Last updated: 25 July 2026
Warden has no account, no analytics, no crash reporting, no ads, and no third-party tracking SDKs. We operate no server that receives your data, and your firewall rules, activity logs and tracker history never leave your phone.
Warden makes outbound connections for exactly four things: (1) forwarding your own DNS lookups to a public resolver you choose (only when tracker blocking or Deep Inspection is on), (2) downloading blocklist updates you have enabled (plain one-way downloads from our list server and public community lists — no identifier, account, or usage data is sent with the request), (3) Google Play billing for the Warden+ subscription, which is handled by Google Play itself under Google's privacy policy — Warden never sees your payment details, and (4) only while you have the Surveillance Map open, looking up publicly-mapped cameras near you, which necessarily sends your approximate position to a third party. Each is explained below.
The Surveillance Map shows publicly-mapped surveillance cameras (from the OpenStreetMap/DeFlock community) around you. To do that it asks the public Overpass API for cameras in the map area you are viewing, and loads map tiles from OpenStreetMap. That request necessarily contains your approximate position (the area being displayed), and those services are operated by third parties under their own privacy policies.
This happens only while the Surveillance Map screen is open. It is not tied to any account or identifier, we never receive or log it, and no other part of Warden transmits your location. Your own detections and tracker-sighting history stay on your device unless you deliberately export them. If you never open the map, Warden never sends your position anywhere.
VpnService to run a local VPN that stays on your phone.BIND_VPN_SERVICE) — the only non-root way to control an app's connections and to monitor traffic. Your traffic is not routed to any Warden server. In Deep Inspection mode, Warden acts as a local proxy: it forwards each connection to its normal destination through your device's own network, so apps keep working, while logging the connection metadata locally.INTERNET) — used for two things. First, to forward your DNS lookups to the public resolver you choose (Cloudflare or Quad9 by default), and only when the tracker blocker or Deep Inspection is on. By default these lookups are sent over encrypted DNS-over-HTTPS (DoH). Warden does not keep a copy of your lookups beyond the on-device activity list you can clear at any time. Second, to download blocklist updates you have enabled — a plain HTTPS download of a public text file (from Warden's list server and the community lists you toggle on). The request carries no account, identifier, or usage data, and we do not log who downloads lists. The firewall and lockdown modes make no outbound connections at all.QUERY_ALL_PACKAGES) — to show the per-app firewall list and to label connections with the app that made them. Never transmitted.ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION) — Android requires location permission to scan Wi-Fi and Bluetooth. Warden uses it to (1) detect nearby surveillance devices (trackers, ALPR/Flock cameras) and (2) record, on your device only, the places where a tracker was seen following you, so it can warn you. Warden never collects your location and never sends it to us. The only case where position data leaves the device is the Surveillance Map's third-party camera lookup described at the top of this policy, while that screen is open.BLUETOOTH_SCAN, BLUETOOTH_CONNECT) — to detect nearby Bluetooth trackers (AirTag, Tile, SmartTag, etc.) and, if you ask, to connect to one so it plays its anti-stalking sound. BLUETOOTH_SCAN is declared neverForLocation.RECORD_AUDIO) — used only for real-time, on-device ultrasonic-beacon detection. Audio is analyzed live and is never recorded, stored, or transmitted.ACCESS_NETWORK_STATE) — to apply your separate Wi-Fi and mobile-data rules to the active network.RECEIVE_BOOT_COMPLETED) — to re-enable the firewall after a restart if you had it on.We never sell your data, and we never share it for advertising or analytics — we do not receive it in the first place. The only data ever transmitted off your device is the Surveillance Map's camera lookup (your approximate map position, sent to OpenStreetMap/Overpass while that screen is open) and your DNS lookups going to the public resolver you selected. Neither is tied to an account or identifier, and neither goes to us.
Everything Warden stores is on your device, in the app's private storage: your firewall rules, your blocklist settings and custom domains, short-lived on-device activity logs (blocked activity, DNS lookups, connections), and your local tracker-sighting history. You can clear the logs in-app, and uninstalling Warden deletes everything.
Warden is a utility with no data collection and is suitable for all ages.
If this policy changes, the "last updated" date above will change and the new policy will ship with the app.
Questions about this policy: valscancella@gmail.com
This policy applies to the Warden Android application (dev.vdub.warden).