Privacy Policy

Last updated: October 8, 2026 · Applies to the WebMedia Scanner Android application and this website.

Summary

WebMedia Scanner is built so that we, the developer, receive no personal data from you at all. Scans run locally on your device; there is no company server, no account and no analytics dashboard on our side. The only data that leaves your device goes to Google — for advertising (AdMob), crash reporting and usage statistics (Firebase) and purchases (Google Play Billing) — under Google's own privacy terms. Pro removes all ads.

Who is responsible (data controller)

  • Application & website: xiaoniubuniu (independent developer). Contact for all privacy matters, including exercising your rights: xiaoniubuniu@gmail.com.
  • Google services: Google LLC (and/or its affiliates, e.g. Google Ireland Limited for EEA/UK users) acts as controller or processor for the data described in "Third-party processing" below, per the Google Privacy Policy.

Data stored on your device — never sent to us

The following stay in the app's private storage area on your phone and are visible only to the app:

  • URLs you scan and their result snapshots (history.json, scan_results.json);
  • your download queue and settings (downloads.json and app preferences);
  • media files you explicitly download, saved to the system Downloads folder or a folder you pick.

Scanned URLs are requested by your device directly from the websites you open. Those websites see your normal browser traffic (IP address, user agent) and are governed by their own privacy policies — we cannot see or control that.

Third-party processing (Google)

When ads are enabled (free version), the following Google technologies process data on your device:

  • Google AdMob (advertising). Google processes identifiers such as the Android Advertising ID (resettable or removable in your device's Google → Ads settings), device information, and your interactions with ads. Ads may be personalised; non-personalised ads can be requested via Google settings. Google may use approximate location derived from IP address for ad targeting. Details: How Google uses information from sites or apps that use its services.
  • Firebase Crashlytics & Analytics (stability & aggregate usage). Google receives crash reports (device model, OS version, app version, stack trace, session info) and anonymised usage statistics (which features are used and how often). We do not see raw events tied to you.
  • Google Play Billing (Pro purchase). Google processes your purchase and account data. The app only receives the entitlement result locally, to switch ads off.

Pro ("remove ads") turns off AdMob loading entirely; Firebase crash/usage reporting continues for all users, because it keeps the app working.

Legal bases (GDPR / UK GDPR)

For EEA/UK users, processing happens on these grounds:

  • Consent (Art. 6(1)(a)) — personalised advertising via AdMob. Consent is captured through Google's consent mechanisms (device-level Google Ads settings and, in regions where Google's consent flow is shown, an in-app prompt). Where no valid consent exists, AdMob serves non-personalised ads instead.
  • Legitimate interest (Art. 6(1)(f)) — Crashlytics crash diagnostics (app stability), Play Billing entitlement checks.
  • Contract (Art. 6(1)(b)) — purchase handling for Pro.
  • We ourselves perform no remote processing: our legitimate-interest assessment does not cover any data flow to us, because there is none.

Your rights, worldwide

Wherever you live, you can ask us (contact above) to help you:

  • Know, access, correct, delete or port any personal data subject to GDPR / UK GDPR / CCPA-CPRA / other applicable laws. Since we store nothing remotely, for app-local data the fastest route is doing it on your device: Settings → Clear scan history, deleting individual downloads, or uninstalling — which removes all app-private data immediately.
  • Object to or restrict processing, and withdraw consent at any time — for ads: device's Google → Ads settings (reset advertising ID or opt out of personalised ads); Pro removes ads outright.
  • Lodge a complaint with your local data-protection authority (list at edpb.europa.eu for the EU) — or with us first so we can try to fix it.

United States — additional notices

  • California (CCPA/CPRA), Colorado, Connecticut, Utah, Virginia and similar state laws. In the preceding 12 months the categories of personal information that third-party processors may have collected through the app are: identifiers (advertising ID, device/app signals), internet or other electronic network activity (ad interactions, app usage events), and inferences derived from usage statistics. We do not sell personal information, and we do not receive any of these categories ourselves. You can opt out of targeted advertising through your device's Google → Ads settings (including "limit ad personalisation") or by purchasing Pro. You may request disclosure/deletion by emailing us — expect a reply within 45 days.
  • Do Not Track: this website is fully static, sets no cookies and contains no trackers, so DNT/GPC signals have nothing to act on here.
  • COPPA: the app is not directed to children under 13 and we knowingly collect nothing from anyone.

Google Play Data Safety — how to read our declaration

Play's Data Safety form marks as "collected" the crash logs, device/other IDs and app-activity data that Firebase and AdMob process under Google. That matches this policy: those flows go to Google only, never to us, and are removed from the ad picture entirely if you buy Pro.

Retention

  • On-device data: kept until you clear it or uninstall (scan history keeps the latest 50 entries; result snapshots keep at most 10 domains, least-recently-used evicted first).
  • Google-side data: retained under Google's schedules — Firebase Analytics default event retention (2 or 14 months), Crashlytics issue data as long as the issue remains open, AdMob log data per Google's advertising-data retention (then de-identified). We cannot lengthen or shorten Google's periods; deletion requests against Google data can be exercised via Google's account/settings channels.

Security

App data lives in Android's sandboxed private storage, inaccessible to other apps; downloads are written through the system media provider or a folder you authorise. Network fetching to the websites you scan uses the protocols those sites publish (TLS where available). A rooted device defeats OS sandboxing — standard Android risk, not app-specific.

International transfers

Google processes data globally and relies on its own transfer mechanisms (e.g. Standard Contractual Clauses) — see Google's Privacy Policy. We transfer nothing ourselves.

Children

The app is a general utility, not directed at children, and we knowingly collect nothing from anyone — of any age. Ad content shown through AdMob is screened by Google's own age-appropriateness and EEA consent enforcement systems, and can be disabled entirely via Pro.

Changes to this policy

Material changes are reflected on this page with a new date above and ship with the next app update. This page remains the current source of truth.

Contact

Questions, requests or complaints: xiaoniubuniu@gmail.com. Please write "privacy" in the subject; we answer within 30 days.