Sently by DIGITALSTALK

Privacy Policy

Effective date: July 2026  ·  Applies to the Sently iOS app and the approtic.in website for Sently.

Sently is a consumer scam & privacy companion for iOS. It helps you check whether a suspicious message, link, QR code, or voicemail might be a scam, watch your email for data breaches, filter scam texts, and keep a friendly eye on your digital safety. Because privacy is the whole point of the product, we try to collect as little about you as we can, and to be honest about what we do collect and why.

This Privacy Policy explains what information Sently collects, how we use it, who processes it on our behalf, and the rights you have. It applies to the Sently mobile application (the “App”) and any related pages we operate on approtic.in (together, the “Service”). Sently is built and operated by DIGITALSTALK PRIVATE LIMITED (“DIGITALSTALK,” “we,” “us,” or “our”), a company incorporated in India and based in Hyderabad, Telangana. DIGITALSTALK PRIVATE LIMITED is the data controller (and, under India’s DPDP Act, 2023, the Data Fiduciary) responsible for the personal data described in this policy, and is the seller of record for Sently on the Apple App Store.

Plain-language summary. We ask for your email so you can sign in and so we can check it against known data breaches. When you ask Sently “is this a scam?”, some checks happen right on your device; if you run the AI deep check, the message text you submit is sent as-is to Google’s Gemini API for analysis, and any link you check is sent to Google Safe Browsing and Cloudflare’s URL Scanner. Our backend and database run on Cloudflare, and our sign-in emails are delivered by Resend. We never ask for your Social Security Number, and passwords are checked in a way that keeps the actual password on your phone. We do not sell your personal data.

1.What we collect & why

We collect only the information we need to provide the features you use. Depending on how you use Sently, that may include:

Information you give us

Information created by using the App

What we deliberately do not collect

On-device processing. Several parts of Sently work locally on your iPhone and do not send your content to us — including the instant scam heuristics in the Scam Shield and the on-device SMS scam filtering. Sently is a safety tool and does not read your general message history; SMS filtering happens within Apple’s Message Filter framework on your device.

2.Legal bases for processing (GDPR / UK GDPR)

If you are in the European Economic Area or the United Kingdom, we process your personal data only when we have a lawful basis to do so. Our bases are:

3.How we use your data

We use the information described above to:

Data-broker removal (helping remove your details from people-search sites) is a feature we are introducing through a specialist partner. If and when you use it, you will be told what information is needed to submit removal requests on your behalf before it is shared.

We do not sell your personal data, and we do not use it for advertising.

4.Third-party processors — including the AI provider

Who our AI provider is. The optional AI “deep check” in Sently is performed by Google, using the Gemini API (generativelanguage.googleapis.com). The App’s consent prompt refers to this as “a third-party AI service” and links here; this section is where that provider is named. The text you submit for a deep check is sent, through our Cloudflare Worker, to Google’s Gemini API, which analyses it and returns a verdict.

DIGITALSTALK PRIVATE LIMITED relies on a small set of service providers (“subprocessors”) to run Sently. They process personal data only to provide their part of the Service. Our core infrastructure — application hosting, the API workers, and our database — runs on Cloudflare (Cloudflare Workers for compute and Cloudflare D1 for the database). All account data you give us is stored in Cloudflare D1.

The disclosures that matter most. Two of these providers receive content, not just account details. Google Gemini receives the full raw text of any message you submit for an AI deep check. Google Safe Browsing and Cloudflare URL Scanner receive the full URLs you ask us to check. Both are triggered only by an action you take, and both are described in §1. The Gemini deep check additionally requires your explicit in-App permission before the first message is ever sent, and you can withdraw it at any time under You → Cloud AI analysis.
Subprocessor Purpose Data involved Region
Cloudflare
(Workers + D1)
Hosts our entire backend: API compute on Cloudflare Workers, and the Cloudflare D1 database that stores all account data Account email, monitored emails/phone, family members’ names and emails, push token, subscription status, breach findings, hashed scam-check records Global / US-EU
Cloudflare
(URL Scanner)
Link-reputation lookup when you check a link or QR code The full URL you asked us to check Global
Resend Transactional email delivery — sending your one-time sign-in code Your email address and the one-time code US
Google
(Gemini API)
AI analysis for the optional “deep check” — Google’s model reads the message and returns a scam verdict The full raw text of the message, link, QR content, or voicemail transcript you submit, including any personal details it happens to contain US / Global
Google
(Safe Browsing)
Checking whether a link is known malware, phishing, or social engineering The full URL you asked us to check US / Global
Apple App Store in-app purchases & subscription management; push notification delivery (APNs) Subscription/transaction status; device push token Global
Optery Data-broker removal (coming soon) — submitting opt-out/removal requests to people-search sites on your behalf Details you provide for removal requests, when you use the feature US
XposedOrNot
(breach-data source)
Checking whether your email appears in known data breaches — your monitored email address is sent to this service to run the lookup Your email address Global
Have I Been Pwned
(Pwned Passwords API)
Checking whether a password you enter in the password checker has appeared in known breaches, using a k-anonymity range query Only a 5-character partial SHA-1 hash prefix of the password — the full password never leaves your device Global

