trasimene.com

Privacy Policy

Last updated: October 7, 2026

This Privacy Policy takes effect on October 21, 2026, except for the sending of file content hashes described in the “Storage files” paragraph, which takes effect on October 22, 2026. Until these dates, the previous version remains applicable. The new processing operations it describes begin only with the version of the app that introduces them, and no earlier than these dates.


: 01

Data Controller

TRASIMENE SAS, 61 Rue de Lyon, 75012 Paris: contact@trasimene.com. In accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act (loi Informatique et Libertés), you have rights over your personal data. The data protection contact can be reached at the same email address.

: 02

Data Collected

User account: email address, first and last name, hashed password (bcrypt, not readable by Trasimène), registration date, unique identifier.

Service usage: access logs (IP, user-agent, timestamp, 30 days), pseudonymised scan events (pseudonymised device ID, aggregated results), push notification tokens (Firebase token, revocable). For real-time protection, our servers also check: the domain of links found in your notifications and SMS messages, as well as, for each notification selected, the app that sent it, its time and the words from a list of known scams that it contains (never the message text; result kept for at most 30 days with scan results), the operator code of your SIM cards (never your phone number) to detect a SIM change, and the package name of unknown apps against the public Play Store listing (not linked to your identity).

Address scanner (QR code or typed address): each address you check is sent to our servers, which compare it with their threat list and with Google Safe Browsing. On iPhone, for the “Secure QR code scanner” and “Sites imitating well-known brands” checks, our servers keep for 30 days, linked to your device, the date and result of each verification, together with a hash of the site name computed using a secret key: without this key, the site cannot be recovered from the hash. This is pseudonymisation: Trasimène holds this key, and these hashes remain personal data. When an address is deemed dangerous, the full address is kept in plain text for the same period, so that it can be shown to you in the check result. As an address may contain personal information (for example an identifier placed in a link you received), only addresses deemed dangerous are kept in this way. This data is erased after 30 days, and upon deletion of your account. Legal basis: contract performance.

Installed apps (Android): to deliver the verdict of the checks that concern your apps, the app sends our servers, at each scan and for each app concerned, its package name and display name, the app that installed it, the fingerprint of its signing certificate and its first installation date. From version 1.2.1, it also sends, for each app concerned: technical characteristics (app version, target Android version, declared category, for example “game”, size of its native code); the status of certain sensitive permissions, that is, whether they are actually granted to it (display over other apps, all files access, reading from and writing to shared storage); and, if you have granted usage data access, its usage time over the last 24 hours (screen time, visible time and time spent working in the background). Our servers use this data to deliver the verdict and keep only the result of the checks, until no later than 30 days after the last scan sent by the phone. Legal basis: contract performance; for usage time, your consent, given by granting usage data access and which can be withdrawn at any time in the phone's settings, in which case the “Suspicious background activity” check remains inactive.

Storage files (Android): to spot dangerous files, the app examines app installation files, archives and files with suspicious extensions (according to a list maintained by our servers) located in your Downloads and Documents folders, at the root of the phone's storage and on a memory card or USB drive that is plugged in. For each of these files, it sends our servers its name, its size, its last modified date and the folder where it is located; for an installation file, it also sends the name of the app it contains and the fingerprint of its signing certificate. From version 1.2.1, it additionally sends a hash (SHA-256) of the content of each file, computed on the phone, to compare it with our database of known malware. The content of the files and their full location are never sent. A hash identifies a specific file: two people who hold the same file obtain the same hash. These hashes are not passed on to any third party. Our servers never keep the hash of a clean file; for a file deemed dangerous, they keep its hash together with the result of the check, which may name it, so that the alert remains displayed as long as the file is on your device, and until no later than 30 days after the last scan sent by the phone. A file that has already been examined is not sent again as long as it does not change. Legal basis: contract performance.

Location (Android): if you allow it, the app accesses precise and approximate location, on all supported Android versions, including when it is not on screen, through its monitoring service, which is indicated by its persistent notification. Android only permits reading cell towers and Wi-Fi access points with this access; this reading is used for two checks. “Fake cell tower detected”: at each scan, the app sends our servers, for each cell tower the phone is attached to, the network type, the signal strength and the tower's identity (LAC/CID, TAC/CI or NCI). “Fake rogue Wi-Fi network”: when several access points broadcast the name of the network you are connected to, the app sends their hardware identifiers (BSSID) and their security type. The app never reads the phone's latitude or longitude, but these identifiers, cross-referenced with public databases of cell towers and Wi-Fi access points, can make it possible to locate the phone approximately, sometimes precisely: we therefore treat them as location data, solely for the purpose of detecting these two attacks. Our servers do not store them; only the result of the check is kept, until no later than 30 days after the last scan sent by the phone. When an anomaly is found, this result states, so that it can be shown to you, the tower concerned (network type, signal strength and, where applicable, identity), or the name of the Wi-Fi network and the BSSIDs of the access points concerned. This detail is erased as soon as the check no longer finds the anomaly. If a technical error occurs during a transmission, these identifiers may appear in the error report sent to our sub-processor Sentry. Legal basis: your consent, given by granting access. You can refuse or withdraw it at any time in the phone's settings: these two checks then remain inactive, as they do when the phone's location is turned off, with no effect on the other checks.

