Bewary is built private by design. We collect the minimum we need to give you a clear verdict, watch your accounts for leaks, and run your subscription. We do not sell your data. Ever.
The short version. What you check is processed to score it, then cached so the next person gets an instant answer. Your email and any numbers you watch are used only to alert you. Card details go straight to Stripe, never to us. Analytics and advertising measurement are controlled by your choice on the website, and the app does not collect the advertising identifier.
Who we are
Bewary is a product of Reply200 Inc. ("Bewary", "we", "us"). This policy covers the Bewary website (bewary.app), Bewary Web, and the Bewary iPhone app. If you contact us, write to privacy@bewary.app.
What we collect, and why
Things you check
When you run a scam check, we receive the text, link, phone number, or image you submit. We send it to our analysis engine and a small set of security vendors to score it, then return a verdict. As part of that analysis, the content of your check is processed by Google's Gemini API, the AI service our engine uses to read what you submitted and explain the verdict. It is used only to answer your check. Images you submit are analyzed and are not stored. If a photo you choose to check carries a location tag in its file, the app converts it on your device into a place name, like a venue or city, and sends only that place name with the check to sharpen the verdict. If you take the photo inside the app, we ask for the standard iOS location permission and use a single location reading the same way, only to attach that place name. Location is never read without your permission, never tracked in the background, and never stored. The iPhone app tells you this and asks for your agreement before your first check.
If you turn on text-message filtering in iOS Settings, texts from unknown senders are routed by iOS to the same engine so spam and scam texts can be filed to junk. That is the whole flow you are enabling, and you can turn it off in iOS Settings at any time.
We cache results so a check that has been seen before is answered instantly for everyone. To keep improving detection and to catch scams circulating across many people, we keep a record of each check: a redacted excerpt of the text and the scam indicators we extract from it (such as links, phone numbers, and crypto wallet addresses), together with the verdict. These records are not linked to your name, your account, or your device, and are kept only for a limited period. Images are analyzed and are not stored. Please do not paste sensitive personal information (passwords, full card numbers, government IDs) into a check. You never need to, and a verdict does not require it.
Account and monitoring data
If you create a Bewary Web account or turn on monitoring, we store the email address you sign in with and any email addresses or phone numbers you ask us to watch. We check those against public breach databases on a schedule and email you only when something new appears. Sign-in is passwordless: we email you a one-time link rather than store a password.
Payment data
Subscriptions are handled by Stripe. Card numbers go directly to Stripe and are never seen or stored by us. We keep a customer reference and your subscription status so we know your account is active. App subscriptions purchased on iPhone are handled by Apple, and we receive only the entitlement, not your payment details.
Device, usage, and security data
We use an app-scoped device identifier to meter free checks and protect subscriptions, Firebase Analytics to understand app usage, and AppsFlyer plus Apple's privacy-preserving attribution system to measure app campaigns. We configure these tools not to collect Apple's advertising identifier. On the website, Google Analytics measures usage; if you accept optional tracking, Meta and TikTok may also receive page and conversion events. Affiliate links record a click identifier, referral labels, IP address, browser information, and advertising click identifiers so we can attribute sales, prevent fraud, and pay the correct partner. Your IP address is also used for rate limiting and abuse prevention.
You can accept or reject optional website tracking when first asked, and change that choice at any time through Analytics choices. Rejecting it does not limit Bewary's features. Essential referral and security records are still used when you deliberately follow an affiliate link.
Who processes data for us
To run Bewary we share the minimum necessary data with a small set of trusted providers, each only for its specific job. We name the ones that touch what you check or what you pay (Google, Stripe, Apple) and describe the rest by category, to keep this accurate as providers change and to avoid handing scammers a map of how our detection works:
- Scam analysis for checking messages, links, phone numbers, and emails. The AI part of this analysis is Google's Gemini API, which processes the content of your check on our instructions and only to produce your verdict. The rest is threat-intelligence services.
- Breach and leak monitoring for checking whether your email or number has appeared in known data breaches
- Payments for subscription billing
- Email delivery for sign-in links and breach alerts
- Analytics and attribution through Google Firebase and Analytics, AppsFlyer, Apple, Meta, and TikTok, subject to the choices and limits described above
- Security and hosting for bot protection, content delivery, and running the service on secured servers
Every provider is contractually bound to use your data only to perform its service for us, to protect it to the same or an equal standard as this policy, and never to sell it.
What we never do
- We never sell or rent your personal data.
- We never relay another person's calls or messages. iOS does not allow it, and we do not want it. The Family feature shares only Bewary's own findings and items a family member chooses to forward.
- We never track your location.
- We never put secret keys or vendor credentials inside the app. All sensitive calls run on our servers.
How long we keep things
Account and monitoring data is kept while your account is active and for a short period afterward, then deleted. Cached check results are retained to keep the service fast and may be anonymized for accuracy over time. You can delete your account at any time from your dashboard or by emailing us, and we will remove your personal data except where we are required to keep records (for example, billing history for tax purposes).
Your rights
Wherever you live, you can ask us to show you the data we hold about you, correct it, delete it, or send you a copy. If you are in the EU or UK, you have these rights under the GDPR. If you are in California, you have them under the CCPA and CPRA, including the right to know and to delete. Since we do not sell data, there is nothing to opt out of, but you are welcome to confirm that with us. To exercise any right, email privacy@bewary.app and we will respond within the time the law allows.
Children
Bewary is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has used Bewary, contact us and we will delete the data.
International transfers
We and our providers may process data in countries other than yours, including the United States. Where required, we rely on recognized safeguards such as the Standard Contractual Clauses to protect your data in transit and at rest.
Security
We encrypt data in transit with TLS, keep all secrets server-side, and limit access to the people who need it. No system is perfect, but we treat your data as if it were our own.
Changes to this policy
If we make a material change, we will update the date above and, for significant changes, notify account holders by email. Continuing to use Bewary after a change means you accept the updated policy.
Contact
Questions, requests, or concerns: privacy@bewary.app. Reply200 Inc., the maker of Bewary.