Privacy Policy
Effective date: [DATE] · Last updated: October 8, 2026
Draft. This policy is awaiting review by a lawyer before Elder Guard launches. Its effective date will be added then.
Elder Guard is made by Upton Software Ltd. Liability Company (“we”, “us”) and is one app with two roles, Guardian and Elder. It helps a trusted person (a “Guardian”) protect someone they care for (a “Elder”) from scam texts, calls, and emails. This policy explains what the app handles and why. It applies to Elder Guard in either role.
Our core principle
Elder Guard is built to keep personal content on the phones involved. Messages, call details, and emails are stored on devices, not on our servers. When information is sent between an Elder and a Guardian, it is end-to-end encrypted: it is scrambled on the sending device and can only be read by the intended Guardian’s device. Our relay service only ever holds this scrambled data briefly, in transit, and cannot read it. Our servers also hold a small amount of account and subscription information, described under “Accounts” and “Subscriptions” below.
Consent
Elder Guard in the Elder role is installed with the knowledge and agreement of the person who uses that phone. Before any Guardian is connected, Elder Guard in the Elder role shows, in plain language, what will be shared and with whom, and the person must agree. On Android, Elder Guard in the Elder role always runs visibly, with an ongoing notification, and is never hidden. Elder Guard is not intended for covert monitoring, and must not be used to monitor anyone without their knowledge and consent.
Information Elder Guard handles in the Elder role
The person using the Elder's phone signs in to Elder Guard in the Elder role with their own account (see “Accounts” below) before anything else happens. Elder Guard works differently on Android and on iPhone in the Elder role, because iPhone does not let an app read texts or screen calls. The table below describes what Elder Guard handles on Android in the Elder role; its iPhone behavior is described after it.
| Data | Why | Where it goes |
|---|---|---|
| Incoming text messages (the sender and the preview shown in the message notification, once the person turns on notification access) | To detect and report likely scams to Guardians | On the Elder's device; forwarded end-to-end encrypted to Guardians the Elder’s settings allow |
| Incoming call details (number, time) | To screen, block, and report likely scam calls | Same as above |
| Incoming email (sender, content) — only if the person sets up an email account | To detect and report likely scam emails | Same as above; the email account password (or sign-in token) is stored only in the device’s secure storage and used only to sign in to that mailbox |
| Contacts | To tell a known contact from a stranger, so trusted people are not flagged or blocked | Read on the device only; not transmitted |
| Links (web addresses) in incoming texts and emails | To warn the person about links to known dangerous or look-alike websites | Checked on the Elder's device only; never transmitted. To do this, Elder Guard in the Elder role periodically downloads a public list of known dangerous websites from a third-party threat-intelligence feed (currently URLhaus by abuse.ch). That download sends no information about the person or their messages, though, like any download, abuse.ch, which runs URLhaus, can see the phone’s IP address. |
| Public scam-number list for call blocking | To stop calls from phone numbers that many people reported to the U.S. Federal Trade Commission (only when a Guardian turns it on) | Downloaded by the Elder's device itself, directly from ftc.gov. The short list used for blocking is worked out on the Elder's device and kept there only. It is never uploaded or shown to Guardians. Guardians see only whether this option is on and the day of the list, never the numbers. ftc.gov can see the phone’s internet address, like any website. Source: United States Federal Trade Commission, www.ftc.gov. |
| Links the person chooses to check (“Check a link”, or shared to Elder from another app) | To tell the person whether a link looks dangerous | Checked on the Elder's device only. Sent to the person’s Guardians, end-to-end encrypted, only if the person taps “Ask my Guardians” |
| Websites a Guardian marks as trusted or to warn about | To fine-tune those link warnings | Sent end-to-end encrypted from the Guardian to the Elder; stored on both devices |
| Device security keys | To encrypt and sign messages between devices | Stored in the device’s secure storage; never leave the device |
On iPhone, Elder Guard in the Elder role:
- does not read, forward or report texts. A text-filter extension, run by iOS for texts from unknown senders, sorts likely scams into Junk on the phone, and nothing about those texts leaves the phone;
- does not receive or report calls. A call-blocking extension blocks the numbers a Guardian lists, and Elder never learns about the calls;
- when a Guardian turns on “Block known scam numbers” for that phone, also blocks calls from numbers many people reported to the U.S. Federal Trade Commission. Elder Guard itself downloads those public lists directly from ftc.gov (ftc.gov can see the phone’s internet address, like any website), works out a short list on the phone, takes out the numbers a Guardian trusts and the contacts it can see, and gives it to the call-blocking extension. Before iOS 18, iOS blocks a listed number even if it is a saved contact, so this is done only while Elder can see all of the person’s contacts, and is paused otherwise; from iOS 18, iOS itself lets saved contacts through. The lists stay on the phone and are never uploaded or shown to Guardians. Elder tells Guardians only whether the option is on and the date of its list. iPhone keeps those numbers until Elder next runs, so turning it off, or a list that gets too old, takes effect then. Source: United States Federal Trade Commission, www.ftc.gov;
- checks email, if the person sets up an email account, when the app is opened and from time to time in the background when iOS allows;
- has a Safari site blocker and “Elder Guard in Safari”, which have Safari stop known dangerous websites and websites a Guardian warned about, without seeing the pages the person opens;
- has a share option, “Check with Elder Guard”, which checks a shared link or text on the phone, and sends it to Guardians, end-to-end encrypted, only if the person taps “Ask my Guardians”;
- may receive a Guardian’s answer to such a question inside the wake-up notification, still encrypted, and opens it on the phone.