We update this list as our providers change. Where required, we put appropriate data-processing terms in place with each subprocessor. Each provider also has its own privacy policy governing how it handles data.

5.International data transfers

DIGITALSTALK PRIVATE LIMITED is based in Hyderabad, India, and our subprocessors operate in various countries, including the United States and the European Union. This means your personal data may be transferred to, stored in, or processed in a country other than the one you live in, where data-protection laws may differ from your own.

When we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum where relevant), or another lawful transfer mechanism recognized under applicable law. You can ask us for more information about the safeguards we use (see §12).

6.Data retention

We keep personal data only for as long as we need it for the purposes described in this policy, and then delete or anonymize it. In general:

7.Security

We take reasonable and appropriate technical and organizational measures to protect your information. These include encryption of data in transit, passwordless one-time-code sign-in, minimizing the data we collect, keeping full passwords off our servers through k-anonymity checks, and doing sensitive processing on your device where practical.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You also play a part: keep your device, Apple ID, and email account protected, and be cautious about what you paste into any tool.

8.Your rights

If you are in the EEA or the UK (GDPR / UK GDPR)

Subject to the law, you have the right to:

You also have the right to lodge a complaint with your local data-protection authority.

If you are in California (CCPA / CPRA)

California residents have the right to:

We do not “sell” your personal information, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. Because we do not sell or share in this sense, there is no opt-out for that to perform — but you may still exercise your other rights above.

If you are in India (DPDP Act, 2023)

As a Data Principal under India’s Digital Personal Data Protection Act, 2023, you have the right to:

To exercise any of these rights, see §12. We will respond within the timeframes required by applicable law and may need to verify your identity first.

9.Children’s privacy

Sently is intended for adults and is not directed to children under 13 (or under 16 where a higher age of digital consent applies). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at abhinay@approtic.in and we will take appropriate steps to delete it. The family “safe word” tool is designed to be set up and used by a responsible adult.

10.Marketing communications

Marketing email is opt-in only. We will not add you to a marketing list unless you have asked to receive it. Every marketing email includes an unsubscribe link, and you can opt out at any time. Opting out of marketing does not stop essential service messages, such as your sign-in code or breach alerts, which are necessary to provide the Service.

11.Cookies

The Sently App does not use advertising cookies. Our website for Sently uses minimal or no non-essential cookies; where any cookies are strictly necessary to load and secure the pages, they are used only for that purpose. We do not use cookies to track you across other websites for advertising.

12.Exercising your rights & contacting us

To make any privacy request — access, correction, deletion, portability, objection, or to withdraw consent — or to ask a question about this policy, contact us:

We may need to verify your identity before acting on a request, and we will respond within the timeframe required by the law that applies to you. If you have authorized an agent to act on your behalf, we may ask for proof of that authorization.

Grievance Officer

In accordance with India's Digital Personal Data Protection Act, 2023, the following individual is designated to address questions, complaints, or grievances regarding the processing of your personal data. We aim to acknowledge every grievance within 72 hours and resolve it within 30 days.

If you are not satisfied with our response, you have the right to escalate your complaint to the Data Protection Board of India.

13.Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in the Service, our providers, or the law. When we make material changes, we will update the effective date at the top and, where appropriate, notify you in the App or by email. Your continued use of the Service after an update means you accept the revised policy.