Messaging notifications (Android): if you grant the app notification access, it examines, for the “Unknown device linked to the account” check, the notifications of monitored messaging apps (Signal, WhatsApp and Telegram, a list maintained by our servers), in order to spot the alert a messaging app displays when a new device is linked to your account. From the title and text of each notification, the app keeps only hashes: each sequence of one to four words is transformed by a hash function (truncated SHA-256), and the text is neither kept nor sent. These hashes, kept in memory for the last 200 notifications from these messaging apps, are sent to our servers at each scan, together with the messaging app that sent each notification and its time. Our servers compare them with the hashes of a list of phrases announcing that a device has been linked, then erase them immediately, without logging or keeping them. The result that is kept (until no later than 30 days after the last scan) states only the number of notifications examined, the number of phrases recognised and, if usage data access is granted, the monitored messaging apps used recently. A hash is not encryption: a sequence of common words can be recovered by computing the hashes of known words. This is pseudonymisation, and these hashes remain personal data. Legal basis: your consent, given by granting notification access; you can withdraw it at any time in the phone's settings, in which case this check remains inactive. For the people whose messages appear in these notifications (your correspondents), the legal basis is legitimate interests (Art. 6.1.f GDPR): the security of your account against a device being linked to it without your knowledge. Safeguards: pseudonymisation by hashes, no text sent, hashes erased immediately after the comparison.

Digital vault: your files, notes and passwords are encrypted at rest with AES-256-GCM. The encryption key is unique to each account and managed server-side in Google Secret Manager under strict access controls. We never sell or share your vault content.

Payment: no card data is stored by Trasimène. All transactions are handled exclusively by our PCI-DSS certified payment provider.

: VPN

VPN & Traffic Data

Trasimène includes a secure VPN (encrypted WireGuard protocol) as a security feature. When you enable it:

No-log: we do not record, inspect, or store the content of your traffic. Only the connection status (connected/disconnected) is logged to operate the service.

DNS security filtering: as a security feature, DNS requests made inside the tunnel are resolved by our own servers and checked against a categorized threat list (malware, phishing, command-and-control, trackers). Only when a domain matches this list do we record that domain and its category, linked to your account for 48 hours, solely to display the corresponding security alert in the app. Benign domains are never recorded and no browsing history is kept. Upstream resolution is handled by Quad9, a privacy-focused resolver.

Own servers: traffic passes only through servers operated by Trasimène (WireGuard), never through third parties.

No monetization: we never sell, share, or redirect your traffic for advertising or commercial purposes.

Automatic connection: for subscribers, automatic VPN connection is enabled by default. On Android, once the VPN has been authorised for the first time, it reconnects when monitoring starts (for example when the phone starts up) and when the VPN screen is opened; on iPhone, a system “on-demand” rule re-establishes the tunnel as soon as a network is available. You can turn it off at any time in the VPN screen. On iPhone, when the end of your subscription is established, the app removes this rule and the VPN configuration from the phone.

On-device access: for protection, the app uses the following access rights. Those the phone asks you to authorise can be refused or withdrawn at any time in its settings; the checks that depend on them then remain inactive. On Android: list of installed apps and Wi-Fi status (granted at installation); notifications (alerts and the persistent protection notification); camera (QR code scanner only); Bluetooth (Bluetooth status, connected devices, nearby Bluetooth attacks); location (cell towers and Wi-Fi access points, see “Location” above); contacts and calendar (counting only, to detect mass deletion); phone state (mobile network type, SIM card change); usage data (volume of data sent, number of connections, dual-account apps, usage time of each app over the last 24 hours); notification access (links in notifications and SMS messages, hashes of messaging notifications, see above); all files access (installation files, archives and suspicious files in storage, see “Storage files” above). On iPhone: notifications (alerts); camera (QR code scanner only); Bluetooth (nearby devices, to spot a Bluetooth attack: for each device seen, the signal strength and whether or not it broadcasts a name or services; neither its identifier nor its name is sent); location while using the app, solely to read the name and security type of the Wi-Fi network you are connected to, this name being kept with the check result; Face ID (unlocking the vault, on the device). This data is never sold.

