1. Who we are
Securely is operated by AE TECHNOLOGIES GROUP LTD, a company registered in England and Wales under company number 17419062, with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. We operate the website securelyapp.co.uk and the Securely Android app, and provide AI-assisted scam, phishing and fraud detection tools, a Scam Prevention Academy, Latest Scam Alerts, Family Pack and Emergency Protection features.
AE TECHNOLOGIES GROUP LTD is the data controller for personal data processed through the service. ICO registration number: ZC241648.
For privacy and data-protection enquiries, contact privacy@securelyapp.co.uk. Written correspondence can be sent to AE TECHNOLOGIES GROUP LTD, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
2. Information we collect
- Account data: email address, display name, preferred language, authentication tokens, profile type (e.g. Adult, Teen, Grandparent, Vulnerable Adult).
- Scan content: messages, links, voice transcripts, screenshots, documents, and OCR-extracted text you submit to any scanner or scam checker. These submissions often contain personal information about other people (for example a sender's name, phone number, email address, photograph or listing details). Securely processes that information only to produce your result and to protect you from fraud; please submit no more than is necessary for the check you are making.
- Derived data: risk scores, AI classifications, scan history, Security Awareness Score, alerts, case notes, timeline events.
- Family data: family memberships, invitations, guardian assignments, trusted contacts, family alerts, shared cases, family activity timeline, monthly family reports. Invite links can be copied or opened in your own messaging apps (for example your device's SMS or WhatsApp app) — Securely itself does not send SMS or WhatsApp messages on your behalf.
- Emergency data: emergency cases, action checklist progress, emergency timeline events.
- Learning & content data: which Scam Prevention Academy lessons you start or complete, which scam alerts or knowledge-hub articles you view, bookmark or save, and which categories you follow. Used only to personalise recommendations and progress tracking inside Securely.
- Notification data: the in-app notifications and emails delivered to you, whether they were opened, and your notification preferences.
- Accessibility settings: your text-size, high-contrast, and reduced-motion preferences, stored so they persist across your devices.
- Subscription & billing data: plan (Free / Founding / Premium / Family), status, provider (Stripe on the web, RevenueCat + Google Play Billing in the Android app), subscription and purchase identifiers, and renewal/cancellation status. Full card details are held only by the payment provider — we receive references and status, never your card number.
- Technical & diagnostic data: information generated when your device connects to our hosting and database infrastructure (such as IP address, browser/device type and request logs) and error diagnostics used to fix faults. In the Android app we use Google Firebase Analytics (Google Analytics for Firebase) to measure app installs/first opens, account creation and subscription events such as trial starts and purchases. This is described in section 13.
- Legal acceptance record (including your IP address): when you accept our Terms, Privacy Policy and related legal agreements, we store a record of that acceptance against your profile. This record includes the date and time of acceptance, the version of the legal terms you accepted, the app version used, and the IP address your device was using at the moment you accepted. This is stored deliberately and kept for as long as your account exists — it is not transient infrastructure logging. See section 2a below.
- Local storage: see our Cookie Policy.
2a. Your IP address and the legal acceptance record
We want to be explicit about this because it goes beyond ordinary server logging. When you accept the Terms & Conditions, Privacy Policy and related legal agreements, Securely writes a legal acceptance record to your profile in our database. That record stores the IP address your device was using at the moment of acceptance, alongside the acceptance timestamp, the version identifier of the legal terms accepted, and the app version.
- Why we store it: to hold reliable evidence of when, and to which version, you agreed to the contract between you and Securely. This protects both sides if there is ever a dispute about what terms applied to your account.
- Lawful basis: our legitimate interests in maintaining an accurate, auditable record of contract formation, and compliance with our legal and consumer-law obligations. It is not used for marketing, profiling, advertising or location tracking.
- What we do not do with it: we do not use your IP address to determine or store your geographic location, build a behavioural profile, or share it with advertisers. It is not sold, and it is not passed to OpenAI, Stripe, RevenueCat or Google.
- Who can see it: it is not visible to other users, including family organisers or guardians. Access is limited to authorised staff of AE TECHNOLOGIES GROUP LTD and to privileged server code processing a legal or support request.
- Retention: it is retained for as long as your account exists, because the agreement it evidences remains in force for that period.
- Deletion: it is stored on your profile record, so it is deleted when you delete your Securely account. Encrypted infrastructure backups may retain a copy for up to 30 days before being overwritten. A separate account-deletion audit entry is kept afterwards as described in our Data Retention & Deletion Policy; that entry does not contain your IP address.
If you re-accept an updated version of our legal terms, a new acceptance record replaces the previous one, capturing the IP address in use at that time.
3. How we use your information
- Provide scam, phishing, and fraud detection results across all scanners and scam checkers.
- Generate AI risk scores, alerts, and PDF reports.
- Maintain your account, history, family memberships, and emergency cases.
- Deliver family-level features: family alerts, shared cases, monthly reports, Family Activity Timeline, Guardian Mode, elderly/child/vulnerable adult protection.
