No ID No Entry Emblem NoIDNoENTRY ← Return to Main Shield
SEC-PRIVACY-2026-V1 • VERSION 2.3

Global Data Privacy Policy

Effective Date: September 2026 • Jurisdictions: EU (GDPR), US (CCPA/CPRA, COPPA), UK, Philippines (RA 10173 DPA), Singapore (PDPA), Australia (Privacy Act 1988)

🔒 HARD RULE 1: ZERO-CLOUD LEAKAGE CONSTITUTION

"Security software should protect your privacy, not harvest your life." Unlike cloud-reliant anti-spam or monitoring tools that upload your personal contacts, SMS message text, call logs, and browsing URLs to remote cloud databases for data mining, No ID No Entry operates on a strict 100% Zero-Cloud Egress architecture. All scans, regex heuristics, and blocklist comparisons execute locally on your physical device.

1. The Zero-Egress Guarantee: What Stays 100% On-Device

The following personal data categories are processed strictly inside volatile device RAM or within your local encrypted SQLite database:

Data Category Egress & Processing Policy
Personal Contacts & Address Book ✅ 0 Bytes Transmitted. Processed locally in hardware TEE. Never uploaded.
Full SMS Text Contents & OTPs ✅ 0 Bytes Transmitted. Evaluated in-memory in sub-50ms intervals. Clean texts are discarded instantly.
Voice Call Logs & Caller Metadata ✅ 0 Bytes Transmitted. Screened locally. Missed calls are protected and cannot be reported.
Personal Browsing History & URLs ✅ 0 Bytes Transmitted. Inspected on-device via local DNS sinkhole. Zero web activity logs leave your phone.
Device Hardware Identifiers (IMEI, IMSI, MAC) ✅ 0 Bytes Collected. We do not read or record persistent hardware serials.
Guardian Master PIN / Password ✅ 0 Bytes Uploaded. Hashed in local hardware TEE (Android Keystore / iOS Secure Enclave). We have zero access.
Child Identity & GPS Location ✅ 0 GPS Tracking. Device pairing uses ephemeral 6-digit PINs; zero child PII is collected or tracked.

2. What We Synchronize Globally (Anonymous Collective Defense)

The Application connects to our external backend (Supabase / Cloudflare R2 Edge CDN) exclusively for periodic differential threat database updates:

No User Identifiers: Telemetry submissions do NOT include user accounts, phone numbers, IP addresses, or device IDs.
10-User Consensus: Voice scam numbers are only promoted to the global delta database after 10 unique, verified devices from distinct subnets confirm the scam.

3. Elevated Operating System Permissions Specification

We request elevated permissions exclusively to enforce on-device defense, adhering strictly to Google Play and Apple developer guidelines:

3.1 Accessibility Service (BIND_ACCESSIBILITY_SERVICE)

Purpose: Detects when prohibited online casino websites or web cashiers (e.g. payments.gcash.com, checkout.paymaya.com, dragonpay.ph) are opened in Google Chrome, disabling deposit buttons ("Pay with GCash") and closing cashier tabs to stop gambling recharges.
Guarantee: The service inspects window titles and URL bars in real-time. It never reads passwords, credit card numbers, personal chat messages, or keystrokes, and stores zero browsing logs.

3.2 Local VpnService (BIND_VPN_SERVICE)

Purpose: Creates a virtual on-device DNS filter. When a web browser or app requests an address matching known online casinos or violent extremist forums, the request is sinkholed to 0.0.0.0.
Guarantee: Internet traffic is never forwarded to remote VPN servers or third-party proxies. Lookups are 100% local.

3.3 Call Screening Service (BIND_SCREENING_SERVICE)

Purpose: Allows the operating system to query our local database in sub-50ms when an unknown call rings, instantly dropping verified robocalls and scam syndicates.
Guarantee: Missed calls are protected and cannot be reported. Call logs remain strictly inside the local SQLite database.

3.4 SMS Receiver (RECEIVE_SMS)

Purpose: Inspects incoming SMS alerts for urgent bank phishing links and credential harvesting forms.
Guarantee: SMS messages are evaluated locally. Clean messages and private conversations are never stored or uploaded.

4. Children's Privacy Protection (COPPA, GDPR-K, PH RA 10173)

We enforce extreme safeguards to protect minor users:

5. Multi-Jurisdictional Legal Compliance

5.1 European Union (GDPR - Regulation EU 2016/679)

Data Minimization (Art. 5(1)(c)): Zero PII collection by architectural design.
Right to Erasure (Art. 17): Uninstalling the Application permanently shreds the on-device encrypted database.
No International Transfers: Personal data never crosses borders because it never leaves your physical phone.

5.2 California Consumer Privacy Act (CCPA / CPRA)

Zero Sale / Sharing of Personal Information: We do NOT sell, rent, or share personal data to third parties, data brokers, or advertising networks.

5.3 Philippines Data Privacy Act of 2012 (RA 10173)

Fully complies with National Privacy Commission (NPC) circulars on fair collection and lawful security operations.

6. Whistleblower & Victim Privacy Vault

When users flag cross-border robocalls, predatory lending apps, or extortion syndicates:

7. Contact Our Data Protection Officer (DPO)

For data privacy inquiries, formal audits, or regulatory compliance requests:

Data Protection Officer: harryjames.nine@gmail.com
Privacy Compliance & Direct Support: harryjames.nine@gmail.com