Elder Guard in Safari on iPhone
“Elder Guard in Safari” on iPhone has no sign-in, does not pair with anyone, makes no downloads or other network requests of its own, and does not read web pages or email. It asks Elder Guard in the Elder role on the same phone which websites to stop, and Safari does the stopping.
Information Elder Guard handles in the Guardian role
Elder Guard in the Guardian role receives the reports an Elder forwards and stores them on the Guardian’s device. Guardians set what to watch, block, or report, and how long reports are kept. Guardians sign in with an email and password, a Google account or, on iPhone, an Apple account (via Firebase Authentication) to identify their device to the relay.
If a Guardian turns on the weekly digest, the app builds it on the Guardian’s phone from counts only: how many reports arrived, and how many looked like scams, per day and type. No sender, number, address or message text is kept for the digest, and it is not sent anywhere.
What we do not do
- We do not store your messages, calls, emails, or contacts on our servers.
- We cannot read the content exchanged between an Elder and Guardians.
- We do not sell personal information.
- We do not use your content for advertising.
Accounts
Everyone who uses Elder Guard signs in with an account: a Guardian using Elder Guard in the Guardian role, and the protected person using Elder Guard in the Elder role on their phone. Sign-in is by email and password, by Google or, on iPhone, by Apple, through Firebase Authentication. An account is either a Guardian’s or a protected person’s, never both.
Our servers store the account itself (the sign-in details Firebase Authentication holds, such as the email address you signed in with) and which of the two it is. Each device has its own keys and its own pairing with each Guardian. Guardian lists, the names a Guardian gives each protected person, reports and settings are kept on the devices, not on our servers.
Subscriptions
Guardians subscribe through Google Play or the App Store, which handle the payment; we never see card or payment details. To keep a subscription working across an Elder’s devices, our servers store:
- For the paying Guardian’s account: which store (Google or Apple) and product were purchased, whether the subscription is active, and when the paid period ends.
- A link between the paying account and each protected device it covers, identified only by that device’s ID (the protected person’s account ID followed by a random tag) — not a name, phone number, or any message content.
- For each protected device: until when it is covered. Elder Guard, when signed in, can read this (so the app in the Guardian role can show whether protection is on); it does not say who is paying.
- A purchase identifier used only to match renewal notices from the store: a one-way, scrambled tag for Google Play purchases, or the store’s own transaction ID for App Store purchases.
Relay messages travel through separate mailboxes depending on what they are for, so our servers can tell whether a message was housekeeping (pairing, the Guardian list, leaving) or everyday traffic (alerts, settings) — but the content of every message stays end-to-end encrypted and unreadable to us either way.
When a Guardian deletes their account, their subscription records and the links to the devices they covered are deleted automatically as part of account deletion. The same happens when a protected person deletes their account: the records for that account’s devices, including their cover and the link to the paying Guardian, are deleted, which frees the paying Guardian’s place for another device.
Service providers
We use Google Firebase for sign-in, for the encrypted relay (Cloud Firestore), and for wake-up notifications (Cloud Messaging, which passes them on through Apple’s and Google’s push services). Wake-up notifications carry no readable content: on iPhone, a Guardian’s answer to an Elder’s question can travel inside one, still encrypted, and only that phone can open it. Firebase processes only encrypted message data and account identifiers on our behalf. See Google’s privacy terms at firebase.google.com/support/privacy.
Retention
Guardians choose how long forwarded reports are kept on their device (from “Do not save” up to one year); items are deleted automatically when that period passes. Encrypted messages waiting in the relay are deleted after delivery, and any left undelivered expire automatically.
Your choices and rights
- The person using the Elder's phone can open Elder Guard in the Elder role at any time to see who protects the phone and review this information.
- The person using an Elder's phone can remove protection at any time. Their Guardians are told, and the data Elder Guard kept on that device is deleted.
- Uninstalling an app removes the data stored by that app on that device.
- You may delete your account and associated data at any time — in Elder Guard in the Guardian role (Settings → Delete account & data), in Elder Guard in the Elder role (menu → Remove protection & delete data, with “Also delete my account” ticked) or via our account deletion page. See that page for full details.
- Depending on where you live, you may have rights to access, correct, or delete personal information (for example under GDPR or CCPA). Contact us to exercise them.
Children
Elder Guard is designed for adults. It is not directed to children under 13, and we do not knowingly collect their information.
Changes
We may update this policy; we will change the “Last updated” date and, for material changes, notify you in the app.
Contact
Upton Software Ltd. Liability Company, 8735 Dunwoody Place, Ste N, Atlanta, GA 30350, United States
Questions or requests:
elderguardadmin@elderguard.info