Legal · Privacy v1.0
Privacy Policy
Edition of 12 September 2026. Drafted with regard to Regulation (EU) 2016/679 (GDPR), Russian Federal Law No. 152-FZ "On Personal Data", CCPA/CPRA (California) and other US state privacy laws. This English text is a convenience translation; the Russian edition prevails in case of discrepancies.
1. Who we are and whom this Policy concerns
The operator of the Shield Checker service ("we") processes data of: (a) account holders — developers and professionals who registered on the website, in the app or via Telegram; (b) check subjects — persons whose devices or documents are checked at a user's initiative. In case (b) the user acts as the data controller and we as a processor on the user's instructions; the user must ensure a legal basis and inform the subjects.
2. What data we process
- Account: login, password hash (bcrypt), Telegram identifier (when linked), tier, balance, transaction history, IP address and sign-in metadata (device model, OS and app version) — for security and abuse prevention.
- Technical device signals (Scan): information on OS and runtime integrity (signs of root/emulation/instrumentation, system properties, loaded modules, network parameters, attestation), derived device and network hashes (Shield ID, Network ID). We do not collect message contents, files, contacts or browsing history.
- Verification (Verify): document and face images, extracted features (MRZ, quality, responses to active illumination), sensor and camera metrics, video-stream injection signs. Biometric templates for identifying a person are not created or stored; images are used to compute signals and produce the user's report.
- Network: IP address, ASN/provider, IP geolocation, VPN/proxy/data-centre signs, TLS connection characteristics.
- Payments: Telegram Stars or cryptocurrency transaction identifiers (addresses, hashes, amounts). We do not receive bank details or card data.
- Website: strictly necessary session cookie (HttpOnly) and a language-preference cookie. No advertising trackers or third-party analytics are used.
3. Purposes and legal bases
- providing the Service and performing the contract (GDPR Art. 6(1)(b); 152-FZ Art. 6(1)(5));
- security, prevention of fraud and abuse of the Service, enforcement of Section 3 of the EULA — legitimate interest (GDPR Art. 6(1)(f); 152-FZ Art. 6(1)(7));
- improving detectors on de-identified and aggregated data — legitimate interest;
- compliance with legal obligations, responding to lawful requests from authorities (GDPR Art. 6(1)(c));
- processing face images during verification — on the instructions of the user-controller, who obtains the subject's explicit consent (GDPR Art. 9(2)(a); 152-FZ Art. 11), or with your explicit consent when you check your own device.
4. Storage and retention
Account data is kept until the account is deleted and for up to 3 years thereafter to the extent necessary to protect rights and fulfil financial obligations. Technical check signals are kept for up to 12 months; document and face images — for up to 30 days to produce and deliver the report, after which they are deleted or irreversibly de-identified. Payment data — for the periods set by tax and accounting law.
5. Transfers and recipients
We use infrastructure providers (hosting, database, object storage, delivery networks) and payment providers acting on our instructions under processing agreements. Data may be processed outside your country; for cross-border transfers the EU Standard Contractual Clauses and the requirements of Art. 12 of 152-FZ apply. We do not sell personal data and do not share it with advertising networks. Disclosure to public authorities — only upon lawful requests.
6. Your rights
EU/EEA and UK: access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest, withdrawal of consent, complaint to the supervisory authority of your place of residence. Russian Federation: rights under Arts. 14–21 of 152-FZ, including information about processing, rectification, blocking, destruction and withdrawal of consent. United States (California and other states): the right to know, to delete, to correct, to opt out of "sale"/"sharing" of data (which we do not perform) and protection from discrimination for exercising rights. Send requests via @MarkAntifrodovich; we respond within 30 days (in Russia — 10 business days) after verifying your identity through the account.
7. Security
Encryption in transit (TLS), password hashing, access segregation, logging of administrative actions, data minimisation in reports (disclosure levels), storage of verification media separately from other data with limited retention. We notify about incidents affecting your rights within the statutory periods (72 hours under GDPR; in Russia — notification of Roskomnadzor within 24/72 hours).
8. Children
The Service is intended for persons over 18 and is not directed at children. We do not knowingly collect data of persons under 16 (EU) / 13 (US, COPPA); if detected, such data is deleted.
9. Cookies
We use a single strictly necessary session cookie for signing in to the cabinet and a cookie that remembers your language choice. Neither requires consent under Art. 5(3) of Directive 2002/58/EC. No analytics or marketing cookies are set.
10. Changes
We give at least 14 days' notice of material changes to this Policy on the website and in the cabinet. The date of the current edition is stated at the top of the document.
11. Contacts
Data questions and subject requests: @MarkAntifrodovich. For EU residents a representative and, where required, a DPO are appointed under Arts. 27 and 37 GDPR; current contacts are published in the cabinet.