Last updated: May 15, 2026
Version: 2.0
Developer: Pocket Guardian
Contact: pocketguardian.app@gmail.com
Application: Pocket Guardian — Device Security Monitor
Package: com.pocketguardian.app
This Privacy Policy explains how Pocket Guardian (“we”, “our”, “the app”, or “the developer”) collects, uses, stores, and protects information when you use our mobile application available on Google Play.
By installing and using Pocket Guardian, you acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy. If you do not agree with any part of this policy, you must not install or use the application.
We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) for users in the European Economic Area, the California Consumer Privacy Act (CCPA) for California residents, and other applicable regional privacy laws.
Pocket Guardian is designed exclusively for the purpose of monitoring your own personal device against unauthorized access. Typical lawful use cases include:
You must read this section carefully before using the application.
By installing and using Pocket Guardian, you represent, warrant, and agree that:
The developer assumes no liability whatsoever for any unlawful, improper, or unauthorized use of this application. Any consequences — civil, criminal, or otherwise — arising from misuse of Pocket Guardian are the sole responsibility of the user.
When a security event occurs, the app may capture a photo using your device’s camera, subject to your settings. Security events that may trigger photo capture include:
Camera selection: You may choose between the front camera (default, to capture a face portrait) and the rear camera (to capture the surrounding environment). This setting is configured globally in Settings → Camera.
Photo quality: You may choose one of three quality modes — Eco (smallest file size), Standard (balanced), or High (maximum detail). All modes produce local JPEG files; quality affects file size and upload speed only.
Photo overlays: You may optionally enable the following information to be burned onto each photo at capture time:
These overlays are rendered locally on your device and are not transmitted separately. The Android ID overlay may qualify as personal data under applicable privacy law; it is disabled by default and only burned into photos if you explicitly enable it.
Storage:
/data/data/com.pocketguardian.app/files/captures/)The app records security events on your device. Each log entry includes: timestamp, event type, event text, camera used (if a photo was taken), and a reference to the associated photo file (if any). Logged event types include:
| Event Type | Description |
|---|---|
| Successful unlock | Device unlocked with correct PIN, pattern, fingerprint, or Face ID |
| Wrong PIN on lock screen | Incorrect PIN, pattern, or password entered on the system lock screen |
| Screen wake while locked | Screen turned on while device was locked, without PIN entry |
| Charger connected | USB cable or wireless charger plugged in |
| Charger disconnected | USB cable or wireless charger unplugged |
| Headset connected | Wired headset or earphones connected via 3.5mm jack or USB-C |
| Headset disconnected | Wired headset or earphones disconnected |
| SIM card change | SIM card removed, inserted, locked, or carrier changed |
| Device picked up | Hardware motion sensor detected the device was moved after being stationary |
| App login – success | Correct PIN entered inside the Pocket Guardian app |
| App login – wrong PIN | Incorrect PIN entered inside the Pocket Guardian app |
Note on motion sensor: The device pickup trigger uses the Android
TYPE_SIGNIFICANT_MOTIONhardware sensor. This sensor does not require any special permission and processes all data entirely on the device’s co-processor. No sensor data is transmitted off the device. This feature is disabled by default because the sensor cannot distinguish between “device picked up” and “device moving in a pocket”, which may generate false positives during walking or running.
All event logs are stored locally on your device as a JSON file and are not transmitted to any server.
Event log filtering: The app provides in-app tools to filter the event log by event type and by date range. This filtering occurs entirely on-device and does not involve any network communication.
Statistics: The app includes a local statistics screen showing event counts, bar charts by day, hourly activity breakdown, and a peak-hour indicator. All statistical computations are performed on-device using only locally stored event log data.
For the sole purpose of identifying and fixing technical errors, the app uses Firebase Crashlytics to collect anonymous diagnostic information in the event of a crash, including:
This data does not include photos, event log content, your PIN, your Android ID, or any personally identifiable information. See Section 5.1 for details.
Crashlytics collection is disabled in debug builds and enabled only in production (release) builds.
If you choose to enable Google Drive synchronization (an optional Premium feature), the app requests access to your Google account using the drive.file OAuth 2.0 scope. This scope grants access only to files that Pocket Guardian itself creates — the app has no ability to read, modify, or delete any other files in your Google Drive. Your credentials are handled entirely by Google’s Sign-In SDK and are never stored by us.
The app allows you to configure a custom display name (“alias”) that replaces “Pocket Guardian” in the system notification shade and on the app’s own login screen. This name is stored locally in SharedPreferences on your device and is never transmitted to any server or third party.
Pocket Guardian offers three optional Premium features that require a one-time in-app purchase via Google Play. No subscription, no recurring charges.
Alarm mode: When enabled, any detected security event triggers the device ringtone at maximum volume. The alarm continues until you open Pocket Guardian and log in. All alarm state is managed locally on your device; no data related to alarm events is transmitted externally.
Active schedule: Restricts monitoring to specific days of the week and a time window you define. Outside the active window all events are silently ignored. Schedule configuration is stored locally in SharedPreferences and never transmitted to any server.
Google Drive backup: Automatically uploads photos and the event log to your personal Google Drive after each event. See Section 3.4 and Section 5.2 for details. Drive sync is disabled by default and requires your explicit opt-in.
The purchase is processed entirely by Google Play Billing. All three features are permanently unlocked after a single purchase and are automatically restored if you reinstall the app. The developer does not store, process, or have access to any payment information. See Section 5.3.
| Data | Purpose | Location |
|---|---|---|
| Photos | Security documentation on your device | Your device only |
| Event logs | Security monitoring history | Your device only |
| Photo overlays (date/time, model) | User-configured metadata burned into photos | Your device only |
| Android ID overlay (if enabled) | Device identification burned into photos | Your device only |
| Statistics | On-device security pattern analysis | Your device only |
| App alias | Custom notification appearance | Your device only |
| Device / crash info | App stability and bug fixes | Firebase Crashlytics |
| Google account token | Drive sync if you enable it | Google’s servers |
| Alarm state | Audible deterrent on any event (Premium) | Your device only |
| Schedule configuration | Restrict monitoring hours and days (Premium) | Your device only |
We do not use your data for advertising, profiling, analytics, or any commercial purpose beyond operating the features of the app. We do not sell, rent, or share your personal data with any third party for commercial purposes.
We use Firebase Crashlytics solely to receive anonymous crash reports that help us fix bugs and improve stability. Crashlytics does not receive your photos, event logs, PIN, Android ID overlay data, or any content generated or stored by the app.
Firebase Privacy Policy: https://firebase.google.com/support/privacy
Google Privacy Policy: https://policies.google.com/privacy
If you enable Drive sync, your photos and event logs are uploaded directly to your personal Google Drive account using Google’s official API. This data goes to your own Drive storage — not to our servers. We act only as a technical intermediary facilitating your own backup.
Files are stored in: My Drive / Pocket Guardian / photos /
The event log is saved as events_log.json in the Pocket Guardian folder.
Premium features are purchased through Google Play’s standard billing system. All payment processing is handled entirely by Google. We do not collect, process, or store any payment card information or financial data.
All locally stored data resides in Android’s private application sandbox (/data/data/com.pocketguardian.app/), which is:
Your access PIN is never stored in plain text. It is protected using PBKDF2-HMAC-SHA1 with 10,000 iterations and a 16-byte cryptographically random salt (generated using SecureRandom). Only the resulting hash and salt are stored in SharedPreferences. This means that even in the event of unauthorized access to your device’s storage, your PIN cannot be recovered or reversed.
The same PBKDF2 mechanism is applied to your secret recovery answer.
Pocket Guardian implements an escalating lockout mechanism to prevent brute-force PIN guessing. After a configurable number of failed attempts, the app enforces an increasing delay before the next attempt is accepted. The lockout state is stored locally on the device.
All data transmitted to Google’s servers (Drive, Crashlytics) uses industry-standard TLS (HTTPS) encryption. We do not operate any proprietary servers — no data is transmitted to infrastructure controlled by the developer.
Pocket Guardian runs a persistent foreground service (EventService) to ensure security events are never missed. To guarantee continuity, the app employs a dual-layer watchdog mechanism:
Both mechanisms operate entirely locally. No network communication is involved. The watchdog is suspended when protection is manually disabled by the user.
On Xiaomi HyperOS, Samsung One UI, and other devices with aggressive battery management, additional user configuration may be required (battery optimisation exemption and AutoStart). The app guides users through this during first-launch onboarding.
The developer has no technical ability to access your photos, event logs, PIN, or any other content. All data is stored either locally on your device or in your own Google Drive account. We do not operate any backend server, database, or cloud storage that receives your personal content.
| Data Type | Retention Period |
|---|---|
| Photos and event logs | Until you delete them, reach the configured event limit, or uninstall the app |
| Google Drive data | Until you delete from your Google Drive |
| Firebase crash reports | 90 days (Firebase standard policy) |
| App settings and alias | Until you change them or uninstall the app |
| Alarm and schedule configuration | Until you change them or uninstall the app |
To permanently delete all photos and event logs from your device:
This action is irreversible and immediately deletes all local content.
Individual events and their photos can be deleted directly from the event log: long-press any entry to enter selection mode, then tap the delete icon.
You may configure a maximum number of stored events under Settings → Storage. When the limit is reached, the oldest entries (and their associated photos) are deleted automatically. Setting the limit to 0 means unlimited storage.
To request deletion of any diagnostic data held by Firebase Crashlytics on our behalf, contact us at pocketguardian.app@gmail.com. We will make reasonable efforts to process your request within 30 days.
All photo capture can be disabled independently per event type in Settings without deleting other data. You may also disable capture globally by turning off the camera permission for the app in Android system settings.
The device pickup (motion sensor) trigger can be disabled independently in Settings → Events & Photos → Log device pickup. This feature is disabled by default.
Alarm mode can be disabled at any time in Settings → Security → Alarm Mode. This is a Premium feature that requires a prior purchase to enable.
The active schedule can be disabled or modified at any time in Settings → Security → Active schedule. When disabled, monitoring is active at all times (subject to the protection toggle).
If you are located in the EEA, Switzerland, or the United Kingdom, the following applies:
Legal bases for processing:
| Processing Activity | Legal Basis |
|---|---|
| Local security monitoring (event log, photos) | Legitimate interest (Art. 6(1)(f)) — you monitor your own device |
| Motion sensor detection | Legitimate interest (Art. 6(1)(f)) — you monitor your own device |
| Android ID photo overlay (if enabled) | Consent (Art. 6(1)(a)) — requires your explicit opt-in in Settings |
| Crash diagnostics | Legitimate interest (Art. 6(1)(f)) — improving app safety |
| Google Drive sync | Consent (Art. 6(1)(a)) — requires your explicit opt-in |
| Premium features | Contract performance (Art. 6(1)(b)) |
Your rights under GDPR:
To exercise any GDPR right, contact us at pocketguardian.app@gmail.com with the subject line “GDPR Request”. We will make reasonable efforts to respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your national supervisory authority.
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
We do not sell, share for cross-context behavioral advertising, or otherwise commercially exploit your personal information.
To submit a CCPA request, contact us at pocketguardian.app@gmail.com with the subject line “CCPA Request”.
Pocket Guardian is intended for users 18 years of age and older and is not directed at children. We do not knowingly collect personal information from:
If you believe we have inadvertently collected information from a minor, please contact us immediately at pocketguardian.app@gmail.com. We will promptly investigate and delete any such information.
The following Android permissions are requested by Pocket Guardian:
| Permission | Reason |
|---|---|
CAMERA |
Capture photos at security events. Can be disabled per event type in Settings. |
RECEIVE_BOOT_COMPLETED |
Resume monitoring automatically after device reboot |
FOREGROUND_SERVICE |
Maintain the monitoring service in the background |
FOREGROUND_SERVICE_CAMERA |
Required on Android 14+ to use the camera from a foreground service |
FOREGROUND_SERVICE_SPECIAL_USE |
Required on Android 14+ for a 24/7 security guard foreground service that does not fit standard foreground service types |
SYSTEM_ALERT_WINDOW |
Required on certain devices (e.g. Xiaomi HyperOS) to display the camera preview surface while the screen is locked, enabling lock screen photo capture |
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS |
Prevent aggressive battery management from stopping the monitoring service |
POST_NOTIFICATIONS |
Display a persistent status notification indicating the service is active |
READ_PHONE_STATE |
Detect SIM card state changes (removal, insertion, lock, carrier change). Optional — SIM monitoring is silently disabled if this permission is not granted. |
USE_FULL_SCREEN_INTENT |
Display the lock screen camera capture window as a full-screen intent on Android 14+ |
WAKE_LOCK |
Briefly wake the CPU to process security events and capture photos when the screen is off |
REQUEST_DELETE_PACKAGES |
Used in the in-app uninstall flow (Settings → Danger Zone → Remove App) |
INTERNET |
Required for Google Drive sync and Firebase Crashlytics. No data is sent unless you explicitly enable Drive sync. |
No undeclared permissions are used. The motion sensor (
TYPE_SIGNIFICANT_MOTION) is accessed via the standardSensorManagerAPI which requires no runtime permission. All permissions are used exclusively for the security monitoring features described in this policy.
Pocket Guardian is provided “as is” and “as available” without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, accuracy, reliability, or non-infringement.
The developer does not warrant that:
To the fullest extent permitted by applicable law, the developer shall not be liable for any:
In jurisdictions that do not allow the exclusion or limitation of liability, our liability is limited to the maximum extent permitted by law.
We reserve the right to update this Privacy Policy at any time. When we make material changes, we will:
Your continued use of Pocket Guardian after any changes constitutes your acceptance of the revised policy. We encourage you to review this policy periodically. The current version is always available at:
https://github.com/pocketguardian/pocketguardian/blob/main/docs/privacy-policy.md
This Privacy Policy and any disputes arising from it shall be governed by and construed in accordance with applicable law. Nothing in this policy limits your statutory rights under the consumer protection or data protection laws of your country of residence.
For any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data:
Email: pocketguardian.app@gmail.com
Please include one of the following subject lines as appropriate:
| Subject Line | Use For |
|---|---|
Privacy Question |
General privacy inquiries |
GDPR Request |
EEA / UK data subject rights requests |
CCPA Request |
California privacy rights requests |
Data Deletion Request |
Request deletion of your data |
We will make reasonable efforts to respond within 30 days.
© 2026 Pocket Guardian. All rights reserved.