Terms of Service
Version 2026-09-30 · Effective September 30, 2026
The short version: Armour (built by Kromeum) is a security companion that scans links, files, and downloads you choose to hand it. We hold the absolute bare minimum needed to make the features you've turned on work for you — your Vault uses Zero-Knowledge Encryption (we genuinely cannot read it), and your scans, chats, and reports are encrypted at rest with a key kept outside the database. No human at Kromeum reads your data — stored ≠ accessed. We don't sell, we don't watch your screen or your other browsers, and we try to be honest about the limits of what any scanner can promise.
1. Who we are
Kromeum is the company that builds and maintains the Armour app ("Armour," "the app," "we," "us," or "our" in these terms refer to the Armour app and the Kromeum team behind it). By creating an account or using Armour, you ("you" or "user") agree to these terms.
1a. Scope of Protection
Armour provides a comprehensive suite of security hardening, verification, and monitoring tools designed to defend you against the overwhelming majority of digital threats — phishing, malware, credential exposure, unsafe links, breached accounts, and more. Our systems are built on layered, industry-leading defenses and are continuously updated as the threat landscape evolves.
Using Armour means you have equipped yourself with one of the most thorough personal security toolkits available. However, no security product — ours or anyone else's — can guarantee absolute immunity from every possible threat. Cybersecurity is a shared responsibility: the strongest technical defenses can still be circumvented when an attacker successfully manipulates a person rather than a system. Social engineering, in particular, targets human judgment rather than software, and remains the single most effective tactic used against individuals worldwide.
By using Armour, you acknowledge that we provide the tools, intelligence, and active protection to keep you safe, and that staying safe also depends on cautious personal decisions — such as not sharing credentials, codes, or sensitive information with anyone who requests them, regardless of how legitimate the request appears. We are committed to doing everything within our power to protect you, and we will continue to evolve Armour to defend against new and emerging threats as they arise.
2. What Armour actually does
- Manual-by-design — you choose what gets scanned. Armour does not enumerate, list, or read the apps and files installed on your device. Every scan is initiated by you handing the app a file, folder, link, or identifier. The Vexa AI assistant follows the same rule — if you ask it to "scan every app on my phone" or "scan everything in my Downloads", it will refuse the auto-crawl and offer the upload path so the choice stays with you. This is a deliberate privacy posture, not a limitation.
- Scans links and files you submit. When you paste a URL, upload a file, or open a link through the in-app browser, we send identifiers (a hash of files, the URL string) to third-party threat-intelligence services to check reputation.
- Runs local checks first (Quick Scan). Magic-byte mismatch detection, SHA-256 hash blocklists (MalwareBazaar), YARA rules, and heuristic checks all run on your device. This is the default for offline-friendly, fast scanning.
- Optional cloud antivirus layer (Deep Scan). When Deep Scan is enabled, the file is also sent to Cloudmersive Advanced Virus Scan (up to 1 GB) in parallel with local checks to detect viruses, embedded macros, scripts, password-protected archives, and OLE-embedded objects. Files larger than the limits skip the corresponding layer. You can toggle Deep Scan off at any time from the Scan page.
- Auto-scan in-app browser downloads (optional). When enabled, files saved to your device through the Armour in-app browser are automatically run through the same scan pipeline you chose (Quick or Deep). On by default to keep new downloads safe; can be disabled from the Scan page.
- Auto-scan OS-level downloads (optional, native shell only). If you set Armour as your default browser and enable OS download scanning in the native app, downloads triggered by the OS download manager are intercepted and pushed into the same scan queue. This requires the Armour native shell and explicit user opt-in. We never silently watch other apps' downloads.
- Trusted-sources allowlist. You can mark specific domains (e.g. github.com) as trusted to skip auto-scans for downloads originating from them. The allowlist lives only on your device.
- Anti-Phishing Shield. Real-time URL interception in the Armour in-app browser. When the shield is on, every link you tap is scanned before it loads.
- Provides the Vexa AI assistant. A conversational guide (powered by the Lovable AI Gateway — Google Gemini for in-app chat, and OpenAI for chats about a specific email) that explains scan results, runs scans on your behalf, and answers security questions. Vexa can navigate the app, trigger scans, read provider status, and analyse files you upload to the chat — all under your direction.
- Acts as an in-app browser shell — not a VPN. Armour does not install a system VPN profile, intercept your device's network traffic, or re-route Chrome/Safari/banking apps through our servers. We pre-scan every URL you open inside Armour before opening it. Most major sites (Google, banks, etc.) block themselves from being embedded — for those we hand off to your system browser after verification. If you browse outside Armour, we see nothing.
- Mega Scan — digital-presence check. Looks up identifiers you provide (email, phone, domain, social handle — all optional, run any combination) against breach, reputation, and exposure sources. The "all clear" celebration only appears when every item you submitted comes back safe.
- Ultimate Scan (subscribers). Runs an antivirus pass and a Mega Scan back-to-back from the home screen for a single combined verdict. Available to active subscribers only.
3. What Armour is NOT
- Not a system-wide antivirus. Even with OS download interception enabled, we do not run as a kernel driver, we don't intercept every network packet, and we don't monitor apps you haven't asked us to scan.
