ScamGuard SOS
Security & Data
For partners, insurers and procurement teams · Last updated: 2 October 2026
ScamGuard SOS is designed to collect as little as possible. There are no accounts and no passwords, and contacts never leave the phone. The only personal data our server holds is a live location, and only while the user is sharing it.
SingaporeServer and database region
No accountsNo logins, passwords or address-book upload
24 h + 7 daysLive-map links expire, then data is deleted
HTTPS onlyAll traffic encrypted in transit
1. What data goes where
| Data | Stored | Kept for |
|---|---|---|
| Emergency contacts, user's name, alert message, policy number, settings | On the user's phone only (browser storage) | Until the user clears it or uninstalls |
| Live location, accuracy, battery level and display name (during an SOS) | ScamGuard server, Singapore | Link works for up to 24 hours, then the record is deleted within 7 days |
| Approximate coordinates (country lookup) | Sent to BigDataCloud; not stored by ScamGuard | Not stored by us |
| SOS text and WhatsApp messages | Sent from the user's own SMS or WhatsApp app | Never seen or stored by ScamGuard |
| Text pasted into the scam checker | Analysed on the phone | Never uploaded |
| Usage analytics | Umami (cookieless, no personal data) and Hotjar (personal fields masked) | Per each provider's retention settings |
2. Insurer assistance channel
- For medical, accident, evacuation and claims situations, the app opens WhatsApp with a message addressed to the partner's own assistance number.
- The user sees the full message (name, policy number, country, location and live-map link) and presses Send themselves. ScamGuard does not see or keep it.
- The policy number is only included in messages to the insurer. It is never sent to personal SOS contacts or to ScamGuard's server.
- Each partner's number and display name are set as server configuration, not in the app's code, so changing them doesn't need an app update.
3. How the live map is protected
- Each link uses a random, unguessable ID (16 random bytes).
- Only the sender's phone holds the 24-byte key that can post locations. The server stores only a SHA-256 hash of that key.
- Links stop working after 24 hours, or as soon as the user taps "I'm safe" or "Stop sharing".
- Location is only read while the app is open. There is no background tracking.
- Link creation is rate-limited per network address to prevent abuse. Map and API pages are excluded from search engines.
4. Security measures
- HTTPS/TLS for all traffic, including the Android app.
- Security headers: location access restricted to the app's own origin, MIME-sniffing blocked, and no referrer leaked to other sites.
- No accounts or stored credentials, so there are none to steal.
- No ads, no ad SDKs and no sale or rental of data.
- Session recordings mask every personal field (names, phone numbers, messages, location and scam-checker text).
- The Android app is a Trusted Web Activity, cryptographically linked to this domain through Digital Asset Links. It is signed by Google Play App Signing.
- Source code is version-controlled on GitHub, and every change is traceable.
5. Hosting, uptime and continuity
- Hosted on Railway in the Singapore region (asia-southeast1), with a managed PostgreSQL database in the same region.
- Every release is health-checked before it receives traffic. If a new version fails, the previous version keeps running.
- Core features keep working even if the server is unreachable: SOS SMS, emergency numbers and the scam checker run on the phone, and the app works offline once installed. Only the live map needs the server.
- If the service stops: very little user data sits on the server, and live-map data expires on its own within days. For licensed partners, source-code escrow or a handover to partner-controlled hosting can be agreed in the contract.
6. PDPA (Singapore) alignment
- Consent: location is only used after the user grants permission and starts an SOS, and every message is reviewed before sending.
- Purpose limitation: data is used only to deliver alerts, show the live map and pick the correct country's emergency numbers.
- Retention limitation: live-location data is deleted automatically (see section 1).
- Access and deletion: requests are handled within 30 days through Delete your data.
- Transparency: see the public Privacy Policy.
- Partner arrangements: a Data Processing Agreement can be signed with each licensed partner.
7. Certifications and testing
ScamGuard SOS does not currently hold SOC 2 or ISO 27001 certification, and it has not yet had an independent penetration test. On request, we can commission an independent security test and complete a partner's vendor security questionnaire as part of onboarding.
Contact
For security questions, due-diligence requests or to report a vulnerability, email scamguardsos@gmail.com or WhatsApp +65 8887 7041.