Privacy Policy
Effective August 2, 2026 · Applies to the ThreatSweep Android application
Scope of this policy
This Privacy Policy describes how ThreatSweep ("the app," "we," "our") handles information when you install and use the app on an Android device. ThreatSweep is a security auditing and app management utility: it inspects the apps already installed on your device, evaluates their permissions and system-level risk signals, and gives you shortcuts to native Android settings.
We do not operate user accounts, and there is no sign-up, login, or profile associated with ThreatSweep. This policy is written to satisfy Google Play's Data Safety and Developer Program Policy disclosure requirements.
Non-Personal Data: what we do not collect
ThreatSweep does not collect, request, store, or transmit any of the following:
- Your name, email address, phone number, or physical address
- Government IDs, account credentials, or authentication tokens
- Contacts, call logs, SMS content, or messages of any kind
- Precise or approximate location data
- Photos, media, or files stored on your device
- Advertising identifiers or cross-app tracking identifiers
The app does not include third-party advertising SDKs or analytics trackers that build a profile of you. Nothing in ThreatSweep is designed to identify you as an individual, and no data we do handle (described below) is ever linked back to a person.
App Hashes: the one thing that leaves your device
To check whether an installed app has a known bad reputation, ThreatSweep can compute a SHA-256 hash — a fixed-length, one-way cryptographic fingerprint — of an installed application's APK file. This hash is a string of 64 characters. It mathematically cannot be reversed back into the original file, and it contains no file content, code, or personal data.
Only this hash is sent, over HTTPS, to the VirusTotal API operated by VirusTotal (a Google-owned service), for the sole purpose of checking it against VirusTotal's public reputation database.
- ✓ The SHA-256 hash of the APK (e.g. 8f14e45f…)
- ✗ The APK file itself, or any part of its contents
- ✗ The app's name, package ID, or icon
- ✗ Your device identifier, IP address logging on our end, or account information
- ✗ Any other app's data, or your permission-audit results
This distinction — a non-reversible fingerprint versus the underlying file or personal data — is the basis for treating App Hashes as non-personal, non-identifying technical data under this policy.
Local processing: what never leaves your device
Every other function of ThreatSweep runs entirely locally, using Android's own on-device APIs:
- Reading the permission list for each installed app (via PackageManager)
- Calculating the device and per-app risk score
- Detecting root access (checking for su binaries, test-keys, and known root packages)
- Detecting whether USB/ADB debugging is currently enabled
- Reading storage and battery status to power the in-app shortcuts
None of the results from these checks — audit findings, risk scores, root status, or the list of apps on your device — are uploaded to ThreatSweep's servers or any third party. We do not operate a backend that stores audit history, and there is nothing for us to retain because it never reaches us in the first place.
Third-party services
ThreatSweep integrates two third-party services, each limited to a specific purpose:
Processes Premium subscription payments. Google, not ThreatSweep, handles your payment method and billing details under Google's own privacy policy.
Receives only SHA-256 hashes (see Section 03) for reputation lookups, subject to VirusTotal's own privacy policy and terms.
Permissions we request and why
Required to list and audit every installed app; without it Android would only show us apps we can already query by default, defeating the purpose of a full device audit.
Lets you uninstall an app flagged as risky directly from the audit results, through Android's standard uninstall confirmation.
Used to notify you when a new app is installed on your device, so it doesn't go unaudited.
Used only for Google Play Billing subscription checks and for sending SHA-256 hashes to VirusTotal, as described above.
Data retention & deletion
Because ThreatSweep does not operate servers that store your audit results, app list, or device information, there is no ThreatSweep-held record of your usage to retain or delete. Any data cached by the app (such as the last computed risk score) stays in local app storage on your device and is removed automatically when you uninstall the app, or immediately if you clear the app's storage from Android Settings.
Children's privacy
ThreatSweep is a general-audience system utility not directed at children, and we do not knowingly collect information from anyone, including children, because we do not collect personal information from any user.
Changes to this policy
If we change how ThreatSweep handles data, we will update this page and revise the effective date above. Material changes affecting how App Hashes or any future data category is handled will also be reflected in the app's Google Play Data Safety section.
Contact
Questions about this policy or ThreatSweep's data handling can be sent to [email protected].