Privacy Policy

Last updated: 29 May 2026 · Effective: 29 May 2026

1. Who we are

ActTrident is a cybersecurity mobile application that helps you make safer decisions before acting on links, QR codes, and other user-initiated actions on your device. Contact us at [email protected].

2. What this policy covers

This policy explains what personal data we collect when you use ActTrident, why we collect it, how long we keep it, who we share it with, your rights under UK GDPR, and how to contact us.

3. Data controller

ActTrident is the data controller for personal data collected through this app. Contact us at [email protected] for data protection enquiries.

4. What data we collect

Account data (if you create an account)

  • Email address — used to create and authenticate your account

  • Password — hashed and salted by Supabase. We never store or have access to your plain-text password.

  • Display name (optional)

Account creation is optional. You can use ActTrident in demo mode without providing any personal data.

Risk check data

All risk checks are performed locally on your device. No URLs, QR codes, or link content are transmitted to our servers.

Camera data

If you use the QR scan feature, camera data is processed entirely on your device. No images or video are captured, stored, or transmitted.

Data we do NOT collect

  • Location data

  • Contacts

  • Financial or payment information

  • Biometric data

  • Advertising identifiers

5. How we use your data

We use your data to create and manage your account, authenticate you, provide the risk check service, send account-related emails, improve app performance, and comply with legal obligations. We do not use your data for advertising, profiling, or automated decision-making.

6. Authentication provider: Supabase

We use Supabase as our authentication backend. Your email address and hashed password are stored on Supabase’s infrastructure. Supabase is GDPR-compliant. Supabase Privacy Policy →

7. Data retention

Account data is kept until you request deletion. Session tokens expire on sign-out. Local device history is deleted when you clear it or uninstall. Crash logs are kept 90 days. Support correspondence is kept 3 years.

8. Who we share your data with

We share your data only with Supabase (our authentication provider) and with law enforcement only where legally required. We do not sell, rent, or share your personal data for marketing or advertising.

9. Your rights under UK GDPR

You have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. Contact [email protected]. We respond within one calendar month.

10. Account deletion

Open the ActTrident app → Account → Request account deletion, or email [email protected] with subject “Account deletion request”. We process requests within 30 days.

11. Security

All data in transit is encrypted using TLS. Passwords are hashed and salted — we never have access to plain-text passwords. Risk check content never leaves your device.

12. Children

ActTrident is not directed at children under 13. Contact [email protected] if you believe a child has provided data.

13. Changes to this policy

We may update this policy from time to time. We will notify you of material changes by updating the date above and displaying a notice in the app.

14. Contact and complaints

Email: [email protected]

To complain to the UK regulator: ico.org.uk · 0303 123 1113

ActTrident Ltd · United Kingdom