- We only ever see the URL being scanned — nothing else.
- We never collect your name, email, IP address, or any personal information.
- We never track your browsing history or build a profile of you.
- Popular trusted sites (Google, YouTube, Instagram, etc.) are recognised locally — no data is even sent to our servers for them.
- The only thing stored on your device is your preferred browser choice (Android app only).
- We do not sell, rent, or share your data with advertisers or any third party for commercial purposes.
1. Overview
WebShield.AI ("we", "us") is an AI-powered phishing detection platform available as a browser extension for desktop browsers and as an Android app. Both products share the same core privacy principle: we scan URLs to protect you, and we do nothing else with your data.
This Privacy Policy applies to both products and explains exactly what is transmitted when you use either of them, how it is used, and what we will never do with it.
By installing the Extension or the App you agree to the practices described here. You may uninstall either product at any time from your browser's extension manager or Android's app settings.
2. What Information Is Transmitted
When you visit a webpage (extension) or tap a link (app), only the URL is sent to our analysis backend. That is the complete extent of data transmission — and even that is skipped entirely for 100+ well-known trusted sites that are recognised locally.
| Data Type | Collected? | Notes |
|---|---|---|
| Page URL | YES | Sent to backend for phishing analysis only. Not logged or stored after analysis. |
| URLs of popular trusted sites | NO | Google, YouTube, Instagram, Amazon and 100+ sites are matched locally — never sent to the backend. |
| Page HTML / content | NO | The backend fetches the page itself; your device sends no page content. |
| Cookies / session tokens | NO | Never accessed or transmitted. |
| Browsing history | NO | Not read or stored by either product. |
| IP address | NO | Not logged or stored on the backend. |
| Name / email / account info | NO | Neither product has an account or registration system. |
| Scan result (verdict + score) | LOCAL ONLY | Extension: cached in browser session storage, cleared when tab closes. App: held in memory only for the current scan. |
| Preferred browser selection | LOCAL ONLY | Android app only. Stored in device SharedPreferences. Never leaves your device. |
3. How the URL Is Used
The URL is used exclusively to run a phishing detection pipeline:
- Rule-based analysis of the URL structure and pattern
- Reputation lookup against Google Safe Browsing and PhishTank databases
- Server-side content fetch and analysis of the target page
- Machine learning model inference based on URL-derived features
After analysis, the backend returns a verdict (SAFE, SUSPICIOUS, or PHISHING) and a risk score. The URL is not logged, stored in a database, or used for any other purpose.
4. Local Data Storage
Browser Extension
The Extension stores scan results locally using chrome.storage.session. This storage:
- Is scoped to your current browser session only
- Is cleared automatically when the tab is closed
- Never leaves your device
- Contains only: the URL scanned, the verdict, the risk score, and detected flags
No data is written to chrome.storage.local or localStorage.
Android App
The app stores one item locally using Android SharedPreferences:
- Preferred browser — the package name and display name of the browser you chose to open safe links in (e.g. Chrome, Firefox). This never leaves your device and can be changed or cleared at any time from within the app.
Scan results are held in memory only for the duration of the current scan and are discarded immediately after. No scan history is written to disk.
5. Third-Party Services
Our backend queries the following external threat intelligence services on your behalf. These services receive the URL being scanned — not your identity or any personal data.
- Google Safe Browsing API — Google's threat database. Governed by Google's Privacy Policy.
- PhishTank — Community-sourced phishing URL database. Governed by PhishTank's Privacy Policy.
6. Permissions Explained
Browser Extension
| Permission | Why It Is Needed |
|---|---|
webNavigation |
To detect when you finish loading a new page so a scan can begin |
activeTab |
To read the URL of the current tab for scanning |
tabs |
To update the extension badge and clear scan cache when a tab closes |
scripting |
To inject the phishing warning banner onto the page if a threat is detected |
storage |
To cache the scan result locally so repeat visits are instant |
<all_urls> |
To scan any website you visit, not just a pre-approved list |
Android App
| Permission | Why It Is Needed |
|---|---|
INTERNET |
To send the URL to our backend API for phishing analysis |
VIBRATE |
To provide haptic feedback when a phishing or suspicious link is detected |
SYSTEM_ALERT_WINDOW |
Required by the React Native framework for development overlay support |
ROLE_BROWSER (runtime) |
To set the app as your default browser so every link you tap is scanned before opening. This role is requested interactively and can be revoked at any time from Android Settings → Default apps. |
7. Default Browser Role (Android App)
When you set WebShield.AI as your default browser, Android routes all HTTP and HTTPS links you tap — from any app such as WhatsApp, SMS, or email — through WebShield.AI before they open. This allows the app to scan the URL first.
WebShield.AI does not function as a full web browser. It does not render web pages, store cookies, or maintain browsing sessions. After scanning, safe links are immediately forwarded to your chosen real browser (Chrome, Firefox, etc.).
8. Children's Privacy
WebShield.AI does not knowingly collect any personal information from anyone, including children under the age of 13. Neither the Extension nor the App contains account registration, forms, or any data submission from the user beyond the URL being scanned.
9. Changes to This Policy
If we make material changes to this Privacy Policy, we will update the "Last updated" date at the top of this page. For the Android app, significant changes will also be noted in the Play Store release notes. Continued use of either product after any changes constitutes acceptance of the updated policy.
10. Contact
If you have any questions or concerns about this Privacy Policy, please reach out:
Questions about your data or this policy?
We'll respond within 48 hours.