- Not a guarantee. No security tool catches 100% of threats. Brand-new phishing pages, freshly rotated domains, abused tunnels (e.g. ngrok, temporary hosts), and zero-day malware can occasionally slip past. Treat our verdicts asstrong signals, not absolute truth.
- Not a substitute for common sense. Don't enter passwords on sites you don't recognize, even if we said "safe."
3b. App-only scope — no system or hardware access
Every feature, function, and protective layer in Armour operates entirely within the app sandbox. We do not access, modify, monitor, or interact with your device's hardware, operating system, system files, kernel, drivers, firmware, or any other apps installed on your device.
- No hardware access. We do not access your camera, microphone, Bluetooth, NFC, GPS/location, accelerometer, gyroscope, biometric sensors, or any other physical sensor.
- No OS-level modification. We do not install system profiles, VPNs, firewalls, kernel extensions, accessibility services, keyboard replacements, or launcher replacements. We do not request root, administrator, or superuser privileges.
- No cross-app access. We do not read, write, enumerate, list, or interact with files, data, storage, caches, keychains, notifications, or processes belonging to other apps on your device — including browsers, banking apps, messaging apps, social media, or system utilities.
- No system monitoring. We do not monitor network traffic outside the Armour in-app browser, log keystrokes, watch clipboard contents (except when you explicitly paste into an Armour input field), or track your activity across other apps.
- No persistent background execution on your device. When you close Armour, all active processes on your device stop. We do not run daemons, background services, or persistent agents on your device after the app is closed. Connected-mailbox scans and Forward & Protect run on ARMOUR's servers, not your device, for as long as you keep them enabled.
- No remote device control. We cannot remotely lock, wipe, locate, factory-reset, or otherwise control your device. Emergency Lockdown affects only Armour app data (vault key, session, local cache) and does not touch system settings or other apps.
Armour is designed as a proactive personal privacy protection ecosystem that stays inside its own boundaries. The only data we ever see is data you voluntarily hand to us within the app.
3a. Limitation of liability — the threats we cannot catch
Armour is a detection and guidance tool, not a shield against every form of compromise. Cybersecurity is a shared responsibility between the tools you use and your own behaviour. By using Armour you acknowledge and accept that neither Kromeum nor the Armour app shall be liable, directly or indirectly, for any loss, damage, breach, identity theft, financial loss, account compromise, data exfiltration, ransomware infection, reputational harm, or other adverse outcome resulting from any of the following categories of attack — all of which fall outside the technical scope of what a client-side scanning and assistant application can reasonably detect or prevent:
- Social-engineering attacks — phishing calls, SMS smishing, voice cloning, deepfakes, impersonation of friends/family/colleagues, romance scams, pig-butchering scams, business-email-compromise, fake support agents, and any scenario where you are persuaded to act against your own interest by a human or AI on the other end of a conversation.
- Credential reuse and weak passwords — breaches of services we did not flag, password reuse across sites, passwords shared with another person, or passwords stored unprotected.
- Network-layer compromise — malicious or misconfigured Wi-Fi routers, rogue access points, evil-twin hotspots, ARP-spoofing, DNS hijacking on your local network, malicious VPN providers, ISP-level interception, BGP hijacks, and man-in-the-middle attacks upstream of your device.
- Device-level compromise outside our process — jailbroken or rooted devices, malicious browser extensions, keyloggers installed by another app, screen-recorders, accessibility-service abuse by other apps, supply-chain attacks on your operating system, firmware implants, hardware tampering, evil-maid attacks, and physical access to an unlocked device.
- Third-party service breaches — compromise of your email provider, cloud storage provider, social network, bank, employer, school, government registry, or any other service that holds your data and is breached on their side.
- Zero-day and novel threats — brand-new malware variants, freshly registered phishing domains, previously-unknown CVEs, supply-chain compromises in software you install, and any attack that has not yet been catalogued by the threat-intelligence sources we query.
- SIM-swap, port-out fraud, and telecom-layer attacks — fraudulent transfer of your phone number to an attacker-controlled SIM, intercepted SMS-based 2FA codes, SS7 protocol attacks, and any compromise rooted in your mobile carrier's systems.
- Physical theft, coercion, and "wrench attacks" — loss or theft of an unlocked device, shoulder-surfing, coerced disclosure of credentials, and any scenario in which an attacker has physical access to you or your hardware.
- Cloud, IoT, and smart-home device compromise — vulnerable smart speakers, cameras, doorbells, TVs, baby monitors, routers, printers, NAS units, and any internet-connected device on your network that is not running the Armour app.
- Browser, OS, and app vulnerabilities outside the Armour in-app browser — exploits delivered through Safari, Chrome, Edge, Firefox, native messaging apps, social apps, gaming clients, or any other software we do not control.
- Insider threats and account sharing — anyone you have given your password, recovery email, recovery phone, backup codes, or unlocked device to, regardless of the relationship.
- Cryptocurrency, smart-contract, and on-chain losses — wallet drainers, malicious dApps, signed malicious transactions, seed-phrase theft, and any loss of digital assets, regardless of how the attacker obtained access.
- Scans you chose not to run — any threat that would have been flagged had you scanned the relevant link, file, or identifier, but did not.
