Privacy Policy
Last updated: September 30, 2026. Plain English. Questions: ops@kromeum.com.
Our Commitment to Your Safety
Your privacy and your safety are inseparable to us. Every feature in Armour — from Zero-Knowledge Vault encryption to scan analysis and breach monitoring — is engineered to protect your data while actively defending you against threats that target it.
Armour gives you access to the same caliber of security hardening, verification, and threat-intelligence resources used to protect high-value targets, packaged into a tool built for everyday people. We treat your data with the care it deserves: encrypted, minimized, and never sold.
While Armour provides robust, continuously evolving protection, we want to be transparent with you: no security platform can promise total immunity from every threat that exists or may emerge. Attacks aimed at the human mind — social engineering, impersonation, urgency-based manipulation — succeed by bypassing technology entirely. We will always do our utmost to detect, warn, and intervene when these attempts cross our systems, and we encourage you to stay cautious whenever something feels off. Together, the protection Armour provides and the awareness you bring make for the strongest possible defense.
The short version
- Kromeum is the company. Armour is the app you're using. Both promises below apply to Armour.
- You decide what gets scanned. Always. Armour never reads, lists, enumerates, or pulls files from your device on its own — not your installed apps, not your APKs, not your Downloads folder, nothing. Every single file, link, or identifier we scan is one you handed us. That's a design choice, not a missing feature.
- We only hold what you've authorized us to hold — the absolute bare minimum needed to make the features you've turned on work for you. Anything sensitive is encrypted before it's written down. Your Vault is zero-knowledge — we genuinely cannot decrypt it, no matter who asks.
- You stay in control. Wipe your local cache any time from Settings → Data & privacy. Export an encrypted backup if you want to keep it on your own cloud or a USB stick.
- We don't sell data. No ads. No tracking pixels.
- No VPN. Ever. Most antivirus apps re-route your whole device through their servers so they can inspect every site, app, and byte you send. Armour doesn't. We give you a privacy-first browser with the scanner built in — browse inside it and we scan the link, browse outside it and we see nothing. Your traffic never crosses our network.
- We never read, monitor, or sync anything from Chrome, Safari, or any other browser on your device. Armour only sees what you hand to it.
- Aligned with GDPR (EU) and CCPA (California).
App-only scope — what we never touch
Armour is a self-contained privacy protection ecosystem. Every feature operates within the app sandbox only. We never reach outside it.
- No hardware access. Camera, microphone, Bluetooth, NFC, GPS/location, biometric sensors, and all physical sensors remain untouched.
- No OS modification. We do not install VPNs, system profiles, kernel extensions, accessibility services, or request root/admin privileges.
- No cross-app access. We cannot read, write, list, or interact with files, data, storage, or notifications belonging to any other app on your device.
- No system monitoring. We do not track your activity in other browsers or apps, log keystrokes, or monitor network traffic outside the Armour browser.
- No background persistence on your device. Armour stops completely on your device when closed. No background services, daemons, or agents keep running on the device. The one exception is server-side: if you turn on a connected-mailbox scan or Forward & Protect, those checks run on ARMOUR's servers (not your device) for as long as you keep them enabled.
- No remote control. We cannot remotely wipe, lock, locate, or factory-reset your device. Emergency Lockdown only clears Armour app data.
This is a deliberate design choice, not a limitation. Proactive personal privacy protection means enforcing boundaries.
The three tiers of how we hold your data
We're specific about this because honest beats catchy. There are three distinct trust levels in Armour:
1. Zero-Knowledge Encryption (we genuinely cannot read it)
Your Vault entries (passwords, notes, files) and Vault sharing use Zero-Knowledge Encryption: data is encrypted on your device with a key derived from your passphrase. The key never leaves your device. Even with full access to our database and our servers, we cannot decrypt a single Vault entry. Lose the passphrase and the data is gone — that's the trade.
2. Encrypted at rest (we hold the key, in a separate vault)
Your scan targets, findings, sandbox reports, Vexa chats, saved scan profiles, support tickets, and any connected-mailbox tokens are encrypted with a master key kept outside the database (Cloudmersive-style KMS, hybrid AES-256-GCM + ML-KEM-768 post-quantum wrap). If our database leaks, the contents are useless without the key. We technically can decrypt this server-side when our pipelines need to (e.g. to run a scheduled scan while you're offline) — so this is not zero-knowledge, and we don't pretend it is.
