Tracker Detect Pro Privacy Notice
This notice explains how the Tracker Detect Pro Android app processes information. It is intentionally specific to the app and does not govern a separate promotional or checkout website.
Individual scan details stay local
Visible third-party app names and package identifiers, file names and paths, finding details, per-app VPN attribution, and blocked-domain history are not sent to Tag Tracker, analytics providers, or advertisers. Aggregate counts and status fields are sent as described below.
Allowed DNS uses encrypted resolution
Tracking Protection answers blocked requests on the device. Allowed query names go to Cloudflare over DNS-over-HTTPS without the requesting app's package identity.
Declining is supported
You can choose Not now for Installed App Checks. File scanning remains available, app checks are skipped, and VPN attribution is shown as Unknown app.
Tracker Detect excludes itself
The app filters its own package, private storage, caches, and Tracker Detect export locations before security results are saved or shown.
1. Information processed on your device
Tracker Detect processes the following information locally when you use the related feature:
- Bluetooth scan results, nearby-device identifiers and signal strength.
- Detection history and, if location permission is granted, the coordinates attached to a detection.
- Files and media you ask the security scanner to inspect, plus the resulting findings.
- Hidden photos, app settings, blocklists, aggregate protection counts, and other feature state.
- For version 10.0.1 and later, Android-visible app details and local VPN attribution described below.
The individual records above remain in app storage until you delete them through an in-app control, clear the app's storage in Android Settings, or uninstall the app. The app can send aggregate scan and protection counts, status, and timing fields without the underlying app, file, domain, or detection identifiers, as described under Information sent off device. Opening a detection map requests map tiles from CARTO or OpenStreetMap infrastructure.
2. Installed App Checks
In version 10.0.1 and later, Tracker Detect asks for affirmative consent before Installed App Checks reads information about apps that Android makes visible to Tracker Detect. This is not a complete list of every installed app. Depending on what Android exposes, the app may read:
- package identifier and app label;
- requested permissions and whether the app has a launcher entry;
- installation source and installation age; and
- the connection owner Android exposes for local DNS attribution.
This information is used only for an on-device security check and local Tracking Protection labels. Package identifiers, app labels, permissions, installer details, individual finding details, and per-app/domain history are kept in app-private storage excluded from Android backup and device transfer. They are not included in analytics, advertising, support, or DNS requests. PostHog receives only the number of flagged apps and files when a security scan completes, not their names, package identifiers, paths, or findings.
You can choose Not now. File scanning remains available, Installed App Checks is skipped, and Tracking Protection uses Unknown app when an app cannot or should not be identified.
Tracker Detect filters its own package and known Tracker Detect storage locations, including its private
files and caches and exported media under Pictures/TrackerDetect. Its own files and package are
not retained or displayed as suspicious scan results.
3. Tracking Protection VPN and Android Auto
Tracking Protection uses Android's VPN service as an on-device DNS firewall. It does not decrypt or inspect the contents of web pages, messages, or other application traffic.
- DNS query names are compared with an on-device blocklist.
- Blocked queries are answered locally.
- Allowed query names are sent to Cloudflare's public resolver over encrypted DNS-over-HTTPS.
- The requesting package identity is not sent to Cloudflare.
- Tag Tracker does not receive DNS query names or use VPN traffic for advertising.
In version 10.0.1 and later, per-app labels and blocked-domain history remain in app-private, no-backup storage. When Installed App Checks is declined or revoked, new blocks are recorded as Unknown app. PostHog can receive VPN lifecycle events and session-level query, block, encrypted-resolution fallback, and error counts, but not query names, domain names, or package identifiers.
Tracking Protection pauses while Android reports an active Android Auto projection and resumes after the projection disconnects. This avoids routing conflicts with Android Auto. Other network conditions can still affect compatibility; you can turn Tracking Protection off at any time.
4. Information sent off device
The app uses the following active services for the stated purposes. A service receives only the fields needed for the feature or event described here.
