A security product should be the most trustworthy app you own.
Here is exactly how we protect TotalHeal itself, what we collect, what we never collect, and where your data lives.
Signed updates you can’t be tricked into installing
TotalHeal’s updates are delivered with The Update Framework (TUF), the open standard used to protect software supply chains. Separate signing keys — root, targets, snapshot and timestamp — sign metadata that expires on a schedule, so an attacker can’t replay an old, vulnerable version (anti-rollback) or freeze you on stale updates (anti-freeze). The root of trust is pinned inside the app.
Threat definitions are signed with an Ed25519 key whose public half is pinned in the app; a definitions file is used only if its signature, size and SHA-256 all match. Releases roll out in stages with automatic health checks, and can be paused or rolled back.
Checked on your device first. The cloud only when it helps.
Only the address or file fingerprint being checked ever leaves your device — never your browsing history or your files’ contents (except a suspicious file you’ve chosen to send for cloud analysis on a paid plan).
What TotalHeal collects
| What | Details |
|---|---|
| Account | Name and email from your TotalHeal ID, your plan, licence and invoices. |
| Devices | Device name, platform and OS version, app version, a random install ID, health score, which protections are on, definitions version, last scan time, last seen. |
| Detections | For a threat found on your device: the file’s SHA-256 fingerprint, detection name, engine, action taken and time. The file path is kept on your device; when it is sent with an event it is used only to show you your own history. |
| Web warnings | For a site the extension or app warned about: the site name (host), verdict and rule that fired — not the full address, and never sites that were simply allowed. |
| Cloud analysis (paid plans, when needed) | A suspicious file (up to 25 MB) is sent for deeper analysis. Its bytes are analysed and not stored; we keep the fingerprint and verdict. |
| Payments | Handled by our payment partner. We receive the payment status and an invoice reference, never your card or UPI PIN. |
What we never collect
- Your browsing history
- The contents of your documents, photos or messages
- Your keystrokes, screen or camera
- Contacts or location
- Data for advertising — we show no ads and never sell or rent your data
Protection runs on your device
Scanning, real-time protection, ransomware detection and most web checks happen locally. If our servers can’t be reached TotalHeal keeps protecting you with the definitions it already has, and it never blocks normal sites just because the cloud is down. Quarantined files are encrypted on your device (ChaCha20-Poly1305) so they can’t run, and you can restore them.
Your account and sign-in
- Sign-in uses OpenID Connect with PKCE. Your password is never seen by the TotalHeal app or this website.
- On your computer, the sign-in token is stored in the system keychain; the website keeps tokens only for the current browser tab.
- Revealing a product key in your account is logged so you can see when it happened.
Where your data lives
Account, licence and device data is stored on servers in India and processed under India’s Digital Personal Data Protection Act, 2023. Update files are served worldwide from a content delivery network; they contain no personal data. See the privacy policy for retention periods and your rights.
Open, licence-clean detection
We only build on permissively licensed components and rules (MIT, Apache-2.0, BSD, MPL). Public threat feeds we use are credited in the app. AI may help explain a detection; it never decides on its own.
Report a vulnerability
Found a security issue in TotalHeal, this website or our APIs? Email [email protected]. Please give us reasonable time to fix it before disclosure; we will acknowledge within 3 working days and keep you updated. Our security.txt has the details.
Questions about privacy? Write to [email protected].

