Scam Rakshak — Privacy Policy

Effective date: 24 July 2026.
Developer: Blu Codeworks, a business registered in Australia, 3/42 Henry Street, Ravenswood, Tasmania 7250, Australia.

Scam Rakshak ("the app") is built by Blu Codeworks to help protect senior citizens from WhatsApp-based scams. This policy explains exactly what the app processes, what stays on the phone, and the one narrow case where data leaves it.

The short version

Why the app needs Notification Access

Scam Rakshak requires Android Notification Access solely to detect scam indicators in WhatsApp activity, on the device. Notification data is not used for advertising, analytics, profiling, or any unrelated purpose.

Notice: what is processed, and why (itemised)

Each item of personal data the app processes, mapped to its specific purpose and manner of processing (DPDPA notice):

Data itemPurposeManner
WhatsApp notification metadata: sender phone number, event type (message / voice / video call), timestamps, call durations, link-present flag Detecting scam patterns from unknown numbers — repeated calls, long pressure calls, suspicious links Processed and stored on the device only
Local copy of the device's contact numbers Ignoring people the senior knows, so only unknown-number activity is analysed Processed and stored on the device only; never uploaded
Behaviour profile: daily statistical summaries (call counts, typical durations) Identifying days that are unusual for this specific senior Computed and stored on the device only
Alert metadata: unknown number(s), attempt counts and types, call minutes, trigger reason, saved-contact label on resolution Alerting the family members the senior explicitly paired with Transmitted via the developer's Firebase project only when family pairing is active; server copies deleted after delivery
Anonymous Firebase installation ID and push (FCM) token Delivering family alerts to the right devices Generated randomly per install; created only when family pairing is used
Display names chosen at pairing: the senior's first name and family members' names, as typed in the app Showing who is who inside family alerts and on the family screens Stored in the pairing records on the server while family pairing is active; removed when the pairing is removed

Message text is processed briefly on-device to determine whether a message contains a web link. The message text is never stored, transmitted, or retained — only a yes/no link flag is kept.

All on-device data lives in the app's private storage, is excluded from device backups, and is deleted when the app is uninstalled. On-device records are automatically pruned on rolling windows, in line with the storage-limitation principle: detailed event records are kept for about 35 days, alert history for 90 days, and the log of unknown-number interactions for 6 months (older months are reduced to statistical summaries — counts and typical durations, no phone numbers — before the raw records are deleted). Data is kept no longer than needed for the purpose it was collected for.

The anonymous installation ID is randomly generated per install, carries no name, phone number, or account, and cannot by itself be linked back to any individual.

What leaves the phone, and to whom

Family alerts. If — and only if — the senior pairs the app with family members (an explicit, code-based pairing the senior initiates), the app sends those specific people alert metadata when scam-pattern thresholds are met: the unknown number(s) involved, the type and count of contact attempts, call minutes, the reason the alert fired, and — when the senior resolves an alert by saving a number — the contact name they chose. Message content is never included, because it is never captured.

Alert data is stored and processed on Google Cloud servers located in India (Mumbai region, "asia-south1"). Delivery of push notifications uses Google's global messaging infrastructure; Google may process limited infrastructure data under its own policies. Alert documents are transport, not storage: they are deleted from our database immediately after dispatch; undelivered notifications are held by Google's messaging service until delivery or expiry. Identity is an anonymous Firebase ID per install — the app never collects the senior's or family members' own phone numbers.

Usage statistics. Scam Rakshak records anonymous counts of protection activity, such as how many alerts were shown, how many numbers were marked as scam or trusted, and how many situations were resolved. These counts are uploaded once a day under a random installation identifier. They never include phone numbers, names, contacts, message content, or any other personal information, and they cannot be linked back to you. Reinstalling the app creates a new identifier with no connection to the old one. We use these statistics to understand how well the protection works, to improve it, and to report overall service numbers. Collection of these anonymous counts is a standard part of how the app operates and cannot be switched off.

Diagnostics you choose to send. The app has a "Send diagnostics to support" option in Settings. If — and only if — you press Send on its confirmation, a copy of the app's protection records on your phone (including the numbers and activity it has recorded) is uploaded to Scam Rakshak's own storage, readable by nobody else, to help resolve a problem. Nothing is ever sent without that press. Diagnostic uploads are used strictly for troubleshooting and are permanently deleted within 30 days of the issue being resolved.

Nothing else leaves the device. The app contains no third-party analytics SDKs, no advertising SDKs, and makes no other network calls.

Security

Data in transit is encrypted (TLS). Server-side access is governed by Firebase security rules on a least-privilege basis: only the senior's device can write its own alert queue, only paired family devices can access their own pairing records, and no client can read another user's data. Access is authenticated via anonymous Firebase authentication. On-device data sits in the app's private storage and is excluded from device backups.

Data retention and deletion

Your rights and withdrawing consent

Consent to family alerting is given by the senior at pairing and can be withdrawn at any time:

If you are in India, the Digital Personal Data Protection Act, 2023 also gives you the right to access a summary of the personal data we process, to have inaccurate data corrected, to have your data erased, and to an effective grievance process. You also have the right to nominate another person to exercise your data rights in the event of death or incapacity. To exercise any of these rights, contact blucodeworks@gmail.com.

Grievance Officer and complaints

Blu Codeworks has designated a Grievance Officer for Scam Rakshak, reachable at blucodeworks@gmail.com. We will acknowledge questions, grievances, and deletion requests within 7 days, and aim to resolve them within 30 days. If you are in India and are not satisfied with our response, you have the right to complain to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.

Payments

Family features are a paid subscription processed entirely by Google Play Billing. The app never sees or stores card or bank details.

Children

The app is intended for adults (seniors and their adult family members) and is not directed at children.

Changes and contact

Material changes to this policy will be reflected in the app listing and at this URL. Questions or deletion requests: blucodeworks@gmail.com.

Developer: Blu Codeworks, 3/42 Henry Street, Ravenswood, Tasmania 7250, Australia. WhatsApp is a trademark of Meta. Scam Rakshak is an independent app, not affiliated with, endorsed by, or sponsored by Meta or WhatsApp.