Privacy Policy
Last updated:
Introduction
Guardexa (xyz.forgebase.guardexa) is an anti-theft and intrusion detection app for Android. We are committed to protecting your privacy. This Privacy Policy explains what data the app accesses, how it is used, and the choices you have.
Intrusion evidence (such as intrusion photos, videos, audio, and event location records) is designed to remain in app-private local storage on your device. Guardexa may also use limited third-party services for analytics, crash reporting, app configuration, in-app ads, advertising measurement, billing, optional email alerts, and on-device face detection for Owner Recognition, as described below.
By using Guardexa you agree to the practices described in this policy. If you do not agree, please uninstall the app.
Camera
Guardexa may use your device camera to capture photos or videos when a potential intrusion is detected. Captured media is stored locally on your device in app-private storage. Guardexa does not upload intrusion evidence to Forgebase or use it for advertising. If you configure email alerts, selected evidence may be sent through your chosen email service as part of those alerts. If you set up Owner Recognition, the camera is also used to scan your face when you set up or test that feature.
Microphone
The microphone permission is used solely to record audio as part of intrusion-detection video capture. Audio recordings are stored locally on your device and are not transmitted externally, except as part of selected evidence in email alerts you configure.
Location
Location data may be collected when an intrusion event is detected, allowing you to see where your device was at the time. This data is stored locally on your device and is not sent to any server. If you have email alerts enabled, location information may be included in the alert email sent through your own Gmail account.
Notifications
Guardexa uses notifications to alert you about intrusion events and to maintain required foreground-service notices on Android. Notification content stays on your device and is not collected or tracked.
Email Alerts
Guardexa offers an optional Gmail-based Email Alerts feature. This feature is disabled by default and is used only if you choose to connect a Google account.
Guardexa uses Google Sign-In and requests only the Gmail scope https://www.googleapis.com/auth/gmail.send to send alert emails from your connected Gmail account.
Guardexa does not read Gmail inbox messages, email history, contacts, labels, drafts, or mailbox content. Guardexa does not modify, delete, scan, or store Gmail messages. Alert emails are sent only to recipient addresses configured by you and may include intrusion details such as detection time, captured evidence, and optional location information based on your enabled settings.
You can disable or disconnect Gmail Email Alerts at any time from app settings. Google account credentials are managed by Google authentication services and are not stored by Guardexa.
Google User Data
Guardexa uses Google user data only for the optional Gmail-based Email Alerts feature. This feature is disabled unless you choose to connect a Gmail account and grant Gmail send permission.
Data Accessed:
Guardexa requests access only to https://www.googleapis.com/auth/gmail.send, which is required to send email messages from your connected Gmail account.
Guardexa does not access, read, collect, scan, modify, delete, or store Gmail inbox messages, email history, labels, contacts, drafts, or mailbox content.
Data Usage: The Gmail send permission is used only to send optional security alert emails configured by you. These alerts may include intrusion-related details such as detection time, captured evidence, and optional location information, depending on your enabled settings.
Data Sharing: Guardexa does not sell Google user data. Guardexa does not share Google user data with advertisers, analytics providers, or unrelated third parties. Email alerts are sent only to recipient addresses configured by you for security notifications.
Data Storage & Protection: Guardexa does not store Gmail mailbox content. Google account credentials are managed by Google authentication services and are not stored by Guardexa. Any authentication or account-connection data required for Gmail Email Alerts is used only to provide the feature and is handled with reasonable security safeguards.
Data Retention & Deletion: Guardexa does not retain Gmail inbox data or mailbox content. You can disconnect Gmail Email Alerts at any time from app settings. You may request deletion of app-related data by contacting contact@forgebase.xyz.
Device Administrator Access
Guardexa requests Device Administrator privileges for the following limited purposes only:
- Watch login attempts — to detect failed unlock attempts on your device.
- Force lock — to lock the device so the user can test intrusion detection.
No other Device Administrator capabilities are used.
Local Storage
All intrusion photos, videos, and location data are stored locally on your device in app-private storage. Guardexa does not upload intrusion evidence to a developer-operated backend server or cloud storage.
Some limited data may still be processed by third-party services used by the app, including analytics, crash reporting and app configuration (Firebase), on-device face detection for Owner Recognition (Google ML Kit), ads shown to certain free users (Google AdMob), advertising measurement (Meta App Events), subscriptions and purchases (Google Play Billing and RevenueCat), and optional account authentication/send-email flows (Google Sign-In and Gmail API). These services are described in this policy.
If you choose to send feedback from the app's rating prompt, Guardexa sends your message to Forgebase with basic technical details, such as the app version, device model, Android version, app language, and whether protection and permissions are enabled. This feedback is stored in Forgebase's Firebase project (Cloud Firestore). If you contact support from the app, you can also choose to attach a diagnostic report with app settings, device details and recent app logs to the email you send. We use this information to understand problems and improve Guardexa. It does not include your intrusion photos, videos, audio, or location records.
Analytics and Crash Reporting
Guardexa uses Firebase Analytics and Firebase Crashlytics, services provided by Google. Firebase Analytics helps us understand app usage and improve product experience. Firebase Crashlytics helps us diagnose crashes, errors, and app stability issues.
Depending on Firebase behavior and app configuration, Google Firebase may process limited technical and app data on our behalf, such as:
- App interactions and feature usage
- App version
- Device model
- Operating system version
- Crash logs and crash timestamps
- Diagnostic and performance information
- Technical identifiers (for example Firebase installation ID, app instance ID, or device identifiers)
Guardexa does not use Firebase Analytics or Crashlytics to collect intrusion evidence content, including intrusion photos, intrusion videos, audio recordings, Gmail message content, or locally stored intrusion history. Guardexa also does not intentionally log precise intrusion-location records to Firebase unless custom analytics/crash logging is explicitly implemented for that purpose.