- Sophisticated, targeted, and state-sponsored attacks — APT groups, nation-state surveillance, commercial spyware (e.g. Pegasus-class), and any adversary with resources beyond the scope of consumer-grade defence.
Armour does its best to detect what is detectable from inside an app sandbox running on your device. To the maximum extent permitted by applicable law, Kromeum, the Armour app, our affiliates, employees, and contractors shall not be liable for any direct, indirect, incidental, special, consequential, exemplary, or punitive damages — including but not limited to loss of profits, revenue, data, goodwill, or other intangible losses — arising out of or related to any of the categories above, or to your use of, or inability to use, the app. Our aggregate liability for any claim arising out of these terms is limited to the greater of (a) the amount you paid us in the twelve months preceding the claim, or (b) USD $50.
You acknowledge that you remain ultimately responsible for your own digital safety: keeping your devices and operating systems updated, using unique passwords, enabling multi-factor authentication on every account that supports it, verifying who you are talking to, and exercising judgement before clicking, downloading, paying, or disclosing.
3b. Scan results are advisory — including “safe” and “proceed with care”
Every verdict Armour shows you — safe, proceed with care, suspicious, malicious, or unable to verify — is advice, not a warranty. A link check can confirm things about a web address; it cannot confirm the human, business, seller, listing, account, or payment page sitting behind that address.
The “proceed with care” verdict exists precisely to be honest about that gap. It means: the website address itself is genuine and nothing flagged it, but part of the link — a profile, a shop page, a cart or checkout, a one-time or session link, a sign-in wall, or temporary hosting — is not something we can independently verify. It is neither a clearance nor an accusation.
If you choose to continue past any Armour warning, advisory, or interstitial screen, that decision is yours alone and taken voluntarily. Armour presenting an “open anyway”, “continue”, or “I understand” option is a courtesy control, not a recommendation, an endorsement, or an assurance of safety, and must not be read as Armour inducing, encouraging, or approving your decision to proceed.
To the maximum extent permitted by applicable law, neither Kromeum, Unitech Enterprise (of which Kromeum is a registered trading name), its sole proprietor, nor any affiliate, employee or contractor accepts any liability for loss, damage, fraud, theft, account compromise, or financial harm arising from your decision to open, sign in to, transact with, download from, or otherwise act upon any link, file, message, caller, or destination — regardless of the verdict Armour displayed, and regardless of whether that verdict was correct.
4. What lives where
We keep only what the features you use need, and anything sensitive is encrypted before it's stored. The honest map of your data is below: some things stay only on your device, your scan results and Vexa chats are stored on our servers encrypted at rest, and your Vault is zero-knowledge.
On our servers — operational metadata only (plaintext, the bare minimum):
- Your account: email address, hashed password (we never see your plaintext password), display name, the version of these Terms you accepted, your subscription tier and trial dates, your role, and scheduled-scan cadence + next-run timestamp. This is what auth, billing, and the cron worker need to function.
On our servers — encrypted at rest (we hold the key in a separate KMS, hybrid AES-256-GCM + ML-KEM-768):
- Scan targets, findings, and sandbox reports:encrypted before they hit the database. Plaintext columns are blanked by trigger. Useless without our master key.
- Vexa chat history and support tickets: same encryption envelope.
- Saved scan inputs (email, phone, domain, socials) if you opted in: ciphertext only.
- Email Protection alerts: only for emails flagged Caution, Suspicious or Malicious — subject, sender, verdict, findings, the level used and up to 5 suspicious link addresses. Never message bodies; safe emails are not stored.
- Connected-mailbox tokens (Gmail / Outlook OAuth refresh tokens) if you connected Email Protection: encrypted at rest. We can decrypt server-side because the cron worker fetches your inbox while you're offline; it cannot run otherwise.
- This is encrypted, not zero-knowledge. If our KMS is compromised, this layer becomes readable. We're explicit about that so you can decide which features you want enabled.
Zero-knowledge — we genuinely cannot read this:
- Vault entries (passwords, notes, files): encrypted on your device with a key derived from your passphrase. The key is never sent to us. Forget the passphrase, the data is gone — there is no reset.
- Vault sharing: per-device ML-KEM keypair, so shared entries are end-to-end encrypted between your devices and recipients. Server only routes ciphertext.
- Encrypted backups: if you export, the file is AES-encrypted on your device with your passphrase before it leaves. We have no copy of the passphrase.
On your device only:
- Local scan-history cache (last 100), the auto-scan queue + per-download history, caller-lookup cache (AES-GCM, per-device key), the trusted-sources allowlist, and the Vault master key (RAM only).
4a. Destructive actions, Kill Switch & trusted devices
Some Vault actions are irreversible — wiping your Vault, removing a trusted device, or revoking a share. To make sure it's really you, Armour now requires email number-match 2FA before any of those run: we email you a fresh 6-digit code, you type it back into the app, and only then does the action execute. Codes are single-use, short-lived, and bound to one purpose, so a code for "wipe all devices" can't be reused to remove a single device.
Kill Switch — 72-hour grace. Arms a scheduled wipe and emails you confirm/cancel magic links. If you don't confirm, nothing is deleted. If you confirm, the wipe runs at the scheduled time. If you cancel, your Vault is preserved.
Kill Switch — immediate. Triggered from a trusted device (typically because another device is lost). The moment you confirm with the 6-digit code, we permanently delete every Vault entry, master-key wrapper, device registration, and share row, plus encrypted attachments in storage. We also push a realtime signal so any other signed-in device clears its local cache (master key in RAM, IndexedDB, downloaded blobs) within seconds — you do not have to reopen those devices for the wipe to take effect.
Trusted devices. Each device that unlocks your Vault registers a record (label you chose, public ML-KEM key, fingerprint, last-seen timestamp). You can list, rename, or revoke any device from Vault → Trusted Devices. Revocation invalidates that device's master-key wrapper, so it cannot unlock the Vault again without re-enrolling and passing the email verification step.
Because the Vault is zero-knowledge, a wipe is genuinely irreversible — Kromeum holds no recovery copy. That is the deliberate trade-off for us not being able to read your Vault.
5. What we do NOT collect or access
- Your other apps, files outside scans, or device contents.
- Your microphone, camera, contacts, or location.
- Browsing activity outside the in-app Armour browser. We do not read, monitor, sync, or import anything from Safari, Chrome, Edge, Firefox, or any other browser on your device — even if Armour is set as your default browser.
- OS-level downloads, unless you have explicitly enabled OS download interception in the Armour native shell. Even then, the file goes through the same scan pipeline you chose; we do not transmit it anywhere we wouldn't have if you'd uploaded it manually.
- Your plaintext password — ever.
- The readable contents of your scan history or Vexa chats — they are stored on our servers only in encrypted form, and no one at Kromeum reads them (see §4 and the Privacy Policy's "When we access your stored data").
- The body of any email — Email Protection, Forward & Protect and the Gmail add-on process it in memory and never store it.
- A list of the apps, APKs, or files installed on your device. Armour does not enumerate or read your device's storage on its own. If you want a particular file, folder, or APK scanned, you upload it — that's the only way anything from your device reaches the scanner.
5a. Sign-in sessions & cookies (important)
When you sign in to Armour, your device receives a session token that keeps you logged in between visits so you don't have to retype your password every time. That token is held by your operating system, your browser, or the native webview's keychain — not by us on a server we control. We never receive a copy of your password and we do not maintain our own "remember me" cookie store on your device.
Because that storage is owned by the OS / browser, in some configurations (for example Android Auto Backup, iCloud Keychain sync, or browser profile sync) your session can survive an uninstall and reappear on reinstall. If that happens you may briefly find yourself signed back in without entering anything — that is your OS or browser restoring its own data, not Armour pulling credentials from a server. We cannot reach into OS-level keychain backups and we are not responsible for the OS / browser's restore behaviour.
On a fresh install Armour will, where possible, force you back to the Sign in screen the first time the app boots so you can confirm it's still you, and you can sign out at any time from Settings to invalidate the session token immediately.
6. Third parties (the one caveat)
To actually check something, we have to ask specialist services. When you use a feature, only the input needed for that check is sent to these providers, under their own terms and privacy policies:
- Google Web Risk, IPQualityScore and urlscan.io — link reputation (IPQualityScore also checks phone numbers and email addresses you look up).
- Cloudmersive — antivirus scanning of files you submit (up to 1 GB), plus link, phone-number and text (e.g. pasted SMS) checks.
- Numverify (apilayer) — phone-number validation.
- XposedOrNot, LeakCheck and Hudson Rock — breach checks on email addresses you submit; Have I Been Pwned (Pwned Passwords) receives only a 5-character hash prefix, never a password.
- crt.sh, Cloudflare DNS and Mozilla Observatory — domain certificate, DNS and web-security checks.
- Lovable AI Gateway — routes AI requests to OpenAI (email AI second opinion and Vexa email chats, sent with zero data retention and not used for training) and Google Gemini (in-app Vexa chat, abuse screening and threat explanations).
- Google (Gmail API) and Microsoft (Graph API) — only if you connect a mailbox.
- Lovable Cloud — hosting, database and transactional email (sign-in, codes, security alerts).
- Apple App Store and Google Play — subscription billing.
- DuckDuckGo — searches typed into Armour Browser.
Important: once data is in a third party's hands, it's governed by their policies, not ours. We are not responsible for how they retain, share, or process what you send through their scanners. If that worries you, don't scan things you wouldn't want their providers to see, or check each provider's policy before scanning sensitive material.
7. What we never do
- Sell your personal data. To anyone. For any price.
- Show you targeted advertising based on what you scan.
- Share your scan history with marketers, employers, governments, or other users — except as required by valid legal process.
- Read your Vexa chats for training without your permission.
8. Deleting your data
You can delete individual scans and Vexa conversations from inside the app at any time. To delete your entire account and all associated data:
- Go to Settings → Account → Delete account, or email us from your registered address.
- All scan history, chat history, profile data, and consent records tied to your account are permanently erased within 30 days.
- Anonymized, aggregated usage stats (no identifiers) may be retained.
- Backups are rotated within 90 days; deleted data disappears from backups by then.
