Legal
Privacy Policy
Last updated: 3 July 2026
In short: Guardian Shield is built to keep your data on your device. Anti-theft evidence (photos, location) is stored locally and sent only to the email address you configure. We do not sell your data or show ads.
This Privacy Policy explains how the Guardian Shield mobile application ("Guardian Shield", "the app", "we", "us") handles information when you use it. Guardian Shield is an Android security and anti-theft application. By installing or using the app, you agree to the practices described here.
1. Our privacy-first approach
Guardian Shield is designed to run on your device. The large majority of processing — app scanning, permission monitoring, the app locker, DNS logging, and anti-theft traps — happens locally and does not leave your phone. We do not operate advertising networks or sell personal information to anyone.
2. Information the app handles
a. Data stored only on your device
- Security PINs. Your lock, duress, and SMS-command PINs are stored only as irreversible cryptographic hashes in Android's Keystore-encrypted storage. They are never stored in plain text and never transmitted off the device.
- Intruder Selfie captures. If enabled, the app uses the front camera to photograph whoever fails the lock screen after repeated attempts. These images are saved in the app's private local storage.
- Installed-app inventory, permission usage, and DNS logs. Generated and kept on the device to power the dashboards; not uploaded to us.
b. Data sent only to your chosen recipient
- Anti-theft alerts. When an anti-theft trap fires (e.g. Duress/SOS mode, failed-unlock
intruder capture, or an SMS
#LOCATE#command), the app may send an intruder selfie and/or your device's location to the emergency email or phone number you configured. This information goes to your recipient, not to the developer. - Location. Background and precise location are used solely for these anti-theft features (locating a lost or stolen device) and for reading the Wi-Fi network name on the Network screen. Location is not tracked or collected by us.
c. Data checked against third-party security services
To provide specific security features, limited data is sent to trusted third parties:
- Breach Scanner — an email address or password you choose to check is queried against XposedOrNot to see whether it appears in known public data breaches. Passwords are checked using privacy-preserving hashing.
- Malware scanning — cryptographic hashes (not the files themselves) of installed apps may be checked against malware-intelligence services such as VirusTotal and our threat database to flag known-malicious software.
- Push notifications — Firebase Cloud Messaging may process a device token to deliver security alerts.
Each third party processes this data under its own privacy policy.
3. Device permissions and why we request them
- Camera — Intruder Selfie captures after failed unlock attempts.
- Location (incl. background) — locating the device during anti-theft events and reading the connected Wi-Fi name.
- SMS (receive & send) — the Offline SMS Control feature, so you can text secret commands to a lost device and receive a location reply.
- Accessibility Service — detects which app is in the foreground (App Locker) and physical key sequences (anti-theft), and never reads your screen content or keystrokes.
- Device Admin — powers the intruder-watch and anti-tamper protections.
- Notifications, foreground service, and wake locks — keep background security services running reliably.
You may grant or revoke any permission in Android Settings at any time; some features will stop working without their required permission.
4. Data sharing
We do not sell, rent, or trade your personal information. Data leaves your device only in the two cases above: (a) to the emergency recipient you configure, and (b) to the named third-party security services strictly to perform the feature you invoked.
5. Data retention and deletion
On-device data (captures, logs, hashed PINs, settings) remains until you delete it in the app or uninstall Guardian Shield. Uninstalling the app removes its local data from your device.
6. Security
Sensitive values such as PINs are stored as hashes in Keystore-backed encrypted storage. The app applies runtime self-protection and code obfuscation. No system is perfectly secure, but we work to protect your data using industry-standard measures.
7. Children
Guardian Shield is not directed to children under 16 and we do not knowingly collect their data.
8. Your rights
Depending on your location (including under the UK GDPR), you may have rights to access, correct, or delete your personal data. Because most data is stored locally, you can exercise these directly in the app or by uninstalling. For anything else, contact us below.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date at the top of this page.
10. Contact
Questions about this policy or your data? Email akashbaloch28@gmail.com.