Privacy Policy
Wifora ("the App", "we", "us", "our"), operated by Tranquil Mind Technology JSC, respects your privacy. This Privacy Policy explains what information the App handles, what little of it leaves your device, how it is used and shared, and the choices and rights you have. By using the App, you agree to this Policy.
Wifora is a Wi-Fi analysis toolkit: it lists the Wi-Fi networks around you, measures your connection speed, charts signal strength, scans the devices on your local network, generates and reads Wi-Fi QR codes, lets you save your own hotspot locations on a map, and helps you manage your phone's hotspot. The App has no user accounts and no login — you do not create a profile, and we operate no server that stores your data. The App contains no advertising SDK and no in-app purchases. Almost everything Wifora produces stays in a local database on your phone.
1. Information we collect
1.1 Information that leaves your device
Only the following leaves your device, and only for the purposes described:
- Crash logs and diagnostics. If the App crashes or hits a fatal error, a crash report is sent to Google Firebase Crashlytics. It contains the stack trace, the App version, your device model and manufacturer, the operating system version, device state at the time (such as free memory and orientation), a randomly generated Firebase installation identifier, and the time of the crash. It does not contain your Wi-Fi passwords, network names, measurement history, or saved locations.
- Your IP address, as an unavoidable part of connecting. Any internet request reveals your IP address to the server that answers it. This happens with the two services below.
- Speed-test traffic. When you run a speed test, the App downloads and uploads blocks of meaningless filler data to Cloudflare's public measurement endpoints (
speed.cloudflare.com). The filler contains no personal information; Cloudflare sees the request itself, your IP address, and standard connection metadata. - Map tile requests. When you open the map or download an offline map region, the App requests map image tiles from the OpenStreetMap tile service. Each request contains the coordinates of the map area you are viewing and identifies the App by name. Because you choose what area to view, these requests can indicate roughly where you are looking on a map. The App does not send your GPS position, your saved hotspots, or any identifier of you to the tile service.
We do not operate our own backend for the App. There is no server of ours that receives your networks, measurements, passwords, scans, or locations.
1.2 Information you provide
None. The App has no registration, no login, no profile, no contact form, and no user-generated content that is uploaded anywhere. Anything you type in the App — a name for a saved hotspot, a note, a generated password — stays in the local database on your phone.
When you tap a share button — to send a Wi-Fi QR image, a speed-test result, or a link to the App — the App hands that item to your phone's system share sheet and you choose the destination yourself. Nothing is sent to us in the process, and we have no visibility into what you share or with whom. Whatever you pick as the destination is governed by that app's own terms and privacy policy.
1.3 Information processed only on your device
The following is created or read on your phone and stored only there, in a local database (Hive) and local preferences. It is not transmitted to us or to any third party:
- Nearby Wi-Fi networks: network names (SSID), hardware identifiers (BSSID), signal strength, channel, frequency band and security type, as reported by Android's Wi-Fi scanner.
- Speed test history: download and upload rates, ping and jitter, and the time of each test.
- Signal strength history: samples recorded while you watch a network's signal.
- Local network scan results: the IP addresses, host names and open ports of devices found on the network you are connected to, and the device type guessed from those ports.
- Saved hotspots: the coordinates, label and notes for locations you deliberately save, plus offline map tiles you choose to download, cached in the App's private storage.
- Wi-Fi QR codes: codes you scan with the camera or open from your gallery are decoded on the device by the barcode-scanning component supplied with your device's Google Play services; the resulting network name and password are shown to you and never uploaded, and neither the camera preview nor the picked image leaves your phone. Codes you generate are rendered on the device.
- Saved Wi-Fi passwords (rooted devices only): on a rooted phone the App can read the Wi-Fi credentials the system has stored, in order to display them to you. This read happens entirely on the device and the result is never transmitted. On a normal, non-rooted phone Android does not permit this, and the App simply explains the limitation instead of reading anything.
- App settings and preferences, including your language choice and the state of onboarding.
2. Android permissions and why the App asks for them
- Internet, network state, Wi-Fi state, change Wi-Fi state, change network state — to run speed tests, load map tiles, read the state of the connection, list and refresh Wi-Fi scans, and reconnect the Wi-Fi radio.
- Precise location and approximate location — Android itself requires a location permission before any app is allowed to see the list of nearby Wi-Fi networks, because Wi-Fi networks can be used to infer position. Wifora needs this permission to show you the network list and signal readings at all. Location is additionally used to centre the map on you and to fill in the coordinates when you choose to save a hotspot. We do not track you: your position is never sent to us or to any third party, and it is not stored anywhere except in the hotspots you deliberately save on your own device.
- Nearby Wi-Fi devices (Android 13 and later) — the modern replacement for the location requirement above when scanning Wi-Fi. The App declares it with the
neverForLocationflag, meaning it is explicitly not used to derive your position. - Camera — only to scan Wi-Fi QR codes. The camera preview is processed on the device; no image or video is stored or uploaded.
- Photos / media selection — only when you choose to read a Wi-Fi QR code from an image you already have. The App opens your device's system photo picker, which hands back the single image you select and gives the App no standing access to the rest of your gallery. That image is decoded on the device and not uploaded.
- Notifications — to show local reminders on your phone, for example when a hotspot timer expires. These notifications are generated on the device; the App has no push-notification service.
