Privacy policy
Guard for Android collects no personal data.
In short
The app collects no personal data. It has no account, no server run by us, no analytics and no ads. Your DNS lookups (the questions your phone asks to find a site's address) go only to the DNS server the app uses, which is the current network's own. While protection runs, the app downloads lists of known dangerous addresses straight from the organisations that publish them. The app sends them no information about you; the section on address lists explains what they can see anyway.
Who is responsible
The data controller is Cocode (Babak Bandpey), bb@cocode.dk. Because the app collects no personal data, we hold no information about you in practice. You can send questions about the app or this policy to the same address.
What the app collects
Nothing that can be tied to you. Specifically:
- No account, and so no name, no email address and no phone number.
- No server run by us. The app sends no data to Cocode. It contacts only the network's DNS server and the publishers of the address lists, as described below.
- No analytics, tracking or ads, and no third-party tools for them.
DNS lookups
A DNS lookup is the question your phone asks to find a site's address, for example "where is example.com?". To filter, the app has to see these lookups. They are handled inside the phone. If a name is on the block list, the app gives an empty answer, and the site does not load. Every other lookup is passed on to the DNS server the app uses.
That is the current network's own DNS server, for example your internet provider's or the Wi-Fi network's. Today the app has no setting for choosing another one. If a later version adds one, this policy will say so. Whoever runs the DNS server can see the lookups under their own rules, just as before you installed the app. The app does not send them to Cocode or to anyone other than that DNS server.
Android calls the app a VPN because it uses Android's VPN feature. A VPN usually sends your traffic to a server run by someone else. This app does not. There is no VPN server, and the local tunnel starts and ends inside the app, on the phone. Only DNS lookups and connections to addresses on the lists below go through the app. The rest of your traffic does not go through the app. While protection runs, Android shows a key icon in the status bar. That is Android's own sign for apps that use its VPN feature. It does not mean your traffic goes to a VPN server.
Lists of dangerous addresses
Some apps and some malicious software go straight to an address (an IP address, the number that identifies a computer on the internet) instead of looking up a name. The name list cannot stop that. So the app downloads lists of known dangerous addresses. While protection runs, the app refuses at once any connection from any app to an address on the lists. The connection never leaves the phone, and the app passes nothing on to the internet. The app counts the refused connections, and a notification tells you which app tried (when Android can say), which address it was and which list it was on.
Which lists
- Spamhaus DROP, for IPv4 and for IPv6, published by The Spamhaus Project:
https://www.spamhaus.org/drop/drop_v4.jsonhttps://www.spamhaus.org/drop/drop_v6.json - Feodo Tracker, the recommended IP blocklist, published by abuse.ch:
https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt
The app fetches nothing else from them but these three files. The lists are data. The app never downloads program code and runs nothing it downloads.
How and how often
The app downloads the lists itself, straight from the publishers, over HTTPS. There is no server of ours in between. It downloads only while protection runs. Once all three lists are downloaded, it normally waits at least 24 hours before fetching again. If a download fails, the app tries again later, after at least an hour. Each time, it fetches all three lists.
What the publishers can see
As with any visit to a website, the publisher can see your IP address, the time and the ordinary details of a network request, for example Android's standard text (the user agent) saying which Android version and which phone is asking. The app sends no account, no identifier and no information about you or about what it has blocked. What the publishers do with what they can see is up to them. We do not see it.
The phone looks up the publishers' names in the ordinary way. So the network's DNS server and your internet provider can see that the phone is downloading the lists, just as with any other website.
Which app tried
To name the app, the app asks Android which app owns a blocked lookup or connection. This happens on the phone. The app can only see the apps that have an icon on the home screen. If Android cannot say which app it was, the notification says only "an app" and the "Recent blocks" list says "An unknown app". The name is shown in the notification for a blocked address and in the "Recent blocks" list on the app's screen. For each app, the list shows how many lookups and connections were blocked and the latest names or addresses it tried to reach. The list exists only in the phone's memory while protection runs, is cleared whenever protection starts or stops, and is never saved or sent anywhere. The notification is Android's, so Android may keep it itself, for example in the notification history.
What stays on the phone
The app counts how many lookups and connections it has blocked. The numbers and the app's settings stay on the phone and are not sent anywhere. The app writes no history of blocked names, addresses or apps. It remembers, in memory only and only while protection runs, which addresses it has already told you about.
The address lists are stored on the phone too, so they can be used without downloading again. If a list is more than 7 days old, the app pauses it, because old lists can block addresses that others use now. The screen tells you when a list is paused. You delete everything by clearing the app's data or uninstalling the app.
The block list of names, AdGuard's DNS filter, comes bundled in the app. The app does not download it from any server. If a later version fetches updates to the name list, this policy will be corrected to say so.
Permissions
VPN
Needed so the app can see DNS lookups and refuse connections to dangerous addresses. Android asks for your permission the first time you tap Start protection. Without it, the app cannot protect the phone. See the section on DNS lookups for what the tunnel does and does not do.
Notifications
Used to tell you if protection stops, and when a connection to a dangerous address has been refused. If you turn notifications off, the app cannot tell you when protection stops, and the screen reminds you of that.
Everything else
The app uses no other permissions. It has no access to your contacts, your location, your files or Android's accessibility features. The app uses Android's ordinary network access, which Android grants automatically, so it can pass lookups on and download the address lists.
Sharing with others
We share no data with anyone, because we have none. The lookups go to the DNS server, and the lists are downloaded from the publishers, as described above. Whoever runs them sees what a server always sees in a connection: your IP address and the time.
Children
The app collects no data from anyone, children included.
Your rights
Under the General Data Protection Regulation (GDPR) you have the right to access, correct and delete your data. Because we hold no information about you, there is nothing to access or delete. Write to bb@cocode.dk if you are in doubt anyway. You can also complain to the Danish Data Protection Agency, Datatilsynet.
This website
The website uses no cookies, no statistics and no JavaScript. The typeface is served from the site itself, so no third party sees your visit. Like any web server, the server the site sits on may keep ordinary access logs.
Changes
If we change the policy, we change the date at the top and say what is new. Older versions can be seen in the project's history on GitHub.
6 October 2026: a new section on lists of dangerous addresses and on the app downloading them. The sections on what stays on the phone, on permissions and on sharing with others are updated.
Contact
Cocode (Babak Bandpey), bb@cocode.dk.