SecureRing Privacy Policy
Last updated: July 13, 2026
SecureRing is operated by an individual doing business as SecureRing, located in California. We are built to protect your family's privacy and collect only the minimum data necessary to provide verified calling and scam-awareness services within your trusted circle. This policy describes what we collect, what we never collect, and your rights. It accompanies our Disclaimer, Limitation of Liability & Data Use Notice, which is the legally binding agreement you accept in-app.
1. Information We Collect
- Account information: Your display name and email address, which you provide when you sign up. Authentication uses your email and password. A phone number is collected only if you choose phone-based login; it is never required.
- Device ID: A persistent device identifier used to bind your cryptographic identity to your device.
- Cryptographic key (Ed25519): A public/private keypair is generated on your device. The public key is shared with SecureRing to verify callers; the private key is generated and stored in your device's secure enclave or keychain and is never transmitted to SecureRing.
- Circle data: The ring IDs, member IDs, and associations needed to route verification requests and alerts within your trusted circle.
- Safe Words: The family verification words you set or that SecureRing generates for you, stored encrypted at rest. Used to verify callers within your circle.
- Device tokens: Push notification tokens (Apple APNs on iOS, Google Firebase Cloud Messaging on Android) so we can alert you to incoming calls and alerts.
- Emergency contacts (optional): Name, phone number, and relationship for trusted contacts you add manually.
- User-reported scam reports (optional): When you choose to report a scam, the scam type, description, and area code you submit are sent to SecureRing to warn other users, along with your reporter identifier and, if you include one, the phone number of the number you are reporting. The phone number of a call you report may also be attached automatically from the call itself.
- In-app purchase records: Your subscription status only. All payment details are processed exclusively by Apple or Google and are never accessible to SecureRing.
2. Information We Do Not Collect
SecureRing does not collect, store, transmit, sell, or otherwise process any of the following, under any circumstances:
- GPS, cell tower, Wi-Fi, or any other location data.
- Device contacts, address books, or relationship graphs.
- Native call history or dialer records — SecureRing does not access, read, or upload your device's native call log; the in-app Call History displays only your SecureRing calls.
- Behavioral analytics, identity-linked diagnostics, or advertising identifiers.
- Audio or video content of any call — providers process streams in transit only; no call content is stored by SecureRing.
- Biometric data of any kind.
- Personal information from children under 13.
3. How We Use Your Information
- To verify caller identity using cryptographic proofs within your circle.
- To send alerts and route calls between your circle members.
- To provide scam-recognition practice scenarios and to warn other users when you report a scam.
- To maintain your account and subscription status.
We do not sell your data. We do not use your data for advertising or for automated decision-making or profiling that produces legal or similarly significant effects.
4. Data Storage and Security
All data is encrypted at rest and in transit using industry-standard protocols. Cryptographic keys are generated on your device; private keys are stored in your device's secure enclave or keychain and are never transmitted to SecureRing. On iOS, your cryptographic keys may be backed up to your own iCloud Keychain (Apple's end-to-end encrypted infrastructure) so you can restore verification after reinstall; SecureRing does not have access to your iCloud Keychain. Account recovery is performed by signing back in with your email and password, which restores your circle memberships from SecureRing's servers — SecureRing does not use or require any separate recovery passphrase.
5. Third-Party Sub-Processors
SecureRing engages the following providers under data processing agreements consistent with applicable law:
- Supabase, Inc. — encrypted database storage under SOC 2 compliant infrastructure.
- Twilio, Inc. — processes audio/video in transit during active calls only; no call content is stored.
- Apple Inc. (APNs) — delivers push notifications to iOS devices; notification payloads contain alert text only.
- Google LLC (Firebase Cloud Messaging) — delivers push notifications to Android devices under equivalent payload restrictions.
- Apple Inc. and Google LLC — process in-app purchase payments exclusively; SecureRing receives subscription status only.
SecureRing is not responsible for these providers' independent privacy practices. We do not share your data with any other third party except as required by law.
6. Your Rights
- Access & portability: You can view your circle and member data at any time in the app.
- Deletion: You can delete your account and all associated data from Settings.
- Correction: You can update your display name and circle membership in the app.
- Withdraw consent: You can revoke permissions (notifications, microphone, camera) at any time in your device Settings.
California residents (CCPA/CPRA): You have the right to know, delete, correct, and limit use of your personal data, and the right to non-discrimination for exercising these rights. EEA and UK residents have rights under the GDPR and UK GDPR, including access, rectification, erasure, portability, and objection. To submit a verifiable request, contact [email protected].
7. Children's Privacy
SecureRing is not intended for children under 13, and use by a minor under 13 is prohibited. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided personal information, we will delete it promptly. If you believe a child under 13 has used the application, contact [email protected] immediately.
8. Data Retention
We retain your data only as long as necessary to provide the service or as required by applicable law. When you delete your account, your associated data is removed within a reasonable period, except where retention is required by law.
9. Changes to This Policy
We may update this policy periodically. We will notify you of significant changes via an in-app notice. The "Last updated" date above reflects the most recent revision.