: 03

Legal Bases for Processing

Contract performance (Art. 6.1.b GDPR): user account management, provision of security service, subscription management.

Consent (Art. 6.1.a GDPR): newsletter delivery, placement of analytics and marketing cookies, reading of cell towers and Wi-Fi access points enabled by location access (Android), hashes of messaging notifications enabled by notification access (Android), app usage time enabled by usage data access (Android). For these three types of access, consent is given by granting the access and can be withdrawn at any time by revoking it in the phone's settings.

Legitimate interests (Art. 6.1.f GDPR): platform security, fraud prevention, technical monitoring (Sentry).

Legal obligation (Art. 6.1.c GDPR): retention of connection logs (French legal requirement, 1 year).

: 04

Retention Periods

Active account: data retained for the duration of the subscription, plus 12 additional months after cancellation (appeal period).


Access logs: 30 rolling days.


Security check results: automatically erased no later than 30 days after the last scan sent by the device, and upon account deletion. The cell tower and Wi-Fi access point identifiers and the notification hashes sent to produce them are not stored as such. The detail of an anomaly stated in a result is erased as soon as the check no longer finds that anomaly. Address scanner history (iPhone): 30 days, then automatic erasure, and upon account deletion.


Newsletter: until unsubscription, then deleted within 30 days.


Vault: data deleted within 7 days of account closure.

: 05

Sub-processors

TRASIMENE SAS uses the following sub-processors, all bound by a GDPR-compliant data processing agreement:

Google Cloud (Google LLC), data hosting, region europe-west1 (EU), https://cloud.google.com/security/compliance/gdpr

PostHog Inc., product analytics, EU servers, https://posthog.com/privacy

Sentry (Functional Software Inc.), error monitoring, https://sentry.io/privacy

Have I Been Pwned (Troy Hunt): dark web monitoring API, no personal data transmitted (partial SHA-1 hash only)

RevenueCat Inc., in-app subscription management, https://www.revenuecat.com/privacy

VirusTotal (Google LLC), APK and URL antivirus analysis, https://support.virustotal.com/hc/en-us/articles/115002168385-Privacy-Policy

Google Safe Browsing (Google LLC), malicious URL verification, https://safebrowsing.google.com/

Resend Inc., transactional email delivery, https://resend.com/legal/privacy-policy

: 06

Cookies

Essential cookies (no consent required): authentication session (NextAuth.js), language preferences.

Analytics cookies (consent required): PostHog, Google Analytics, anonymised audience measurement, service improvement.

Marketing cookies (consent required): Meta Pixel, TikTok, LinkedIn, X, targeted advertising and campaign measurement.

You can manage your cookie preferences at any time via the Manage cookies button at the bottom of the page.

: 07

Your GDPR Rights

Under Articles 15 to 22 of the GDPR, you have the following rights:

Right of access (Art. 15) · Right to rectification (Art. 16) · Right to erasure (Art. 17) · Right to data portability (Art. 20) · Right to object (Art. 21) · Right to restriction of processing (Art. 18) · Right to withdraw consent at any time.

To exercise your rights: contact@trasimene.com, response within 30 days. Proof of identity may be requested.

: 08

Complaints to a Supervisory Authority

If you believe that processing of your personal data does not comply with applicable regulations, you have the right to lodge a complaint with the relevant supervisory authority. In France: Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, https://www.cnil.fr.

: 09

International Transfers

Some sub-processors (Sentry, Have I Been Pwned) may process data outside the European Union. Such transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission, or by equivalent safeguards.

: 10

Minors

Access to the service is restricted to adults; minors must obtain the express consent of the holder of parental authority (see ToS). In accordance with article 45 de la loi Informatique et Libertés (French Data Protection Act), a minor under 15 years of age cannot consent alone to the processing of their personal data: the joint consent of the minor and the holder of parental authority is required. The holder of parental authority may exercise GDPR rights on behalf of the minor by writing to contact@trasimene.com.

: 11

Post-mortem Directives

In accordance with article 85 de la loi Informatique et Libertés (French Data Protection Act), you may set directives regarding the retention, erasure and disclosure of your personal data after your death, and modify them at any time by writing to contact@trasimene.com. In the absence of directives, your heirs may exercise certain rights under the conditions provided by law.