ShieldStep Limited — Registered in Kenya (PVT-A71MBLRO)
The Short Version: : ShieldStep is built on a privacy-first architecture. We never read your SMS messages, we never access your M-Pesa balance or transaction history, and we never share your personal data with third parties for advertising. All financial detection and trigger mitigation happen entirely locally on your device.
ShieldStep Limited ("ShieldStep", "we", "our", or "us") is committed to protecting your privacy. The only data transmitted to our secure operational servers consists of basic account registration parameters:
We use your registration data strictly to maintain, authenticate, and administer your account profile. Your phone number is utilized solely to route integrated M-Pesa Express transactions and verify active protection states. We never sell, distribute, rent, or lease your profile details to third-party marketing networks or analytics brokers.
ShieldStep operates on a strict Privacy-First, Data-Isolated Architecture. All screen scanning, string token comparisons, and transaction interception happen completely locally on your device.
Unlike traditional apps, ShieldStep explicitly rejects remote surveillance infrastructures. We do not collect, view, read, or upload your private text messages (SMS), personal bank balances, banking PINs, mobile money transaction histories, or generic browser activities. All validation loops occur entirely within the temporary, volatile memory of your local Android device and are never transmitted to our remote servers
To implement absolute, un-bypasable behavioral guardrails against gambling relapse and support addiction recovery, the App replaces traditional device administration models with sensitive system hooks. By activating the service, you explicitly grant consent for:
Operational Purpose: ShieldStep uses this API to ephemerally parse layout structures in real-time. It checks for targeted East African sportsbook signatures, gambling app packages, and mobile carrier-level menu pop-ups (specifically tracking the 'com.android.stk' SIM Toolkit payment pathway).
Anti-Bypass Enforcement: The Accessibility Service monitors system nodes inside the native Android Settings package to detect and dismiss immediate actions to force-stop or delete ShieldStep while an active subscription or a 24-hour cooling-off countdown is actively processing.
Data Privacy: All information processed by the Accessibility API is handled strictly in volatile memory. It is structurally isolated, never written to persistent disk storage, and never transmitted over an internet link.
Operational Purpose: This permission allows ShieldStep to superimpose an interface wrapper over active apps. When a blacklisted gambling intent is flagged, this layout displays your contractively requested 15-minute urge cool-down screen.
Data Privacy: No background interactions or keystrokes are recorded through this overlay layer.
When you initiate an application deactivation from within the ShieldStep user interface, your account state initializes a mandatory 24-hour cooling-off countdown window. Throughout these 24 hours, your profile configuration parameters remain active on our secure validation servers to guarantee the persistent execution of local device safeguards during critical urge sessions. Upon expiration of the 24-hour timer, your remote status is updated to inactive, system hooks are released, and normal application uninstallation capabilities are fully restored.
Under Kenyan data protection law (the Data Protection Act, 2019) and applicable regulations, you have the right to:
To exercise any of these rights, contact us at admin@shieldstep.co.ke. We will respond within 30 days.
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes via an in-app notification at least 14 days before the changes take effect. Your continued use of ShieldStep after the effective date of any changes constitutes your acceptance of the revised policy
ShieldStep Limited is registered in the Republic of Kenya (Company No: PVT-A71MBLRO, KRA PIN: P052552576N) and complies with Data Controller registration requirements under the Office of the Data Protection Commissioner (ODPC). Our designated Data Protection Officer can be reached at:
Email: admin@shieldstep.co.ke
We aim to respond to all privacy inquiries within 5 business days.