Legal

Privacy Policy

Last updated: 15 May 2026  ·  Effective: 15 May 2026  ·  Questions: [email protected]

Plain-language summary: We collect only what is necessary to provide the service. We do not sell your data. Submitted APK files are analyzed in isolation and stored per your plan's retention period, then permanently deleted. Anonymized threat indicators (hashes, IOCs) may be shared with the security community to improve collective defenses. EU/EEA users have full GDPR rights including access, erasure, and portability.

1. Data Controller Identity

This Privacy Policy describes how the Droidwatch platform ("Droidwatch," "we," "us," "our") processes personal data when you use the Service. For the purposes of the EU General Data Protection Regulation (GDPR) and UK GDPR:

Data Controller: Droidwatch

Service: Droidwatch Android APK Security Analysis Platform

Contact: [email protected]

Where Enterprise customers use the Service to process personal data belonging to their own users or customers, Droidwatch acts as a Data Processor on their behalf. A GDPR Art. 28-compliant Data Processing Agreement is available at /dpa.

2. Scope of This Policy

This policy applies to all personal data processed by Droidwatch in connection with:

It does not apply to third-party services linked from our platform. We encourage you to review the privacy policies of any third-party services you use.

3. Data We Collect

3.1 Submitted Files

When you upload an APK (or XAPK, AAB) for analysis:

APK files may incidentally contain personal data (e.g., user data embedded in the app, developer credentials). We do not intentionally extract or store such data beyond what is necessary for security analysis. If you believe you have submitted a file containing sensitive personal data, contact us at [email protected] for early deletion.

3.2 Account Data (Registered Users)

3.3 Usage and Technical Data

3.4 Anonymous Sessions

Users without an account are identified by a temporary session token stored in the browser's localStorage. No persistent user profile is created. Anonymous session data (analysis runs) is deleted per the Anonymous plan retention period.

4. Lawful Basis for Processing (GDPR Art. 6)

For users in the EU/EEA or UK, we rely on the following lawful bases:

Processing ActivityLawful BasisGDPR Article
Creating and managing your accountPerformance of a contractArt. 6(1)(b)
Delivering analysis results and reportsPerformance of a contractArt. 6(1)(b)
Sending transactional emailsPerformance of a contractArt. 6(1)(b)
Security, abuse prevention, rate limitingLegitimate interestArt. 6(1)(f)
Improving detection rules (anonymized data)Legitimate interestArt. 6(1)(f)
Marketing and product communicationsConsent (opt-in only)Art. 6(1)(a)
Compliance with legal obligationsLegal obligationArt. 6(1)(c)
Audit log retention for SOC 2 complianceLegitimate interest / Legal obligationArt. 6(1)(c)/(f)

Where processing is based on legitimate interest, you may object at any time (see Section 11). Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.

5. How We Use Your Data

6. Threat Intelligence Sharing

To improve collective security defenses, Droidwatch may:

We do not share the raw APK binary, your account identity, your email address, or the full analysis report with any third party without your explicit written consent, except as required by applicable law.

7. Sub-processors and Third Parties

We use the following categories of sub-processors to deliver the Service. We maintain Data Processing Agreements with each where required by GDPR:

Sub-processorPurposeData SharedLocation
Cloud infrastructure providerHosting, storage, databaseAll service data, encrypted at restEU / configurable per Enterprise plan
VirusTotal (Google)Threat intelligence hash lookupFile hashes (SHA-256) onlyUSA (SCCs apply)
AbuseIPDBIP reputationIP addresses from submitted filesUSA (SCCs apply)
AlienVault OTX (AT&T)IOC enrichmentIPs and domains from submitted filesUSA (SCCs apply)
URLhaus (abuse.ch)URL reputationURLs and domains from submitted filesSwitzerland (adequacy decision)
Payment providerPayment processingBilling details (not stored by Droidwatch)As per provider's policy
Transactional email providerEmail deliveryEmail address, notification contentEU / SCCs apply

We do not use advertising networks, third-party analytics, or social media tracking pixels.

8. International Transfers

Droidwatch is designed to minimize international data transfers. Where transfers outside the EU/EEA are necessary (e.g., threat intelligence lookups against US-based services), we rely on the following safeguards:

Enterprise customers may request that all data remain within a specified geographic region. Contact [email protected] to discuss data residency options.

9. Data Retention

PlanAnalysis ReportsRaw APK FileAccount Data
Anonymous3 daysDeleted after analysisN/A (no account)
Free (registered)7 daysDeleted after analysisUntil account deletion
Pro90 days30 daysUntil account deletion
Enterprise365 daysPer agreementPer agreement

Audit logs are retained for a minimum of 12 months for SOC 2 compliance and security purposes, even after account deletion, unless a longer period is required by law.

You may request early deletion of any of your analysis runs from within the app or by contacting us. Account deletion requests are processed within 30 days. We may retain anonymized, non-identifiable data derived from your submissions after deletion.

10. Data Security

Despite these measures, no system is completely secure. In the event of a personal data breach that is likely to result in high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and within 72 hours of becoming aware, as required by GDPR Art. 33–34.

11. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

To exercise any of these rights, contact [email protected]. We will respond within 30 calendar days. We may ask you to verify your identity before processing the request. No fee is charged for reasonable requests.

If you are dissatisfied with our response, you have the right to lodge a complaint with your national data protection supervisory authority.

12. Cookies and Local Storage

Droidwatch does not use advertising cookies, cross-site tracking cookies, or third-party analytics scripts. We use browser localStorage only to store:

No third-party tracking pixels or social media scripts are loaded. Cloudflare Turnstile (CAPTCHA) may set a functional cookie to verify human users on login and registration; no persistent tracking is performed by this widget.

13. Children's Privacy

The Service is intended for security professionals and software developers aged 18 and over. We do not knowingly collect personal data from minors under 18. If you believe a minor has created an account, please contact us at [email protected] and we will promptly delete the account and associated data.

14. Enterprise and Data Processing Agreements

Enterprise customers who use the Service to process personal data on behalf of their own users or customers act as Data Controllers, and Droidwatch acts as their Data Processor. In this capacity, we commit to processing data only on documented instructions from the customer and in accordance with GDPR Art. 28.

Our standard Data Processing Agreement (DPA) is available at /dpa. It covers:

Customers requiring customized DPA terms should contact [email protected].

15. Changes to This Policy

We may update this Privacy Policy to reflect changes to our Service, sub-processors, or legal obligations. For material changes, we will provide at least 30 days' notice via email (for registered users) or a prominent notice in the Service. The "Last updated" date at the top of this page reflects the current version. Previous versions are available upon request.

16. Contact and Complaints

If you are located in the EU/EEA, you have the right to lodge a complaint with your national data protection authority. A list of supervisory authorities is available at edpb.europa.eu.