SECURITY SENTINEL / BY ZARZARA
Privacy Policy
Your content is analyzed on-device. Local scan history, Firebase Analytics, Google ML Kit, map requests, system backups and website visits each have different data implications, explained below.
01. Who we are and what this covers
Security Sentinel is an Android application provided by Zarzara. This policy describes how the app handles selected files, text, scan results and technical data. It also explains what happens when you visit this app’s pages on zarzara.app or contact support. For privacy requests, email support@zarzara.app.
02. Content you choose to analyze
The app accesses text you enter or paste and images or documents you select. This content can include personal details, readable text in images, faces, embedded location, authorship, device information and other metadata. The app uses it to identify supported sensitive patterns, display findings, apply the changes you select and create an output copy.
Content analysis happens on your device. The app does not upload your selected files, pasted text or scan reports to a Zarzara server. Face detection looks for faces in an image; it does not identify who a person is. Detection results can be incomplete or incorrect.
03. Permissions and clipboard
Photo/media or storage access supports selecting content and displaying recent images. Android’s media-location permission allows the app to inspect original location tags embedded in a selected photo; the app does not request live device-location permission. File access may also be granted through Android’s system file picker.
Clipboard content is read when you choose Paste from Clipboard. Copy Cleaned Text writes the selected result to the system clipboard. Android, keyboards and other apps may handle clipboard content according to their own permissions and settings. You can manage app permissions in Android Settings; denying access may limit related features.
04. Local storage and scan history
To reopen previous results, the app stores copies of scanned original content and associated reports in its private app storage, along with filenames, file sizes, timestamps and material types. This includes original sensitive content even after you make a cleaned copy. History can remain available after the original file is moved or deleted.
History uses a 40 MB content budget and evicts older entries as needed. This is a size-based limit, not an automatic deletion schedule. Preferences and recent-file references are also stored locally. Working drafts may remain in memory during the app session. Generated cleaned or redacted files may be held in the app cache until Android or you clear it.
05. Google ML Kit
Security Sentinel uses Google ML Kit for supported image and text analysis. Google states that ML Kit processes input images and text on-device and does not send that input or its analysis results to Google servers.
The SDK may connect to Google for model downloads, updates and technical diagnostics. Google’s disclosed metrics include device and app information, installation identifiers, API configuration, performance, event and error information, input/output sizes and configured languages. These are handled under Google’s policies. Some model-based functions may be unavailable without a successful download or required device services.
06. Firebase Analytics
Security Sentinel uses Google Analytics for Firebase to understand app usage and improve navigation. Analytics is enabled by default. Google receives app-instance identifiers, app and device information, session and engagement events, and fixed screen names. It can derive approximate location from network IP information.
Our screen events contain only predefined screen names. We do not attach scanned text, images, documents, filenames, file paths, detected findings or photo GPS coordinates to Analytics events. Advertising ID collection and ad personalization are disabled in the app.
Analytics data is sent to Google over encrypted connections and retained according to the Analytics property settings and Google’s policies. Clearing local scan history does not delete Analytics events already sent. Contact support@zarzara.app for privacy requests.
07. Photo location maps
When a report displays a map for location embedded in a photo, the app requests map tiles from tile.openstreetmap.org. The provider receives your IP address, a technical user-agent string and tile coordinates and zoom level corresponding to the area shown. Those requests can reveal the approximate area associated with the photo.
The photo itself and its scan report are not sent with these requests. Tile requests can occur automatically when the location preview is displayed and when its zoom changes. If the connection fails or the device is offline, the app uses a local fallback illustration. OpenStreetMap Foundation’s policy governs its handling of request data.
08. Android backup and files you export
Android system backup and device transfer are enabled for the app. Depending on your Android version, device vendor, Google account and backup settings, app data such as history copies, reports and preferences may be included in cloud backups or transferred to another device. This is managed by Android and your backup provider, rather than a Zarzara synchronization service.
When you save a clean copy, the location or document provider you choose may be local storage or a cloud service. Copies you later share, exported files and clipboard content are outside the app’s private history storage. Their handling depends on your chosen destinations and services.
09. Deletion and retention controls
Delete an individual entry in Inspection History Log or use Settings → Clear History to remove the app’s saved history copies and reports. This does not delete original files, exported copies, the clipboard, all app caches or copies already held by another service.
Use Android’s app storage controls to clear cache or clear all app storage. Uninstalling normally removes private app data, but exports and system backups can remain. Manage backups through Android and your backup provider, and delete exported content from its destination. Zarzara cannot remotely retrieve or erase files stored only on your device. No app account is required, so there is no Security Sentinel account to delete.
10. Website visits and support
Visiting zarzara.app, including these legal pages, is separate from scanning content in the Android app. The website’s analytics records page path, referring page, browser/user-agent, IP address, available country information, visit time and an event identifier. The site uses Upstash Redis to store up to the latest 10,000 visit events; older events are displaced as new ones arrive rather than on a fixed time schedule. Hosting services may also process request logs under their own policies.
If you email support, Zarzara and its email provider receive your address, message and anything you attach to respond to the request. Please avoid sending sensitive source files unless needed and you choose to do so. Support correspondence is kept as needed to address the request, follow up and meet applicable obligations. Contact support to request deletion of information you have sent us.
11. Purposes, providers and your rights
Device-local processing provides the scanning and cleanup functions you request. Technical metrics help providers maintain their services; app and website analytics help Zarzara understand usage, and support messages let us respond. The app has no advertising SDK, ad-personalization features or Zarzara account service. Zarzara does not sell your scanned content.
Where applicable, service provision, legitimate interests in maintaining services and responding to support, consent where required, and legal obligations provide the bases for processing. Network and support providers may process information outside your country under their policies and applicable transfer safeguards.
Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, or withdraw consent where processing relies on it. Contact support@zarzara.app about data Zarzara holds. You may also complain to your local data-protection authority. For device-only content, use the controls above; for provider-held information, consult that provider’s rights process.
12. Security and children
The app uses Android private storage for its working data and HTTPS for map requests; ML Kit documents HTTPS protection for its technical data, and Firebase Analytics uses encrypted connections. These measures are not a guarantee against unauthorized access. Protect your device, review exported copies and consider your system backup settings.
Security Sentinel is a general-purpose utility and is not specifically directed to children. If you believe a child has sent personal information to Zarzara through support, contact us so we can address it.
13. Changes and contact
We may update this policy when the app or its data handling changes. The effective date at the top identifies the current version; material changes will be communicated as required by applicable law. Contact Zarzara at support@zarzara.app with questions about this policy.
Provider information
Questions? support@zarzara.app
Back to Security Sentinel →