3. Operational metadata (plaintext, the absolute minimum)
Email, hashed password, display name, subscription tier and trial dates, your role, scheduled-scan cadence + next-run timestamp, and audit-log entries (action + timestamp, no payload). This is what auth, billing, and our cron worker need to function. Nothing else.
When we access your stored data
Stored does not mean watched. No human at Kromeum reads, browses, mines, or analyses your data. What is stored is only ever touched automatically, on your behalf, when you trigger an action that needs it:
- You run a scan → the scanner decrypts the target only long enough to scan it, writes the result back encrypted, and forgets the plaintext.
- You scheduled a scan → the cron worker decrypts the target at the scheduled time, scans it, and re-encrypts. Disable the schedule and the worker stops touching it.
- You connected a mailbox → the inbox-scanner decrypts the access token only when it checks your mailbox for new mail, and only fetches what your "What we can see" level allows. Disconnect and the token is wiped.
- An email reaches Forward & Protect or the Gmail add-on → it's checked in memory, only a flagged result is written (encrypted), and the rest is discarded.
- You opened a chat → Vexa decrypts your conversation only to render it back to you in the same session.
- Your Vault is never decrypted server-side at all — the key isn't on our servers in the first place.
We do not run analytics on your scan contents, train models on your data, profile you, or look at your records to "improve the product". The only time a human at Kromeum could ever see encrypted-tier data is if you explicitly send us a support ticket asking us to look at a specific scan — and even then, only that scan, only with your written ask, and only for as long as the ticket is open.
What's only on your device
- Local scan-history cache — the last 100 scans, for instant recall. Your authoritative history is the encrypted copy on our servers; this is just a fast cache.
- Scan queue + retry state — the in-progress queue, progress bars, and per-download history for the in-app browser and OS-download interceptor. IndexedDB only.
- Caller-lookup cache — past phone-reputation results, AES-GCM encrypted with a per-device key in IndexedDB. 30-day TTL. Never uploaded.
- Trusted-sources allowlist — domains you've marked as trusted to skip auto-scans.
- Vault master key — derived from your passphrase in RAM, never persisted to disk in unwrapped form, never sent anywhere.
- Encrypted backups — if you export, the file is AES-encrypted on your device with your passphrase before it ever leaves. We can't decrypt it.
Local caches live in your browser's IndexedDB / local storage. If you clear browser data or uninstall, the local copy is gone. The encrypted server copy of scans / chats / Vault is unaffected until you delete your account.
Destructive-action verification (email number-match 2FA)
Before we let anyone wipe your Vault, remove a trusted device, or trigger any other irreversible action, we email you a fresh 6-digit code and ask you to type it back into the app. You see the code on whichever device opens the email, and the app you're acting on only ever sees what you type — the real code never travels through the browser tab requesting the action.
The codes are short-lived (single-use, ~10 minutes), stored as a hash on our side, and tied to a single purpose (e.g. wipe all devices) so a code issued for one action can't be replayed for another. We log the purpose and timestamp for your own audit trail; we do not log the code itself.
If you didn't request the email, ignoring it is enough — nothing happens without the typed code.
Kill Switch & trusted devices
Armour gives you two ways to nuke a compromised setup:
- 72-hour grace Kill Switch — arms a scheduled wipe and emails you confirm/cancel magic links. If nothing is confirmed, nothing is deleted. If you confirm, the wipe runs at the scheduled time. If you cancel, your Vault is preserved and we email you to say so.
- Immediate cross-device wipe — used when a device is lost and you're holding a trusted one. The moment you confirm (gated by the email 6-digit code above), we delete every Vault entry, master-key wrapper, device registration, and share from our database, and we broadcast a realtime signal so any other device that's currently signed in clears its local copy (master key in RAM, IndexedDB cache, attachments) within seconds — without waiting for an app reopen.
Each device that unlocks your Vault registers a trusted-device record: a label you chose, a public ML-KEM key, a fingerprint, and timestamps. You can see the full list in Vault → Trusted Devices, sign a device out from another device, or revoke its share access. Revocation invalidates that device's session token and its master-key wrapper, so it can't unlock again without re-enrolling.
