Privacy Policy for Vartus
Effective date: August 6, 2026
com.security) handles your data. Developer: Antigravity Projects OU. Contact: support@vartus.app.Overview
Vartus is a device security app: it scans installed applications for threats, monitors network traffic locally through a VPN interface, and performs device integrity checks. Most features work fully offline; network-based features are available only to account holders.
Data We Collect and Why
(a) Data processed only on your device (never transmitted)
- Full metadata of installed applications (versions, permissions, signatures, icons) — used for local threat scanning.
- The VPN monitor's network traffic journal: domains (DNS/SNI), IP addresses, ports, and per-app traffic volume.
- Scan results, the trusted apps list, and the in-app PIN code (the PIN is stored in Keystore-encrypted storage).
(b) Data collected when you sign in to an account
Accounts are issued on request; this is a premium feature. When you are signed in we collect:
- Credentials: username and password (the password is transmitted over HTTPS and stored server-side only as a hash).
- Device identifier
deviceKey— a random string generated by the app; not a hardware identifier (not IMEI, not Android ID, not the advertising ID). - The list of installed applications: package names, display names, and a system-app flag.
- Session tokens (access / refresh JWT) — stored on the device in encrypted storage (Android Keystore / EncryptedSharedPreferences).
For the installed-apps list we do not upload versions, permissions, signatures, icons, or your device model.
(c) Data we do NOT collect
We do not collect any of the following:
- Location
- Contacts
- Camera or microphone
- SMS
- User files
- Hardware identifiers
- Payment data
- Advertising / ad identifiers
- Third-party analytics or crash reporting (the app contains no analytics SDKs)
Sensitive Permissions
QUERY_ALL_PACKAGES— Vartus is a device security app; access to the full list of installed applications is required to scan them for malware indicators. This is the core functionality of the app.PACKAGE_USAGE_STATS(Usage Access, granted manually by the user) — used to verify that protection features have not been disabled; this data never leaves the device.BIND_VPN_SERVICE(VPN) — local traffic monitoring, as described above. Your traffic is not routed through any external server and HTTPS is not decrypted.- Foreground service (
specialUse, subtypelocalTrafficMonitor) and notifications — so the VPN monitor keeps running while the app is closed.
Data Retention
Account data and installed-apps snapshots are retained while the account is active. Upon account deletion they are removed within 30 days. Local data is removed together with the app (allowBackup=false — no Google cloud backups are made).
Data Sharing
We do not sell, rent, or share your personal data with any third parties. Data is not used for advertising. The only exception is where disclosure is required by law.
Security
All data transmission uses HTTPS. Passwords are stored only as hashes (bcrypt / argon). Session tokens and the in-app PIN are kept on the device in encrypted storage with keys held in the Android Keystore. The local VPN traffic journal is encrypted at rest with AES-256-GCM using an Android Keystore key.
Account and Data Deletion
You can request deletion of your account and associated data at any time — including without installing the app. See our Account and Data Deletion page for the process and what is removed.
Children
The app is not directed to children under 13, and we do not knowingly collect data from children.
Changes to This Policy
Updates are published on this page with a new effective date. Continued use of the app after an update constitutes acceptance of the revised policy.
Contact
Antigravity Projects OU — support@vartus.app