Tracker Detect Pro Privacy Notice

Tag Tracker LLC · Last updated August 4, 2026

This notice explains how the Tracker Detect Pro Android app processes information. It is intentionally specific to the app and does not govern a separate promotional or checkout website.

Version coverage. This notice describes Tracker Detect Pro 10.0.1 and later. Version 10.0.1 introduced the Installed App Checks consent, local per-app VPN attribution, expanded self-exclusion, and Android Auto pause-and-resume behavior described below. Earlier installed builds may not provide those exact controls or protections. Update through Google Play when version 10.0.1 or later is offered to your device.

Individual scan details stay local

Visible third-party app names and package identifiers, file names and paths, finding details, per-app VPN attribution, and blocked-domain history are not sent to Tag Tracker, analytics providers, or advertisers. Aggregate counts and status fields are sent as described below.

Allowed DNS uses encrypted resolution

Tracking Protection answers blocked requests on the device. Allowed query names go to Cloudflare over DNS-over-HTTPS without the requesting app's package identity.

Declining is supported

You can choose Not now for Installed App Checks. File scanning remains available, app checks are skipped, and VPN attribution is shown as Unknown app.

Tracker Detect excludes itself

The app filters its own package, private storage, caches, and Tracker Detect export locations before security results are saved or shown.

1. Information processed on your device

Tracker Detect processes the following information locally when you use the related feature:

The individual records above remain in app storage until you delete them through an in-app control, clear the app's storage in Android Settings, or uninstall the app. The app can send aggregate scan and protection counts, status, and timing fields without the underlying app, file, domain, or detection identifiers, as described under Information sent off device. Opening a detection map requests map tiles from CARTO or OpenStreetMap infrastructure.

2. Installed App Checks

In version 10.0.1 and later, Tracker Detect asks for affirmative consent before Installed App Checks reads information about apps that Android makes visible to Tracker Detect. This is not a complete list of every installed app. Depending on what Android exposes, the app may read:

This information is used only for an on-device security check and local Tracking Protection labels. Package identifiers, app labels, permissions, installer details, individual finding details, and per-app/domain history are kept in app-private storage excluded from Android backup and device transfer. They are not included in analytics, advertising, support, or DNS requests. PostHog receives only the number of flagged apps and files when a security scan completes, not their names, package identifiers, paths, or findings.

You can choose Not now. File scanning remains available, Installed App Checks is skipped, and Tracking Protection uses Unknown app when an app cannot or should not be identified.

Tracker Detect filters its own package and known Tracker Detect storage locations, including its private files and caches and exported media under Pictures/TrackerDetect. Its own files and package are not retained or displayed as suspicious scan results.

3. Tracking Protection VPN and Android Auto

Tracking Protection uses Android's VPN service as an on-device DNS firewall. It does not decrypt or inspect the contents of web pages, messages, or other application traffic.

In version 10.0.1 and later, per-app labels and blocked-domain history remain in app-private, no-backup storage. When Installed App Checks is declined or revoked, new blocks are recorded as Unknown app. PostHog can receive VPN lifecycle events and session-level query, block, encrypted-resolution fallback, and error counts, but not query names, domain names, or package identifiers.

Tracking Protection pauses while Android reports an active Android Auto projection and resumes after the projection disconnects. This avoids routing conflicts with Android Auto. Other network conditions can still affect compatibility; you can turn Tracking Protection off at any time.

4. Information sent off device

The app uses the following active services for the stated purposes. A service receives only the fields needed for the feature or event described here.

Google Play
Product and offer identifiers, purchase status, transaction timing, price, purchase tokens, restores, and the Google account context managed by Google Play to operate purchases and subscriptions.
Adapty
Pseudonymous app and subscription identifiers, products and offers, trial or purchase status, entitlements, transaction timing, price and revenue information, purchase tokens, acquisition context, and the onboarding intent described below, used to operate subscriptions and measure purchase performance.
Google Firebase Analytics and Crashlytics
App-instance and pseudonymous identifiers, device and operating-system metadata, app version, acquisition and feature events, crash stack traces, and diagnostics used to understand reliability and core app use.
PostHog
Pseudonymous identifiers, app version and acquisition context, onboarding progress and selections, paywall and purchase events, support or cancellation events, and diagnostics used for activation, retention, troubleshooting, and product measurement. Scan events can include the trigger, requested and actual duration, all-clear or threats-found status, total detected-device count, and suspicious- device count. Security-scan events include only flagged-app and flagged-file counts. VPN events can include start or stop, session query and block counts, encrypted-resolution fallback and error counts, error operation and type, and whether a custom-domain rule was added or removed. These events do not contain app names, package identifiers, file names or paths, DNS query names, domain values, or detection identifiers.
Onboarding intent sent to PostHog and Adapty
If the intent screen is shown, selecting an option immediately continues onboarding and sends one of four values: “I know I’m being tracked” (known_threat), “I’m not sure, but I want to check” (suspected_tracking), “I want better privacy awareness” (privacy_guardian), or “I misplaced my own device” (find_my_device). The first two can reveal a personal-safety concern. Some acquisition routes skip this screen.
Meta
Pseudonymous advertising, installation, or device identifiers and selected trial, purchase, and app events used for advertising attribution and campaign measurement.
Cloudflare public DNS
Allowed DNS query names and ordinary network metadata needed to resolve them. The requesting app's package identity is not sent. Cloudflare states that public-resolver transaction and debug logs are deleted within 25 hours, although aggregated information may be kept longer.
CARTO and OpenStreetMap map infrastructure
When you open a detection map, Tracker Detect requests CARTO Dark Matter or OpenStreetMap Mapnik map tiles. The requested tile coordinates identify the displayed geographic area, and the selected tile service receives ordinary network information such as your IP address.
Tag Tracker customer-experience services hosted on Vercel
If you choose support chat, cancellation feedback, purchase support, or an emailed safety guide, the app sends the text or email address you submit and the context needed to provide that service. Context can include device manufacturer and model; Android and app version; locale and time zone; install and update timing; onboarding-completed status; premium, subscription, and acquisition context; and a PostHog pseudonymous identifier. Protection context is limited to whether background, VPN, and private- DNS protection are enabled, the aggregate blocked-this-week count, and last-block time. Scan context is limited to the all-time scan count and the last scan's time, all-clear or threats-found status, and aggregate AirTag, other-tracker, Bluetooth-device, suspicious-device, and total-device counts. It does not contain the names, package identifiers, paths, domains, or detection identifiers behind those counts.
Opening this static policy page also sends ordinary web-request metadata, such as IP address, browser information, requested path, and time, to Vercel as the hosting provider.
Gmail
If you request the Tracker Safety Guide by email, Tag Tracker's currently configured Gmail delivery route receives your email address and the requested guide message so it can send the email. Provider routing can change; this notice will be updated if a different production email processor is used.
OpenAI and Make
When you choose in-app support chat, messages and relevant troubleshooting or subscription context may be processed to generate and route a response and provide support observability.
Individual third-party installed-app details, app-security and local-file finding details, package-to-domain attribution, blocked-domain history, DNS query names, and detection identifiers are excluded from these transmitted categories. Only the aggregate counters and status fields identified above are sent.

