01 · Introduction
In short: This page is the central Privacy Policy for Protectstar Android apps. The separate Data Disclosure also explains Google Play-specific and app-specific data flows.
Protectstar Inc. (“Protectstar,” “we,” “us,” or “our”) respects and protects your privacy. This Privacy Policy describes which personal data and sensitive user data our Android apps and related services process, the purposes for which they are processed, which service providers may be involved, how long data is retained, and what rights you have.
This Privacy Policy applies worldwide to the Android apps listed below and to related online features, including Protectstar AI Cloud, MY.PROTECTSTAR, in-app purchases, push notifications, support, and security updates.
By using our services, you acknowledge this Privacy Policy. Where the processing of personal or sensitive data requires consent or a specific in-app disclosure, we obtain that consent separately, explicitly, and before the relevant processing takes place.
You can find a compact overview at Your Privacy. You can find the technical and Google Play-specific detailed disclosure at Data Disclosure for Protectstar Android Apps. For Firewall AI and DNS Changer, there is also the VPNService Disclosure.
02 · Which apps does this Privacy Policy cover?
This Privacy Policy applies to the following Protectstar Android apps:
- Anti Spy Android
- Antivirus AI Android
- Camera Guard Android
- DNS Changer Android
- Firewall AI Android
- Micro Guard Android
- iShredder Android
iShredder Android transmits personal data to Protectstar only when you use optional online features, particularly MY.PROTECTSTAR, license/purchase verification, in-app purchases, or support features. Secure deletion of files, folders, or contacts takes place locally on your device; the contents of deleted files or contacts are not transmitted to Protectstar.
03 · Legal bases for processing
Depending on the feature and jurisdiction, we process personal data on one or more of the following bases:
- Performance of a contract or steps before entering into a contract, when data is required to provide an app feature, a MY.PROTECTSTAR account, a license, a purchase, a subscription, or support service.
- Consent, when a feature requires it, especially for cloud analyses that require consent, sensitive Android permissions, optional online features, or certain notification settings.
- Legitimate interest, in security, abuse prevention, integrity, fraud prevention, stability, error reduction, and protection of our infrastructure, provided your rights and interests do not override those interests.
- Legal obligations, for example, tax, accounting, security, compliance, or recordkeeping obligations.
You can withdraw consent you have given at any time with effect for the future. Withdrawal may cause certain security or online features to be limited or no longer available.
04 · What categories of data do we process?
We process only data that is required for security, feature delivery, licensing, purchases, notifications, or support.
| Data Category | Examples | Purpose |
| Installed apps | Package name, app name, app version, installation source | Malware and spyware detection, firewall rules, security assessment |
| Checksums | SHA-256, MD5 of apps or files | Digital fingerprints for integrity and threat checks; complete apps or files are not transmitted |
| File metadata | File path/name when required for security analysis, false-positive review, or a specific support case | Threat assessment and short-term security analysis; no permanent raw storage unless required for a specific security or support case |
| Device and app metadata | OS version, manufacturer, model, form factor, app version, installation source | Compatibility, reducing false positives, push delivery, licensing, security analysis |
| Network/WhoIs data | User-selected IP address or domain, derived Geo-IP information | Display of WhoIs and Geo-IP information in Firewall AI or DNS Changer |
| Account data | UserId, email address, first name, last name, authentication data, device and license information | MY.PROTECTSTAR account, license management, device management, support |
| Purchase data | Purchase history, product SKU, subscription status, Google Play purchase reference | Feature unlocks, subscription management, fraud prevention, legal records |
| Push delivery data | FCM token or Firebase installation identifier, app version, Firebase User-Agent | Technical delivery of push notifications and topic subscriptions |
| Support data | Email address, message, voluntary information, technical diagnostic data if provided | Handling support and privacy requests |
Hash values themselves do not contain file contents. However, accompanying data such as package name, file path/name, device model, or installation identifiers may, depending on the context, create pseudonymous links to a device. For that reason, we treat them as protected data and disclose them transparently.