- Curate and publish the Scam Prevention Academy and Latest Scam Alerts, and personalise which lessons, alerts and articles we recommend to you based on your scan history and interests.
- Send in-app notifications and transactional emails covering scam alerts, security tips, product updates, subscription notifications and account changes.
- Apply your accessibility preferences (text size, high contrast, reduced motion) across the app.
- Improve detection accuracy, alert quality and app reliability using de-identified and aggregated signals and error diagnostics.
- Respond to support requests and security reports.
- Comply with legal obligations and protect against abuse.
4. Lawful bases (UK GDPR)
- Contract — to provide the service you signed up for, including subscription billing and delivery of core scam-protection features.
- Legitimate interests — improving detection, keeping scam alerts and articles up to date, personalising in-app recommendations, preventing abuse, and securing the platform.
- Consent (or another appropriate lawful basis) — optional marketing emails, family invitations, and sharing safety information about another person within a Family Pack. You can withdraw consent at any time from Preferences or by using the unsubscribe link in any optional email.
- Legal obligation — accounting records, tax records, and lawful requests from authorities.
5. AI features and how your data is handled
Securely uses artificial intelligence across the Message Scanner, Voice Scam Detection, Link Checker, every Scam Checker (Marketplace, Ticket, Seller Profile Risk, Identity Verification, Rental, Job, Romance and any future checker), OCR of screenshots and documents, alert generation, case summarisation, and recommended-lesson selection.
- Content you submit to a scanner, checker, OCR or case-summary feature — including message text, link details, transcripts, uploaded screenshots and documents, and text extracted from them — is transmitted over TLS to OpenAI, which processes it through its API to produce your result.
- OpenAI acts as our processor for these requests. Under the OpenAI API data terms in force at the time of writing, content submitted through the API is not used by OpenAI to train its models by default, and API content may be retained for a limited period for abuse and misuse monitoring before deletion. We do not control OpenAI's own terms and they may change; you should also review OpenAI's published API data-usage policies.
- We do not sell your submissions, and we do not use them to train our own models. Securely does not train a proprietary model — it combines large-language-model analysis with our own scam-detection logic and pattern rules.
- Sensitive details (bank passwords, PINs, one-time codes) should be redacted before submission wherever possible — Securely will never ask you for them.
- How to interpret AI outputs is explained in our AI Disclaimer.
- A small number of secondary features — automated triage of feedback you send us, and drafting of our own educational content — are processed through the Lovable AI Gateway using Google Gemini models. Your scans, checks and uploaded evidence are not sent to these models.
6. Safety education, scam alerts and articles
The Scam Prevention Academy, Latest Scam Alerts feed and knowledge-hub articles are produced by Securely and are updated as new threats and techniques are identified. Each alert or article is tagged with categories (for example Banking & Payment, AI Voice Cloning, Fake Delivery, Marketplace, Romance, Job, Identity Theft). Alerts and articles are written and published by Securely from information available to us, including public sources such as official warnings and consumer-protection publications; producing them does not use your personal data.
We record which lessons you start or complete, which alerts and articles you view, bookmark, or save, and which categories you follow. This is used only to show you relevant content inside Securely and to keep your learning progress. It is not sold, and it is not used for third-party advertising.
Scam alerts describe threats we are aware of at the time of publication. They are informational and do not cover every scam — see the AI Disclaimer.
7. Notifications
Securely currently delivers notifications in two ways: inside the app (the bell icon and Notifications page, on web and Android) and by email. We do not currently send Android push notifications; if we introduce them in future we will update this policy and the Notification Policy first.
The main categories of notification are:
- Scam alerts — new or trending scams we think you should know about.
- Security updates and safety tips.
- Product updates — new Securely features and improvements.
- Subscription notifications — trial expiry, renewal, payment issues, plan changes.
- Family and emergency notifications — where you are on a Family Pack, including guardian and critical-alert escalation.
You can customise categories from Preferences, and every optional email includes an unsubscribe link. Turning off notifications does not affect your subscription or account.
8. Accessibility settings
Securely lets you personalise text size, contrast, reduced motion, and other accessibility options. These preferences are stored against your account so they follow you between devices, and they are used only to render the app in a way that suits you. See our Accessibility Statement.
9. Subscriptions, payments and provider data
Securely supports two payment routes depending on where you subscribed:
- Stripe is the sole payment processor for subscriptions purchased through the Securely website. Stripe collects and stores your payment card details; we receive a customer reference, subscription status and invoice metadata.
- Google Play Billing processes every subscription purchased inside the Securely Android app, as required by Google Play's Payments Policy. Google collects the payment and holds the payment method on your Google account.
- RevenueCat is our subscription management platform for the Android app. It receives Google Play purchase events and tells Securely which entitlement (Founding / Premium / Family) is active. We share your Securely user identifier and subscription identifiers with RevenueCat for this purpose.
Subscription state is stored in Securely as plan, status and provider references only. We do not store full card numbers, CVCs or bank credentials. Detail on plans, renewals, cancellation and refunds is in our Subscription & Billing Policy.
