← PrivacyBrew

Privacy Policy

Short version: PrivacyBrew doesn't collect your data. No accounts, no ads, no analytics — and no INTERNET permission, so it's technically incapable of sending anything off your device. The rest of this page explains that permission by permission, so you don't have to take our word for it.

What PrivacyBrew reads, and why

PrivacyBrew reads information Android already exposes about your installed apps — their names, permissions, and optionally when they were last used — and displays it in plain language, entirely on your device. It requests exactly two permissions:

QUERY_ALL_PACKAGES — lets PrivacyBrew list your installed apps and read their already-granted permissions via Android's PackageManager. By default this is a plain metadata read: just each app's name and permissions — the same information Android's own Settings app can show you.

One additional feature, Deep Tracker Scan (Settings → Advanced), is fully opt-in and off by default, and uses this same permission to go further: with your explicit consent, it reads the actual installed code of other apps directly from your device's storage, to detect tracker/ad SDKs invisible to the metadata-only method above. This never runs automatically or in the background — only when you enable it and tap "Scan Now." The only thing kept is a small list of detected SDK names per app; none of the other app's actual code, resources, or any other data is copied, stored, or sent anywhere.

PACKAGE_USAGE_STATS (optional, off by default) — powers one opt-in feature: showing when you last opened an app. Android requires granting this explicitly in system Settings, and you can revoke it at any time; every other part of the app works the same without it. Read on-device only, never transmitted.

PrivacyBrew does not request INTERNET, location, camera, microphone, contacts, storage, or anything else — there was no legitimate use for any of them, so we didn't ask.

What PrivacyBrew doesn't do

External links

A few places in the app open an external link when you tap it — for example, a data broker's opt-out page, or an app's Play Store "Data safety" listing. Nothing is fetched automatically; it opens in your browser or the Play Store app, under that site's own privacy policy, and PrivacyBrew never reads or stores anything from it.

This website

Everything above describes the PrivacyBrew Android app. This website (privacybrew.app) is a separate, static, script-free page: it doesn't use cookies, analytics, or tracking pixels of any kind. It's hosted on GitHub Pages, which — like any web host — automatically logs basic connection data (e.g. IP address, browser type, request timestamp) as part of serving the page; we don't control or access those logs beyond what GitHub's own hosting infrastructure retains. See GitHub Pages' documentation for details on that infrastructure-level logging.

Data retention

PrivacyBrew keeps no logs, databases, or files on our servers — we don't have any. The on-device items listed above stay only on your device, only until you clear the app's data or uninstall it, at which point 100% of it is gone.

Children's privacy

PrivacyBrew isn't directed at children and doesn't knowingly collect information from anyone, children included — it doesn't collect information from anyone at all.

Changes to this policy

If a future update changes what data is read or how, we'll update this page and the in-app version with a new effective date before that change ships.

Contact

Questions about this policy: privacybrew@protonmail.com