Privacy Policy
What PrivacyBrew reads, and why
PrivacyBrew reads information Android already exposes about your installed apps — their names, permissions, and optionally when they were last used — and displays it in plain language, entirely on your device. It requests exactly two permissions:
QUERY_ALL_PACKAGES — lets PrivacyBrew list your installed apps and read their already-granted permissions via Android's PackageManager. By default this is a plain metadata read: just each app's name and permissions — the same information Android's own Settings app can show you.
One additional feature, Deep Tracker Scan (Settings → Advanced), is fully opt-in and off by default, and uses this same permission to go further: with your explicit consent, it reads the actual installed code of other apps directly from your device's storage, to detect tracker/ad SDKs invisible to the metadata-only method above. This never runs automatically or in the background — only when you enable it and tap "Scan Now." The only thing kept is a small list of detected SDK names per app; none of the other app's actual code, resources, or any other data is copied, stored, or sent anywhere.
PACKAGE_USAGE_STATS (optional, off by default) — powers one opt-in feature: showing when you last opened an app. Android requires granting this explicitly in system Settings, and you can revoke it at any time; every other part of the app works the same without it. Read on-device only, never transmitted.
PrivacyBrew does not request INTERNET, location, camera, microphone, contacts, storage, or anything else — there was no legitimate use for any of them, so we didn't ask.
What PrivacyBrew doesn't do
- No account or sign-in — nothing to register for, nothing tied to your identity.
- No analytics, telemetry, or crash reporting. No third-party SDK reports back to us or anyone else.
- No advertising — no ad SDKs, no ad IDs used, no targeting.
- No off-device data storage. Most screens are
recomputed live from Android's current state every time you open them. A
few small things are kept locally on your device so the app doesn't lose
useful context between opens:
- UI preferences — theme, text size, and whether you've dismissed the intro or tab tour
- Access notices you've dismissed, so a reviewed item doesn't keep reappearing (Settings → Dismissed Access)
- A snapshot of each app's last-seen permissions, used only to flag what's new since your last visit
- Up to 90 days of daily tracker/sensitive-permission totals, used only for the Home screen trend line
- If you tell PrivacyBrew you've reset your Android Advertising ID (Settings): the self-reported date, just so PrivacyBrew can remind you it's been a while — the reset itself always happens in Android's own system Settings, never inside PrivacyBrew
- If you tell PrivacyBrew you've submitted a California DROP request or a request to one of the individual data-broker sites in the Opt-Out tab: the self-reported submission date (and, optionally for DROP, your own tracking ID) — the request itself always happens on that broker's or California's own site, never inside PrivacyBrew, and is never verified automatically, only self-reported by you
- If you've enabled the opt-in Deep Tracker Scan feature (off by default): a cache of which tracker SDKs were found in each scanned app's actual code, per app version, so an unchanged app isn't re-scanned every time — turning the feature off stops it being used immediately, and "Clear cached results" deletes it entirely
External links
A few places in the app open an external link when you tap it — for example, a data broker's opt-out page, or an app's Play Store "Data safety" listing. Nothing is fetched automatically; it opens in your browser or the Play Store app, under that site's own privacy policy, and PrivacyBrew never reads or stores anything from it.
This website
Everything above describes the PrivacyBrew Android app. This website (privacybrew.app) is a separate, static, script-free page: it doesn't use cookies, analytics, or tracking pixels of any kind. It's hosted on GitHub Pages, which — like any web host — automatically logs basic connection data (e.g. IP address, browser type, request timestamp) as part of serving the page; we don't control or access those logs beyond what GitHub's own hosting infrastructure retains. See GitHub Pages' documentation for details on that infrastructure-level logging.
Data retention
PrivacyBrew keeps no logs, databases, or files on our servers — we don't have any. The on-device items listed above stay only on your device, only until you clear the app's data or uninstall it, at which point 100% of it is gone.
Children's privacy
PrivacyBrew isn't directed at children and doesn't knowingly collect information from anyone, children included — it doesn't collect information from anyone at all.
Changes to this policy
If a future update changes what data is read or how, we'll update this page and the in-app version with a new effective date before that change ships.
Contact
Questions about this policy: privacybrew@protonmail.com