1. Who we are
TipOffly is a service of [Company legal name], a company incorporated in India (CIN: [CIN]) with its registered office at [registered address] ("TipOffly", "we", "us"). For the purposes of the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), we are the Data Fiduciary for the personal data described in this policy.
This policy applies to the TipOffly mobile apps, the TipOffly website and the family web console (together, the "Services").
2. What we collect
| Data | Why we need it |
|---|---|
| Mobile number and name | To create your account, sign you in with a one-time code and link family members. |
| Email address (optional) | For receipts, account recovery and replies to your support requests. |
| Family links and roles | To know who is a guardian, child or elder in your family group, and what each person has agreed to share. |
| Safety alerts | The type of risk detected (for example "likely scam call"), the time and the device. Not the content of the message or call. |
| Location (only if switched on) | For arrival alerts, lost-phone location and check-ins, shared only with the family members you choose. |
| Payment records | Plan, amount, date and invoice details. Card and UPI details are handled by our payment partner, not stored by us. |
| Device and app data | App version, device model, operating system and crash reports, to keep the app working and secure. |
| Consent records | What you agreed to and when, as required by the DPDP Act. |
| Scam reports you choose to send us | Only the reported number, UPI ID, link or SMS sender and the scam type, never who sent it. Two staff review it before it can warn other phones. See "Also tell TipOffly" in section 3. |
| Your 18+ confirmation | When you sign in, or before you accept a guardian role, you confirm that you are 18 or older. We keep that you confirmed it and when, so we know you can be a guardian and give consent for a child. If a date of birth under 18 is on record for you, we refuse the confirmation and flag the account for a check. |
| A child's date of birth | When a guardian adds a child, the guardian gives the child's date of birth. We use it only to work out the child's age group, so the right protections and consent rules apply, and to stop a child's profile from being confirmed as an adult. It is stored encrypted. |
3. What stays on your phone
Scam checks run on your device. The text of your messages, your call audio, your photos, your contacts and your browsing history are analysed on the phone and are not uploaded to our servers.
When a risk is found, only a short alert (the risk type, time and device) is sent to the family members who have agreed to receive it. Alerts between family members are end-to-end encrypted, so our servers relay them without being able to read them.
Reporting a scam. When you tap Report in the app, the check is marked as reported on your phone only, and the app shows the official places to report it: the 1930 helpline, cybercrime.gov.in and Chakshu on Sanchar Saathi. If you report through one of those services, it handles your report under its own terms. Nothing about your report is sent to us unless you turn on "Also tell TipOffly" for that report.
Also tell TipOffly (optional, for each report). If you turn it on, we receive only the phone number, UPI ID, website link or SMS sender you reported and the scam type you picked. Anything after a "?" in a link, your notes and the money you lost stay on your phone. We do not record who sent the report: it is not linked to your account, your phone or your number. To stop misuse we keep a daily count of reports for each account and each phone, as scrambled codes that do not include what was reported, and delete it within 2 days. Two TipOffly staff review a reported value, and only if both approve can it be used to warn other phones.
Screenshots you check. When you share a screenshot to the app from another app, or pick one inside the app, its text is read on your phone, in English or Hindi. The picture is not saved or uploaded, and its text never leaves your phone. Google Play services, which provides the text reader and the QR code scanner, may record that the reader or scanner was used, as it does for its other features; that record has no picture or text. If nothing suspicious is found, the app's check history keeps only "Screenshot checked" and the time, not the text, whichever way the screenshot reached the app. If a warning sign is found, the history keeps the start of the text (at most 280 characters) so you can look back at the warning, and deletes it after 30 days. A QR code you pick from your gallery is read on your phone in the same way, and the picture is not kept.
Shop QR history (optional, off by default). The shop QR check looks for a scammer's QR sticker pasted over a shop's own. If you turn on "Remember shops on this phone", the app keeps, for each shop whose QR showed no warning signs, the shop's name and the UPI ID in its QR, so a different QR at the same shop stands out next time. It is kept on your phone only and never uploaded or shared. At most 100 shops are kept, each deleted 90 days after you last checked it. You can clear it with Forget in the app, switching the setting off clears it too, and it is included when you download a copy of your data.
Anti-theft (optional). If you set it up, these stay on your phone: your trusted contacts' numbers, a scrambled form of your command PIN, a short log of anti-theft events (only the last 30), your lost-mode message and the saved locations described under "Last location". None of it is sent to us.