05 · App-specific processing
Firewall AI & DNS Changer
Firewall AI and DNS Changer use Android VPNService locally on your device to filter network traffic and provide DNS/firewall features. We do not operate an external Protectstar VPN server, and no VPN tunnel to Protectstar is established.
- Blocklists: Via
https://api.protectstar.com/api/get-blocklists-info, the app package name may be processed to provide current filter lists. - WhoIs: Via
https://api.protectstar.com/api/whois, only the IP address or domain selected by the user in the WhoIs view, together with derived technical network and Geo-IP information, is processed. No GPS location of your device is transmitted. - OpenStreetMap: When you use the map view, the app retrieves map tiles from OpenStreetMap. For technical reasons, OpenStreetMap receives at least your IP address and a User-Agent that identifies the app. This feature is used solely to display maps.
We do not collect complete browsing histories, permanently stored domain histories, or browsing profiles.
Anti Spy & Antivirus AI
Anti Spy and Antivirus AI may process app package names, SHA-256/MD5 checksums, installation source, app version/code, device metadata, and, where necessary for security analysis, file paths/names.
-
https://api.protectstar.com/api/get-deep-detective-packages-shas-info — threat checks for apps and files based on checksums and package names. -
https://api.protectstar.com/api/add-statistic-item and https://api.protectstar.com/api/add-file-statistic-item — analysis of detected threats and creation of aggregated security statistics.
Complete apps or files are not transmitted to Protectstar. Permanent threat statistics contain only aggregated or anonymized security information without file paths, file names, or device-related identifiers.
Camera Guard & Micro Guard
Camera Guard and Micro Guard monitor locally on your device whether camera or microphone access occurs and warn you about unwanted access.
We do not record photos, videos, audio data, conversations, or any other camera/microphone content, and we do not transmit such content to Protectstar. If app or device metadata is processed for push notifications, licensing, MY.PROTECTSTAR, or support, the corresponding sections of this Privacy Policy apply.
iShredder Android
iShredder overwrites and deletes files, folders, or contacts locally on your device. The contents of deleted files, folders, or contacts are not transmitted to Protectstar. Personal data is transferred to Protectstar only for optional online features such as MY.PROTECTSTAR, license/purchase verification, in-app purchases, or support.
06 · Android permissions and in-app disclosure
Some apps require sensitive Android permissions so their core functionality can work. Before activating features or sensitive permissions that require consent, we display a clear in-app disclosure explaining the data category, purpose, processing, and necessary recipients.
| Permission / API | Apps | Purpose |
QUERY_ALL_PACKAGES | Anti Spy, Antivirus AI, Firewall AI, DNS Changer | Detection and assessment of installed apps, malware/spyware protection, and app-based firewall rules. A limited package query is not sufficient for these core features. |
MANAGE_EXTERNAL_STORAGE, READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE | Antivirus AI, iShredder | Antivirus file protection or secure deletion. SAF/MediaStore are not reliably sufficient for full malware scanning or byte-accurate overwriting. |
READ_CONTACTS, WRITE_CONTACTS | iShredder | Optional local secure deletion of contacts. Contacts are not transmitted to Protectstar. |
READ_PHONE_STATE | Firewall AI, where required; not DNS Changer | Technical telephony and network states for firewall features. We do not transmit IMEI, IMSI, SIM serial number, or phone number to Protectstar unless this has been expressly disclosed and approved separately. |
PACKAGE_USAGE_STATS | Anti Spy, Antivirus AI, Camera Guard, Micro Guard | Detection of the foreground app to attribute security-relevant events, such as screen-capture protection or camera/microphone warnings. |
SYSTEM_ALERT_WINDOW | Anti Spy, Antivirus AI, Camera Guard, Micro Guard | Display of security alerts over other apps. |
SCHEDULE_EXACT_ALARM | Anti Spy, Antivirus AI | User-defined scan times. |
Android VpnService | Firewall AI, DNS Changer | Local firewall, DNS, and network filtering features without an external VPN server. |
For optional secure deletion of contacts in iShredder, the Android Contact Picker is not sufficient because iShredder must locally delete selected contacts or — where technically possible — overwrite them with placeholder values before deletion and perform the deletion in a verifiable way. Contact permissions are used exclusively for this local feature; contacts are not transmitted to Protectstar.
