ViperAI Shield

Privacy Policy

Effective September 11, 2026 · Astratic Technologies LLC ("Viper", "we")

Viper checks messages for scams, protects your family, and helps with everyday tasks. It's built to know as little about you as a tool like this can. This page says exactly what exists, where, and how to erase it — in plain language.

Using Check

Check works without signing in. A random anonymous account ID supports authorization and usage limits; it does not itself contain a name or email. Submitted content is sent to Viper's server. Core scam assessment uses Viper-operated server logic and governed threat intelligence. Check content is not sent to an external model provider. We do not sell submissions, use them for advertising, or train our own models on them.

Raw message text is processed without saving the body to the check database. This does not mean every check leaves no record. Signed-in checks can save a minimal history entry: an identifier such as a domain or phone number, a display summary, assessment, reasons and time. Canonical analysis can retain a content hash, normalized hostname, risk evidence and pseudonymous actor reference. Explicit non-navigation URL analysis can retain the submitted URL; Browser Guard navigation checks do not retain the full URL in that analysis record.

Caller lookup reads existing number information. Reporting a number is a separate action that stores the reported number and an abuse-prevention reporter reference for review. Reports do not automatically become verified threat evidence. Safe Preview and sender verification can save signed-in summaries and normalized identifiers. File triage processes uploaded bytes without saving the file; it returns structural findings and a file hash. Watches, recovery cases and intentionally shared checks retain the information needed for those features until removed or account deletion, subject to the exceptions below. There is no blanket automatic expiry for all these records.

Photos and screenshots you submit

Images you explicitly choose for analysis are sent to our server for supported Content Credentials checks. Pixel-based model analysis and OCR are currently unavailable; missing credentials do not establish that an image is authentic. Viper's image-check handler does not save the uploaded image after processing. This is separate from a bug report you deliberately send with a screenshot, which is retained with that report. Our infrastructure providers process requests as described below. Avoid submitting account numbers, medical records or other unnecessary sensitive content.

Your account

Account features use a shared Viper identity. The iPhone app is not yet publicly available; its supported candidate features are described here for beta users. By default that account is the same kind of anonymous ID — no name or email needed. You may optionally sign in with Apple or Google to use the same identity across supported Viper surfaces. Your provider may share your name and email. Email/password sign-in is not offered, and your email is not used for marketing.

Your conversations & tasks

Connecting Google (optional)

Google Calendar and Gmail connections are retired. Viper no longer starts these connections, exchanges their authorization codes, or sends email or changes calendar events through them. Previously stored connection records and credentials are not automatically revoked by this retirement. Deleting your Viper account removes its associated connection records from the active account database; to revoke a previously granted Google permission, use your Google Account connections. This is separate from Sign in with Google, which remains an identity option and does not grant calendar or email access.

What our server keeps

Threat records and intentional reports

Security analysis may retain a hostname, findings and a pseudonymous attribution reference. An explicit report can retain the reported identifier and reporter reference for abuse prevention and review. Consumer history, feedback, household state and Trusted Circle sharing are not independent corroboration and do not automatically authorize shared blocking.

Chrome Browser Guard 1.0.1

For a supported top-level navigation, Browser Guard sends the navigation URL to Viper's analysis endpoint. The extension does not strip the path, query string or fragment before sending it. URLs can contain sensitive information; do not assume this is a hostname-only request. The extension does not read page-body text, extract the tab title, or send a page referrer as part of that check. It has no page-content script.

The server derives the hostname and checks known threat records, lookalike patterns and available domain-registration data. A recently registered domain alone is not proof of a scam. Blocking follows the server's governed enforcement decision; not every warning blocks navigation. Optional AI-site blocking uses the extension's supported domain list.

Allowed and blocked navigation assessments can retain hostname-level security records, timestamps, findings and pseudonymous actor references. The navigation analysis record does not save the submitted full URL or page content. These security records have no verified blanket automatic expiry. Operational request/error logs may also be retained by hosting providers under their policies; we do not promise zero diagnostic retention.

On your device, a hostname decision cache lasts up to about an hour. Recent blocked-host entries expire after about a day and are bounded in number. Allowlist choices and installed blocking rules remain until removed, replaced or the extension's data is cleared. Clearing extension data does not erase server records.

The Chrome Web Store's Web history category covers navigation URLs processed for protection. Its Website content declaration is broader than the current extension's page-reading behavior: version 1.0.1 does not extract page bodies. We are reviewing the listing categories and copy for a precise metadata correction; this policy describes the shipped runtime rather than implying those categories mean background page reading.

Blocking scam and AI sites

If you switch on Viper's protection (the "DNS Shield"), the phone you set it up on sends its address lookups — the step that turns a name like example.com into a number — to Viper's own resolver rather than your carrier's. That is how Viper refuses a known scam site, and, on a Family plan, the AI apps and sites a parent chooses to block: the lookup is turned away, so connections using those restricted domains can be blocked. Apps using other domains, their own DNS, or a VPN may bypass these restrictions. The standalone download profile uses Quad9 directly rather than the account-linked Viper resolver. Every resolver, including the one your phone uses today, necessarily sees the names it is asked to resolve; what matters is what is done with them.