Intruder photo (optional, off by default). If you turn it on, the app asks for the camera and, after 2 wrong screen PINs in a row, takes one photo with the front camera, at most once every 5 minutes. The person in the photo is not told. Intruder photos stay on your phone, are never uploaded or shared, are deleted after 30 days (only the 20 newest are kept), and you can see and delete them in the app at any time.
Lost mode. When a trusted contact texts the LOCK command with your PIN, the phone locks and its lock screen shows your lost-mode message and the number you chose for it, so whoever finds the phone can return it. Your trusted contacts' numbers are never shown. A copy of what the lock screen shows is kept on the phone so the message survives a restart, and it is removed when lost mode ends with the STOP command or in the app.
LOCATE. When a trusted contact texts the LOCATE command with your PIN, the app replies by SMS only to that saved trusted number, never to any other number the message claims to come from. The reply has the phone's location as coordinates to 5 decimal places (about 1 metre) in a map link, and how old the reading is, if Android allows location at that moment. The reply is not sent to us. The app keeps the location it found as the "last place seen" (see "Last location"). The SMS goes through your mobile operator like any other text.
Last location (part of anti-theft). While anti-theft is on, the app keeps up to two places on your phone: the last place it saw the phone (noted while the app is open and Android allows location, and when it answers LOCATE) and the place it kept when the battery ran low or the phone was switching off. Each is stored as coordinates rounded to 4 decimal places (about 11 metres), with the time, the battery level and the reason. They are deleted 30 days after they were kept, when you tap "Forget saved locations", or when you turn anti-theft off. They are never sent to us.
Texting the last location (optional, off by default). If you turn on "Text it to my trusted contacts", the app sends that place by SMS from your phone to your trusted contacts' numbers, as a map link with how old the reading is, when the battery runs low or the phone is switching off, at most once every 30 minutes. An ordinary low battery counts too, so your contacts may get a text when nothing is wrong. The SMS goes through your mobile operator like any other text and is not sent to us.
Motion alarms (optional, off until you arm them). While you have armed the pickpocket or charger alarm, the app reads the phone's motion sensor (only while the phone is locked) and whether the charger is plugged in, to know when to sound the alarm. Nothing is read when the alarms aren't armed. So the alarms come back if Android stops the app, it keeps on the phone, until the alarms are turned off: which alarms are armed, when arming started and ends, whether an alarm is going off, and how many wrong PINs were typed. It also adds a line to the anti-theft log when an alarm rings or stops. Nothing is sent to us or to anyone else.
Notification access (optional). If you turn it on, the app reads new notifications on your phone from chat apps (such as WhatsApp, Telegram, Messenger and Instagram), SMS apps, and payment and bank apps (such as Google Pay, PhonePe, Paytm, BHIM, CRED and bank apps, only to spot money requests), and it notices when a screen-sharing app such as AnyDesk or TeamViewer is running. This is checked on the phone and never uploaded. Payment and screen-sharing warnings can be switched off separately in the app.
Call screening (optional). If you turn it on, the app checks the number of an incoming call on your phone and warns you when it matches a reported scam number. It never records or listens to your calls.
After-call prompt (optional, off by default). A separate setting lets the app ask "Was this call suspicious?" when an answered call from a number you don't have saved ends, with buttons to check or report the number. To know when the call ends, the app asks for the phone permission and reads only whether the phone is ringing, on a call or idle. It does not read your call log or who you talk to. The prompt is never shown during quiet hours, and at most once per number every 30 minutes. The number is checked on the phone and nothing is sent to us. The prompt stays in the app's inbox on your phone for 30 days.
4. How we use personal data
- To provide the Services you asked for, including scam warnings, family alerts, location features and anti-theft tools.
- To keep accounts secure, prevent fraud and abuse, and fix faults.
- To process payments, issue GST invoices and handle refunds.
- To answer support requests and complaints.
- To improve our scam detection using reported numbers, links and anonymous, aggregated statistics.
- To meet legal obligations, such as tax records, lawful requests from authorities and cyber-security incident reporting.
We do not sell personal data. We do not use it for third-party advertising, and we do not build advertising profiles of anyone, least of all children.
5. Consent and legal basis
We process personal data on the basis of your consent, given through a clear notice in the app before each feature is switched on, or for legitimate uses permitted by the DPDP Act, such as complying with the law or responding to a medical emergency.
You can withdraw consent at any time from Settings → Privacy in the app. Withdrawing is as easy as giving consent. It stops the related processing from that point on, but does not affect processing done before, and some features may stop working.
You may also manage your consent through a registered Consent Manager where this becomes available under the DPDP Act.
6. Children and family accounts
Family features for anyone under 18 are switched on only after we obtain verifiable consent from their parent or lawful guardian, as required by Section 9 of the DPDP Act. We verify the guardian's identity using [verification method].