Closing the disclosure, navigating away, pressing the Back or Home button, remaining inactive, or an automatically disappearing notice does not constitute consent. If you do not consent, we do not transmit security analysis data to the Protectstar AI Cloud and do not transmit MY.PROTECTSTAR account data for that feature. Technically necessary processing by Google Play, Firebase Cloud Messaging, OpenStreetMap, or other features you actively use is described separately.
07 · Firebase Cloud Messaging
We use Firebase Cloud Messaging (FCM) exclusively for the technical delivery of push notifications and for managing topic subscriptions, such as security alerts, update notices, or important app messages.
Technical identifiers and metadata may be processed in this context, in particular FCM token or Firebase installation identifier, app version, Firebase User-Agent, OS version, model, brand, form factor, and installation source.
We do not use Firebase Cloud Messaging for advertising, profiling, app activity tracking, or behavioral analysis. Firebase Analytics and Firebase Crashlytics are not enabled or included in the Android apps named above unless expressly stated otherwise in the respective app.
You can disable push notifications at any time in your device’s system settings.
08 · In-app purchases, subscriptions, and MY.PROTECTSTAR
In-app purchases and subscriptions
Some apps offer paid features, subscriptions, or one-time purchases via Google Play Billing. Purchase history, product SKU, subscription status, and technical purchase references may be processed so we can unlock features, verify purchases, prevent fraud, and satisfy legal recordkeeping requirements. You can manage or cancel subscriptions through Google Play.
Our apps do not display third-party advertising and are not monetized through the sale of data or advertising profiles.
MY.PROTECTSTAR account
Use of a MY.PROTECTSTAR account is optional. Apps with account integration may process data via https://my-api.protectstar.com.
- User data: UserId, email address, first name, last name, and authentication data. If you use a password, we do not store the plain-text password, only a salted cryptographic verification value.
- Device data: User-defined device name, manufacturer, model, device design name, board, and hardware specifications.
- Product and license data: Product SKU, app package name, activation ID, and activation key.
09 · Service providers, recipients, and sharing
We do not sell personal data and do not share it for advertising, tracking, profiling, or monetization purposes.
Processing by service providers or technical recipients takes place only where technically required or based on your use of a feature:
- Google / Firebase — technical delivery of push notifications via Firebase Cloud Messaging.
- Google Play Billing — processing of in-app purchases and subscriptions through your Google Play account.
- bunny.net CDN — fast and secure delivery of downloads, update files, or malware signatures, in particular for Anti Spy and Antivirus AI, where these are retrieved through our CDN. Necessary connection and security data may be processed, for example IP address (anonymized in logs), time, requested path/URL, HTTP headers including User-Agent, country/region, and amount of data transferred. No advertising, no tracking, no profiling. Searchable CDN logs are currently retained for 3 days; permanent log storage/forwarding is disabled.
- OpenStreetMap / OpenStreetMap Foundation — map tiles when you use the WhoIs map view in Firewall AI or DNS Changer.
- Hosting/cloud providers — operation of
api.protectstar.com and my-api.protectstar.com on ISO 27001-certified servers in Germany. - Support and communication services — (email and ticket systems, where used) — only to the extent required to handle your support, privacy, or account request.
All service providers are limited to the relevant purpose. Where they act as processors or service providers, appropriate contractual obligations are in place.