Because Vault data is zero-knowledge, a wipe is genuinely irreversible — we hold no recovery copy. That's the trade-off for us not being able to read it in the first place.
Sign-in sessions & cookies
When you sign in, your device receives a session token that keeps you logged in so you don't have to retype your password every time you open the app. This token is stored by your browser or by your operating system's webview / keychain — not by us on a server we control. We never receive a copy of your password.
Because the OS owns that storage, in some cases (Android Auto Backup, iCloud Keychain, browser profile sync, etc.) your session can survive an uninstall and reappear on reinstall — so you may find yourself silently signed back in without typing anything. That is your OS / browser restoring its own data, not Armour pulling credentials from a server. We don't store your login state on your device ourselves, and we cannot reach into OS-level keychain backups.
On a fresh install Armour will, where possible, force you back to the Sign in screen the first time the app boots so you can confirm it's still you. You can also sign out at any time from Settings, which invalidates the session token.
Third parties (the one caveat)
To actually scan something, we have to ask specialist services. When you use a feature, only the input needed for that check is sent from our servers to:
- Google Web Risk, IPQualityScore and urlscan.io — receive links you check (and links found in emails at the Full read-only level) for phishing / malicious-site reputation. IPQualityScore also receives phone numbers and email addresses you look up.
- Cloudmersive — receives files you scan (Deep Scan, Itemized Scan, download checks), links, phone numbers and text you ask us to check (for example a pasted SMS), for virus, threat, spam and validation checks.
- Numverify (apilayer) — receives phone numbers you look up, for carrier and line-type validation.
- XposedOrNot, LeakCheck and Hudson Rock — receive the email address you run a breach check on. Have I Been Pwned (Pwned Passwords) receives only the first 5 characters of a password's SHA-1 hash, never the password.
- crt.sh, Cloudflare DNS and Mozilla Observatory — receive domain names you scan, for certificate, DNS and web-security checks.
- Lovable AI Gateway — routes AI requests to the model providers we use: OpenAI for the AI second opinion on emails and for Vexa chats about emails, and Google Gemini for in-app Vexa chat, abuse screening and link/file threat explanations. Email analysis and email chats are sent with storage disabled (zero data retention) and are not used to train models.
- Google (Gmail API) and Microsoft (Graph API) — only if you connect a mailbox, to read the parts of new mail your chosen level allows.
- Lovable Cloud — hosts our servers and database and sends our transactional email (sign-in, codes, security alerts).
- Apple App Store and Google Play — handle subscription purchases; we receive only the purchase receipt needed to confirm your plan.
- DuckDuckGo — if you type a search (not a web address) into Armour Browser, it is opened as a DuckDuckGo search.
Once data is in a third party's hands, it's governed by their privacy policies, not ours. We are not responsible for how they retain, share, or process what you send through their scanners. If that's a concern, don't scan things you wouldn't want their providers to see — or read each provider's policy first.
What we don't do
- Sell, rent, or trade your data — ever.
- Run third-party advertising trackers or pixels.
- Read your scan inputs for marketing or model training.
- Watch your screen, microphone, camera, contacts, or location.
- Read what you do in Chrome, Safari, or any other browser on your device.
- Auto-scan files on your device unless you've explicitly enabled OS-level interception in the native shell.
- Enumerate, list, or read your installed apps / APKs / device files on our own.Even if you ask Vexa to "scan every app on my phone" or "scan all my downloads automatically", Armour will not crawl your device. Vexa will explain why and offer the upload path so you choose what gets handed to the scanner.
- Store any of the above in plaintext, or in any form we can read without our master key.
Acceptable Use — Strictly Prohibited
By using Armour, you agree strictly and unconditionally that you will:
- NOT use Armour to access, scan, monitor, intercept, or collect any data belonging to another person, entity, or account without their explicit, informed, written consent. This includes — but is not limited to — scanning someone else's phone number, email address, domain, social-media handle, files, passwords, credentials, accounts, devices, or digital assets.
