do collect and why.
This Privacy Policy explains what information Sently collects, how we use it, who processes it on our behalf, and the rights you have. It applies to the Sently mobile application (the “App”) and any related pages we operate on approtic.in (together, the “Service”). Sently is built and operated by DIGITALSTALK PRIVATE LIMITED (“DIGITALSTALK,” “we,” “us,” or “our”), a company incorporated in India and based in Hyderabad, Telangana. DIGITALSTALK PRIVATE LIMITED is the data controller (and, under India’s DPDP Act, 2023, the Data Fiduciary) responsible for the personal data described in this policy, and is the seller of record for Sently on the Apple App Store.
1.What we collect & why
We collect only the information we need to provide the features you use. Depending on how you use Sently, that may include:
Information you give us
- Your email address — used to sign you in with a one-time code (we do not use passwords for your Sently account) and to scan for data breaches associated with that address.
- Additional emails and a phone number you choose to monitor — if you opt to watch extra email addresses or a phone number for breaches or scam exposure, we store those identifiers so we can run and repeat those checks for you.
- Content you submit for scam checking — the text, links, QR-code contents, or voicemail transcripts you paste or share into the “AI Scam Shield” to ask “is this a scam?” A first-pass check runs on your device. If you choose the optional AI deep check, the raw text of your message is transmitted in full to Google’s Gemini API (generativelanguage.googleapis.com) so that Google’s model can analyze it and return a verdict. Whatever that message contains — including any names, phone numbers, account references, or other personal details a sender put in it — leaves our systems and is processed by Google. Please do not paste anything you would not want analyzed by a third-party AI service.
We ask your explicit permission in the App before this ever happens. Cloud AI analysis is off until you accept a prompt that tells you exactly what is sent, that it goes to a third-party AI service through our server, and that links to this Privacy Policy — where that provider is identified by name as Google (Gemini API), in §4 below. If you decline, Sently keeps working using only the on-device checks and nothing you type is sent to Google. You can turn this permission on or off at any time in the App under You → Cloud AI analysis. - Links you ask us to check — when you check a link or QR code, the full URL is sent to Google Safe Browsing (safebrowsing.googleapis.com) and to Cloudflare’s URL Scanner for a reputation lookup. This tells those providers which URLs you are checking.
- Family members you add to the “safe word” tool — if you use the family feature, you may give us the name, relationship, and email address of other people (for example a parent, partner, or child). This is personal data about someone other than you. You are responsible for having a proper basis to share it, and you should tell those people that their details are stored in Sently. We use it only to operate the family safe-word feature; we do not market to them. You can edit or delete any family member at any time in the App, and deleting your account deletes all family-member records.
Information created by using the App
- Device push token — an identifier provided by Apple so we can send you breach and safety alerts by push notification.
- Subscription status — whether you have an active free trial or paid plan (e.g., Sently Plus or Family), so the App can unlock the right features. This status is determined on your device via Apple’s StoreKit and is not transmitted to or stored on our own servers — billing and entitlement records are held by Apple. See §3 and our Terms.
- Scam-check records — when a scam check runs, we store a record containing a one-way SHA-256 hash of the checked message, the risk score, and the verdict. We store the hash rather than the message itself, so the original text is not recoverable from our database. This lets us de-duplicate repeat checks and monitor abuse of the Service.
- Breach findings — the names of breaches your monitored email appears in, so we can show you your exposure history and alert you to new matches.
What we deliberately do not collect
- No Social Security Numbers and no government identity numbers.
- No financial-account logins, card numbers, or bank credentials.
- No passwords. When Sently checks whether a password has appeared in a breach, it uses a k-anonymity range query against the Have I Been Pwned Pwned Passwords API (api.pwnedpasswords.com): only a short, partial hash prefix leaves your device, the full password is never transmitted, and we never store your password.
2.Legal bases for processing (GDPR / UK GDPR)
If you are in the European Economic Area or the United Kingdom, we process your personal data only when we have a lawful basis to do so. Our bases are:
- Performance of a contract (Art. 6(1)(b)) — to create your account, sign you in, run breach and scam checks you request, and provide the features of your plan.
- Consent (Art. 6(1)(a)) — for the optional AI deep check that sends your submitted content to Google’s Gemini service, for monitoring additional emails or a phone number you add, and for optional marketing emails. For the Gemini deep check that consent is collected through an explicit in-App prompt that names Google, and can be withdrawn in the App under You → Cloud AI analysis. You may withdraw consent at any time (see §8 and §12).