9. Your responsibilities — STRICT PROHIBITIONS
By creating an account or using Armour in any way, you agree to the following strict, unconditional, and non-negotiable obligations. Violation of any item in this section is a material breach of these Terms.
- STRICTLY PROHIBITED: Using Armour for another person's data. You will NOT use Armour to access, scan, monitor, intercept, investigate, or collect any data, identifier, file, account, credential, password, device, or digital asset belonging to another person, entity, or account without their explicit, informed, written consent. This includes — but is not limited to — scanning someone else's phone number, email address, domain, social-media handle, files, passwords, credentials, accounts, devices, or digital assets. Every scan, lookup, and check must be performed on datayou own or have explicit legal authorisation to analyse. The liability for any unauthorised scan is entirely yours.
- STRICTLY PROHIBITED: Hacking, malicious, or unlawful activity. You will NOT use Armour to conduct, facilitate, assist, prepare for, or support any hacking, cracking, intrusion, unauthorised access, surveillance, stalking, harassment, fraud, identity theft, social-engineering, phishing, vishing, smishing, malware distribution, botnet operation, ransomware deployment, denial-of-service, credential-stuffing, brute-force, password-guessing, account-takeover, or any other malicious, unlawful, harmful, or unauthorised activity against any person, system, network, service, or organisation. Armour is a defensive security tool — using it offensively is forbidden.
- Per-scan attestation. Every scan intake form requires you to tick two boxes before submission: (1) you have read and accept these Terms and the Privacy Policy, and (2) the data you are entering is your own and only yours or you have the owner's explicit permission. You acknowledge that scanning anyone else's identifiers, accounts, files, or domains without their explicit permission may be illegal in your jurisdiction and may violate data-protection, privacy, computer-fraud, and cybercrime laws. If you do so, neither Kromeum nor the Armour app is responsible — the liability is entirely yours.
- Don't try to weaponize the scanner — e.g. submitting illegal malware samples, child sexual abuse material, or targeting third-party systems for harm.
- Keep your account credentials secure. You're responsible for activity on your account.
- Don't resell, scrape, or build a competing service from Armour's API responses.
- You are responsible for the safety of the data on your own device. Because your scan history, sandbox reports, backups, and chats live in your browser's local storage, their security is in your hands — keep your device locked, your OS patched, and your backup passphrase safe. We cannot recover, restore, or protect data we never had a copy of. If your device is lost, stolen, compromised, or wiped, that data is gone.
- Third-party scanners are a separate matter. The one exception to "we don't have your data" is what gets sent to the third-party scanning engines listed in section 6. Any liability for how those providers handle, retain, or share that data falls on them, governed by their privacy policies and terms — not Armour. If a third-party provider mishandles data, your remedy is with that provider directly, subject to whatever their policies allow.
Enforcement. Any breach of this section may result in immediate and permanent account termination, deletion of all associated data, reporting to law-enforcement or regulatory authorities where required by law, and pursuit of all available civil and criminal remedies — including injunctive relief, statutory damages, and attorneys' fees.
10. Limitation of liability
Armour is provided "as is" and "as available". We do not warrant that scans will be 100% accurate or that the service will be uninterrupted. To the maximum extent permitted by law, we are not liable for indirect or consequential damages — including data loss, business loss, or harm caused by malware or phishing that our scanner failed to detect. You agree that you use Armour as one layer of defense among many, not as a sole safeguard.
10b. Subscriptions, auto-renewal & cancellation
Paid Armour subscriptions are sold and billed primarily through the Apple App Store and Google Play. All payments, renewals, refunds and cancellations are governed by the applicable store's terms. Subscriptions auto-renew at the end of each billing period at the then-current price unless you cancel in your store account at least 24 hours before the renewal date. Cancelling stops the next charge; you keep paid access until the end of the current period and are then moved to the free tier. Promotional pricing (e.g. "70% off your first period") applies only to the first billing period; subsequent renewals are at the regular price shown on the pricing page.
Complimentary and lifetime access. Kromeum may also grant free, promotional, or lifetime paid-tier access directly at its sole discretion — for example to team members, partners, or users who have been explicitly invited. These grants are recorded in our systems and are subject to the same terms as store-bought subscriptions, including the right to downgrade or revoke the grant in cases of abuse, fraud, or breach of these terms.
10c. Email Protection, Forward & Protect and the Gmail add-on
- Opt-in and read-only. Connecting Gmail uses the read-only gmail.readonly scope; Outlook uses Mail.Read. While scanning is on, ARMOUR's servers check new mail on a schedule. ARMOUR never sends, deletes, labels or moves your mail.
- "What we can see". You choose Senders only, Headers or Full read-only, and ARMOUR only fetches or analyses what that level allows — for connected mailboxes, forwarded mail and the add-on alike.
- Forward & Protect. You forward the emails you choose to your personal scan.kromeum.com address using your own Gmail filter; ARMOUR never signs into your Gmail. Deleting the address deletes its alerts and discards later mail unread.
- Gmail add-on. Reads only the email you have open, when you open it or tap Scan. You can unlink or revoke it at any time.
- Storage. Message bodies are never stored. Only flagged results are saved, encrypted, as described in §4 and the Privacy Policy. Disconnecting a mailbox deletes its alerts (and, for Gmail, revokes our access at Google).
