๐ Key Highlights
- There are no accounts and no sign-up. We never ask for your name, email, phone number, or any social login.
- WiFi scan results, connected-network details, LAN device lists, signal readings, heatmaps, history and vault entries are processed and stored only on your device.
- Vault passwords are encrypted with AES-256-CTR under a hardware-backed key, authenticated with HMAC-SHA256, and are never transmitted anywhere.
- Data reaches our server only when you deliberately contribute a hotspot, vote, report an entry, or share a speed sample. Nothing is uploaded in the background.
- Contributed coordinates are rounded to 5 decimal places and full BSSIDs are never stored on our server โ the server rejects them outright.
- Location permission is requested at the moment you open the Map tab, never at first launch, and never used for background or continuous tracking.
- We do not sell, rent, or trade your personal information.
Overview
WiFi Map: WiFi Unlocker (the "App", package com.epsilon.wifi_map) is published by Epsilon Developers, an independent software publishing brand operated by Satyam Kushwaha and Anurag Mahajan ("Developer", "we", "us", "our").
This Privacy Policy explains what information the App collects, uses, stores, processes, discloses and protects, and what choices you have. By downloading, installing, accessing or using the App, you acknowledge that you have read and understood this Policy.
The App is deliberately built local-first. The overwhelming majority of what it does happens entirely on your phone with no network call at all. A small, clearly-marked set of features โ the community hotspot map, speed testing, ads, purchases and crash reporting โ involve third parties or our own server, and each one is described in full below.
This Policy applies to the WiFi Map Android application and to this website. It does not apply to other Epsilon Developers products, or to any third-party website or service linked from within the App.
1 Data We Collect
The table below lists every category of data the App touches, and where it goes. "On-device only" means the data is written to the App's private sandbox directory and is never transmitted by us.
| Category | What it includes | Where it goes |
|---|---|---|
| A. WiFi scan data | SSID (network name), BSSID (access point MAC address), signal strength (RSSI), frequency, channel, channel width, band (2.4 / 5 / 6 GHz), security capability string (Open / WEP / WPA / WPA2 / WPA3 / Enterprise), vendor OUI prefix | On-device only |
| B. Connected-network details | Currently connected SSID, local IP address, subnet mask, gateway IP, DNS server addresses, DHCP lease information, link speed | On-device only |
| C. Speed test measurements | Download and upload throughput, latency, jitter, failed-request ratio, timestamp, endpoint used. Your public IP address is necessarily visible to the measurement endpoint as part of any ordinary network request. | Cloudflare Our Worker (fallback) History on-device |
| D. LAN device discovery | IP addresses reachable on your own local subnet, TCP connect timing, inferred hostnames, vendor inferred from MAC prefix where available. This traffic never leaves your local network. | On-device only |
| E. Vault entries | Network names and passphrases that you type, generate, or scan from Android's own share-WiFi QR code. Stored as ciphertext. | Encrypted local DB |
| F. Precise location | Device latitude and longitude, obtained only while the Map tab is open, and only after you grant permission. Used to centre the map and to stamp a contribution you choose to submit. | On-device Rounded, if you contribute |
| G. Community contributions | Hotspot name, venue type, security type, coordinates rounded to 5 decimal places, vendor OUI prefix, your permission attestation, and โ only if you explicitly add one โ a venue passphrase. | Our server |
| H. Votes, reports and takedowns | The hotspot identifier, whether the entry worked, the reason selected when reporting, and a timestamp. | Our server |
| I. Install ID | A random UUID generated on your device on first launch. It is not a device identifier, not the Android ID, and not the advertising ID. It exists so the server has something to rate-limit and to attribute moderation decisions to, without knowing who you are. | Our server |
| J. Speed samples attached to a hotspot | If you choose to share a speed result against a community hotspot: download, upload and ping figures, and a timestamp. | Our server |
| K. Camera frames | Used solely by the WiFi QR import scanner. Frames are decoded in memory on the device, are never written to storage, and are never uploaded. | Processed in memory |
| L. Advertising data | Android Advertising ID (AAID), IP address, device model, OS version, coarse country/region, app interaction and ad performance events, and your consent choices recorded through Google's User Messaging Platform. | Google AdMob |
| M. Purchase data | Purchase state, product identifier and purchase token for the two one-time products. Payment details never reach us โ Google Play processes them. | Google Play Billing |
| N. Analytics & crash diagnostics | Screen views, feature-open events, ad-serve outcomes, session length, purchase funnel events, and โ on a crash โ the stack trace, device model, OS version and locale. | Firebase |
| O. Local history | Timestamped speed test results, scan snapshots, heatmap grids and deep-scan reports, kept in a local SQLite database. | On-device only |
| P. Map tile cache | Precomputed public hotspot tiles downloaded from a CDN and cached locally for seven days. These are read-only public data; the request carries no identifier of yours. | Cached on-device |
| Q. Diagnostic tool inputs | Hostnames or IP addresses you type into Ping & Traceroute or DNS & IP Info. These are sent to the host or resolver you targeted, exactly as any network tool would. We do not log or store them. | Target host / resolver |
We never collect: your name, email address, phone number, contacts, calendar, photos, files, SMS, call logs, installed-app list, microphone audio, or any social account. The App requests none of those permissions and has no code path that could read them.
2 What Stays On Your Device
The following features run entirely on your phone. They make no request to us, and in most cases no network request at all:
- WiFi Scanner โ reads the Android WiFi scan results. Vendor lookup uses a bundled offline database, so no request is made.
- Channel Analyzer โ computes congestion and recommends a channel from the scan results already in memory.
- Signal Meter and Signal Heatmap โ sample RSSI as you walk. The grid is drawn and stored locally.
- Who's On My WiFi โ probes addresses on your own subnet. That traffic stays inside your LAN.
- Password Generator and Password Auditor โ generation uses the platform cryptographic RNG; strength estimation runs against bundled rules. Nothing typed into the auditor leaves the device.
- Password Vault โ see ยง8.
- Router Access โ detects your gateway address and opens it in your browser. It never attempts a login and ships no credential list.
- Network Deep Scan โ runs staged local analysis and produces a score and a list of fixes. The report is generated on-device.
- History โ a local Drift/SQLite database in the App's private sandbox.
- Nearby now (Map tab) โ the list of networks your phone can currently hear. This layer is measured locally and is never uploaded.
Android's application sandbox keeps this directory inaccessible to other apps. Uninstalling the App removes all of it.
3 What Reaches Our Server
We operate a small edge API on Cloudflare Workers, with storage in Cloudflare D1, R2 and KV. It exists for one purpose: the community hotspot map. It has no login, holds no user profile, and receives data only from actions you take deliberately.
| Action | What is sent | Triggered by |
|---|---|---|
| Contribute a hotspot | Name, venue type, security type, rounded coordinates, vendor OUI prefix, optional venue passphrase, permission attestation, install ID, timestamp | You tapping Submit on the contribution sheet |
| Vote on an entry | Hotspot ID, works / does not work, install ID | You tapping a vote control |
| Report an entry | Hotspot ID, reason, optional free-text note, install ID | You submitting a report |
| Share a speed sample | Download, upload, ping, hotspot ID, install ID | You choosing to attach a result |
| Fetch remote configuration | Nothing identifying. A plain read of feature flags and ad-frequency values. | App start |
| Speed test fallback | The measurement request itself. Your IP is visible to the endpoint as with any HTTP request. | Only if the primary Cloudflare endpoint is unreachable |
The offline outbox
Contributions, votes and reports are written to a local queue first and uploaded afterwards, because people add hotspots exactly where connectivity is worst. Until an upload succeeds the App shows the item as queued, never as sent. If no backend is configured for a given build, items simply remain queued locally and nothing is transmitted.
Request signing
Writes carry an HMAC signature computed over the install ID, a timestamp and the request body. This is anti-abuse plumbing, not authentication of you as a person โ it lets the server reject replayed and forged writes and enforce a per-install write limit.
Map reads never touch our server. Hotspot tiles are precomputed and served from a CDN as static files. Browsing the map sends us nothing.
4 How We Use Information
Information is used only to power the feature you are using, to keep the community dataset usable, and to keep the App working:
- To deliver the feature you opened. Scan data drives the scanner and analyzer; measurements drive the speed test; local probes drive device discovery.
- To build and moderate the community map. Contributions, votes and reports feed a moderation state machine and a quality score, so that entries which do not work fall away and entries which are reported are reviewed.
- To prevent abuse. The install ID and request signature enforce rate limits and let us block an install that poisons the dataset.
- To show ads in the free version, subject to the consent choice you make in the Google-provided consent form.
- To honour a purchase by checking entitlement against Google Play.
- To fix crashes and improve the App using aggregated diagnostics.
- To answer you when you email us.
We do not build advertising or behavioural profiles of you ourselves, we do not combine data across Epsilon Developers apps, and we do not perform automated decision-making that produces legal or similarly significant effects.
5 App Permissions
Permissions are kept to the minimum the features actually need, and each is requested at the point of use rather than at first launch.
| Permission | Why it is needed | When asked |
|---|---|---|
NEARBY_WIFI_DEVICESneverForLocation |
Reading WiFi scan results on Android 13 and above. It is declared with the neverForLocation flag, which tells the OS the App does not derive your location from it. |
When you open the WiFi Scanner or any tool that needs a scan |
ACCESS_FINE_LOCATION |
Two distinct purposes: below Android 13 the OS returns no WiFi scan results at all without it; on every version the Map tab needs it to show where you are. | On entering the Map tab, after the in-app disclosure. Below Android 13, also for scanning. |
ACCESS_COARSE_LOCATIONAndroid 12 and below only |
Fallback for scan results on older releases. Capped at API 32 in the manifest. | Same moment as fine location, on older devices |
ACCESS_WIFI_STATE |
Reading scan results and the connected network's details. Read-only. | Granted at install (normal permission) |
CHANGE_WIFI_STATE |
Starting a scan, and handing a network to the system "add network" sheet when you tap Connect. | Granted at install (normal permission) |
INTERNET, ACCESS_NETWORK_STATE |
Speed test, map tiles, ads, purchases, contributions. | Granted at install (normal permissions) |
CAMERA |
Scanning Android's share-WiFi QR code to import a network into the vault. Nothing else uses the camera. | When you open the QR scanner |
com.google.android.gms.permission.AD_ID |
Required by Google for access to the Android Advertising ID on Android 13 and above, used by AdMob. | Granted at install (normal permission) |
Permissions the App deliberately does not request
The App declares no QUERY_ALL_PACKAGES, no accessibility service, no SYSTEM_ALERT_WINDOW overlay, no background location, no contacts, storage-scope, SMS, call-log, or microphone permission.
Revoking a permission
You may revoke any permission at any time via Settings โ Apps โ WiFi Map โ Permissions. Revoking location disables the Map tab's "my location" and, on Android 12 and below, WiFi scanning. Revoking camera disables QR import. Everything else keeps working.
Speed Test, Password Generator, Password Auditor, Vault, Router Access, History and Settings all work with no runtime permission granted.
6 Location & Prominent Disclosure
Location is the most sensitive permission the App asks for, so it is worth being exact about it.
6.1 What location is used for
- Centring the map on where you are, so nearby community hotspots are the ones you see first.
- Choosing which map tiles to fetch for the area on screen.
- Stamping a contribution you choose to submit, with the coordinates rounded to 5 decimal places before they are stored or sent.
- On Android 12 and below only, satisfying the operating system's requirement that an app hold location permission before it is allowed to read WiFi scan results at all.
6.2 What location is never used for
- Background or continuous tracking. The App holds no background-location permission and starts no foreground service for location.
- Building a location history or movement profile.
- Location-targeted advertising by us. (Google AdMob independently infers a coarse country/region from your IP address โ see ยง9.)
- Sale or transfer of location data to data brokers. We do not do this and have no commercial relationship of that kind.
6.3 Prominent disclosure
Before Android's runtime permission dialog appears, the App shows a dedicated in-app disclosure screen during onboarding that names the data (location), the purpose (finding nearby hotspots and placing a contribution) and whether it is shared. That screen carries no advertising, requests no permission itself, and cannot be swiped past without acknowledgement. This satisfies Google Play's prominent-disclosure requirement, and it is deliberately placed before the OS prompt rather than buried in this document.
On Android 13 and above the scanner does not ask for location at all โ it uses NEARBY_WIFI_DEVICES with neverForLocation. You can use every scanning feature without ever granting location, and only lose the Map tab's "my location" marker and the ability to contribute.
7 Community Map & Shared Credentials
The community layer of the map is user-generated content. This section explains its privacy properties; the rules governing what may be posted are in the Community Guidelines, and network owners can request removal through the Network Owner Removal page.
7.1 What a contribution contains
When you contribute a hotspot you supply the venue name, venue type, security type and โ optionally โ the passphrase for a venue you are entitled to share. The App attaches the coordinates rounded to 5 decimal places (roughly one metre of precision removed) and the vendor OUI prefix. It attaches your install ID so the entry can be rate-limited and moderated.
7.2 What is deliberately not stored
- Full BSSIDs are never stored. Only the first three octets โ the manufacturer prefix โ are kept. The server rejects a full MAC address outright rather than truncating it silently. A full BSSID is a stable identifier for a specific access point and, in aggregate, a location database; we do not want one and do not keep one.
- Precise coordinates are never stored. Rounding happens on the device before transmission.
- Your identity is never stored. There is no account, no email, no device identifier โ just the random install ID.
7.3 Permission attestation
Contributing requires you to affirm that you have the right to share the network in question. Sharing a passphrase you are not entitled to share is a violation of the Acceptable Use Policy and will result in removal and, on repetition, in your install being blocked from contributing.
7.4 Moderation
New entries enter a pending state. They become visible after corroboration from distinct installs or after manual approval, and are automatically flagged for review once they accumulate negative reports. Removed entries are deleted from the published tiles on the next rebuild, and because tiles are replaced atomically rather than merged, a removed entry disappears from devices rather than lingering in a stale cache.
7.5 Credentials for community entries
Where a community entry carries a venue passphrase, that credential is stored encrypted on the server and delivered per hotspot on request, rather than baked into the public tile. That is what makes a takedown effective: revoking one record removes it everywhere, instead of it surviving in every tile every device has already cached.
Anything you contribute is public. Do not put your home network, your personal passphrase, or any information you would not post publicly into a contribution. Contributions are intended for venues that offer WiFi to their customers or the public.
8 Password Vault & Encryption
The vault holds network credentials that you typed, generated in the App, or scanned from Android's own share-WiFi QR code. It is entirely local.
8.1 How entries are protected
- A random 256-bit key is generated on your device and held in
flutter_secure_storage, which on Android is backed by EncryptedSharedPreferences โ the key material is wrapped by the Android Keystore and does not leave the device. - Each passphrase is encrypted with AES-256 in counter mode under a per-entry nonce, then authenticated with an HMAC-SHA256 tag computed over nonce โ ciphertext. Encrypt-then-MAC means a tampered record fails to verify rather than decrypting to garbage.
- Only the ciphertext is written to the local database. The key is never written into it.
- Nothing in the vault is uploaded, synced, backed up to our servers, or shared with any third party.
8.2 What this protects against, and what it does not
This design protects your vault against another app reading the database file, and against an attacker who obtains the database without the Keystore-held key. It does not protect against malware running with root privileges on your device, nor against someone who has your unlocked phone in their hands. Keep a screen lock enabled.
8.3 Device backup
Where Android's backup mechanism is enabled on your device, encrypted values may be included in a device backup by the operating system. That backup is governed by Google's terms, not ours, and the ciphertext remains unreadable without the corresponding Keystore key.
9 Advertising & Consent
The free version of WiFi Map displays advertising supplied by Google AdMob. Advertising is removed entirely for anyone holding the Remove Ads or Pro purchase.
9.1 What AdMob receives
- Android Advertising ID (AAID) โ a resettable identifier you control
- IP address, used for ad delivery and coarse country/region inference
- Device model, OS version, language, screen characteristics
- Ad interaction and performance events (impression, click, completion)
- The consent choices you made in the Google consent form
This information is processed by Google under Google's own privacy policy. We do not control it, and we do not receive the underlying identifiers back.
9.2 Consent (UMP)
The App initialises Google's User Messaging Platform before any ad is requested. Where you are in the EEA, the UK, Switzerland, or a US state with an applicable privacy signal, UMP presents the appropriate consent or preference form and records your choice. If consent cannot be resolved, the App treats that as a refusal and does not request ads โ it does not fall back to serving them anyway.
You can revisit your choice at any time from Settings โ Privacy โ Ad privacy options inside the App.
9.3 Mediation partners
AdMob mediation may be used to fill inventory from additional advertising networks. Where mediation is active, the participating networks receive the same categories of advertising data listed above under their own privacy policies. The current mediation partners are listed on the Data Safety Declaration page and kept up to date there.
9.4 Opting out
- Reset or delete your Advertising ID: Android Settings โ Privacy โ Ads. Deleting it stops personalised advertising; you will still see non-personalised ads.
- Change your consent choice in the App at Settings โ Privacy.
- Remove ads entirely with a one-time purchase (ยง12).
9.5 How ads behave
Rewarded advertising is always opt-in, always states the reward before it plays, and always presents a decline option at equal visual weight. No core feature of the App sits behind an advertisement. No advertisement is shown on the consent screen, the prominent-disclosure screen, a permission screen, the paywall, or while a measurement is running.
10 Analytics & Diagnostics
The App uses Firebase Analytics, Firebase Crashlytics and Firebase Remote Config.
| Service | What it is for | What it receives |
|---|---|---|
| Analytics | Understanding which features are used and how often, so development effort goes to the right places, and measuring the effect of ad-frequency settings on retention. | Screen views, feature-open events, ad outcomes, session length, purchase funnel events, a Google-generated app instance ID |
| Crashlytics | Diagnosing crashes and non-fatal errors. | Stack trace, device model, OS version, locale, app version, and a breadcrumb trail of recent screens |
| Remote Config | Adjusting ad frequency caps, feature flags and kill switches without shipping a new release. | A configuration fetch; no personal data is sent |
Analytics events are not tied to your name, email or any identifier you supplied, because you never supplied one. Crash reports are used to fix defects and are not used to build a profile of you.
Turning analytics off
Analytics collection follows your advertising consent choice. If you decline consent in the Google-provided form โ or if consent cannot be resolved โ analytics is switched off along with advertising, and Firebase is instructed to reset the app instance ID. You can revisit that choice at Settings โ Privacy โ Ad privacy options, which appears wherever privacy law entitles you to change it.
You can also stop collection entirely by revoking the App's network access at the operating-system level, or by uninstalling. A dedicated analytics switch, independent of ad consent, is planned; this Policy will be updated when it ships.
If a build ships without Firebase configuration, Analytics, Crashlytics and Remote Config all no-op silently and the App runs on compiled-in defaults. In that state no analytics data is collected at all.
11 Third-Party Services
Each service below operates under its own privacy policy. We have no control over their practices and encourage you to read them.
๐ Google AdMob
Serves advertising in the free version. Receives the Advertising ID, IP address and ad interaction events.
Google Privacy Policy โ๐ก๏ธ Google User Messaging Platform
Collects and records your advertising consent choice where privacy law requires one.
Google Privacy Policy โ๐ Google Play Billing
Processes the two one-time purchases. Your payment details are handled entirely by Google and never reach us.
Google Play Terms โ๐บ๏ธ Google Maps SDK for Android
Renders the map. Google receives the map requests your device makes, including the viewport being displayed.
Google Privacy Policy โ๐ฅ Firebase (Analytics, Crashlytics, Remote Config)
Usage analytics, crash diagnostics and server-tunable configuration.
Firebase Privacy โโก Cloudflare โ speed measurement
Speed tests connect to Cloudflare's public measurement endpoints. Your IP is visible to Cloudflare as part of the request.
Cloudflare Privacy โโ๏ธ Cloudflare โ our infrastructure
Our own edge API and its storage run on Cloudflare Workers, D1, R2 and KV. Cloudflare is our processor and acts on our instructions.
Cloudflare Privacy โ๐ฆ Google Play Services
Underlying Android platform services used for purchase verification, ads and maps.
Google Privacy Policy โโฒ Vercel
Hosts this website. Vercel processes standard web server request logs, including IP address and user agent.
Vercel Privacy โWe do not sell personal information, and we do not share it for cross-context behavioural advertising beyond the advertising described in ยง9, which is subject to your consent choice.
12 In-App Purchases
WiFi Map offers two one-time, non-consumable products. There is no subscription and nothing auto-renews.
| Product | Identifier | What it does |
|---|---|---|
| Remove Ads | wifimap_remove_ads | Removes banner, native, interstitial and app-open advertising permanently. |
| Pro | wifimap_pro | Everything in Remove Ads, plus all optional depth features unlocked permanently without watching anything. |
All payment processing is performed by Google Play Billing. We receive only the purchase state, product identifier and purchase token. We never see or store your card number, billing address, bank details or Google account.
Entitlement is stored locally and re-verified against Google Play. Refunds are governed by the Purchase & Refund Policy.
13 Data Retention
| Data | Retained | Until |
|---|---|---|
| Scan history, speed test history, heatmaps, deep-scan reports | On your device | You clear them in Settings, or uninstall the App |
| Vault entries | On your device, encrypted | You delete the entry, clear all data, or uninstall |
| Map tile cache | On your device | 7 days per tile, matching the tile's own cache header |
| Queued contributions awaiting upload | On your device | Uploaded, or cleared by you |
| Published community hotspot entries | Our server | Removed on takedown, on moderation rejection, or when quality score collapses |
| Votes, reports and speed samples | Our server | Retained while the parent hotspot exists; deleted with it |
| Install ID against server records | Our server | Deleted on a verified deletion request, or with the records it is attached to |
| Abuse and rate-limit counters | Our server | Rolling window, typically 30 days |
| Analytics events | Firebase | Per Google's retention setting for the project, currently 14 months |
| Crash reports | Firebase Crashlytics | 90 days, per Google's default |
| Support email correspondence | Our mailbox | 24 months, then deleted |
Where a longer period is required to comply with a legal obligation, to resolve a dispute, or to enforce our agreements, we retain the minimum necessary for that purpose and no longer.
14 Legal Basis for Processing
Where the EU or UK General Data Protection Regulation, India's Digital Personal Data Protection Act 2023 and the Digital Personal Data Protection Rules 2025, or a comparable law applies, we rely on the following bases:
| Basis | Applies to |
|---|---|
| Consent | Location, camera and notification permissions; advertising and the consent choice recorded through UMP; analytics where you leave it enabled; submitting a contribution to the community map. |
| Performance of a contract | Delivering the features you requested, including speed testing, map tile delivery and honouring a purchase. |
| Legitimate interests | Preventing abuse of the contribution endpoint, moderating the community dataset, diagnosing crashes and securing the service โ balanced against your rights, and limited to what is necessary. |
| Legal obligation | Responding to lawful requests and complying with statutory duties, including breach notification. |
Under the DPDP framework, we act as a Data Fiduciary for the limited personal data described in ยง3, and the notice requirements of that framework are satisfied by this Policy together with the in-app disclosure and consent screens. Where processing rests on consent, you may withdraw it at any time โ through the App's Settings, through Android's permission settings, or by writing to us. Withdrawal does not affect processing carried out before withdrawal, and may limit features.
15 Your Rights
Depending on where you live, you may have the right to access, correct, delete, restrict, port or object to the processing of your personal data, to withdraw consent, to nominate another person to exercise your rights on your behalf (DPDP), and to complain to a supervisory authority. Because the App holds almost everything locally and has no account, most of these you can exercise directly and instantly:
Delete your data
Settings โ Privacy โ Delete everything wipes history, vault and cached tiles immediately.
Access your data
Everything the App holds about you is visible in History, Vault and Reports. There is no hidden profile.
Port your data
Deep-scan reports and heatmaps export as files you keep. Ask us for any server-side record tied to your install ID.
Opt out of ads
Change your consent choice in Settings, reset your Advertising ID, or buy Remove Ads.
Turn off analytics
Analytics follows your ad consent choice โ decline it, and no events are sent. Settings โ Privacy โ Ad privacy options.
Revoke location
Android Settings โ Apps โ WiFi Map โ Permissions. The Map tab degrades; nothing else does.
Remove a contribution
Report the entry in-app, or use the Network Owner Removal form for a network you control.
Ask us anything
contact@epsilondevelopers.xyz โ we reply within 7 business days.
To exercise a right that needs our involvement, email contact@epsilondevelopers.xyz with enough detail to locate the record โ for server-side data, that means your install ID, which is shown at Settings โ About this app, then long-press the version number. We do not ask for identity documents; the install ID is the only thing that ties a server record to a device, and possession of it is what we can verify.
If you are unsatisfied with our response you may complain to your local supervisory authority โ in India, the Data Protection Board of India; in the EEA or UK, your national data protection authority.
16 Deleting Your Data
There are three routes, and full instructions are on the Data Deletion page.
- In-app, immediately. Settings โ Privacy โ Delete everything removes every local database, the vault (including its encryption key), cached tiles and queued uploads.
- Uninstall. Android's sandbox model removes all App data on uninstall.
- Server-side records. Email us your install ID and we will delete the contributions, votes, reports and speed samples associated with it, within 30 days. Published hotspot entries that other users have since corroborated may be retained in de-identified form, with your install ID severed from them, so that the community dataset does not lose verified public venue information โ you may still request full removal of a specific entry and we will action it.
Your install ID is a random UUID with no connection to your identity. It is the only handle we have on server-side data, so quoting it is what lets us find and delete that data.
17 Children's Privacy
The App is not directed to children. It is rated for a general audience, is not enrolled in Google Play's Designed for Families programme, and is not tagged for child-directed treatment in AdMob.
We do not knowingly collect personal data from a child under 13, or under the higher age of digital consent applicable where you live โ 16 in several EEA states, and 18 under India's DPDP Act, which requires verifiable parental consent for a child's personal data and prohibits behavioural advertising directed at children.
If you believe a child has used the App and that personal data has been collected, write to contact@epsilondevelopers.xyz and we will delete it promptly.
18 International Data Transfers
We are based in India. The infrastructure we use is globally distributed:
- Cloudflare Workers, D1, R2 and KV run at edge locations worldwide; requests are typically served from the point of presence nearest to you.
- Google (AdMob, Firebase, Play Billing, Maps) processes data in Google's global infrastructure, principally the United States and the EEA.
- Vercel serves this website from its global edge network.
Where personal data is transferred out of the EEA or UK, the transfer relies on the safeguards our processors maintain โ principally the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and, where applicable, the EUโUS and UKโUS Data Privacy Framework certifications held by those providers. Under the DPDP Act, transfers are made to jurisdictions not restricted by the Central Government.
19 Security
Measures in place include:
- TLS on every network request the App makes.
- AES-256 encryption with HMAC-SHA256 authentication for vault entries, under a key held in Android's hardware-backed Keystore (ยง8).
- HMAC request signing and per-install rate limits on every write to our server.
- Server-side encryption of community venue credentials, delivered per hotspot rather than embedded in public tiles.
- Data minimisation by design โ coordinates rounded before transmission, full BSSIDs rejected at the server, no accounts to breach.
- Android application sandboxing, which keeps local data inaccessible to other installed apps.
No method of electronic storage or transmission is perfectly secure. We do not claim absolute protection, and you remain responsible for the security of your own device, screen lock and network.
20 Breach Notification
If a personal data breach occurs that affects data we control, we will:
- notify each affected user without undue delay, by in-app notice and โ where we have an address โ by email;
- notify the Data Protection Board of India as required by the DPDP Rules 2025, including an initial intimation without delay and a detailed report within the prescribed period;
- notify the competent supervisory authority within 72 hours where the GDPR or UK GDPR applies;
- describe what happened, what data was involved, what we are doing about it, and what you should do.
Because the App holds no accounts, no passwords of ours, no email addresses and no payment data, the realistic blast radius of a breach of our systems is the community hotspot dataset and the install IDs attached to it.
21 What This App Cannot Do
These limits are technical facts about Android, stated here because apps in this category frequently imply otherwise:
It cannot read the passwords already saved on your phone. There is no API on a non-rooted Android device that exposes a saved network's passphrase. The App contains no such capability, the native bridge exposes no such method, and the vault holds only what you typed, generated, or imported from Android's own share-WiFi QR code.
It cannot recover, guess, crack or brute-force anybody's WiFi password. No feature attempts it, and none ever will. Any app claiming to do so is either fabricating the result or breaking the law.
It cannot connect you to a network silently. Joining a network always ends in a system dialog that Android controls and you confirm. If you decline that dialog, nothing happens.
The word "Unlocker" in the App's name refers to unlocking access to public and community-shared WiFi โ venue passwords contributed by people entitled to share them, and QR codes you scan yourself. It does not refer to defeating anyone's security.
23 This Website
This website is a set of static pages hosted on Vercel. It:
- sets no cookies and uses no local storage;
- runs no analytics, no tag manager, no advertising pixel and no third-party tracker;
- loads no third-party fonts or scripts โ the stylesheet and the small amount of JavaScript are served from this domain;
- embeds no social widgets and no comment system.
Vercel, as our hosting provider, processes ordinary web server request logs โ IP address, user agent, requested path, timestamp โ for delivery, security and abuse prevention. That processing is governed by Vercel's privacy policy. We do not receive or analyse those logs for marketing.
Because no cookies are set, no cookie banner is required or shown.
24 Changes to This Policy
We may update this Policy as the App changes or the law does. When we do, we update the "Last updated" date at the top of this page. For material changes โ a new category of data, a new recipient, or a new purpose โ we will also show an in-app notice and, where consent is legally required for the change, ask for it again rather than assuming it.
Changes take effect on publication. Continuing to use the App after a change means you accept the updated Policy; if you do not, you can stop using the App and uninstall it.
25 Contact & Grievances
- Publisher
- Epsilon Developers โ independent software publishers
- Operated by
- Satyam Kushwaha & Anurag Mahajan
- Country
- India
- Role under DPDP
- Data Fiduciary
- Grievance contact
- contact@epsilondevelopers.xyz
- Response time
- Within 7 business days; formal grievances resolved within 30 days
Please put "Privacy request" in the subject line, and include your install ID if the request concerns server-side data. If you are dissatisfied with the outcome, you may escalate to the Data Protection Board of India or to your local supervisory authority.
Questions about your privacy?
Privacy requests, data deletion, takedowns and support all reach the same inbox. We aim to reply within 7 business days.
โ๏ธ contact@epsilondevelopers.xyz