5. Android permissions

The app requests permissions only when needed for the feature you choose. These can include Bluetooth scan and connection, nearby-device access, location, notifications, file or photo access, background location, foreground-service access, and the Android VPN consent screen. Android Settings lets you review or revoke system permissions. Revoking a required permission can make the related feature unavailable.

Installed App Checks uses only package visibility Android permits through the app's narrow declarations. The app does not request Android's broad QUERY_ALL_PACKAGES permission in version 10.0.1.

6. Retention and deletion

Local information

Local information stays on your device until you use a feature-specific delete control, clear Tracker Detect storage, or uninstall the app. Turning off Installed App Checks in version 10.0.1 and later revokes future app/package reads, clears the saved app-security scan, and deletes existing per-app, package, and blocked- domain Tracking Protection statistics. It does not clear the separate aggregate weekly block count or last-block time. If Tracking Protection remains on, later blocks are recorded as Unknown app.

Turning Tracking Protection off stops new filtering but does not by itself erase earlier local records. To remove all app-private data, use Android Settings > Apps > Tracker Detect > Storage & cache > Clear storage (wording varies by device), or uninstall Tracker Detect.

Information held off device

Cloudflare's public-resolver timing is described above. Google Play, Adapty, Firebase, PostHog, Meta, CARTO, OpenStreetMap infrastructure, Vercel, Gmail, OpenAI, and Make retain information under their own service terms and privacy notices. There is no single retention period for every off-device category. Tag Tracker keeps support and feedback records while a request is open and as needed for follow-up; subscription and transaction records as needed for entitlement, dispute, accounting, fraud-prevention, and legal duties; and pseudonymous analytics and operational records as needed to measure the app, diagnose reliability, protect the service, and maintain necessary backups. Provider records are not guaranteed to be erased by an in-app action.

You can request access, correction, or deletion for matching records under Tag Tracker's control by using the contact in Privacy requests and contact. We may need identifiers that let us locate the record and verify the request. Legal, security, fraud-prevention, financial, dispute, and backup requirements may limit or delay deletion. Emailing us does not erase information stored only on your device; use the device controls above for that information.

7. Your choices

If the onboarding intent screen is shown, one of the four options listed above must be selected to continue; some acquisition routes skip the screen. Changing or clearing the locally saved answer does not delete an event already sent to PostHog or Adapty. A matching pseudonymous record may require a provider or app identifier to locate.

Version 10.0.1 does not provide a separate in-app opt-out for Firebase, PostHog, Meta, or Adapty event collection. Limiting or resetting Android's advertising identifier can reduce advertising identification, but it does not stop all analytics, crash, subscription, or product events. Uninstalling the app stops future app-originated events but does not automatically delete records already held off device. Use the contact below to make an applicable privacy request.

Depending on where you live, applicable law may provide additional rights over information controlled by Tag Tracker. Contact us to make a request. We do not sell individual third-party installed-app details and package identifiers, local file findings, per-app VPN attribution, blocked-domain history, or DNS query names; those categories do not leave the app.

8. Children

Tracker Detect is not directed to children under 13, and we do not knowingly request direct contact information from a child under 13. If you are a parent or guardian and believe a child submitted personal information to a Tag Tracker service, contact us so we can investigate and take appropriate action.

9. Privacy requests and contact

Depending on applicable law, you may have rights to request access, correction, deletion, restriction, portability, or objection for personal information controlled by Tag Tracker LLC. Email support@tagtracker.tech. Include only the identifiers needed to locate the relevant record; do not email passwords, payment-card details, or recovery codes.

Tag Tracker LLC
30 N Gould Street, Ste R
Sheridan, WY 82801
United States

10. Changes to this notice

We may update this notice when app features, providers, or legal requirements change. We will update the date at the top and provide additional notice when required.