Security and privacy
What a guardian can see, what they can never see, and how the underlying account security works — all of this describes the guardian dashboard as it is actually built today.
What a guardian can see
- Risk level (low, medium, high, or critical)
- Category (SMS, call, UPI, app, or website)
- The time an alert happened
- Whether a device is currently protected
What a guardian can never see
- Message text
- Call audio
- One-time passwords or codes
- Passwords
- Payment amounts or payees
- Phone numbers
Consent, not just an account
A protected family member must explicitly grant access before a guardian sees anything about them, and can withdraw that consent at any time. Withdrawing consent hides that family member’s data from the guardian on the next request — it is not a delayed or best-effort change.
Account and session security
Sign-in uses a one-time email code, not a password. Sessions are stored as a random token in the browser; only its cryptographic hash is ever stored on the server. A guardian can export their own account data or delete their account at any time — deleting an account revokes all of that guardian’s access without touching the protected family member’s own data.
Where data lives
The guardian dashboard and its database are hosted in the Mumbai (India) region.