Privacy Policy for LinkShield
Official data protection and privacy declaration for LinkShield Mobile (com.linkshield.app). Engineered with a Zero-Trust, Privacy-by-Design architecture to safeguard users without surveillance.
Zero Accounts Required
No registration, no email address, and no personal credential collection to use LinkShield.
On-Device Heuristics
Punycode detection, deceptive TLD analysis, and credential harvesting defense run locally in device memory.
Auto Tracker Stripping
Invasive marketing tokens (utm_, fbclid, gclid) are scrubbed before link handoff.
Zero Data Monetization
We never sell, broker, or trade your browsing activity with advertisers or data brokers.
Introduction & Overview
Welcome to LinkShield("we", "our", or "us"). LinkShield is an Android mobile security utility engineered to protect users from malicious hyperlinks, phishing campaigns, deceptive redirects, and invasive trackers shared through messaging platforms, social media, SMS, and web applications.
We believe that cybersecurity software must respect user privacy as a fundamental human right. LinkShield operates under a Privacy-by-Design and Zero-Trust architecture:
This Privacy Policy explains what information LinkShield processes, why it is needed, how it is protected, and your rights and controls over your data.
Information We Process & How We Use It
AURLs & Hyperlinks
What We Receive: When you tap a link in a third-party app (such as WhatsApp, Telegram, Discord, Signal, SMS, or an email client) while LinkShield is configured as your default browser or link handler, the clicked URL (http:// or https://) is routed to LinkShield for real-time safety inspection. You may also manually paste a URL into the app.
- Local Heuristics (On-Device):LinkShield locally evaluates the URL for Punycode/homograph spoofing, direct IP hostnames, deceptive subdomains, suspicious top-level domains (TLDs), and sensitive credential harvesting keywords. This step runs entirely within your device's memory.
- URL Unshortening (Direct from Device): If a URL belongs to a known shortening service (e.g.,
bit.ly,tinyurl.com,t.co), LinkShield performs standard HTTP redirect queries directly from your device to the destination server to resolve the final landing page. - Privacy Tracker Stripping (On-Device): LinkShield automatically identifies and strips invasive marketing and tracking parameters (such as
utm_source,utm_medium,fbclid,gclid,mc_cid,igshid, etc.) before presenting the cleaned link to you. - External Threat Feed Lookups: To defend against zero-day malware and newly reported phishing campaigns:
- URLhaus (abuse.ch): The URL is verified against the open malware dataset hosted by abuse.ch (
https://urlhaus-api.abuse.ch/v1/url/). - Google Safe Browsing & VirusTotal (Optional):If you choose to configure your own Google Safe Browsing or VirusTotal API keys in Settings, the URL is submitted to Google's or VirusTotal's respective developer endpoints under their standard API terms.
- URLhaus (abuse.ch): The URL is verified against the open malware dataset hosted by abuse.ch (
AsyncStorage). We maintain a rolling history of up to 50 recent scans. No scan history is ever uploaded to or stored on our servers. You can delete your entire history at any time with one tap.BClipboard Data
What We Access:If the "Auto-Scan Clipboard" feature is enabled in Settings, LinkShield inspects the system clipboard when the application is brought to the foreground solely to detect whether a valid web URL is copied.
How We Use It: If a URL is detected, LinkShield populates it into the scanner to allow you to verify it immediately without manual typing.
What We Do NOT Do: LinkShield never reads, uploads, or logs non-URL clipboard data (such as passwords, credit card numbers, or personal text). Clipboard reading only occurs while the app is actively displayed on screen. You can disable clipboard scanning at any time in Settings.
CDevice Telemetry & Firebase Analytics
LinkShield uses Google Firebase Analytics (@react-native-firebase/analytics) to monitor application performance, evaluate stability, and measure high-level cybersecurity efficacy.
To guarantee that no Personally Identifiable Information (PII) or sensitive tokens are collected:
- All query strings (
?key=value), URL fragments (#hash), and user session tokens are stripped and discarded before any analytics event is logged. - Only high-level, pseudonymized metadata is logged (e.g., sanitized domain hostname such as
example.com, whether HTTPS was used, threat verdict category, threat score range, and scan duration).
Controls: You can opt out of analytics data collection at any time through the application Settings.
DPush Notifications & Remote Configuration
Firebase Cloud Messaging (FCM): We use FCM (@react-native-firebase/messaging) to broadcast critical security advisories (e.g., zero-day phishing campaigns) and app update notifications. FCM uses an anonymous, randomly generated device registration token managed by Google Play Services. LinkShield subscribes to public broadcast topics (all_users, threat_bulletins, app_updates). We do not link push tokens to any personal user profiles.
Firebase Remote Config: We use Remote Config (@react-native-firebase/remote-config) to dynamically sync high-risk TLD lists, app update thresholds, and engine parameters without requiring a full app store release. Remote Config collects standard non-personal client device parameters (e.g., OS version, app version, country locale). You may also configure a custom remote configuration URL in Settings if preferred.
EUser Preferences & Settings
Your preferred default browser package name, protection toggles, custom whitelisted domains, custom blacklisted domains, and optional threat feed API keys are stored locally on your device in protected storage. They are never transmitted to our servers.
