In final testing

NexGuard isn’t on Google Play yet. Join early access and we’ll send the install link the day it opens.

Home Solutions Privacy-conscious users

Privacy-first

Encrypted on device, and
no one over your shoulder

If you care where your data goes, NexGuard is designed for you. Nothing leaves your device unencrypted, nothing runs silent surveillance — link and message checks only happen when you paste something in — and where we do hold a key, such as media you choose to open on the web, the app and this site say so.

On-device encryption · No background reading · You start every check

Private by designTold plainly: which keys we hold, and which we never will.

Privacy-first

Protection that doesn’t watch you

On-device encryption

Files are sealed with a hardware-backed key before they’re ever stored.

No background reading

No silent access to SMS, calls, mic, camera or screen — ever.

You initiate every check

Scam and link analysis are paste-only, run on demand, when you ask.

Specifics

What “private by design” means here

The permissions we don’t ask for

NexGuard requests internet access, network state, notifications, biometric unlock, and a normal permission that reports how strong your screen lock is rated. That is the whole list. No SMS or call log, no contacts, no microphone, no camera, no background location, and no accessibility service.

No accessibility service, deliberately

Many security apps route features through Android’s accessibility API, which can read the content of every screen. We don’t. App Lock uses your device’s own authentication for NexGuard itself, and points you at Android’s Private Space or screen pinning for other apps — less powerful for us, and far less to trust us with.

Analysis starts when you start it

Link and message checks run on text you paste in, at the moment you paste it. Nothing watches your clipboard, your notifications or your messages waiting for something to inspect.

What we can still see

Honesty cuts both ways. We hold your account email, your subscription status, that a vault item exists and when it changed, and the scores your device reports. We can’t read the item, its name or its contents — but we’re not going to pretend the account itself is invisible.

Questions

Privacy-conscious users: common questions

Can anyone at NexGuard read my vault?
No. Items are encrypted on your device with a key held in the Android Keystore that cannot be exported, and the server receives only ciphertext. There is no staff tool, no support override and no recovery path that decrypts your data, because the key required to do it never reaches us.
Does NexGuard read my notifications or messages?
No. It holds no notification-listener access and no SMS or call-log permission, so there is nothing to read from. This is also why one-time codes stay private: an app that could read your notifications could read your login codes.
What happens if I forget my backup passphrase?
Your encrypted backup cannot be recovered. The passphrase derives the key, and it never leaves your device, so nobody — including us — can unlock it for you. That’s the direct cost of the design, and we’d rather state it than bury it.
Is my data sent to any third parties?
Security analysis runs on our own engines rather than a third-party threat feed, so your links and messages aren’t forwarded to an outside vendor for scoring. Paid plans are purchased through Google Play, which handles payment details — we never receive or store your card.

Get early access

Privacy you don’t have to configure

Get NexGuard free — encrypted on your device by default, with nothing watching in the background.