- Legitimate interests (Art. 6(1)(f)) — to keep the Service secure, prevent abuse and fraud, debug problems, and maintain and improve core functionality, balanced against your rights and freedoms.
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose information to comply with applicable law.
3.How we use your data
We use the information described above to:
- Sign you in with a one-time code and maintain your account;
- Check your email (and any additional identifiers you add) against known data-breach sources and notify you of matches;
- Analyze content you submit to tell you whether it looks like a scam, including the optional AI deep check and link-reputation checks;
- Filter likely scam SMS messages on your device;
- Send you breach alerts and safety notifications by push;
- Provide the friendly AI companion (“Pax”) and the family “safe word” tool;
- Manage your subscription entitlements and free trial;
- Keep the Service secure, prevent misuse, fix bugs, and improve reliability;
- Communicate with you about the Service, and — only if you opt in — send you marketing emails you can unsubscribe from at any time.
Data-broker removal (helping remove your details from people-search sites) is a feature we are introducing through a specialist partner. If and when you use it, you will be told what information is needed to submit removal requests on your behalf before it is shared.
We do not sell your personal data, and we do not use it for advertising.
4.Third-party processors — including the AI provider
Who our AI provider is. The optional AI “deep check” in Sently is performed by Google, using the Gemini API (generativelanguage.googleapis.com). The App’s consent prompt refers to this as “a third-party AI service” and links here; this section is where that provider is named. The text you submit for a deep check is sent, through our Cloudflare Worker, to Google’s Gemini API, which analyses it and returns a verdict.
DIGITALSTALK PRIVATE LIMITED relies on a small set of service providers (“subprocessors”) to run Sently. They process personal data only to provide their part of the Service. Our core infrastructure — application hosting, the API workers, and our database — runs on Cloudflare (Cloudflare Workers for compute and Cloudflare D1 for the database). All account data you give us is stored in Cloudflare D1.
| Subprocessor | Purpose | Data involved | Region |
|---|---|---|---|
| Cloudflare (Workers + D1) |
Hosts our entire backend: API compute on Cloudflare Workers, and the Cloudflare D1 database that stores all account data | Account email, monitored emails/phone, family members’ names and emails, push token, subscription status, breach findings, hashed scam-check records | Global / US-EU |
| Cloudflare (URL Scanner) |
Link-reputation lookup when you check a link or QR code | The full URL you asked us to check | Global |
| Resend | Transactional email delivery — sending your one-time sign-in code | Your email address and the one-time code | US |
| Google (Gemini API) |
AI analysis for the optional “deep check” — Google’s model reads the message and returns a scam verdict | The full raw text of the message, link, QR content, or voicemail transcript you submit, including any personal details it happens to contain | US / Global |
| Google (Safe Browsing) |
Checking whether a link is known malware, phishing, or social engineering | The full URL you asked us to check | US / Global |
| Apple | App Store in-app purchases & subscription management; push notification delivery (APNs) | Subscription/transaction status; device push token | Global |
| Optery | Data-broker removal (coming soon) — submitting opt-out/removal requests to people-search sites on your behalf | Details you provide for removal requests, when you use the feature | US |
| XposedOrNot (breach-data source) |
Checking whether your email appears in known data breaches — your monitored email address is sent to this service to run the lookup | Your email address | Global |
| Have I Been Pwned (Pwned Passwords API) |
Checking whether a password you enter in the password checker has appeared in known breaches, using a k-anonymity range query | Only a 5-character partial SHA-1 hash prefix of the password — the full password never leaves your device | Global |
We update this list as our providers change. Where required, we put appropriate data-processing terms in place with each subprocessor. Each provider also has its own privacy policy governing how it handles data.
5.International data transfers
DIGITALSTALK PRIVATE LIMITED is based in Hyderabad, India, and our subprocessors operate in various countries, including the United States and the European Union. This means your personal data may be transferred to, stored in, or processed in a country other than the one you live in, where data-protection laws may differ from your own.
When we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum where relevant), or another lawful transfer mechanism recognized under applicable law. You can ask us for more information about the safeguards we use (see §12).
6.Data retention
We keep personal data only for as long as we need it for the purposes described in this policy, and then delete or anonymize it. In general:
- Account data (your email, monitored identifiers, push token, subscription status) is kept while your account is active.
- Sign-in codes are short-lived and expire quickly after they are issued.
