Short Summary
This policy applies to the Google Play version of EdgePhishGuard, version 1.0. The main phishing detection workflow runs locally on the Android device. EdgePhishGuard does not upload analyzed text, notifications, clipboard text, OCR text, QR codes, or analyzed URLs to external servers to decide whether content is phishing.
The app may store a local analysis history on the device and may use technical services such as Firebase Remote Config and Firebase Crashlytics for configuration, stability, and diagnostics.
1. Controller and Contact
Controller: EdgePhishGuard, a project developed and maintained by an independent developer.
Contact email: edgephishguard.support@gmail.com
You can use this email for privacy questions, data protection requests, rights requests, or questions about the data practices described in this policy.
2. Purpose of EdgePhishGuard
EdgePhishGuard is a mobile security tool intended to help users detect possible malicious links, suspicious messages, fraudulent QR codes, and text matching phishing patterns before interacting with them.
The app uses local analysis, heuristic rules, local blocklists, language identification, Google ML Kit, MediaPipe, and TensorFlow Lite. Its purpose is defensive, security-focused, and user-protective only.
3. Data the App May Access or Process
Depending on the features the user uses or enables, EdgePhishGuard may access or process the following data locally:
- Manually entered text: text or URLs that the user types or pastes into the app for analysis.
- Text shared with or opened in EdgePhishGuard: text, URLs, or content received through Android actions such as Share, Open with, or Process text.
- Clipboard: text that the user chooses to analyze through a manual paste or import action inside the app. EdgePhishGuard does not perform permanent silent clipboard monitoring.
- Notifications: title, text, expanded text, source app, app package, and posting time, only if the user enables Android notification access.
- Camera, QR, and OCR: images or frames processed temporarily to read QR codes or extract text through OCR. The app does not store camera images as personal photos.
- URLs, domains, and risk signals: links extracted from text, notifications, QR codes, or OCR to calculate risk locally.
- Local analysis history: date, source, preview, analyzed text or URL, content hash, primary domain, result, risk score, alert threshold, detected language, evidence tags, and technical analysis details.
- User preferences: alert thresholds, enabled or disabled modules, and local privacy or protection settings.
- Limited technical data: app version, Android version, device model, technical installation identifiers, crash logs, and metadata needed for remote configuration, stability, or file delivery.
The Google Play version is not designed to collect contacts, precise location, financial data, passwords, banking credentials, microphone data, personal photos, or a full inventory of installed apps.
4. Permissions, Access, and Purpose
| Permission or access | Purpose | User control |
|---|---|---|
| Camera | Scan QR codes and extract text through OCR to detect suspicious links or text. | Requires Android permission and is used when the user opens the scanning feature. |
| Notification access | Locally analyze notifications that may contain suspicious text or links. | Enabled manually in Android settings and revocable at any time. |
| System notifications | Show alerts when risk exceeds the configured threshold. | Can be revoked in Android or in app settings. |
| Internet / network | Download remote configuration, security parameters, or technical updates and send crash diagnostics when Crashlytics is integrated. | Content analyzed for phishing is not uploaded to make the risk decision. |
| Shared text, opened links, and manual clipboard input | Analyze content that the user explicitly sends to EdgePhishGuard. | Analysis starts through a user action or a user-enabled feature. |
5. Local Processing and On-Device Storage
The main detection engine is designed to run on the device. This includes text and URL analysis, language identification, QR scanning, OCR, heuristic rules, TensorFlow Lite models, and local blocklist lookups.
EdgePhishGuard may store a local history using SQLite/Room. This history may include the analyzed text or URL, a preview, content hash, input source, risk results, scores, evidence tags, and analysis details. This storage helps the user review previous analyses and understand why an alert was shown.
History and preferences remain on the device until the user clears history inside the app, deletes app data through Android, or uninstalls EdgePhishGuard. Cloud backup configuration excludes persisted private app data; local device-to-device transfer may migrate app data according to Android settings.
6. Data Sent Outside the Device
For the phishing decision, EdgePhishGuard does not send analyzed content off the device. In particular, it does not send notification text, manually entered text, clipboard text, OCR text, QR code contents, or analyzed URLs to a server to make the risk decision.
Some technical features may communicate with external services:
- Firebase Remote Config: may download configuration parameters, minimum supported version, latest version, and update settings. Google/Firebase may process technical data such as IP address, installation identifier, app version, device model, operating system version, and technical logs necessary to provide the service.
- Firebase Crashlytics: may receive crash reports, stack traces, app version, Android version, device model, technical state, and installation identifiers. EdgePhishGuard limits custom keys to technical metadata such as feature, operation, source, build type, and failure stage; it does not intentionally include user content, notifications, OCR text, clipboard text, or URLs in those keys.
- Firebase Hosting, GitHub, or another static host: may be used to publish this policy, distribute configuration files, lists, or updates. The hosting provider may process technical access logs such as IP address, date, requested resource, and user agent.
When Google Play Data Safety defines "collection" as transmitting data off the device, text, URLs, QR codes, OCR, and notifications processed only locally are not collected by EdgePhishGuard. Technical data transmitted to providers should still be declared consistently in the Data Safety listing.
7. Third Parties and Technical Providers
| Provider or technology | Use | Data processed |
|---|---|---|
| Google ML Kit, MediaPipe, and TensorFlow Lite | OCR, QR scanning, language identification, and local inference. | On-device processing for enabled features. |
| Firebase Remote Config | Remote configuration and version control. | Technical app, installation, device, and network data needed to provide the service. |
| Firebase Crashlytics | Crash diagnostics and stability monitoring. | Crash reports, traces, technical identifiers, and app/device metadata. |
| Firebase Hosting, GitHub, or another host | Publication of the policy and distribution of technical files. | Technical access logs processed by the provider. |
EdgePhishGuard does not sell personal data, does not use advertising, does not share analyzed content with advertisers, and does not use user content for personalized advertising.
8. Legal Basis
Where the General Data Protection Regulation or similar laws apply, processing is based on:
- Consent: for sensitive permissions or access such as camera, notifications, notification access, and optional features.
- Performance of a user-requested function: when the user enters text, shares content, opens a URL, or requests QR/OCR scanning.
- Legitimate interest: to keep the app secure, stable, and updated using limited technical data.
- Legal compliance: where necessary to respond to applicable legal obligations.
9. Retention and Deletion
- Local history: kept on the device until the user deletes it inside the app, clears app data, or uninstalls EdgePhishGuard.
- Local preferences: kept while the app is installed or until the user changes or deletes them.
- Crash reports: kept for the period necessary to diagnose and fix errors, according to the provider's settings and policies.
- Server logs: may be retained by hosting providers for security, operation, and legal compliance.
EdgePhishGuard does not require users to create an account. Therefore, there is no in-app account to delete. For requests about technical data processed outside the device, email edgephishguard.support@gmail.com.
10. User Rights and Controls
The user can:
- Grant or revoke permissions in Android settings.
- Enable or disable available protection modules.
- Change alert thresholds and local preferences.
- Clear local history inside the app.
- Remove local data by uninstalling the app or clearing app data through Android.
- Request access, rectification, erasure, restriction, or objection where applicable.
11. Security
EdgePhishGuard applies data minimization, local processing by default, and permission limitation to specific features. Technical communications with external providers should use secure connections such as HTTPS. Although reasonable measures are applied, no system can guarantee absolute security against every technical risk, operating system error, or device configuration issue.
12. Children
EdgePhishGuard is not specifically directed to children. The app does not intend to knowingly collect personal data from children or profile children for advertising. If you believe that a child's information has been processed inappropriately, contact the controller to request review or deletion where applicable.
13. International Transfers
Phishing analysis is mainly performed on the device. If external services such as Firebase, Google, or GitHub are used, limited technical data may be processed outside the European Economic Area. In that case, processing relies on the contractual, technical, and legal safeguards offered by the relevant provider.
14. Automated Decisions
EdgePhishGuard automatically calculates a phishing risk score and may show an alert when the risk exceeds the configured threshold. This decision does not produce legal effects for the user, does not make financial or legal decisions, and does not permanently block access to external services. The user remains in control of whether to review the alert, ignore the warning, or continue.
15. Changes to This Policy
This policy may be updated to reflect changes in the app, permissions, technical providers, Google Play requirements, or legal requirements. The latest update date will appear at the top of this page.
16. Contact
If you have questions about this policy or data processing in EdgePhishGuard, please contact: