Transparency First

Privacy Policy

We protect you from phishing. Here's exactly what we do — and don't do — with your data.

Browser Extension Android App

Last updated: June 14, 2026  ·  Version 3.0

TL;DR — The Short Version

1. Overview

WebShield.AI ("we", "us") is an AI-powered phishing detection platform available as a browser extension for desktop browsers and as an Android app. Both products share the same core privacy principle: we scan URLs to protect you, and we do nothing else with your data.

This Privacy Policy applies to both products and explains exactly what is transmitted when you use either of them, how it is used, and what we will never do with it.

By installing the Extension or the App you agree to the practices described here. You may uninstall either product at any time from your browser's extension manager or Android's app settings.

2. What Information Is Transmitted

When you visit a webpage (extension) or tap a link (app), only the URL is sent to our analysis backend. That is the complete extent of data transmission — and even that is skipped entirely for 100+ well-known trusted sites that are recognised locally.

Data Type Collected? Notes
Page URL YES Sent to backend for phishing analysis only. Not logged or stored after analysis.
URLs of popular trusted sites NO Google, YouTube, Instagram, Amazon and 100+ sites are matched locally — never sent to the backend.
Page HTML / content NO The backend fetches the page itself; your device sends no page content.
Cookies / session tokens NO Never accessed or transmitted.
Browsing history NO Not read or stored by either product.
IP address NO Not logged or stored on the backend.
Name / email / account info NO Neither product has an account or registration system.
Scan result (verdict + score) LOCAL ONLY Extension: cached in browser session storage, cleared when tab closes. App: held in memory only for the current scan.
Preferred browser selection LOCAL ONLY Android app only. Stored in device SharedPreferences. Never leaves your device.

3. How the URL Is Used

The URL is used exclusively to run a phishing detection pipeline:

After analysis, the backend returns a verdict (SAFE, SUSPICIOUS, or PHISHING) and a risk score. The URL is not logged, stored in a database, or used for any other purpose.

The backend is a stateless API. It processes the URL and returns a result. No persistent record of your request is kept.

4. Local Data Storage

Browser Extension

The Extension stores scan results locally using chrome.storage.session. This storage:

No data is written to chrome.storage.local or localStorage.

Android App

The app stores one item locally using Android SharedPreferences:

Scan results are held in memory only for the duration of the current scan and are discarded immediately after. No scan history is written to disk.

5. Third-Party Services

Our backend queries the following external threat intelligence services on your behalf. These services receive the URL being scanned — not your identity or any personal data.

These API calls originate from our backend server, not your device. Third-party services do not receive your IP address or any identifying information.

6. Permissions Explained

Browser Extension

PermissionWhy It Is Needed
webNavigation To detect when you finish loading a new page so a scan can begin
activeTab To read the URL of the current tab for scanning
tabs To update the extension badge and clear scan cache when a tab closes
scripting To inject the phishing warning banner onto the page if a threat is detected
storage To cache the scan result locally so repeat visits are instant
<all_urls> To scan any website you visit, not just a pre-approved list

Android App

PermissionWhy It Is Needed
INTERNET To send the URL to our backend API for phishing analysis
VIBRATE To provide haptic feedback when a phishing or suspicious link is detected
SYSTEM_ALERT_WINDOW Required by the React Native framework for development overlay support
ROLE_BROWSER (runtime) To set the app as your default browser so every link you tap is scanned before opening. This role is requested interactively and can be revoked at any time from Android Settings → Default apps.

7. Default Browser Role (Android App)

When you set WebShield.AI as your default browser, Android routes all HTTP and HTTPS links you tap — from any app such as WhatsApp, SMS, or email — through WebShield.AI before they open. This allows the app to scan the URL first.

WebShield.AI does not function as a full web browser. It does not render web pages, store cookies, or maintain browsing sessions. After scanning, safe links are immediately forwarded to your chosen real browser (Chrome, Firefox, etc.).

You can revoke the default browser role at any time via Android Settings → Apps → Default apps → Browser app.

8. Children's Privacy

WebShield.AI does not knowingly collect any personal information from anyone, including children under the age of 13. Neither the Extension nor the App contains account registration, forms, or any data submission from the user beyond the URL being scanned.

9. Changes to This Policy

If we make material changes to this Privacy Policy, we will update the "Last updated" date at the top of this page. For the Android app, significant changes will also be noted in the Play Store release notes. Continued use of either product after any changes constitutes acceptance of the updated policy.

10. Contact

If you have any questions or concerns about this Privacy Policy, please reach out:

Questions about your data or this policy?
We'll respond within 48 hours.

Contact Us