- Content submitted for a scam deep check is used to return a result. We do not store the message text itself — only a one-way hash, the score, and the verdict (see §1) — so we cannot reconstruct what you submitted or build a content profile of you. Once the text is transmitted to Google’s Gemini API, Google’s own retention and terms govern that copy, and we cannot delete it on your behalf.
- Family-member records (name, relationship, email) are kept while your account is active or until you delete that member in the App.
- If you delete your account, we delete or de-identify your personal data within a reasonable period, except where we must keep certain records to comply with law, resolve disputes, or enforce our agreements.
7.Security
We take reasonable and appropriate technical and organizational measures to protect your information. These include encryption of data in transit, passwordless one-time-code sign-in, minimizing the data we collect, keeping full passwords off our servers through k-anonymity checks, and doing sensitive processing on your device where practical.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You also play a part: keep your device, Apple ID, and email account protected, and be cautious about what you paste into any tool.
8.Your rights
If you are in the EEA or the UK (GDPR / UK GDPR)
Subject to the law, you have the right to:
- Access a copy of the personal data we hold about you;
- Rectification — correct data that is inaccurate or incomplete;
- Erasure — ask us to delete your personal data (“right to be forgotten”);
- Portability — receive your data in a structured, commonly used, machine-readable format;
- Object to processing based on our legitimate interests, and object to direct marketing at any time;
- Restrict processing in certain circumstances;
- Withdraw consent at any time where we rely on consent (this does not affect processing already carried out).
You also have the right to lodge a complaint with your local data-protection authority.
If you are in California (CCPA / CPRA)
California residents have the right to:
- Know what personal information we collect, use, and disclose;
- Delete personal information we hold about you;
- Correct inaccurate personal information;
- Opt out of the “sale” or “sharing” of personal information;
- Not receive discriminatory treatment for exercising your rights.
If you are in India (DPDP Act, 2023)
As a Data Principal under India’s Digital Personal Data Protection Act, 2023, you have the right to:
- Access a summary of the personal data we process and the processing activities;
- Correction, completion, updating, and erasure of your personal data;
- Grievance redressal from us as the Data Fiduciary;
- Nominate another individual to exercise your rights in the event of death or incapacity;
- Withdraw consent where processing is based on consent.
To exercise any of these rights, see §12. We will respond within the timeframes required by applicable law and may need to verify your identity first.
9.Children’s privacy
Sently is intended for adults and is not directed to children under 13 (or under 16 where a higher age of digital consent applies). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at abhinay@approtic.in and we will take appropriate steps to delete it. The family “safe word” tool is designed to be set up and used by a responsible adult.
10.Marketing communications
Marketing email is opt-in only. We will not add you to a marketing list unless you have asked to receive it. Every marketing email includes an unsubscribe link, and you can opt out at any time. Opting out of marketing does not stop essential service messages, such as your sign-in code or breach alerts, which are necessary to provide the Service.
12.Exercising your rights & contacting us
To make any privacy request — access, correction, deletion, portability, objection, or to withdraw consent — or to ask a question about this policy, contact us:
- Email: abhinay@approtic.in
- Company: DIGITALSTALK PRIVATE LIMITED · approtic.in
- Registered address: 138, New Hema Nagar, Lane No. 8, McDowell's Colony, Boduppal, Hyderabad, Telangana 500092, India
- Phone: +91 96666 59359
We may need to verify your identity before acting on a request, and we will respond within the timeframe required by the law that applies to you. If you have authorized an agent to act on your behalf, we may ask for proof of that authorization.
Grievance Officer
In accordance with India's Digital Personal Data Protection Act, 2023, the following individual is designated to address questions, complaints, or grievances regarding the processing of your personal data. We aim to acknowledge every grievance within 72 hours and resolve it within 30 days.
- Grievance Officer: Abhinay Gajji, Founder
- Entity (Data Fiduciary): DIGITALSTALK PRIVATE LIMITED
- Address: 138, New Hema Nagar, Lane No. 8, McDowell's Colony, Boduppal, Hyderabad, Telangana 500092, India
- Email: abhinay@approtic.in
- Phone: +91 96666 59359
If you are not satisfied with our response, you have the right to escalate your complaint to the Data Protection Board of India.
13.Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in the Service, our providers, or the law. When we make material changes, we will update the effective date at the top and, where appropriate, notify you in the App or by email. Your continued use of the Service after an update means you accept the revised policy.