- Guardians see safety alerts by category (for example "possible stranger contact"). They cannot read the child's messages, chats or photos.
- The child's app always shows what is shared with the family.
- Daily steps are optional and the child's own choice. They are shared only if a guardian with an active safety-insights permission asks and the child says yes on their phone, which needs Android's Physical activity permission. The child's phone sends one step total per day for the last 7 days, end to end encrypted, so we can't read it. It never sends when or where the child walked. The totals are kept on the phones for 30 days and deleted when the child stops sharing, when the guardian's permission ends, or where step sharing is switched off for the country. Steps stay off where the country can't be confirmed.
- We do not use children's data for advertising or for any tracking beyond the safety features the guardian has switched on.
- Adult family members, including elders, choose for themselves what they share, and can change it at any time.
You must only add a person to your family group if you are their parent or lawful guardian, or if they are an adult who has agreed to join.
We have also written a short privacy notice for kids and teens in plain words, which children can read for themselves.
8. Where data is stored
Personal data held on our servers is stored in India. If we ever need to transfer data outside India, we will do so only to countries not restricted by the Government of India under the DPDP Act, and with safeguards in place.
9. How long we keep it
| Data | Kept for |
|---|---|
| Location history | 7 days, then deleted automatically. |
| Intruder photos (on your phone only) | 30 days, then deleted automatically. At most the 20 newest are kept. |
| Check history and in-app inbox (on your phone only) | 30 days, then deleted automatically. |
| Shop QR history, if you turn it on (on your phone only) | 90 days after you last checked each shop, then deleted automatically. At most 100 shops are kept. Cleared at once with Forget or by switching it off. |
| Anti-theft setup and event log (on your phone only) | Until you change or remove them in the app, or delete the app's data. Only the last 30 events are kept. |
| Your 18+ confirmation | While your account is active, then deleted with the account. Where a consent record must be kept as proof, it is kept for as long as the law requires. |
| A child's date of birth | While the child's profile exists. Deleted within [30] days of the guardian removing the profile or closing the account. |
| Safety alert logs | 30 days, then deleted automatically. |
| Scam reports sent to TipOffly (not linked to you) | Until two staff decide on the reported value, then up to 13 months. An approved value stays in our scam list until it is removed. The daily counts used to stop misuse are deleted within 2 days. |
| A child's daily step totals (on the child's and the guardian's phones only; we can't read them in transit) | 30 days, then deleted automatically. Deleted at once when the child stops sharing, when the guardian's permission ends, or where step sharing is switched off for the country. |
| Account and family details | While your account is active. Deleted within [30] days of closing your account. |
| Payment and invoice records | As long as tax law requires (currently up to 8 years). |
| Security logs | As long as required by law, including CERT-In directions. |
When we no longer need personal data for the purpose it was collected for, or you withdraw consent, we delete it unless the law requires us to keep it.
10. Security
We use reasonable security practices, including end-to-end encryption for family alerts, encryption in transit and at rest, access controls with multi-factor authentication for staff, and regular security testing.
If a personal data breach occurs, we will inform the Data Protection Board of India and the people affected, as required by the DPDP Act, and report cyber-security incidents to CERT-In within the required time.
Found a security weakness in TipOffly? Please tell us privately: see Report a security issue.
11. Your rights
Under the DPDP Act you have the right to:
- Access a summary of the personal data we process about you and how we use it.
- Correct, complete or update your personal data.
- Erase your personal data, unless we must keep it by law.
- Withdraw consent at any time.
- Nominate someone to exercise your rights if you die or are unable to.
- Seek redress for complaints, first through our Grievance Officer and then with the Data Protection Board of India.
Most of these can be done directly in the app under Settings → Privacy. You can also write to privacy@tipoffly.com. We will reply within [the time prescribed under the DPDP Rules].
13. Grievance Officer
If you have a question or complaint about how we handle personal data, contact our Grievance Officer, appointed under the DPDP Act, the Information Technology Act, 2000 and the Consumer Protection (E-Commerce) Rules, 2020:
[Name], Grievance Officer
[Company legal name], [registered address]
Email: grievance@tipoffly.com
Phone: [number], [working hours] IST
We acknowledge complaints within 48 hours and aim to resolve them within [the time prescribed by law, and no later than one month]. If you are not satisfied, you can complain to the Data Protection Board of India.
14. Changes to this policy
We will tell you in the app and by email before any significant change takes effect, and ask for fresh consent where the law requires it. The date at the top shows when this policy was last updated.