EdgePhishGuard Privacy Policy

Android on-device anti-phishing application with local analysis of text, links, QR codes, OCR content, and notifications when the user enables that protection.

Last updated: June 23, 2026

Leer esta política en español

Short Summary

This policy applies to the Google Play version of EdgePhishGuard, version 1.0. The main phishing detection workflow runs locally on the Android device. EdgePhishGuard does not upload analyzed text, notifications, clipboard text, OCR text, QR codes, or analyzed URLs to external servers to decide whether content is phishing.

The app may store a local analysis history on the device and may use technical services such as Firebase Remote Config and Firebase Crashlytics for configuration, stability, and diagnostics.

1. Controller and Contact

Controller: EdgePhishGuard, a project developed and maintained by an independent developer.

Contact email: edgephishguard.support@gmail.com

You can use this email for privacy questions, data protection requests, rights requests, or questions about the data practices described in this policy.

2. Purpose of EdgePhishGuard

EdgePhishGuard is a mobile security tool intended to help users detect possible malicious links, suspicious messages, fraudulent QR codes, and text matching phishing patterns before interacting with them.

The app uses local analysis, heuristic rules, local blocklists, language identification, Google ML Kit, MediaPipe, and TensorFlow Lite. Its purpose is defensive, security-focused, and user-protective only.

3. Data the App May Access or Process

Depending on the features the user uses or enables, EdgePhishGuard may access or process the following data locally:

The Google Play version is not designed to collect contacts, precise location, financial data, passwords, banking credentials, microphone data, personal photos, or a full inventory of installed apps.

4. Permissions, Access, and Purpose

Permission or accessPurposeUser control
CameraScan QR codes and extract text through OCR to detect suspicious links or text.Requires Android permission and is used when the user opens the scanning feature.
Notification accessLocally analyze notifications that may contain suspicious text or links.Enabled manually in Android settings and revocable at any time.
System notificationsShow alerts when risk exceeds the configured threshold.Can be revoked in Android or in app settings.
Internet / networkDownload remote configuration, security parameters, or technical updates and send crash diagnostics when Crashlytics is integrated.Content analyzed for phishing is not uploaded to make the risk decision.
Shared text, opened links, and manual clipboard inputAnalyze content that the user explicitly sends to EdgePhishGuard.Analysis starts through a user action or a user-enabled feature.

5. Local Processing and On-Device Storage

The main detection engine is designed to run on the device. This includes text and URL analysis, language identification, QR scanning, OCR, heuristic rules, TensorFlow Lite models, and local blocklist lookups.

EdgePhishGuard may store a local history using SQLite/Room. This history may include the analyzed text or URL, a preview, content hash, input source, risk results, scores, evidence tags, and analysis details. This storage helps the user review previous analyses and understand why an alert was shown.

History and preferences remain on the device until the user clears history inside the app, deletes app data through Android, or uninstalls EdgePhishGuard. Cloud backup configuration excludes persisted private app data; local device-to-device transfer may migrate app data according to Android settings.

6. Data Sent Outside the Device

For the phishing decision, EdgePhishGuard does not send analyzed content off the device. In particular, it does not send notification text, manually entered text, clipboard text, OCR text, QR code contents, or analyzed URLs to a server to make the risk decision.

Some technical features may communicate with external services:

When Google Play Data Safety defines "collection" as transmitting data off the device, text, URLs, QR codes, OCR, and notifications processed only locally are not collected by EdgePhishGuard. Technical data transmitted to providers should still be declared consistently in the Data Safety listing.

7. Third Parties and Technical Providers

Provider or technologyUseData processed
Google ML Kit, MediaPipe, and TensorFlow LiteOCR, QR scanning, language identification, and local inference.On-device processing for enabled features.
Firebase Remote ConfigRemote configuration and version control.Technical app, installation, device, and network data needed to provide the service.
Firebase CrashlyticsCrash diagnostics and stability monitoring.Crash reports, traces, technical identifiers, and app/device metadata.
Firebase Hosting, GitHub, or another hostPublication of the policy and distribution of technical files.Technical access logs processed by the provider.

EdgePhishGuard does not sell personal data, does not use advertising, does not share analyzed content with advertisers, and does not use user content for personalized advertising.

8. Legal Basis

Where the General Data Protection Regulation or similar laws apply, processing is based on:

9. Retention and Deletion

EdgePhishGuard does not require users to create an account. Therefore, there is no in-app account to delete. For requests about technical data processed outside the device, email edgephishguard.support@gmail.com.

10. User Rights and Controls

The user can:

11. Security

EdgePhishGuard applies data minimization, local processing by default, and permission limitation to specific features. Technical communications with external providers should use secure connections such as HTTPS. Although reasonable measures are applied, no system can guarantee absolute security against every technical risk, operating system error, or device configuration issue.

12. Children

EdgePhishGuard is not specifically directed to children. The app does not intend to knowingly collect personal data from children or profile children for advertising. If you believe that a child's information has been processed inappropriately, contact the controller to request review or deletion where applicable.

13. International Transfers

Phishing analysis is mainly performed on the device. If external services such as Firebase, Google, or GitHub are used, limited technical data may be processed outside the European Economic Area. In that case, processing relies on the contractual, technical, and legal safeguards offered by the relevant provider.

14. Automated Decisions

EdgePhishGuard automatically calculates a phishing risk score and may show an alert when the risk exceeds the configured threshold. This decision does not produce legal effects for the user, does not make financial or legal decisions, and does not permanently block access to external services. The user remains in control of whether to review the alert, ignore the warning, or continue.

15. Changes to This Policy

This policy may be updated to reflect changes in the app, permissions, technical providers, Google Play requirements, or legal requirements. The latest update date will appear at the top of this page.

16. Contact

If you have questions about this policy or data processing in EdgePhishGuard, please contact:

edgephishguard.support@gmail.com