1. Overview
Securely is operated by AE TECHNOLOGIES GROUP LTD, a company registered in England and Wales under company number 17419062 (ICO registration number: ZC241648), with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. To run the service we rely on a small number of third-party providers. This page lists the providers actually in use, what each processes, and why. It supplements Section 12 of our Privacy Policy. We do not sell personal data, and we do not currently use a third-party product-analytics or advertising provider. Each provider below acts on our instructions and is bound by data-processing terms; none is permitted to use your data for its own purposes. Because Google Play’s Data Safety section treats any transfer to a third party as “sharing” — including transfers to a processor — the transfers described here are what our Play Store listing declares as shared data.
2. Current providers
| Provider | Purpose | Data processed |
|---|---|---|
| Supabase | Database, authentication, file storage, realtime | Account data, scan history, uploaded evidence, cases, alerts, preferences |
| Lovable | Application hosting, build and deployment of the web app and server functions | Request traffic and infrastructure/diagnostic logs |
| OpenAI | AI analysis of submitted content (scanners, scam checkers, OCR, case summaries) | Message text, link details, transcripts, uploaded screenshots/documents and extracted text |
| Lovable AI Gateway (Google Gemini models) | Automated triage of user feedback; drafting Securely's own educational content | Feedback text you submit, and our own draft article content |
| Stripe | Website subscription payments, invoicing and receipts | Email address, payment method (held by Stripe), subscription and invoice metadata |
| Google Play Billing / Google Play services | Android app distribution and in-app subscription payments | Google account payment data (held by Google), purchase and order identifiers |
| Google Firebase Analytics (Google Analytics for Firebase) | Android app analytics: install/first open, account creation and subscription lifecycle measurement | Firebase app instance identifier, Android advertising identifier (where device settings allow), app events; subscription events are supplied to Google Analytics via RevenueCat |
| RevenueCat | Android subscription entitlement management | Securely user identifier, purchase and subscription identifiers, entitlement status |
| Lovable (managed email service) | Transactional and opted-in email, unsubscribe and bounce handling | Email address, message content, delivery and open status |
| Google Fonts | Web font delivery for securelyapp.co.uk | Your IP address and user-agent, sent by your browser when a page loads fonts |
3. A note on AI processing
Content you submit to a scanner, checker, OCR or case-summary feature is sent to OpenAI's API over TLS so it can be analysed and a result returned. Under the OpenAI API data terms in force at the time of writing, API content is not used to train OpenAI's models by default and may be retained for a limited period for abuse monitoring before deletion. Separately, feedback you send us and our own draft educational content are processed through the Lovable AI Gateway using Google Gemini models; your scans, checks and uploaded evidence are not sent to those models. These providers set their own terms, which may change. Avoid pasting passwords, PINs or one-time codes into any scan.
3a. How these providers map to the Google Play “Data shared” label
- OpenAI — receives the content you submit for analysis: message and listing text, links, call transcripts, case notes, and uploaded screenshots, photos and documents. Declared on Play as sharing of “Other in-app messages”, “Photos” and “Files and docs”.
- RevenueCat and Stripe — receive your Securely user identifier and subscription/purchase identifiers so your entitlement matches your account. Declared on Play as sharing of “User IDs”. Stripe also receives your email address for receipts and invoicing.
- Supabase and Lovable — host the database, storage and application. They hold data on our behalf as infrastructure rather than receiving an onward transfer for their own use.
- Payment card details — never pass through Securely. Stripe and Google Play Billing collect them directly on their own checkout surfaces, so “Payment info” is declared as not collected by us.
- Your stored IP address — the IP captured in your legal acceptance record stays in our own database and is not transferred to OpenAI, Stripe, RevenueCat or Google.
“Shared” in the Play sense does not mean sold, rented or traded. Securely does none of those things.
4. International transfers
Several providers are based outside the UK, including in the United States. Where personal data is transferred internationally we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision, as offered by the provider.
5. Changes to this list
We will update this page when we add or remove a provider that processes personal data. Questions: privacy@securelyapp.co.uk.
Questions? Reach us at privacy@securelyapp.co.uk or support@securelyapp.co.uk.