- Your mailboxes only. You may only connect, forward or scan mailboxes you own or are authorised to use (see §9).
- Verdicts are advisory. Emails are rated Safe, Caution, Suspicious or Malicious (likely scam). Like every Armour result, these are guidance, not a guarantee (see §3b).
- Early access. Gmail direct-connect is currently invite-only early access while Google completes verification, and may change or be withdrawn.
10c-1. Vexa AI
- Vexa's answers are AI-generated guidance and may be wrong.
- They aren't legal, financial or professional advice.
- Vexa will never ask you for passwords, codes or payments. Never follow instructions to do so from anyone claiming to be Vexa.
- You must not try to manipulate, prompt-inject or jailbreak Vexa (see §9).
10d. Call & Text Protection — what we can and cannot do
Call & Text Protection does not intercept calls, block calls, or read your messaging apps. Caller lookups are performed only on numbers you submit. SMS analysis checks only text you paste in, on our servers, and doesn't store it. Reputation sources are best-effort — a "legit" verdict is not a guarantee, and an "unknown" verdict does not mean safe. Treat verdicts as guidance, not as proof.
11. Intellectual property, anti-copying & idea protection
The Armour app, the Kromeum brand, the Vexa AI assistant persona, the scan-pipeline architecture, the in-app browser shield design, the "Mega Scan / Ultimate Scan" product concepts, all source code, object code, UI designs, layouts, copy, iconography, logos, color systems, animations, illustrations, sound effects, scan-result schemas, sandbox-report formats, marketing materials, documentation, and every other expressive or functional element of the product are the exclusive property of Kromeum and are protected by copyright, trademark, trade-secret, database-right, and other applicable intellectual-property laws worldwide.
You are strictly prohibited from doing any of the following, in whole or in part, with or without modification, for commercial or non-commercial purposes:
- Copying, cloning, mirroring, re-skinning, or producing a derivative of the Armour app, its UI, its flows, its copy, or its visual identity.
- Reverse-engineering, decompiling, disassembling, or attempting to extract the source code, scan logic, prompts, threat-intel routing, or any internal protocol of the app, except to the limited extent such activity is expressly permitted by applicable law that cannot be contractually waived.
- Re-publishing the app — or any meaningful portion of it — under a different name, brand, or distributor on any app store, website, repository, or distribution channel.
- Using the Armour, Kromeum, or Vexa names, logos, icons, or trade dress in your own product, marketing, store listing, domain name, social handle, or any user-facing surface, in a way likely to cause confusion, association, or implied endorsement.
- Taking, adapting, or commercialising the ideas, concepts, product structure, feature set, scan-pipeline design, or business model presented in this app for the purpose of building a competing product, whether by you, your employer, your client, an AI you operate, or any third party acting on your behalf.
- Scraping, harvesting, or systematically extracting copy, layouts, prompts, AI conversations, scan reports, or other content from the app to train, fine-tune, evaluate, or seed any machine-learning model, dataset, embedding store, or generative system.
- Removing, hiding, or altering any copyright, trademark, "All Rights Reserved", or attribution notice that appears in the app, in exported reports, or in any associated material.
- Sub-licensing, renting, leasing, lending, selling, reselling, transferring, or otherwise commercially exploiting your access to the app or any part of it.
No implied license. Nothing in these Terms — and nothing about the fact that the app is publicly downloadable — grants you any license, right, title, or interest, by implication, estoppel, or otherwise, in or to any of Kromeum's intellectual property, beyond the limited, revocable, non-exclusive, non-transferable right to install and personally use the app for its intended purpose.
Feedback. If you send us suggestions, feature requests, bug reports, or other feedback, you grant Kromeum a perpetual, irrevocable, worldwide, royalty-free license to use, modify, and incorporate that feedback into the product without any obligation or compensation to you. You agree that feedback is not confidential to you.
Enforcement. Violations of this section cause irreparable harm for which monetary damages alone are inadequate. We may seek immediate injunctive relief in any court of competent jurisdiction, in addition to any other remedies available at law or in equity (including statutory damages, attorneys' fees, account termination, store-listing takedowns, and DMCA / equivalent regional notices). You agree to indemnify and hold Kromeum harmless from any claim arising out of your breach of this section.
All rights not expressly granted are reserved by Kromeum.
12. Confidentiality, IP protection & non-circumvention (NDNCA)
This section is the consumer-facing form of our Non-Disclosure, Non-Circumvention, Non-Use, Non-Access & Intellectual Property Protection Agreement ("NDNCA"). It applies automatically and unconditionally to every person who downloads, installs, opens, accesses, views, demos, screenshots, screen-records, observes, or is otherwise exposed to the Armour app, the Kromeum platform, or any related material — whether or not you have signed any separate document. There is no opt-out form, no signature page, and no negotiable terms: by reaching this app in any form you accept this section in full. Ignorance of this section is not a defence. The full long-form NDNCA (v2) governs internally and is incorporated here by reference; in any conflict between the plain-English summary below and the long-form NDNCA, the long-form NDNCA controls.
