ThreatLens – Privacy Policy
Introduction
ThreatLens ("the App") is a mobile security scanner. This policy explains what data the app accesses, what is sent to external services, and how your privacy is protected.
Data Accessed On-Device (Never Sent to Our Servers)
The App reads the following data solely on your device for security analysis:
Installed applications — via the QUERY_ALL_PACKAGES permission, to scan apps for known vulnerabilities and permission risks.
App usage statistics — via the PACKAGE_USAGE_STATS permission, to assess security posture of running apps.
None of this data leaves your device or is stored by us.
Data Sent to Third-Party Services
1. Password Breach Check (HaveIBeenPwned)
When you use the Password Leak Scanner feature:
Your password is hashed locally using SHA-1.
Only the first 5 characters of that hash are sent to api.pwnedpasswords.com (k-anonymity model). Your full password and full hash are never transmitted.
HaveIBeenPwned's privacy policy applies: https://haveibeenpwned.com/Privacy
2. CVE Vulnerability Database (NIST NVD)
The App fetches publicly available Android CVE records from https://services.nvd.nist.gov. No user data is sent in this request.
Data We Do NOT Collect
We do not collect, store, or transmit your name, email, location, contacts, or any personally identifiable information.
We have no servers that receive or store user data.
We do not use advertising SDKs or analytics tracking.
Children's Privacy
The App does not knowingly collect data from children under 13.
Changes to This Policy
We may update this policy. Continued use of the App after changes constitutes acceptance of the updated policy.
Contact
Questions? Email: vdwapps@gmail.com

Comments
Post a Comment