- Schedule exact alarm — so a hotspot timer fires at the moment you set.
- Foreground service and wake lock — to keep a running measurement or timer alive while the screen is off.
- Shizuku (optional) — if you have the separate Shizuku app installed and you grant it, Wifora can ask it to run a local system command that turns your phone's hotspot off, which Android does not otherwise allow an ordinary app to do. This is a local device operation only: it collects nothing and sends nothing anywhere. Without Shizuku the App simply opens the system settings screen for you instead.
3. How we use information
- To provide and operate the App — scanning, measuring, charting, scanning the local network, reading and generating QR codes, mapping and managing your hotspot.
- To keep the App stable — crash reports are used to find and fix defects.
- To remember your preferences and history on your device — settings, language, and your measurement and hotspot records.
- To comply with the law — where we are legally required to act.
We do not use your information for advertising, we do not profile you, and we make no automated decisions about you.
4. Third-party services
These are the only third parties that receive anything as a result of your use of the App:
| Service | What it receives | Purpose | Policy |
|---|---|---|---|
| Google Firebase Crashlytics (Google LLC) | Crash and error reports, device and OS model, app version, Firebase installation identifier, IP address | Crash reporting and stability diagnostics | firebase.google.com/support/privacy |
Cloudflare, Inc. — speed.cloudflare.com | Speed-test requests and filler payloads, IP address, connection metadata | Measuring your download speed, upload speed, ping and jitter | cloudflare.com/privacypolicy |
| OpenStreetMap tile service (OpenStreetMap Foundation / OpenStreetMap Deutschland) | Requests for map tiles at the coordinates you are viewing, IP address, App user agent | Displaying and caching the map | osmfoundation.org/wiki/Privacy_Policy |
The App uses Firebase Core solely as the plumbing required by Crashlytics. The App integrates no advertising SDK, no advertising identifier, no analytics product, no attribution or tracking SDK, no payment or billing SDK, and no sign-in provider.
5. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising or targeted advertising. We disclose information only:
- to the three service providers listed in section 4, strictly for the purposes stated there;
- when required by law, legal process, or a valid government request;
- to protect the rights, safety, or property of users, the public, or us;
- in connection with a merger, acquisition or sale of assets, in which case this Policy continues to apply to the transferred information.
6. Legal bases for processing (EEA / UK — GDPR)
- Legitimate interests — operating the App, diagnosing crashes, and keeping the App secure and functioning.
- Consent — where you grant an Android runtime permission (location, camera, photos, notifications) you consent to that specific use; you can withdraw it at any time in your device settings.
- Legal obligation — where we must retain or disclose information to comply with the law.
7. Data retention
- On your device: your measurement history, saved hotspots, offline map tiles and settings remain until you delete them in the App, clear the App's storage, or uninstall the App. Uninstalling removes all of it.
- Crash reports: retained by Google Firebase Crashlytics in accordance with its own retention schedule (crash-free statistics and reports are kept for a limited period, typically up to 90 days for detailed reports).
- Speed-test and map-tile requests: handled by Cloudflare and the OpenStreetMap tile service under their own logging and retention practices; we receive no copy.
8. Your rights
EEA / UK (GDPR). You have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, to withdraw consent at any time, and to lodge a complaint with your national data-protection authority.
California (CCPA / CPRA). You have the right to know what personal information is collected and how it is used and disclosed, to delete it, to correct it, to opt out of its sale or sharing for targeted advertising — we do not sell or share personal information for advertising — and not to be discriminated against for exercising these rights.
Other regions. Comparable rights under Brazil's LGPD, Canada's PIPEDA and similar laws are honoured.
Because the App has no accounts and stores no data about you on our systems, you can exercise most rights yourself and immediately: delete records inside the App, revoke a permission in Android settings, clear the App's storage, or uninstall the App. If you want us to act on a crash report, write to the address in section 13; because we cannot identify you from a crash report on its own, please include your device model, the App version, and the approximate date and time of the crash so we can locate the report.
9. Children's privacy
The App is a general-purpose network utility intended for users aged 13 and over (or the higher age of digital consent in your country). It is not directed at children, it has no social features, no chat, no user-to-user content and no advertising. We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us and we will delete it.
10. International data transfers
The service providers named in section 4 operate globally, so the limited information described in this Policy may be processed in countries other than yours, including the United States and countries in the European Union. Where required, transfers rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
11. Data security
Traffic between the App and the services in section 4 uses HTTPS/TLS. Your measurement history, saved hotspots and any credentials shown to you are stored in the App's private, sandboxed storage on your device, which other apps cannot read on a normal Android installation. Please note that a rooted device weakens these operating-system protections. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Third-party content and links
The map is drawn from map data and imagery provided by OpenStreetMap contributors, and the App can open external destinations such as your system settings or your app store. We do not control third-party content or destinations and are not responsible for them; their own terms and privacy policies apply.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted at this address with a new "Last updated" date. Continued use of the App after an update means you accept the revised Policy.
14. Contact us
Tranquil Mind Technology JSC No. 3, Alley 98, Vu Trong Phung Street, Thanh Xuan Ward, Hanoi City, Vietnam Email: contact@tranquilmind.co
© 2026 Tranquil Mind Technology JSC (@Tranquil Mind Technology JSC). All rights reserved.