12.1 Sole ownership
Armour, Vexa, and the Kromeum platform — including every line of source, compiled and object code, algorithms, cryptographic protocols, AI system prompts and tool-loop design, scan pipelines, YARA rules and heuristics, the zero-knowledge vault architecture (passphrase derivation, AES-GCM, ML-KEM-768 sharing), UI/UX designs, wireframes, mockups, branding (Armour, Vexa, Kromeum names, logos, taglines, trade dress), business plans, pricing models, financial projections, trade secrets and know-how — are the sole, exclusive, and absolute property of the Owner (Kromeum / Unitech Enterprise). No right, title, licence, or interest of any kind passes to you by downloading, using, viewing, observing, or paying for the app. All rights not expressly granted in these Terms are reserved.
All rights reserved. All intellectual property in and to Armour, Vexa, Kromeum and every component, asset and derivative of the platform is explicitly and exclusively owned by the Owner and the Owner's company (Kromeum / Unitech Enterprise). No co-ownership, joint authorship, work-for-hire claim, implied licence, fair-use carve-out, or transfer of any kind arises in favour of any user, contributor, viewer, contractor, collaborator, platform, vendor or third party — ever. Any attempt to claim, register or assert ownership of any part of this IP by anyone other than the Owner is null, void, and a material breach of these Terms.
No third party — including any development platform, no-code or low-code tool, AI-assisted development environment, hosting provider, cloud platform, or SaaS we may have used to build or host Armour — has any ownership, licence, or rights in or to the Armour app, the Kromeum brand, or any IP we created. The identity of any such tool is itself confidential.
12.2 What is "confidential"
"Confidential Information" means all information, data, materials, knowledge and communications of any kind — tangible or intangible, oral or written, observed or overheard, digital or physical, marked or unmarked — that relates in any way to Armour, Kromeum, Vexa, our business, technology, strategies, or IP. Marking is not required; everything about the platform is confidential by default. This expressly includes information you acquire by observation or inference (watching a demo, viewing a screen, inferring implementation from response times or UI behaviour), and information retained in your memory after exposure.
12.3 All deployments are protected — named or not
Protection covers every form in which Armour or Kromeum exists or may exist in future, including production, staging, development, preview, demo, beta (TestFlight, Play Internal/Closed/Open), internal, white-label, mirrored, embedded, API-only, archived, cached, and any future deployment, on any domain, subdomain, IP address, hosting provider, app-store listing, screen recording, screenshare or device. The fact that a particular URL, environment, or access point is not named in these Terms does not exclude it from protection. Accessing any instance of the platform without prior written authorisation from the Owner is a breach — including via any development platform's own domain, preview system, or shared workspace, even if no login is required and even if you have a legitimate account with that tool.
12.4 What you must not do
- No disclosure or publication — do not share, transmit, post, broadcast, reference, describe, or allude to Armour's features, technology, design, business model, pricing, or any Confidential Information through any medium (social media, forums, academic papers, podcasts, press, hypothetical or anonymised framing). No disclosure to co-workers, advisors, lawyers, accountants, investors or family without our prior written consent.
- No copying, recording or capture — do not photograph, screenshot, screen-record, transcribe, sketch, annotate or otherwise capture any part of the app or any display showing it, by any means (cameras, phones, wearables, smart glasses, recording pens, hidden devices, contact-lens displays, neural interfaces, or any technology now existing or invented in future).
- No competitive / derivative use — do not use anything you see in Armour to build, design, develop, fund, advise or contribute to a competing product or service. Do not treat any observed UI/UX, feature concept, product idea or business model as inspiration, reference or template. Do not reverse-engineer, decompile, disassemble or reconstruct any aspect of the platform by any means. Do not file any patent, trademark, design or IP application incorporating or inspired by the platform. Do not register any domain, brand name, app name or entity similar to Armour, Vexa or Kromeum.
- No circumvention — do not contact, approach or engage our partners, investors, distributors, vendors or employees, and do not attempt to acquire Armour or its IP through any channel other than directly with the Owner, without prior written consent.
- No scraping, crawling or probing — do not use any automated script, bot, crawler, spider, scraper, or data-extraction tool against any deployment of the platform. Do not perform port scanning, service enumeration, subdomain discovery, certificate-transparency mining, WHOIS analysis, traffic analysis, packet sniffing or any reconnaissance directed at our infrastructure or any associated person or system.
- No AI input or AI reverse-engineering — do not input, feed, transmit, upload or expose any Confidential Information to any AI, ML, LLM, generative-AI, neural-network or analytical system (including ChatGPT, Gemini, Copilot, Claude, Perplexity, Grok, DeepSeek or any successor), and do not use any AI tool to reconstruct, approximate or replicate any aspect of the platform from observed outputs or behaviours.
- No unauthorised access — do not attempt to access the app, our systems, infrastructure or data by any unauthorised means, including hacking, cracking, brute-force or credential-stuffing attacks, exploitation of any vulnerability or misconfiguration, SQL injection, XSS, CSRF, SSRF, malware, spyware, session hijacking, social engineering, phishing or vishing of our staff or vendors, abuse of expired or revoked credentials, or access to any backup, snapshot or disaster-recovery copy.