For the Viper DNS resolver specifically, allowed lookups are not written to its account activity table. Resolver and infrastructure processing is distinct from the Browser Guard assessment records described above. When you are signed in and a blocked scam or AI domain is turned away, Viper may keep that domain and a daily count against your account — or, on a Family plan, against the family, so the organiser's "what was blocked" view can show it. That is the blocked domain only: never the sites you were allowed to visit, not sold or used for advertising.

Quad9 states that it does not store individual user IP addresses or construct per-user browsing histories; its policy describes aggregate security telemetry, including truncated network information. See Quad9’s privacy policy. If Viper's resolver ever cannot answer — an outage, or a network fighting it — the lookup falls through to Quad9, the same privacy-respecting non-profit resolver Viper's own resolver builds on, so your internet keeps working. This adds no new company and exposes nothing a resolver does not already see; it is intended to preserve connectivity, but no fallback can guarantee availability.

How our website is measured

To understand how many people reach viperai.co and whether the site is working — how many visit, which pages they read, whether the free checker completes — we use our own first-party, privacy-preserving analytics. There is no Google Analytics, no advertising SDK, and no third-party tracker; the only network call our measurement makes is to Viper's own first-party ingestion endpoint, which runs on Cloudflare.

What it records: a random, resettable ID stored by your browser (it is not a fingerprint, carries no name or email, and is not derived from your device), a session ID that resets after 30 minutes of inactivity, the coarse type of page you're on (for example "home" or "pricing" — never the full address or its contents), a broad device class (mobile, tablet, or desktop), your country (from your network, nothing finer), the bare domain of the site that referred you, acquisition-source and bounded campaign tags, and which product actions occurred (such as starting a check or viewing pricing). When you are signed in, the server can associate these first-party events with your verified account ID; anonymous tokens are not used for that account attribution. IP-derived, salted rate-limit identifiers protect the ingestion endpoint.

What it never records: the contents of anything you check or type, the specific URLs you visit, your name, email, or phone, any device or browser fingerprint, any advertising identifier, and it never follows you across other websites. Clearing your browser’s site data resets the local IDs; it does not erase previously recorded events. Account deletion unlinks the account ID from retained analytics rows. Event records have no verified blanket automatic expiry.

What we never do

Not for protected health information

Viper is a consumer tool and is not HIPAA-certified. Please don't paste medical records or other protected health information into it.

Deleting your data

Delete account uses Viper's server deletion process to remove your authentication account and associated active profile, usage, personal device/pairing records, history, watches, recovery cases, notifications and submitted bug reports, including their attached screenshots. Completion is confirmed only after the server operation succeeds. Signing out, uninstalling or clearing browser data is not a request to delete server data.

Deletion is not an immediate purge of every copy everywhere. Shared household records needed by remaining members, separately governed security/report records, legally required billing records, provider logs and backup copies may remain under their applicable purposes and retention schedules. Copies already shared with another person may remain with that person. We cannot promise immediate permanent erasure from backups or third-party systems. Contact privacy@viperai.co for a deletion request or questions about retained records.

Service providers and model processing

Vercel hosts the website and Safe Preview connection service, processing visitor requests and related network data. An explicit Safe Preview request sends the submitted destination URL (including its query string) and your Viper session credential to that service for authorization. Target websites receive fixed technical request headers, not your Viper credential or browser cookies. The connection service does not consume page bodies or write submitted URLs or credentials to application logs; hosting-provider operational retention still applies. Supabase hosts authentication, databases, functions and stored account/report data. Cloudflare runs Viper's DNS infrastructure and the first-party endpoint that receives this website's analytics, where it also assigns the country described above; Quad9 provides upstream or standalone DNS resolution as described above. Apple provides supported sign-in, native services such as geocoding, and existing in-app billing. Google provides optional sign-in. Legacy calendar/email grants may remain in your Google Account until revoked, as explained above. Stripe supports existing web billing infrastructure; new public web purchases are not currently offered.

Viper performs core scam assessment using Viper-operated server logic and governed threat intelligence. No external model provider processes current Check, image, conversation or recovery requests. Enhanced semantic, OCR and pixel-based analysis are unavailable while Viper-operated inference is evaluated. No provider fallback is enabled. Cloud speech is also unavailable; supported native clients can use the device voice.

Viper-operated does not mean on-device or that Viper owns the hosting hardware. Supabase hosts backend processing and account data, and Vercel serves this website and the Safe Preview connection service. The storage and operational-log qualifications in this policy still apply. We do not use submissions to train models. If optional model processing is introduced, its scope and retention will be disclosed before activation.

Infrastructure provider policies: Vercel and Supabase. Previously submitted content may remain subject to the policies and retention obligations that applied when it was processed; removing an integration does not retroactively erase a provider's records.

Children

Viper is rated for users 13 and up and is not directed at children.

Changes & contact

If this policy changes materially, the app will say so before the change applies. Questions: privacy@viperai.co.