Privacy Policy
Last updated: 2026-09-21
AppXpose is a privacy scanner, so it would be absurd to be vague about our own data handling. This page describes what stays on your phone, what reaches our servers, who else sees it, and how long we keep it. If anything here is unclear, email mahere@appxpose.app.
1. Who is responsible
The controller responsible for processing your data is:
Fluxera LLC
75 E 3rd St, Ste 7
Sheridan, Wyoming 82801
United States
mahere@appxpose.app
Fluxera LLC operates the AppXpose Android app and the appxpose.app website. Data protection questions and data subject requests go to the address above.
2. What data we process
When you scan an app, the following is sent to our servers:
- Metadata of the scanned app: package name, app name, version, category, size, install and update dates, installer source, the full list of permissions it requests and which of those are granted, the hash of its signing certificate, its data usage, and its icon. This is data about the app, not about you, but it does describe which apps you have installed.
- Tracker findings: the names of trackers matched on your device, plus, for unknown code, the first three segments of the package path (for example
com.example.analytics). Never full class lists, never bytecode. - Device fingerprint: a one way SHA-256 hash of your Android ID together with device model and manufacturer. It enforces the free tier quota and cannot be reversed to identify you. It changes on reinstall or factory reset.
- Quota and entitlement: scans used in the current weekly window, and whether the device has an active Pro or GUARD entitlement.
- Purchase data: the Google Play purchase token and product ID, so we can verify a purchase with Google and unlock the right tier.
- IP address: seen by our servers for every request, as with any internet service. We store it only in hashed form, for abuse prevention.
- Community votes and comments: stored without author identity, with a profanity filter.
- Contact form and feedback: the name, email address, subject and message you enter into the contact form yourself, and the rating and text you send as in-app feedback.
- Usage and diagnostic data: the app's build number with every request, which onboarding steps you completed and how long they took, whether the device hit the scan limit, which offers it was shown and, when we test two variants of an offer against each other, which variant the device was dealt. All of it is tied to the device fingerprint, not to a name.
- Partner links: if you installed the app through a partner's link, the app stores that partner's code, sends it along with requests, and reports the install and any later purchase (including the purchase token) against that code. Partners see the number, product, amount and status of purchases attributed to them, never your device fingerprint.
GUARD subscribers additionally send the list of installed package names once a day, so the service can tell you when one of your apps changes. Package names only, nothing else. We do not store the list itself, only how many packages were checked and which alerts were delivered. The Spyware Check, when you start it, sends the package names together with the hashes of their signing certificates. Neither the list nor the matches are stored, only a per device counter of how often and when the check last ran, and daily totals that carry no device reference. Search terms you enter in the App Index are sent to answer the search and are not stored.
Partner program. If you apply as a partner, you send us your name, email address, social profiles and a description of your content. For accepted partners we keep an account with name, email, username, a salted password hash, and the payouts made.
The appxpose.app website
- Delivery: Cloudflare serves the pages and, as a technical necessity, sees your IP address and browser type.
- Audience measurement: Ahrefs Web Analytics, without cookies. It receives the page you opened, the referring page, browser and device type, and your IP address, from which, according to Ahrefs, only the country is derived and which is not stored.
- Fonts: the typefaces are served from our own server. Nothing is loaded from Google Fonts.
- Survey widget: the footer loads a script from feedbackfirst.dev, whose operator sees your IP address when it loads. It receives content only if you fill in the survey.
- Clicks on the Play Store button: we count them on our own server, with the page path and a hash of your IP address so that repeated clicks are not counted twice. If you arrive through a partner link, that click is likewise recorded against the partner's code with an IP hash.
- No cookies: we set none. Only the partner dashboard keeps a login token in your browser's local storage after sign in, without which the login cannot work.
3. What we never process
- No account needed, no phone number. We hold an email address only if you give it to us yourself: in the contact form or in a partner application.
- No app content: no messages, photos, files, or anything from inside the apps you scan.
- No location, contacts, call logs, or browsing history.
- No IMEI, MAC address, or other persistent hardware identifier.
- No tracking across other apps or websites, and no advertising or analytics SDK that runs in the background. AppXpose itself never reads the Google Advertising ID. The AdMob SDK may read it, but only after you tap "Watch Ad" and only for free users. See Section 6.
- No APK bytecode. Scanning reads it on your device and it never leaves.
4. What runs where
Tracker detection runs on your device. Parsing the DEX bytecode, matching signatures and mapping permissions all happen locally, and the bytes of the apps you scan are never uploaded.
The written report is not produced locally. The app metadata and permission list described in Section 2 are sent to our servers and from there to our AI provider, which generates the risk explanation. Reports are cached on our servers so that scanning a popular app is instant for the next person. If you would rather nothing left your device at all, this app cannot offer that, and we would rather say so plainly than imply otherwise.
5. Legal bases
Under Article 6(1) GDPR we rely on:
- Performance of a contract, Art. 6(1)(b): producing the scan you asked for, enforcing the free tier quota, and delivering the Pro or GUARD features you paid for.
- Legitimate interests, Art. 6(1)(f): keeping the service available and preventing abuse, improving tracker detection from aggregated findings (see Section 8), and measuring how the app, our offers and the website are used, including tests of offer variants, and attributing referrals to partners. Our interest is running a functioning security product; the data involved describes applications rather than people.
- Consent, Art. 6(1)(a): rewarded advertising, which only ever runs after you tap "Watch Ad" and accept the ad consent dialog, and push notifications, which need your permission. You can withdraw either at any time.
- Legal obligation, Art. 6(1)(c): retaining transaction records where tax law requires it.
6. Third parties and international transfers
We use the following processors and services:
- Cloudflare (USA, global edge): hosts our Worker, the D1 database and edge caching.
- Anthropic (USA): generates the natural language risk explanation. It receives the app metadata and permission list, including the app's install and update dates and its data usage on your device, never bytecode, never your device fingerprint, never your IP.
- Google Play Billing: handles all purchases. We never see your card details.
- Google Play Integrity: confirms the request comes from a genuine, unmodified install, which is how we stop forged premium claims.
- Google Play Install Referrer: tells us which campaign or partner link led to an install.
- Google AdMob (free tier only): rewarded video ads, and only those. No banners, no interstitials, no app open ads. Premium and GUARD users do not initialize the SDK at all. When a free user watches a rewarded ad, Google receives device model, OS version, app version, language and region, IP address, the Google Advertising ID unless you have reset it, and ad interaction data.
- RevenueCat (USA): payment analytics in observer mode. Receives the Play purchase token, product ID, price and currency, with a random anonymous ID. It never sees your name, email, card details or scan data, and cannot initiate or modify purchases.
- Have I Been Pwned: we only fetch its public list of known breaches and match it against app vendors on our own server. Nothing about you is sent, not even an email address.
- MalwareBazaar / abuse.ch and Koodous: malware reputation lookups. They receive only the SHA-256 hash of a scanned APK.
- Zoho Mail (EU): delivers contact form messages and partner applications to us.
- Ahrefs (Singapore), feedbackfirst.dev: on the website only, see Section 2.
Transfers outside the EEA. Fluxera LLC is based in the United States, and several processors above are too, so your data is processed outside the EEA. These transfers are based on the European Commission's Standard Contractual Clauses, or on the EU-U.S. Data Privacy Framework where the provider is certified under it. You can request a copy of the safeguards from the address in Section 1.
For every external tool and data source AppXpose relies on, see the Credits & Data Sources page.
7. How long we keep things
- Scan reports: kept indefinitely in our cache. A report describes an application, not a person, and reuse is what makes a scan instant for the next user.
- Device record and everything tied to the fingerprint (quota and entitlement, the device's scan history and tracker findings, purchase mapping, integrity checks, onboarding and offer data, delivered GUARD alerts): deleted when you ask, and automatically six months after the device last used the app. Devices with a purchase are excepted; their records follow tax and accounting retention. The findings from your scans (app, trackers, permissions, risk score) are kept without any reference to the device and feed the aggregated statistics described in Section 8. See Data Deletion.
- Request logs: 30 days.
- Error and quota logs: 180 days.
- Signature sync records: 12 months, so we can detect bulk extraction of our tracker database after the fact.
- Hashed IP counters for abuse prevention: at most 7 days. IP hashes attached to community votes, partner link clicks and website clicks are kept as long as the record they belong to. Votes and comments are stored with that IP hash only, not with your device fingerprint.
- Purchase records: for as long as tax and accounting law requires.
- Contact messages, feedback and partner applications: until your request is resolved, then deleted on request.
8. Aggregated app statistics
Every scan makes the next one better. From the findings we build aggregated statistics about applications: which trackers appear in which apps, which permissions tend to occur together, how a category behaves on average. This is the basis of our tracker database and of the research we publish.
These statistics describe apps, not people. They contain no device fingerprint, no IP address, and nothing that links a finding back to the person who scanned it. We may publish them, and we may make them available to third parties such as researchers, journalists or commercial partners, including for a fee.
What we do not do, and are telling you now rather than quietly changing later: we do not sell or share your device fingerprint, your list of installed apps, or your usage of the app. Those stay with us.
9. Your rights
Under the GDPR you have the right to access your data, to have it rectified or erased, to restrict or object to its processing, and to receive it in a portable format. Where processing rests on consent, you may withdraw that consent at any time without affecting what happened before.
One practical note: we hold no name, email or account, so the only handle we have on your data is the device fingerprint. To exercise a right you generally need to send it to us. You can copy it in the app under Settings, About, Device ID. Without it we usually cannot locate any record, and we will not ask you for additional identifying information just to make a lookup possible.
- Request deletion of your device record: see Data Deletion.
- Turn off notifications in the app under Settings, or in Android's app settings.
- Reset or delete your advertising ID in Android Settings, Privacy, Ads.
- Uninstall the app at any time, which removes all local data.
You also have the right to lodge a complaint with a data protection supervisory authority, in the EU or EEA member state of your residence, place of work, or the place of the alleged infringement.
10. Children
AppXpose is not directed at children. In the EEA, where processing rests on consent, we address users aged 16 and over, or younger with the consent of a parent or guardian, depending on the age set by the member state. Elsewhere the app is not directed at children under 13. We do not knowingly collect data from children.
11. Changes
If we change this policy, the "Last updated" date at the top changes too. Material changes are announced in the app.
12. Contact
Privacy questions, data deletion requests, or anything else: mahere@appxpose.app, or by post to Fluxera LLC at the address in Section 1.