- No dark-web or illicit acquisition — do not acquire, purchase, solicit or receive any Confidential Information, source code, credentials or data relating to us through any dark-web marketplace, underground forum, data broker, data-dump site or any illicit channel; do not commission or fund any third party to do so; and do not use any data you know, suspect, or have reason to believe was obtained unlawfully, regardless of how it reached you.
Inspiration is strictly forbidden. Drawing inspiration, ideas, concepts, aesthetics, structure, flows, terminology, naming, or any creative or technical cue from Armour, Vexa, Kromeum or any part of this app — whether to build a new product, feature, service, side-project, hobby project, portfolio piece, academic work, prompt, dataset or anything else — is strictly prohibited and absolutely forbidden. This applies whether the resulting work is commercial or non-commercial, public or private, free or paid, identical, similar, adjacent, transformed, abstracted or "merely inspired by". Any such use is a material breach and the Owner will pursue all available legal action, including civil lawsuits, injunctions, account of profits, criminal complaints and cross-border enforcement, without further notice.
12.5 No public-source, prior-knowledge or independent-development exemption
Information about Armour, Kromeum or the platform that happens to be discoverable through search engines, social media, press, App Store / Play Store listings, GitHub, archived sites, a development platform's preview system, or any other public source remains Confidential Information for the purposes of this section if it originates from us or the platform. You may not use the public live app for competitive analysis, reverse-engineering, benchmarking or feature cataloguing. If, after exposure to Confidential Information, you build anything substantially similar to or informed by what was disclosed, that work product is presumed to be derived from Confidential Information; the burden of proving otherwise lies entirely with you. Any claim of prior knowledge requires verifiable written evidence dated before any disclosure.
12.6 Recording, wearables & screen-sharing
In any meeting, demo, call or session where the platform is shown or discussed, no recording of any kind may be made without our prior explicit written consent for that specific recording. You may not share, broadcast or make available any screen capture or screen-share of any deployment to anyone we have not expressly authorised in writing.
12.7 Remedies, liquidated damages & criminal exposure
You acknowledge that any breach of this section will cause us irreparable harm for which monetary damages alone are inadequate, and that we are entitled to seek immediate injunctive relief, specific performance and all equitable remedies in any court of competent jurisdiction, without posting bond and without proving actual financial loss. In addition to all other remedies, you agree to the following liquidated damages as a genuine pre-estimate of loss (cumulative, not in substitution):
- Unauthorised disclosure to a single recipient — USD 1,000,000 per disclosure.
- Use of Confidential Information in a competing product — USD 10,000,000 plus all profits derived.
- Any recording in violation of §12.6 — USD 500,000 per recording.
- Any AI-input breach under §12.4 — USD 2,000,000 per instance.
- Unauthorised access attempt (hacking or illicit means) — USD 5,000,000 per incident plus all legal costs.
- Access via dark web or commissioned theft — USD 10,000,000 per incident.
- Filing any IP application incorporating Confidential Information — USD 5,000,000 plus assignment of all such applications to the Owner.
- Each day a breach continues unremediated — USD 50,000 per day.
You will fully indemnify, defend and hold harmless the Owner, Kromeum, Unitech Enterprise, and their successors from all claims, losses, damages, costs, legal fees and liabilities arising from your breach. The prevailing party in any action recovers all legal costs and attorneys' fees on a full indemnity basis. You acknowledge that breaches may also constitute criminal offences under the Indian Information Technology Act 2000 (as amended), the US Computer Fraud and Abuse Act, the UK Computer Misuse Act 1990, the US Defend Trade Secrets Act, the EU Trade Secrets Directive, applicable copyright and wiretapping laws, and equivalent legislation in every jurisdiction. We will report suspected breaches to law enforcement in any applicable jurisdiction without notice to you.
12.8 Perpetual term & multi-jurisdictional enforcement
Your obligations under this section are perpetual — they continue in full force forever, with no expiry, no sunset, and no right of termination by you, and bind your heirs, personal representatives, successors and assigns. This section is governed by the laws of India (the Owner's primary jurisdiction) and is additionally enforceable in any jurisdiction where you are domiciled, where any breach occurs, or where the Owner chooses to bring proceedings. You irrevocably submit to the jurisdiction of any court selected by the Owner and, to the maximum extent permitted by law, waive any right to a jury trial in any action arising from or related to this section. The Owner may apply for emergency injunctive relief or a temporary restraining order from any court of competent jurisdiction without prior notice and without completing any dispute-resolution process.
12.9 Binding effect of access
Accessing, viewing, downloading, installing, opening, receiving or being present during any disclosure relating to Armour or Kromeum — whether or not any separate document has been executed — constitutes acceptance of this section and creates a binding obligation to the fullest extent permitted by law. Electronic acceptance (including by tapping "I agree" in the app) is valid and binding and is as enforceable as a wet-ink signature.
13. Changes to these terms
We can update these terms when we add features, change providers, or comply with law. When we change anything material, we'll bump the version above and ask you to re-accept the next time you sign in. Trivial fixes (typos, clarifications) won't trigger a re-prompt.
14. Contact
Questions, data-deletion requests, or legal notices:
ops@kromeum.com
By creating an Armour account, you confirm you've read and agree to these Terms (version 2026-09-30) and our Privacy Policy.
© 2026 Kromeum. All Rights Reserved.