10. Family data & shared visibility
Within a Family Pack, certain data is visible to other family participants as described in our Family Pack Terms — for example, family alerts to the organiser and guardians, shared cases to case participants, and aggregated family-level metrics. Securely does not surface the raw content of a member's individual scans to other members unless the member adds that scan to a shared case or it has triggered a family alert. Family visibility is processed on the basis of the member's informed consent when joining, or another appropriate lawful basis (for example the legitimate interests of safeguarding a family member, or a parent or guardian acting for a child or vulnerable adult where they have authority to do so).
11. Children and vulnerable adults
Securely is not directed at children under 13. Users aged 13–17 may use Securely only within a Family Pack established by a parent or legal guardian. Family Pack also supports protection profiles for elderly users and vulnerable adults. Full safeguards are in our Child & Vulnerable Adult Protection Policy, written in line with the UK Children's Code. We do not collect dates of birth and we do not technically verify age — these are requirements you accept when you create an account or set up a Family Pack.
13. Product improvement and diagnostics
Securely does not build advertising profiles or sell usage data. In the Android app we use Google Firebase Analytics (Google Analytics for Firebase) to measure a small set of events: app install/first open, onboarding steps, language and country selection, account-creation progress, account creation, and subscription lifecycle events (free-trial start, trial conversion, purchase, renewal, cancellation and expiry) which are supplied to Google Analytics by our subscription processor RevenueCat. Firebase collects a device-level app instance identifier and, where your device settings allow it, the Android advertising identifier; you can reset or delete the advertising identifier in your device settings. We use this data to understand where people leave onboarding and how many people install Securely, create an account and start a subscription, including measuring the effectiveness of our own advertising for the app. No email address, name, scan content, screenshots, messages or checker results are ever sent to Firebase. The web version of Securely does not currently run any third-party analytics. We also use aggregated in-app signals (such as feature usage counts stored in our own database) and technical error diagnostics from our hosting and database providers to improve detection quality, reliability and performance. See also our Cookie Policy.
14. International transfers
Some providers are located outside the UK (including in the United States). Where this is the case, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision, as offered by that provider, to ensure equivalent protection. Where you are located in the EEA, equivalent EU GDPR safeguards apply.
Securely is operated from the United Kingdom and personal data is stored and processed in our providers' UK, EU and US regions regardless of where you use the app. If you use Securely outside the UK and EEA — for example in India — your data is transferred to and handled under this policy and UK data protection law, in addition to any mandatory rights you have under local law. You can exercise the rights in Section 17 wherever you are located.
15. Data security
Data is encrypted in transit using TLS, and our infrastructure providers apply encryption at rest to the databases and file storage holding your data. Access is restricted and logged. Row-level security controls what any signed-in user can access at the database layer. Shared reports support expiring links and password protection, with access logging. See our Security page for the full controls. We will never ask for your banking passwords, PINs, or one-time codes.
16. Data retention
Retention periods for scans, OCR text, uploaded evidence, reports, cases, alerts, family activity, notifications, support messages, deletion audit records and billing records are set out in our Data Retention & Deletion Policy. You can delete most items from your dashboard at any time, or close your account from Account Settings.
Deleting your account is automated and complete. Before your account records are removed, Securely erases every screenshot, photo and document you uploaded from our secure file storage — including any upload whose database record is missing — and then deletes the associated database rows, your profile, and your authentication record. The erase step is scoped to your own private storage folder, so it cannot affect another user’s files. Encrypted infrastructure backups may retain copies for up to 30 days before being overwritten.
17. Your rights (UK GDPR / EU GDPR)
You have the right to access, correct, delete, restrict, port, and object to processing of your personal data, and to withdraw consent at any time. Exercise these rights by emailing privacy@securelyapp.co.uk — you do not need the Android app to make a request. UK users may lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk. EEA users may complain to their local supervisory authority.
18. Automated decision-making
Securely generates AI-driven risk scores and classifications. These are decision-support tools, not legal decisions, and do not produce legal or similarly significant effects on you within the meaning of UK GDPR Article 22. You can challenge any classification by submitting feedback or contacting support.
19. Account deletion
You may request deletion of your Securely account at any time from Account Settings on the website or in the app, or by emailing privacy@securelyapp.co.uk. Deletion removes your login, profile, scans, alerts, feedback, family membership, support messages and subscription record, and cancels an active website (Stripe) subscription so it cannot renew. Google Play subscriptions must be cancelled in the Play Store. A limited deletion audit record and legally required billing records are retained — see our Account Deletion Policy for exactly what is kept and why.
20. Changes
We may update this policy. Material changes will be notified by email or in-app notice, and where our legal-acceptance system requires it you will be asked to accept the updated terms.
21. Contact
- Privacy & GDPR: privacy@securelyapp.co.uk
- Support: support@securelyapp.co.uk
- Billing: billing@securelyapp.co.uk
- Security: security@securelyapp.co.uk
Questions? Reach us at privacy@securelyapp.co.uk or support@securelyapp.co.uk.