- Google Play
- Product and offer identifiers, purchase status, transaction timing, price, purchase tokens, restores, and the Google account context managed by Google Play to operate purchases and subscriptions.
- Adapty
- Pseudonymous app and subscription identifiers, products and offers, trial or purchase status, entitlements, transaction timing, price and revenue information, purchase tokens, acquisition context, and the onboarding intent described below, used to operate subscriptions and measure purchase performance.
- Google Firebase Analytics and Crashlytics
- App-instance and pseudonymous identifiers, device and operating-system metadata, app version, acquisition and feature events, crash stack traces, and diagnostics used to understand reliability and core app use.
- PostHog
- Pseudonymous identifiers, app version and acquisition context, onboarding progress and selections, paywall and purchase events, support or cancellation events, and diagnostics used for activation, retention, troubleshooting, and product measurement. Scan events can include the trigger, requested and actual duration, all-clear or threats-found status, total detected-device count, and suspicious- device count. Security-scan events include only flagged-app and flagged-file counts. VPN events can include start or stop, session query and block counts, encrypted-resolution fallback and error counts, error operation and type, and whether a custom-domain rule was added or removed. These events do not contain app names, package identifiers, file names or paths, DNS query names, domain values, or detection identifiers.
- Onboarding intent sent to PostHog and Adapty
- If the intent screen is shown, selecting an option immediately continues onboarding and sends one of
four values: “I know I’m being tracked” (
known_threat), “I’m not sure, but I want to check” (suspected_tracking), “I want better privacy awareness” (privacy_guardian), or “I misplaced my own device” (find_my_device). The first two can reveal a personal-safety concern. Some acquisition routes skip this screen. - Meta
- Pseudonymous advertising, installation, or device identifiers and selected trial, purchase, and app events used for advertising attribution and campaign measurement.
- Cloudflare public DNS
- Allowed DNS query names and ordinary network metadata needed to resolve them. The requesting app's package identity is not sent. Cloudflare states that public-resolver transaction and debug logs are deleted within 25 hours, although aggregated information may be kept longer.
- CARTO and OpenStreetMap map infrastructure
- When you open a detection map, Tracker Detect requests CARTO Dark Matter or OpenStreetMap Mapnik map tiles. The requested tile coordinates identify the displayed geographic area, and the selected tile service receives ordinary network information such as your IP address.
- Tag Tracker customer-experience services hosted on Vercel
- If you choose support chat, cancellation feedback, purchase support, or an emailed safety guide, the app sends the text or email address you submit and the context needed to provide that service. Context can include device manufacturer and model; Android and app version; locale and time zone; install and update timing; onboarding-completed status; premium, subscription, and acquisition context; and a PostHog pseudonymous identifier. Protection context is limited to whether background, VPN, and private- DNS protection are enabled, the aggregate blocked-this-week count, and last-block time. Scan context is limited to the all-time scan count and the last scan's time, all-clear or threats-found status, and aggregate AirTag, other-tracker, Bluetooth-device, suspicious-device, and total-device counts. It does not contain the names, package identifiers, paths, domains, or detection identifiers behind those counts.
- Opening this static policy page also sends ordinary web-request metadata, such as IP address, browser information, requested path, and time, to Vercel as the hosting provider.
- Gmail
- If you request the Tracker Safety Guide by email, Tag Tracker's currently configured Gmail delivery route receives your email address and the requested guide message so it can send the email. Provider routing can change; this notice will be updated if a different production email processor is used.
- OpenAI and Make
- When you choose in-app support chat, messages and relevant troubleshooting or subscription context may be processed to generate and route a response and provide support observability.
5. Android permissions
The app requests permissions only when needed for the feature you choose. These can include Bluetooth scan and connection, nearby-device access, location, notifications, file or photo access, background location, foreground-service access, and the Android VPN consent screen. Android Settings lets you review or revoke system permissions. Revoking a required permission can make the related feature unavailable.
Installed App Checks uses only package visibility Android permits through the app's narrow declarations. The
app does not request Android's broad QUERY_ALL_PACKAGES permission in version 10.0.1.
6. Retention and deletion
Local information
Local information stays on your device until you use a feature-specific delete control, clear Tracker Detect storage, or uninstall the app. Turning off Installed App Checks in version 10.0.1 and later revokes future app/package reads, clears the saved app-security scan, and deletes existing per-app, package, and blocked- domain Tracking Protection statistics. It does not clear the separate aggregate weekly block count or last-block time. If Tracking Protection remains on, later blocks are recorded as Unknown app.
Turning Tracking Protection off stops new filtering but does not by itself erase earlier local records. To remove all app-private data, use Android Settings > Apps > Tracker Detect > Storage & cache > Clear storage (wording varies by device), or uninstall Tracker Detect.
Information held off device
Cloudflare's public-resolver timing is described above. Google Play, Adapty, Firebase, PostHog, Meta, CARTO, OpenStreetMap infrastructure, Vercel, Gmail, OpenAI, and Make retain information under their own service terms and privacy notices. There is no single retention period for every off-device category. Tag Tracker keeps support and feedback records while a request is open and as needed for follow-up; subscription and transaction records as needed for entitlement, dispute, accounting, fraud-prevention, and legal duties; and pseudonymous analytics and operational records as needed to measure the app, diagnose reliability, protect the service, and maintain necessary backups. Provider records are not guaranteed to be erased by an in-app action.
You can request access, correction, or deletion for matching records under Tag Tracker's control by using the contact in Privacy requests and contact. We may need identifiers that let us locate the record and verify the request. Legal, security, fraud-prevention, financial, dispute, and backup requirements may limit or delay deletion. Emailing us does not erase information stored only on your device; use the device controls above for that information.
7. Your choices
If the onboarding intent screen is shown, one of the four options listed above must be selected to continue; some acquisition routes skip the screen. Changing or clearing the locally saved answer does not delete an event already sent to PostHog or Adapty. A matching pseudonymous record may require a provider or app identifier to locate.
- Decline or later turn off Installed App Checks.
- Turn Tracking Protection off or revoke Android VPN consent.
- Review or revoke Android system permissions.
- Avoid opening a detection map if you do not want a map-tile request.
- Do not submit optional support text, cancellation feedback, or an email-guide request.
- Reset or limit the Android advertising identifier and advertising personalization in Android or Google settings, where available.
- Clear app storage or uninstall the app to remove app-private local data.
Version 10.0.1 does not provide a separate in-app opt-out for Firebase, PostHog, Meta, or Adapty event collection. Limiting or resetting Android's advertising identifier can reduce advertising identification, but it does not stop all analytics, crash, subscription, or product events. Uninstalling the app stops future app-originated events but does not automatically delete records already held off device. Use the contact below to make an applicable privacy request.
Depending on where you live, applicable law may provide additional rights over information controlled by Tag Tracker. Contact us to make a request. We do not sell individual third-party installed-app details and package identifiers, local file findings, per-app VPN attribution, blocked-domain history, or DNS query names; those categories do not leave the app.
8. Children
Tracker Detect is not directed to children under 13, and we do not knowingly request direct contact information from a child under 13. If you are a parent or guardian and believe a child submitted personal information to a Tag Tracker service, contact us so we can investigate and take appropriate action.
9. Privacy requests and contact
Depending on applicable law, you may have rights to request access, correction, deletion, restriction, portability, or objection for personal information controlled by Tag Tracker LLC. Email support@tagtracker.tech. Include only the identifiers needed to locate the relevant record; do not email passwords, payment-card details, or recovery codes.
Tag Tracker LLC30 N Gould Street, Ste R
Sheridan, WY 82801
United States
10. Changes to this notice
We may update this notice when app features, providers, or legal requirements change. We will update the date at the top and provide additional notice when required.