Parakh a MagenSec app

Privacy Policy

Last updated: 31 July 2026 · Applies to the Parakh mobile app and parakh.magensec.app
The short version. Parakh is built privacy-first. The free, on-device protection checks links entirely on your phone — those links never leave your device. With a plan, cloud link checking is included and on by default; it is described in full in section 2b and you can switch it off in Settings at any time. Family Guardian stays opt-in. We don’t sell your data, show ads, or build advertising profiles. You can use core protection without signing in.

1. Who we are

Parakh (with its AI assistant, Officer MAGI) is a personal digital-safety app — part of the MagenSec platform — published by XenoCraft Labs Pvt. Ltd. (Hyderabad, India). This policy explains what data Parakh collects, why, who it’s shared with, and your choices. It is separate from the MagenSec enterprise products.

Contact: support@magensec.app

2. What we collect and why

a. On-device protection no data leaves your device

Parakh’s core link, QR and app checks run on your device using offline models. The links you open, the pages you preview, and the SMS/messages you check are analysed locally and are not sent to us. Optional local history stores only the URL and its safety score on your device (never page content or cookies) and you can clear it anytime.

b. Cloud analysis on with a plan · you can switch it off

Cloud checking is part of every paid plan and of your 30-day trial, and it is on by default once you sign in. For higher-risk or shortened links Parakh sends the link (or a one-way hash of it) to our servers for a second-opinion verdict, checked against reputable safe-browsing and threat-intelligence sources. “Protected Preview” can open a risky link on our servers so it never touches your device or IP. These are lookups that return only a safety verdict — we don’t use them to profile you, and we don’t sell them.

What is never sent. Before anything leaves the phone the address is reduced to its canonical form: the query string, the fragment and any username or password are stripped, and links whose path identifies a person or a session — password resets, sign-in and verification links, invitations, payment and checkout pages, and chat links such as wa.me/<number> — are refused, not sent. Stored addresses are encrypted and expire automatically.

Turning it off. Open Parakh → Settings → Cloud Intelligence and switch it off. On-device checking continues to work, and the app tells you on the home screen which of the two modes is running. If you switch it off, it stays off — an update will not turn it back on.

c. Account (optional — needed for Circle, Family Guardian and purchases)

If you sign in (with Google, or another sign-in provider we support), we receive your email address and basic profile (name, profile photo). We use it to run your account, your shared Circle, and billing. You can use free on-device protection without an account.

d. Device & diagnostic data

To deliver protection, licensing and aggregate statistics, the app periodically sends a minimal heartbeat: a device identifier (a random id, or a hash derived from your account — not your phone number or advertising ID), app version, device model, OS version, coarse region/country, and which protections are enabled (e.g. default browser, Secure DNS, cloud protection). We publish only aggregate, anonymised figures (e.g. “links checked”) on our public dashboard.

e. Family Guardian (opt-in)

If you use Family Guardian, we store the link between a guardian and the person they watch over (established with a pairing code) and send a scam alert when a watched device hits a serious threat. This is designed for adults looking after family; it is not covert monitoring.

f. Suspicious-link reports

When you report a link, we receive the URL and anything you paste in (e.g. the scam SMS text and an optional reason). Our team reviews it to improve protection for everyone. Reports are deleted 30 days after we reach a verdict.

g. Billing

What we collect depends on where you buy. Inside the app, Google Play takes the payment and is the seller of record — we are told that a purchase happened, not your name, address or card. On this website we invoice you ourselves, so we collect your name and, for a GST tax invoice, your billing state and (for a business) your GSTIN. Website payments are processed by PayU (India) or PayPal (international); Parakh does not receive or store your full card details.

h. Support access to a Circle

Our staff can open a Circle’s own console to help the person who runs it — to build a training course they asked us for, or to see the screen they are describing. We are treated as a co-admin, never an owner: we cannot transfer a Circle, delete it, or close an account. No membership is created, so we never appear on your Team page, in your invites, or in your seat count.

Every one of these visits is recorded — who looked, which Circle, what they did, and when — including visits where nothing was changed. Ask us at support@magensec.app and we will tell you whether anyone at MagenSec has opened your Circle, and why.

3. How your data is shared

We do not sell your personal data and we don’t use it for advertising. We share data only with the service providers needed to run Parakh, under contract, grouped by what they do:

Access by our support team

A small number of authorised staff may access your account information — your profile, devices, Circles and licences — only when needed to provide support, resolve a problem, or keep the service secure. This access is limited to what’s necessary and is logged, and these support views are read-only. Staff do not read your on-device link history or the content of pages you preview — that stays on your device.

We may disclose data if required by law, or to protect users’ safety and our rights.

4. Retention

5. Your choices & rights

6. Children

Parakh is a general-audience safety app and is not directed at children under 13. Family Guardian is intended for adults looking after family members.

7. Changes

We’ll update this page when our practices change and revise the “Last updated” date above.

8. Data Safety summary

A plain-language map of the data types above, for reference and for the app-store Data Safety disclosure.

Data typeCollected?Shared?Purpose
Email addressOnly if you sign inNoAccount, Circle, receipts
Name / profileOnly if you sign inNoAccount & invoices
Links you checkOn device; sent for cloud checks while those are onSafe-browsing services (for the check)Threat detection
Reported links / pasted SMSOnly when you reportNoReview & improve protection
Device & app infoYes (heartbeat)NoProtection, licensing, aggregate stats
Approximate location (country)Coarse onlyNoCurrency & regional protection
Payment infoBy PayU/PayPal, not usPayment processorPurchases
Advertising IDNoNo

Data is encrypted in transit. We don’t sell data or use it for advertising.

This policy is provided for transparency and app-store compliance. Please have it reviewed by qualified counsel before you rely on it for a specific jurisdiction (e.g. India DPDP Act, GDPR).