What We Never Collect
To eliminate ambiguity, LinkShield NEVER collects, stores, or transmits:
Android Device Permissions & System Roles
LinkShield requests and utilizes only the minimum system permissions necessary to deliver link inspection:
| Permission / Role | Why It Is Needed | User Control |
|---|---|---|
Default Browser Roleandroid.app.role.BROWSER / ACTION_VIEW | Allows Android to route tapped hyperlinks to LinkShield before opening them in a web browser. | Set or revoked at any time via Android System Settings ➡️ Apps ➡️ Default apps ➡️ Browser app. |
Internet Accessandroid.permission.INTERNET | Required to query abuse.ch URLhaus threat feeds, perform redirect unshortening, and receive security advisories. | System permission required for core functionality. |
Post Notificationsandroid.permission.POST_NOTIFICATIONS | On Android 13+, allows LinkShield to notify you of critical security bulletins and engine updates. | Can be accepted, declined, or toggled off at any time in Android Settings or LinkShield Settings. |
| Clipboard ReadApp-level toggle | Allows LinkShield to detect copied URLs when you switch to the app. | Can be toggled on/off in LinkShield Settings ("Auto-Scan Clipboard"). |
Third-Party Services & Data Sharing
LinkShield collaborates only with reputable security infrastructures and standard developer tooling:
An initiative of the Bern University of Applied Sciences in Switzerland dedicated to tracking and sharing malicious URLs. Target URLs submitted for threat verification are governed by the abuse.ch Privacy and Terms.
Services: Firebase Analytics, Firebase Cloud Messaging, Firebase Remote Config.
Data Processed: Pseudonymized device identifiers, sanitized event logs, and IP addresses handled according to the Google Privacy Policy and Firebase Data Processing Terms.
If you optionally enter your own API key, queries are sent directly from your device to Google or VirusTotal under your personal API quota and terms.
When a link is declared safe or you tap "Open in Browser", LinkShield executes an explicit Android package intent to launch your chosen browser. Once handed off, all subsequent web navigation, cookies, and page interactions are governed exclusively by your chosen browser and the destination website's privacy policy.
Data Storage, Retention & Security
All scan logs, whitelist/blacklist rules, and settings are stored locally on your device using Android's sandboxed private storage (AsyncStorage). No other application on your device can access this data without root access.
Scan history is automatically capped at a maximum of 50 entries, with older entries automatically purged on a first-in, first-out basis.
You can immediately erase your entire scan history at any time by tapping "Clear All History" on the History screen. Uninstalling LinkShield permanently erases all locally stored data.
All network communications initiated by LinkShield (including threat feed lookups, redirect requests, and Firebase communications) enforce modern cryptographic transport security (HTTPS / TLS 1.2+).
Your Rights & Choices (GDPR & CCPA/CPRA)
Whether you reside in the European Economic Area (EEA), the United Kingdom, California, or elsewhere, LinkShield provides direct, on-device mechanisms to exercise your privacy rights:
All data LinkShield stores about your scans is directly visible to you on the History screen.
You can wipe all stored scan data at any time via the "Clear All History" button, or by clearing app data in Android Settings.
- You can disable clipboard reading in Settings.
- You can unsubscribe from notification topics in Settings.
- You can disable analytics telemetry in Settings.
- You can change your default browser at any time in Android Settings to bypass LinkShield.
- We do not sell your personal information.
- We do not share your personal information for cross-context behavioral advertising.
- We do not discriminate against users for exercising their privacy rights.
Children's Privacy (COPPA & Global Standards)
LinkShield is a general-purpose security utility and is not directed at children under the age of 13 (or under 16 in certain jurisdictions). We do not knowingly solicit, collect, or process personal data from children.
If you become aware that a child has provided us with personal information, please contact us immediately, and we will take prompt steps to remove such data.
Google Play Data Safety Reference
For complete transparency when reviewing LinkShield on the Google Play Store, here is our official Google Play Data Safety declaration:
| Data Type | Collected | Shared | Ephemeral | Purpose | Encrypted |
|---|---|---|---|---|---|
| Web Browsing (URLs) | No | Yes* | Yes | Core security scanning (URLhaus / Threat Feeds) | Yes (HTTPS) |
| App Interactions (Actions & Screens) | Yes | No | No | App functionality & analytics | Yes (HTTPS) |
| Diagnostics / Performance | Yes | No | No | Stability, crash logs & performance analysis | Yes (HTTPS) |
| Device / Push Identifiers | Yes | No | No | Push notifications (Firebase FCM) | Yes (HTTPS) |
| Personal Info (Name, Email, etc.) | No | No | No | Not collected | N/A |
| Financial / Payment Info | No | No | No | Not collected | N/A |
| Location (GPS / Coarse) | No | No | No | Not collected | N/A |
| Photos / Videos / Files | No | No | No | Not collected | N/A |
Changes to This Privacy Policy
We may periodically update this Privacy Policy to reflect enhancements to our detection algorithms, changes in legal requirements, or additions to our security feeds. When changes are made:
- We will update the "Last Updated" date at the top of this document.
- In the event of material modifications, we will notify you through an in-app notice or a Firebase push advisory.
- Continued use of LinkShield after an update constitutes acceptance of the revised policy.
Contact Us & Legal Inquiries
If you have questions, feedback, or concerns regarding this Privacy Policy or our security practices, please contact us: