Last updated: 23 September 2026
Warden has no account, no analytics, no crash reporting, no ads, and no third-party tracking SDKs. Your traffic never passes through us, and your firewall rules, activity logs and tracker history never leave your phone. The one server we run is a small list server that delivers blocklists and, for Warden+ subscribers, confirms with Google Play that the subscription is valid (details below).
Warden makes outbound connections for exactly four things: (1) forwarding your own DNS lookups to a public resolver you choose (only when tracker blocking or Deep Inspection is on), (2) downloading blocklist updates you have enabled (one-way downloads from our list server and public community lists — free lists carry no identifier, account, or usage data; for Warden+ subscribers the curated-list download also carries the Google Play purchase token so our server can confirm the subscription, see below), (3) Google Play billing for the Warden+ subscription, which is handled by Google Play itself under Google's privacy policy — Warden never sees your payment details, and (4) only while you have the Surveillance Map open, looking up publicly-mapped cameras near you, which necessarily sends your approximate position to a third party. Each is explained below.
The Surveillance Map shows publicly-mapped surveillance cameras (from the OpenStreetMap/DeFlock community) around you. To do that it asks the public Overpass API for cameras in the map area you are viewing, and loads map tiles from OpenStreetMap. That request necessarily contains your approximate position (the area being displayed), and those services are operated by third parties under their own privacy policies.
This happens only while the Surveillance Map screen is open. It is not tied to any account or identifier, we never receive or log it, and no other part of Warden transmits your location. Your own detections and tracker-sighting history stay on your device unless you deliberately export them. If you never open the map, Warden never sends your position anywhere.
VpnService to run a local VPN that stays on your phone.BIND_VPN_SERVICE) — the only non-root way to control an app's connections and to monitor traffic. Your traffic is not routed to any Warden server. In Deep Inspection mode, Warden acts as a local proxy: it forwards each connection to its normal destination through your device's own network, so apps keep working, while logging the connection metadata locally.INTERNET) — used for two things. First, to forward your DNS lookups to the public resolver you choose (Cloudflare or Quad9 by default), and only when the tracker blocker or Deep Inspection is on. By default these lookups are sent over encrypted DNS-over-HTTPS (DoH). Warden does not keep a copy of your lookups beyond the on-device activity list you can clear at any time. Second, to download blocklist updates you have enabled — a plain HTTPS download of a text file (from Warden's list server, the community lists you toggle on, or any list URL you add yourself — Warden fetches exactly that address, once a day, with nothing attached). Free-list requests carry no account, identifier, or usage data. If you subscribe to Warden+, the download of the curated Warden+ list also sends your Google Play purchase token and product ID, so the list server can ask Google Play whether your subscription is valid before serving the paid list. That is its only use: the raw token is never stored or logged — the server keeps only a one-way hash of it next to the answer (valid or not, product, expiry) for at most 8 days, so it doesn't have to ask Google on every refresh and paying users aren't locked out if Google is briefly unreachable. The list server runs on Cloudflare, which processes ordinary request metadata (such as IP address) to operate the service under Cloudflare's own privacy policy; Warden's code does not read or keep it. The firewall and lockdown modes make no outbound connections at all.QUERY_ALL_PACKAGES) — to show the per-app firewall list and to label connections with the app that made them. Never transmitted.ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION) — Android requires location permission to scan Wi-Fi and Bluetooth. Warden uses it to (1) detect nearby surveillance devices (trackers, ALPR/Flock cameras) and (2) record, on your device only, the places where a tracker was seen following you, so it can warn you. Warden never collects your location and never sends it to us. The only case where position data leaves the device is the Surveillance Map's third-party camera lookup described at the top of this policy, while that screen is open.BLUETOOTH_SCAN, BLUETOOTH_CONNECT) — to detect nearby Bluetooth trackers (AirTag, Tile, SmartTag, etc.) and, if you ask, to connect to one so it plays its anti-stalking sound. BLUETOOTH_SCAN is declared neverForLocation.RECORD_AUDIO) — used only for real-time, on-device ultrasonic-beacon detection. Audio is analyzed live and is never recorded, stored, or transmitted.ACCESS_NETWORK_STATE) — to apply your separate Wi-Fi and mobile-data rules to the active network.RECEIVE_BOOT_COMPLETED) — to re-enable the firewall after a restart if you had it on.We never sell your data, and we never share it for advertising or analytics. The only data ever transmitted off your device is the Surveillance Map's camera lookup (your approximate map position, sent to OpenStreetMap/Overpass while that screen is open), your DNS lookups going to the public resolver you selected, and — for Warden+ subscribers only — the purchase token our list server uses to confirm your subscription with Google Play, as described above. None of it is tied to an account.
Everything Warden stores is on your device, in the app's private storage: your firewall rules, your blocklist settings and custom domains, short-lived on-device activity logs (blocked activity, DNS lookups, connections), and your local tracker-sighting history. You can clear the logs in-app, and uninstalling Warden deletes everything.
Warden is a utility with no data collection and is suitable for all ages.
If this policy changes, the "last updated" date above will change and the new policy will ship with the app.
Questions about this policy: valscancella@gmail.com
This policy applies to the Warden Android application (dev.vdub.warden).