Data Deletion
Last updated: 2026-09-21
AppXpose is built so there is almost nothing to delete in the first place. Using the app requires no name, email address or phone number. What sits on our servers is tied to a device fingerprint. This page exists so you can get rid of it — and so Google Play can verify that the option exists. For background on what we store and why, read the Privacy Policy.
1. What's actually stored on our servers
The following is tied to your device fingerprint:
- Device fingerprint — a one-way hash of device characteristics. It cannot be reversed to identify you.
- Quota and entitlement — scans used, bonus scans earned via rewarded ads or sharing with their cooldown timestamps, and whether the device has a Pro or GUARD entitlement.
- Scan history — which apps this device scanned, with risk score and time, plus the trackers, permissions, installer source and certificate hash found for each app.
- Purchase mapping — the Google Play purchase token, product and amount, linked to the device the purchase was made on.
- Usage and diagnostic data — completed onboarding steps, offers shown, the variant dealt in offer tests, scan limits reached, Play Integrity results, and request and error logs.
- GUARD and Spyware Check — how many packages were checked and which alerts were delivered, and how often the Spyware Check ran. We do not store the list of your installed apps.
- Partner attribution — only if you installed the app through a partner link: the install and purchase recorded against that partner code.
- Community votes and comments — only if you actively voted or commented. Stored without author identity and without the device fingerprint, only with a hash of the IP address.
None of it contains a name, email address, location, chat history or app contents. We hold an email address only if you gave it to us yourself: through the contact form or a partner application. It is not linked to your device, see point 5.
2. The fastest way: uninstall
Uninstalling the AppXpose app removes 100% of the local data on your device — scan history, cached results, GUARD events, settings, encrypted preferences, everything. Android handles this automatically.
The server-side records tied to your device fingerprint are not affected by this at first. They are deleted automatically six months after the device last used the app. If you want them removed sooner, use the request flow below, and copy the fingerprint before you uninstall.
3. Request server-side deletion
To have your server-side records removed before that, send us an email:
Subject
Data Deletion Request
In the body, include
- Your device fingerprint (open AppXpose → Settings → About → tap "Device ID" to copy it).
- Optional: which device model, so we can confirm we deleted the right one.
You don't need an account or any login. The fingerprint is the only thing that ties data to your device, and you can copy it directly from inside the app.
4. What we delete
When we process your request, we remove everything listed in point 1 that is tied to your fingerprint:
- Device record with quota, bonus scans, cooldowns and entitlement (subject to point 6 below)
- The link between your device and its scan history and tracker findings. The findings themselves (app, trackers, permissions, risk score) are kept without any device reference, see below.
- Usage and diagnostic data, logs, GUARD and Spyware Check counters
- The link between your device and a partner attribution
- The mapping of purchases to your device
What remains are findings and statistics about apps that no longer relate to any device, and purchase records where tax and accounting law requires us to keep them. Community votes and comments cannot be matched to your device, because they were never stored with the fingerprint. If you want a comment removed, tell us the app and the wording.
5. What is not tied to your device
- No email and no name linked to your device. If you gave us an email address through the contact form or a partner application, we delete that data when you ask us from that address.
- No location, contacts, photos, or media.
- No content of the apps you scanned (DEX parsing is local-only).
- No Google Advertising ID is held on our servers. AppXpose itself never reads the GAID. The Google AdMob SDK may read it for free users who voluntarily watch a rewarded ad, but that data goes to Google, not to us — see the Privacy Policy Section 6.
6. Subscription and Google Play purchases
If you have an active Pro or GUARD subscription, deleting your server-side record does not cancel or refund your Google Play subscription. You need to manage that separately:
- Cancel a subscription: Play Store → Profile → Payments & subscriptions → Subscriptions.
- Request a refund: Play Store refund policy.
We never see your card details — Google Play handles all payment data on its own systems, which we cannot delete from. Refer to Google's privacy policy for that side.
7. How long it takes
Server-side deletion is processed manually by the developer. Expect a response and confirmation within 30 days, usually much faster. If you don't hear back within 30 days, please send a follow-up email — it may have been caught by a spam filter.
8. Children
AppXpose is not directed at children. In the EEA, where processing rests on consent, we address users aged 16 and over; elsewhere the app is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has used the app and want their server-side fingerprint removed, contact us using the same address above.
9. Contact
Data deletion, privacy questions, or anything else: mahere@appxpose.app