Guardexa also uses Firebase Remote Config, and reads settings stored in Cloud Firestore, to receive app settings from Forgebase without an app update, such as how the subscription offer is presented, how long the free preview lasts, whether ads are shown, and the minimum supported app version. Remote Config uses your app's Firebase installation ID to select the settings it returns. These settings are only delivered to the app; Guardexa does not send intrusion evidence to Remote Config or Cloud Firestore.
Learn more: Google Privacy Policy and Firebase Privacy and Security.
Advertising (Google AdMob)
Guardexa may display ads to certain free users through Google AdMob (Google Mobile Ads), a service provided by Google. Not all users see ads. Guardexa Pro subscribers do not see ads.
When ads are requested or shown, Google and its advertising partners may collect or receive information such as:
- Advertising ID and other device identifiers
- IP address (which may be used to estimate an approximate location)
- Device and app information, such as device model, operating system version, and app version
- Ad interactions and measurement data, such as ad impressions and taps
- Your consent and privacy choices, where applicable
Google uses this information to serve ads, measure ad performance, prevent fraud and abuse, and limit how often the same ad is shown. This information is collected by Google through the Google Mobile Ads SDK and handled under Google's own privacy policies.
In regions where consent is required, including the European Economic Area (EEA), the United Kingdom, and Switzerland, Guardexa uses Google's consent management tool. You may be asked to give or refuse consent for certain advertising purposes, such as storing information on your device or showing personalized ads. Ads are personalized only if you consent; otherwise, Google may show non-personalized or limited ads. In other regions, ad personalization depends on applicable law and your device's ad settings.
Where Google requires it, you can review or change your choices at any time from Ad privacy in Guardexa Settings. You can also reset or delete your advertising ID from your Android device settings.
Guardexa does not send intrusion evidence or security data to Google AdMob, and this data is not used for advertising. This includes failed unlock attempts, intrusion history, captured photos, captured videos, microphone/audio recordings, location evidence, email alert content, and your private files or media.
Learn more: Google Privacy Policy, How Google uses information from apps that use its services, and Google Mobile Ads SDK data disclosure.
Meta App Events (Advertising Measurement)
Guardexa uses the Meta App Events SDK for limited advertising measurement and basic conversion analytics. This helps us understand campaign performance and high-level conversion outcomes. It is not required for core app security functionality.
Guardexa may send limited marketing or conversion events to Meta, such as app open, onboarding completed, paywall viewed, checkout started, subscription or purchase completed, and rating intent.
Depending on SDK behavior and your device environment, Meta may receive app activity related to those events, purchase or conversion event data, and device or other identifiers used for analytics and advertising measurement.
Guardexa does not send sensitive security or intrusion-evidence data to Meta. This includes failed unlock attempts, intrusion history, captured photos, captured videos, microphone/audio recordings, location evidence, email alert content, and your private files or media.
Premium Subscriptions
Guardexa offers optional premium features through Google Play Billing, managed via RevenueCat. Purchase and subscription information is handled by Google Play and RevenueCat in accordance with their own privacy policies. Guardexa does not directly collect or store your payment information.
Learn more: RevenueCat Privacy Policy.
Background Operation
To function as an anti-theft and intrusion detection tool, Guardexa may run in the background and request a battery-optimization exemption. This allows the app to reliably monitor for intrusion events. Background monitoring does not upload intrusion evidence to Forgebase. If you configure email alerts, they may be sent in the background when an intrusion is detected.
Stealth Mode
Guardexa includes an optional stealth mode that minimizes the app's visible presence on your device. This feature is designed to prevent a potential thief from discovering and disabling the app. Stealth mode does not change how your data is collected or stored.
Owner Recognition
Owner Recognition is an optional Guardexa Pro feature that helps Guardexa tell when a failed unlock attempt was probably made by you. It is off unless you set it up.
During setup, Guardexa uses your front camera to take a short series of face scans and, on your device, turns them into a face profile: a set of numbers that describes your facial features. Guardexa saves only this face profile, in app-private storage on your device. It does not save the setup images.
After a failed unlock attempt, Guardexa compares the face in the front-camera photo with your face profile, on your device. Attempts recognized as yours are saved with an Owner label and do not trigger alerts.
Guardexa does not upload your face profile or setup images to Forgebase or share them with third parties. Face detection uses Google's ML Kit on your device; ML Kit may send Google technical information about its use, such as performance metrics, as described in the ML Kit data disclosure.
You can turn Owner Recognition off at any time in Settings → Protection → Owner Recognition; your face profile is kept until you remove it. To delete it, open Owner Recognition and choose Remove owner recognition data. Uninstalling Guardexa also deletes it.
Data Security
We take your data security seriously. Intrusion evidence is stored locally in app-private storage and protected by Android's built-in sandboxing and file-permission model.
Limited technical, analytics, crash-reporting, advertising, purchase/subscription, and authentication/send-email related data may be processed by the third-party services described in this policy.
While no method of storage or transmission is 100% secure, we strive to use reasonable safeguards to protect your information.
Children's Privacy
Guardexa is not intended for use by children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided data through the app, please contact us so we can address the situation.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected on this page with a revised "Last updated" date. We encourage you to review this page periodically.
Contact
If you have any questions or concerns about this Privacy Policy or Guardexa's data practices, please contact Forgebase, the company behind Guardexa:
- Email: contact@forgebase.xyz
- Website: https://forgebase.xyz