Last updated: 15 May 2026 · Effective: 15 May 2026 · Questions: [email protected]
Plain-language summary: We collect only what is necessary to provide the service. We do not sell your data. Submitted APK files are analyzed in isolation and stored per your plan's retention period, then permanently deleted. Anonymized threat indicators (hashes, IOCs) may be shared with the security community to improve collective defenses. EU/EEA users have full GDPR rights including access, erasure, and portability.
This Privacy Policy describes how the Droidwatch platform ("Droidwatch," "we," "us," "our") processes personal data when you use the Service. For the purposes of the EU General Data Protection Regulation (GDPR) and UK GDPR:
Data Controller: Droidwatch
Service: Droidwatch Android APK Security Analysis Platform
Contact: [email protected]
Where Enterprise customers use the Service to process personal data belonging to their own users or customers, Droidwatch acts as a Data Processor on their behalf. A GDPR Art. 28-compliant Data Processing Agreement is available at /dpa.
This policy applies to all personal data processed by Droidwatch in connection with:
It does not apply to third-party services linked from our platform. We encourage you to review the privacy policies of any third-party services you use.
When you upload an APK (or XAPK, AAB) for analysis:
APK files may incidentally contain personal data (e.g., user data embedded in the app, developer credentials). We do not intentionally extract or store such data beyond what is necessary for security analysis. If you believe you have submitted a file containing sensitive personal data, contact us at [email protected] for early deletion.
Users without an account are identified by a temporary session token stored in the browser's localStorage. No persistent user profile is created. Anonymous session data (analysis runs) is deleted per the Anonymous plan retention period.
For users in the EU/EEA or UK, we rely on the following lawful bases:
| Processing Activity | Lawful Basis | GDPR Article |
|---|---|---|
| Creating and managing your account | Performance of a contract | Art. 6(1)(b) |
| Delivering analysis results and reports | Performance of a contract | Art. 6(1)(b) |
| Sending transactional emails | Performance of a contract | Art. 6(1)(b) |
| Security, abuse prevention, rate limiting | Legitimate interest | Art. 6(1)(f) |
| Improving detection rules (anonymized data) | Legitimate interest | Art. 6(1)(f) |
| Marketing and product communications | Consent (opt-in only) | Art. 6(1)(a) |
| Compliance with legal obligations | Legal obligation | Art. 6(1)(c) |
| Audit log retention for SOC 2 compliance | Legitimate interest / Legal obligation | Art. 6(1)(c)/(f) |
Where processing is based on legitimate interest, you may object at any time (see Section 11). Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
To improve collective security defenses, Droidwatch may:
We do not share the raw APK binary, your account identity, your email address, or the full analysis report with any third party without your explicit written consent, except as required by applicable law.
We use the following categories of sub-processors to deliver the Service. We maintain Data Processing Agreements with each where required by GDPR:
| Sub-processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Cloud infrastructure provider | Hosting, storage, database | All service data, encrypted at rest | EU / configurable per Enterprise plan |
| VirusTotal (Google) | Threat intelligence hash lookup | File hashes (SHA-256) only | USA (SCCs apply) |
| AbuseIPDB | IP reputation | IP addresses from submitted files | USA (SCCs apply) |
| AlienVault OTX (AT&T) | IOC enrichment | IPs and domains from submitted files | USA (SCCs apply) |
| URLhaus (abuse.ch) | URL reputation | URLs and domains from submitted files | Switzerland (adequacy decision) |
| Payment provider | Payment processing | Billing details (not stored by Droidwatch) | As per provider's policy |
| Transactional email provider | Email delivery | Email address, notification content | EU / SCCs apply |
We do not use advertising networks, third-party analytics, or social media tracking pixels.
Droidwatch is designed to minimize international data transfers. Where transfers outside the EU/EEA are necessary (e.g., threat intelligence lookups against US-based services), we rely on the following safeguards:
Enterprise customers may request that all data remain within a specified geographic region. Contact [email protected] to discuss data residency options.
| Plan | Analysis Reports | Raw APK File | Account Data |
|---|---|---|---|
| Anonymous | 3 days | Deleted after analysis | N/A (no account) |
| Free (registered) | 7 days | Deleted after analysis | Until account deletion |
| Pro | 90 days | 30 days | Until account deletion |
| Enterprise | 365 days | Per agreement | Per agreement |
Audit logs are retained for a minimum of 12 months for SOC 2 compliance and security purposes, even after account deletion, unless a longer period is required by law.
You may request early deletion of any of your analysis runs from within the app or by contacting us. Account deletion requests are processed within 30 days. We may retain anonymized, non-identifiable data derived from your submissions after deletion.
Despite these measures, no system is completely secure. In the event of a personal data breach that is likely to result in high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and within 72 hours of becoming aware, as required by GDPR Art. 33–34.
Depending on your jurisdiction, you have the following rights regarding your personal data:
To exercise any of these rights, contact [email protected]. We will respond within 30 calendar days. We may ask you to verify your identity before processing the request. No fee is charged for reasonable requests.
If you are dissatisfied with our response, you have the right to lodge a complaint with your national data protection supervisory authority.
Droidwatch does not use advertising cookies, cross-site tracking cookies, or third-party analytics scripts. We use browser localStorage only to store:
No third-party tracking pixels or social media scripts are loaded. Cloudflare Turnstile (CAPTCHA) may set a functional cookie to verify human users on login and registration; no persistent tracking is performed by this widget.
The Service is intended for security professionals and software developers aged 18 and over. We do not knowingly collect personal data from minors under 18. If you believe a minor has created an account, please contact us at [email protected] and we will promptly delete the account and associated data.
Enterprise customers who use the Service to process personal data on behalf of their own users or customers act as Data Controllers, and Droidwatch acts as their Data Processor. In this capacity, we commit to processing data only on documented instructions from the customer and in accordance with GDPR Art. 28.
Our standard Data Processing Agreement (DPA) is available at /dpa. It covers:
Customers requiring customized DPA terms should contact [email protected].
We may update this Privacy Policy to reflect changes to our Service, sub-processors, or legal obligations. For material changes, we will provide at least 30 days' notice via email (for registered users) or a prominent notice in the Service. The "Last updated" date at the top of this page reflects the current version. Previous versions are available upon request.
If you are located in the EU/EEA, you have the right to lodge a complaint with your national data protection authority. A list of supervisory authorities is available at edpb.europa.eu.