Parakh (with its AI assistant, Officer MAGI) is a personal digital-safety app — part of the MagenSec platform — published by XenoCraft Labs Pvt. Ltd. (Hyderabad, India). This policy explains what data Parakh collects, why, who it’s shared with, and your choices. It is separate from the MagenSec enterprise products.
Contact: support@magensec.app
Parakh’s core link, QR and app checks run on your device using offline models. The links you open, the pages you preview, and the SMS/messages you check are analysed locally and are not sent to us. Optional local history stores only the URL and its safety score on your device (never page content or cookies) and you can clear it anytime.
Cloud checking is part of every paid plan and of your 30-day trial, and it is on by default once you sign in. For higher-risk or shortened links Parakh sends the link (or a one-way hash of it) to our servers for a second-opinion verdict, checked against reputable safe-browsing and threat-intelligence sources. “Protected Preview” can open a risky link on our servers so it never touches your device or IP. These are lookups that return only a safety verdict — we don’t use them to profile you, and we don’t sell them.
What is never sent. Before anything leaves the phone the address is reduced to its
canonical form: the query string, the fragment and any username or password are stripped, and
links whose path identifies a person or a session — password resets, sign-in and
verification links, invitations, payment and checkout pages, and chat links such as
wa.me/<number> — are refused, not sent. Stored addresses are
encrypted and expire automatically.
Turning it off. Open Parakh → Settings → Cloud Intelligence and switch it off. On-device checking continues to work, and the app tells you on the home screen which of the two modes is running. If you switch it off, it stays off — an update will not turn it back on.
If you sign in (with Google, or another sign-in provider we support), we receive your email address and basic profile (name, profile photo). We use it to run your account, your shared Circle, and billing. You can use free on-device protection without an account.
To deliver protection, licensing and aggregate statistics, the app periodically sends a minimal heartbeat: a device identifier (a random id, or a hash derived from your account — not your phone number or advertising ID), app version, device model, OS version, coarse region/country, and which protections are enabled (e.g. default browser, Secure DNS, cloud protection). We publish only aggregate, anonymised figures (e.g. “links checked”) on our public dashboard.
If you use Family Guardian, we store the link between a guardian and the person they watch over (established with a pairing code) and send a scam alert when a watched device hits a serious threat. This is designed for adults looking after family; it is not covert monitoring.
When you report a link, we receive the URL and anything you paste in (e.g. the scam SMS text and an optional reason). Our team reviews it to improve protection for everyone. Reports are deleted 30 days after we reach a verdict.
What we collect depends on where you buy. Inside the app, Google Play takes the payment and is the seller of record — we are told that a purchase happened, not your name, address or card. On this website we invoice you ourselves, so we collect your name and, for a GST tax invoice, your billing state and (for a business) your GSTIN. Website payments are processed by PayU (India) or PayPal (international); Parakh does not receive or store your full card details.
Our staff can open a Circle’s own console to help the person who runs it — to build a training course they asked us for, or to see the screen they are describing. We are treated as a co-admin, never an owner: we cannot transfer a Circle, delete it, or close an account. No membership is created, so we never appear on your Team page, in your invites, or in your seat count.
Every one of these visits is recorded — who looked, which Circle, what they did, and when — including visits where nothing was changed. Ask us at support@magensec.app and we will tell you whether anyone at MagenSec has opened your Circle, and why.
We do not sell your personal data and we don’t use it for advertising. We share data only with the service providers needed to run Parakh, under contract, grouped by what they do:
A small number of authorised staff may access your account information — your profile, devices, Circles and licences — only when needed to provide support, resolve a problem, or keep the service secure. This access is limited to what’s necessary and is logged, and these support views are read-only. Staff do not read your on-device link history or the content of pages you preview — that stays on your device.
We may disclose data if required by law, or to protect users’ safety and our rights.
Parakh is a general-audience safety app and is not directed at children under 13. Family Guardian is intended for adults looking after family members.
We’ll update this page when our practices change and revise the “Last updated” date above.
A plain-language map of the data types above, for reference and for the app-store Data Safety disclosure.
| Data type | Collected? | Shared? | Purpose |
|---|---|---|---|
| Email address | Only if you sign in | No | Account, Circle, receipts |
| Name / profile | Only if you sign in | No | Account & invoices |
| Links you check | On device; sent for cloud checks while those are on | Safe-browsing services (for the check) | Threat detection |
| Reported links / pasted SMS | Only when you report | No | Review & improve protection |
| Device & app info | Yes (heartbeat) | No | Protection, licensing, aggregate stats |
| Approximate location (country) | Coarse only | No | Currency & regional protection |
| Payment info | By PayU/PayPal, not us | Payment processor | Purchases |
| Advertising ID | No | No | — |
Data is encrypted in transit. We don’t sell data or use it for advertising.