- NOT use Armour to conduct, facilitate, assist, or prepare for any hacking, cracking, intrusion, surveillance, stalking, harassment, fraud, identity theft, social-engineering, phishing, vishing, smishing, malware distribution, botnet operation, ransomware deployment, denial-of-service, credential-stuffing, brute-force, or any other malicious, unlawful, or unauthorised activity against any person, system, network, or organisation.
- NOT submit content you do not have the legal right to handle. Every scan, lookup, or check must be performed on data you own or have explicit authorisation to analyse. You are solely responsible for verifying that right before submission.
- NOT attempt to reverse-engineer, decompile, disassemble, probe, fuzz, exploit, or circumvent any part of Armour, its infrastructure, its APIs, or its third-party scanning providers.
Violation of any of the above is a material breach of these terms and may result in immediate and permanent account termination, deletion of all associated data, reporting to law-enforcement or regulatory authorities where required by law, and pursuit of all available civil and criminal remedies.
Email Protection (optional)
Email Protection is off until you turn it on. There are three ways to use it, and one "What we can see" setting that applies to all of them:
- Senders only — From, To, Subject and Date. No other headers, no message body.
- Headers — all headers (including routing and SPF/DKIM results). No message body.
- Full read-only — headers, body and links.
1. Connect Gmail or Outlook (direct, read-only)
- You connect your own mailbox and can turn scanning on or off. While it's on, ARMOUR's servers check new mail on a schedule.
- Gmail uses the read-only scope gmail.readonly (plus basic sign-in scopes to know which account you connected). Outlook uses Mail.Read. ARMOUR never sends, deletes, labels or moves your mail.
- ARMOUR only fetches what your chosen level allows — for Senders only and Headers, the message body is never downloaded.
- Access tokens are encrypted at rest. Message content is processed in memory and never stored.
- Only emails flagged Caution, Suspicious or Malicious (likely scam) are saved, encrypted: subject, sender, verdict, findings, the level used, and up to 5 suspicious link addresses. Safe emails leave no trace.
- Disconnecting Gmail revokes ARMOUR's access at Google and deletes that mailbox's alerts. Disconnecting Outlook deletes our saved access and that mailbox's alerts; to fully remove the grant on Microsoft's side, also remove ARMOUR from your Microsoft account's app permissions.
- Gmail direct-connect is currently invite-only early access while Google completes verification.
2. Forward & Protect
- You get a personal forwarding address on scan.kromeum.com and choose which emails to forward using your own Gmail filter. ARMOUR never signs into your Gmail.
- Forwarded mail is processed on ARMOUR's servers. Parts outside your chosen level are discarded before analysis. The same storage rules as above apply — flagged results only, encrypted, never the body.
- Gmail's forwarding confirmation code is stored only temporarily: it's cleared once you confirm it, when your first forwarded email arrives, or once it expires after 24 hours.
- Deleting the address deletes its alerts, and any later mail sent to it is discarded unread.
3. ARMOUR in Gmail (Gmail add-on)
- The add-on uses gmail.addons.current.message.readonly, so it reads only the email you have open, when you open it or tap Scan. It can't read the rest of your inbox.
- That email is sent to ARMOUR's server for a check. Parts outside your chosen level are discarded before analysis. Body text is never stored. Flagged results are saved as above.
- Chats with Vexa inside the add-on are not stored by ARMOUR. The add-on keeps the conversation in Google's temporary per-user cache for up to 30 minutes.
- You can unlink the add-on or revoke its access at any time from Email Protection.
4. Vexa AI and email
- AI analysis — the AI second opinion at the Full read-only level, and Vexa chats about an email — sends only the minimum email content needed to the AI provider, with zero data retention. It isn't used for training, and ARMOUR doesn't log the prompts.
- In-app Vexa chats are stored encrypted, like the rest of your Vexa history. When you open an alert in Vexa, only the alert's saved details are included — never the email body.
Google user data — Limited Use
ARMOUR's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Google user data is used only to provide and improve the user-facing email-safety features you turned on.
- It is not sold, not used for advertising, not used for credit or lending decisions, and not transferred except to the processors listed above (to provide the feature), for security, or when legally required.
- No human reads it, unless you explicitly ask us to (for example in a support ticket), for security or abuse investigation, or when legally required.
- It is not used to develop, improve or train generalized AI/ML models, and it is never sent to AI providers that train on it.