10 · Data retention, deletion, and account deletion
We do not retain personal data longer than necessary for the respective purpose.
| Data Category | Retention |
| Security analysis requests | Package names, SHA-256/MD5 hashes, and, where required, file paths/names are processed briefly for cloud analysis and discarded after a few seconds. |
| Threat statistics | Retained permanently only as aggregated or anonymized security information without file paths, file names, or device-related identifiers. |
| Account, license, and purchase data | As long as your account exists, a contract or license is active, or legal retention obligations, fraud prevention, security records, or billing records require it. |
| FCM tokens and technical push data | As long as the app is installed, push notifications are enabled, or the token is required for delivery. |
| CDN connection and security logs | Currently 3 days at bunny.net, with IP anonymization by default; no use for advertising, tracking, or profiling. |
| Support and privacy requests | As long as required to process the request and satisfy legal recordkeeping or limitation-period requirements. |
Delete MY.PROTECTSTAR account
If you have created a MY.PROTECTSTAR account, you may request deletion of your account and the associated data at any time:
If we must temporarily retain certain data for legitimate reasons such as legal retention, security, fraud prevention, or billing records, we will transparently inform you about the purpose and duration.
11 · How we protect your data
We protect personal data and sensitive user data through appropriate technical and organizational measures. These include, in particular:
- Transmission via HTTPS/TLS with modern cipher suites,
- encryption of data at rest where technically applicable,
- access restrictions based on need-to-know and least-privilege principles,
- logging of administrative access,
- system hardening, patch management, firewalls, and monitoring,
- backups and recovery tests,
- incident response processes and statutory notification obligations,
- regular security and privacy training.
Our cloud infrastructure for security analyses runs on ISO 27001-certified servers in Germany.
12 · International data transfers
Protectstar Inc. is headquartered in the United States and offers its apps worldwide. Our app cloud servers for security analyses are located in Germany. Depending on the feature, service provider, support case, or global delivery, personal data may be transferred to or processed in other jurisdictions.
For international transfers, we use appropriate safeguards, in particular contractual privacy agreements, Standard Contractual Clauses, technical safeguards, and data minimization. For users in the European Economic Area, Switzerland, and the United Kingdom, we comply with the applicable requirements for international data transfers.
13 · Your privacy rights
Depending on your jurisdiction, you have rights with respect to your personal data. These include in particular:
- access to information about the processing of your data,
- correction of inaccurate data,
- deletion of your data,
- restriction of processing,
- objection to certain processing activities,
- data portability,
- withdrawal of consent with effect for the future,
- complaint to a competent data protection supervisory authority.
For users in California and other U.S. states, additional rights to know/access, correct, delete, and opt out of sale, “sharing,” or targeted advertising may apply. We do not sell personal data and do not share it for cross-context behavioral advertising.
To exercise your rights, contact us at . We may verify your identity before processing a request.
14 · Children, special categories, and automated decisions
Children
Our apps are not directed to children under 13 years of age or, where local law provides otherwise, under 16 years of age. We do not knowingly collect personal data from children. If you believe that a child has provided personal data to us, please contact us at so we can delete the information.
Special categories
We do not request special categories of personal data, such as health, religion, political opinions, sexual orientation, or comparable sensitive categories, through our apps and do not want to receive such data.
Automated decisions
We do not make automated decisions that have legal or similarly significant effects on you. Security assessments are used solely to detect and defend against malware, spyware, or other digital threats.
15 · Alignment with Google Play, Data Safety, and in-app disclosures
We align this Privacy Policy, our Data Disclosure for Apps, the in-app disclosures, Play Console Data Safety statements, active app versions, SDKs, permissions, and actual data flows for each package name.
If data processing, SDKs, permissions, purposes, recipients, or retention periods change, we update this Privacy Policy, the app disclosure, and the Google Play information. Where required by law or by Google Play, we obtain renewed explicit consent before new data processing takes place.
16 · Changes and contact
Changes
We may update this Privacy Policy to reflect changes to our apps, technologies, service providers, legal requirements, or data processing. We may communicate material changes via a website notice, email to the address linked to your account, and/or an in-app notice.
Changes apply from the stated update date. Continued use does not replace separate consent where a new processing activity requires explicit consent by law or by Google Play.
Contact
If you have questions about this Privacy Policy or our data practices, please contact us at:
Protectstar Inc.
4281 Express Lane, Suite L3604
Sarasota, FL 34249, USA
Email: