Privacy Policy (Direct APK)
Effective September 21, 2026 · Applies to the ThreatSweep Direct Android application (sideloaded APK)
Scope of this policy
This Privacy Policy describes how ThreatSweep ("the app," "we," "our") handles information when you install and use the direct sideloaded APK build of the app on an Android device. ThreatSweep is a security auditing and app management utility: it inspects the apps already installed on your device, evaluates their permissions and system-level risk signals, and gives you shortcuts to native Android settings.
To provide multi-device protection and Family Sharing, ThreatSweep allows you to create an account using your email address or a third-party provider like Google.
What we collect (and what we do not collect)
Because ThreatSweep Direct supports multi-device synchronization and Family Sharing, data handling is divided into two distinct categories:
A. Account Data (What we now collect):
- Email Address: Used as your login identity and for subscription communication.
- Authentication Identifiers: If you use "Sign in with Google," we receive a unique token from Google to verify your identity.
- Family Group Data: We store your unique User ID (UID) in a secure database if you create or join a Family Sharing group.
B. Security Audit Data (What we still DO NOT collect):
ThreatSweep does not collect, request, store, or transmit any of the following:
- Your physical address or phone number
- Government IDs, banking credentials, or payment card details
- Contacts, call logs, SMS content, or messages of any kind
- Precise or approximate location data
- Photos, media, or files stored on your device
- Advertising identifiers or cross-app tracking identifiers
The app does not include third-party advertising SDKs or analytics trackers that build a profile of you. Nothing in ThreatSweep's audit engine is designed to identify you as an individual, and no security audit data is ever linked back to a person or your account.
App Hashes: the one thing that leaves your device
To check whether an installed app has a known bad reputation, ThreatSweep can compute a SHA-256 hash — a fixed-length, one-way cryptographic fingerprint — of an installed application's APK file. This hash is a string of 64 characters. It mathematically cannot be reversed back into the original file, and it contains no file content, code, or personal data.
Only this hash is sent, over HTTPS, to the VirusTotal API operated by VirusTotal (a Google-owned service), for the sole purpose of checking it against VirusTotal's public reputation database.
- ✓ The SHA-256 hash of the APK (e.g. 8f14e45f…)
- ✗ The APK file itself, or any part of its contents
- ✗ The app's name, package ID, or icon
- ✗ Your device identifier, IP address logging on our end, or account information
- ✗ Any other app's data, or your permission-audit results
This distinction — a non-reversible fingerprint versus the underlying file or personal data — is the basis for treating App Hashes as non-personal, non-identifying technical data under this policy.
Local processing: what never leaves your device
Every other function of ThreatSweep runs entirely locally, using Android's own on-device APIs:
- Reading the permission list for each installed app (via PackageManager)
- Calculating the device and per-app risk score
- Detecting root access (checking for su binaries, test-keys, and known root packages)
- Detecting whether USB/ADB debugging is currently enabled
- Reading storage and battery status to power the in-app shortcuts
None of the results from these checks — audit findings, risk scores, root status, or the list of apps on your device — are uploaded to ThreatSweep's servers or any third party. We do not operate a backend that stores audit history, and there is nothing for us to retain because it never reaches us in the first place.
Third-party services
ThreatSweep Direct integrates the following third-party services, each limited to a specific purpose:
Used to manage your user account, secure your login, and store Family Sharing group memberships. Your data is protected by Google’s enterprise-grade security.
We use RevenueCat and Stripe to process and manage your Premium subscription. ThreatSweep does not see or store your credit card details; these are handled directly by Stripe. RevenueCat manages your "entitlement" (PRO status) using your unique account ID.
If you choose to sign in with Google, Google will share your email address and profile identity with us for the sole purpose of creating your ThreatSweep account.
Receives only SHA-256 hashes (see Section 03) for reputation lookups, subject to VirusTotal's own privacy policy and terms.
Permissions we request and why
Required to list and audit every installed app; without it Android would only show us apps we can already query by default, defeating the purpose of a full device audit.
Lets you uninstall an app flagged as risky directly from the audit results, through Android's standard uninstall confirmation.
Used to notify you when a new app is installed on your device, so it doesn't go unaudited.
Used for checking subscription status via RevenueCat, performing reputation lookups via VirusTotal, and synchronizing your account and Family Sharing status with our secure database.
Data retention & deletion
You may request the deletion of your account and all associated cloud data (Email, UID, and Family Group membership) at any time by contacting us at [email protected]. Deleting the app from your device does not automatically delete your cloud-hosted account information.
Because ThreatSweep does not operate servers that store your audit results, app list, or device information, there is no ThreatSweep-held record of your security scan usage to retain or delete. Any data cached by the app (such as the last computed risk score) stays in local app storage on your device and is removed automatically when you uninstall the app, or immediately if you clear the app's storage from Android Settings.
Children's privacy
ThreatSweep is a general-audience system utility not directed at children, and we do not knowingly collect personal information from children under 13 (or under 16 where applicable). If we discover that an account has been created by a child without parental consent, we will promptly delete the account and associated cloud data.
Changes to this policy
If we change how ThreatSweep handles data, we will update this page and revise the effective date above. Material changes affecting how your data is handled will be communicated through the app or website.
Contact
Questions about this policy, ThreatSweep's data handling, or account deletion requests can be sent to [email protected].