Google user data — ARMOUR in Gmail
When you install and use the ARMOUR in Gmail add-on, it accesses Google user data only through the three scopes listed below, only while you are using it, and only for the email-safety features described here.
What the add-on can access
- Only the email you have open. The add-on reads the single email currently open in Gmail, at the moment you scan it or open the add-on — never the rest of your inbox, never your other mail, and never automatically or on a schedule. Nothing happens unless you act.
What each permission is for
- gmail.addons.execute — runs the ARMOUR add-on inside Gmail's own interface, so the scan can appear in the email you're viewing.
- gmail.addons.current.message.readonly — reads the one email you currently have open so ARMOUR can check it for phishing and scams. Read-only: the add-on can't send, delete, label, move or change any mail.
- script.external_request — sends that one email's content to ARMOUR's servers (armour.kromeum.com) for phishing/scam analysis, and receives the verdict back.
What is stored — and what isn't
- The email's body and content are never stored. They are analyzed in memory and discarded.
- Only emails flagged Caution, Suspicious or Malicious are saved, encrypted: the subject, sender, verdict and what the scan found. The result is tied to your ARMOUR account, and you can delete it at any time from Email Protection.
No selling, no ads, no AI training
Google user data accessed through this add-on is never sold, never used for advertising, and never used to train AI models.
Compliance
ARMOUR's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How to revoke access
- In your Google Account, go to Security → Third-party access (or myaccount.google.com/permissions) and remove ARMOUR.
- Or disconnect from within the ARMOUR app: Email Protection → the ARMOUR in Gmail card, where you can unlink the add-on and delete its saved alerts.
Call & Text Protection (optional)
Caller lookups send only the number you typed to our phone-reputation providers — nothing else from your phone is sent. SMS scam analysis checks only the text you paste in yourself, on our servers and with the text-checking provider listed above; it isn't stored. We do not read your call log, your messaging app, or block calls system-wide. We only tell you whether what you handed us looks legit or scammy.
Subscriptions & billing
Most paid plans are billed and managed by Apple App Store or Google Play. Subscriptions auto-renew at the end of each period unless cancelled in your store account at least 24 hours before renewal. Cancelling stops the next charge; your paid access continues until the current period ends. Refunds are handled by the store under their refund policies.
Kromeum may also grant complimentary, promotional, or lifetime paid-tier access directly at its sole discretion. These grants are recorded as part of your account metadata (subscription tier and expiry) and do not involve store billing.
Data retention and deletion
- Email alerts stay until you delete them, disconnect the mailbox (or delete the forwarding address / unlink the add-on source), or delete your account.
- Safe emails and message bodies are never kept.
- Deleting your account removes everything we store server-side, including connected mailboxes (Gmail access is revoked first), alerts, forwarding addresses and their results, scans and Vexa history.
How your data is protected
- All traffic between the app, our servers and our providers uses TLS (HTTPS).
- Sensitive data is encrypted at rest as described in "The three tiers" above; the Vault is zero-knowledge.
- Database access rules restrict each account to its own rows, privileged keys stay server-side, and staff access to encrypted data requires a separate one-time-code approval that is audit-logged.
Children
Armour is not directed to children under 13 (or the higher minimum age that applies where you live), and we don't knowingly collect their data. If you believe a child has created an account, contact us and we'll delete it.
Your rights
You can export your local data as an encrypted backup, wipe your local history, or delete your account (and everything we store server-side) at any time from Settings → Data & privacy. Account deletion removes your email, password hash, and display name from our servers permanently.
Contact
Privacy questions, takedown requests, or data-subject access requests: ops@kromeum.com.
Intellectual property
The Armour app, the Kromeum and Vexa brands, all source code, UI designs, copy, scan-pipeline architecture, and product concepts are the exclusive property of Kromeum. Copying, cloning, reverse- engineering, re-skinning, or taking the ideas, structure, or feature set of this app to build a competing product is strictly prohibited. See our Terms of Service for full details. All Rights Reserved.
Armour (built by Kromeum) is a security tool. Scan results and exported backups may include sensitive information about you or your assets. Treat them like any other security report.
© 2026 Kromeum. All Rights Reserved.
