Skip to main content
SmartScan Forensic
Threats How it works Engines C-Level FAQ Download
  • English
  • Deutsch · Home
  • Italiano · Home
  • Español
  • Português BR
  • العربية

Privacy Policy

Last updated: July 6, 2026  ·  Effective date: July 6, 2026  ·  Version: 3.0

Our commitment: SmartScan is built by security professionals who understand the sensitivity of forensic data. We collect only what is strictly necessary, encrypt everything, and delete data promptly. Your privacy is not a policy — it is an architectural constraint.

Table of contents
  1. 1. Who we are
  2. 2. Data we collect
  3. 3. How we use your data
  4. 4. Legal basis (GDPR)
  5. 5. Data retention
  6. 6. Data security
  7. 7. Your rights (GDPR)
  8. 8. International transfers
  9. 9. Website cookies
  10. 10. Third parties
  11. 11. Children's privacy
  12. 12. Policy changes
  13. 13. Contact us

1. Who we are

Secure Path Ltd ("we", "us", "our") operates the SmartScan Forensic mobile applications for iOS and Android, distributed through the Apple App Store and Google Play Store, and this website at smartscanforensic.com.

DetailInformation
Company nameSecure Path Ltd
RegistrationEngland & Wales
Data Protection Officerdpo@securepath.biz
ICO registrationC1895044
iOS bundleltd.securepath.smartscanforensic
Android packagecom.securepath.smartscan

2. Data we collect

2.1 Device identity

SmartScan does not require registration, email, name, phone number or any personal identifier. On first launch, the mobile app generates a random Device UID locally on your device. This identifier is:

  • generated by the app on-device using cryptographic random
  • never linked to your Apple ID, Google Account, phone number or email
  • the only identifier stored on our servers to track your scan credits
  • the value you paste into the "Claim your free scan" form on this website

You may optionally provide your Apple ID or Google Account through the platform's native In-App Purchase system when buying scan credits — this identifier is handled by Apple/Google and never shared with us in plain form; we only receive a purchase receipt token used to verify the transaction.

2.2 Analysis data (PCAP)

Important: PCAP files may contain sensitive network traffic. We analyse them for spyware indicators only. We do not access, store, or analyse payload content beyond what is necessary for threat detection.

  • PCAP / PCAPNG files captured during the scan window (10 to 30 minutes, configurable)
  • Metadata — file size, capture start/end timestamps, analysis duration
  • Results — detected threats, confidence scores, IOCs, MITRE ATT&CK mapping

2.3 Network anonymisation architecture (WireGuard tunnel)

SmartScan captures traffic through a WireGuard VPN tunnel operating at Layer 3 (Network Layer) of the OSI model. Understanding this architecture is critical to evaluating the privacy characteristics of captured data:

OSI layer What SmartScan sees What SmartScan CANNOT see
1 (Physical) Nothing — no access to radio/cellular/Wi-Fi physical layer Carrier signal, cell tower ID, IMEI, IMSI, SIM/eSIM ICCID
2 (Data link) Nothing — WireGuard operates above this layer MAC addresses, ARP tables, Ethernet frames, Wi-Fi BSSID
3 (Network) Only the WireGuard tunnel IP (10.x.x.x) assigned by our server Real device IP, ISP public IP, NAT gateway, GeoIP location
4 (Transport) TCP/UDP ports and session metadata (within the tunnel) Source port mappings from the ISP's NAT/CGNAT
5–7 (Session / App) DNS queries, TLS handshakes (SNI), HTTP metadata — all routed through the tunnel Any traffic that does not traverse the WireGuard tunnel

Encapsulation process:

  1. The device establishes a WireGuard tunnel to our capture server.
  2. All device traffic is encapsulated in ChaCha20-Poly1305 encrypted UDP packets.
  3. On arrival at the capture server, traffic is decapsulated — the outer headers (real IP) are discarded.
  4. The PCAP records only the inner packet, with the tunnel-assigned private IP as source.
  5. The original device IP, ISP identity and geographic location never enter the PCAP file.

Forensic-legal implication: The PCAP files generated during a SmartScan analysis contain exclusively traffic from within the WireGuard tunnel interface, bearing only the ephemeral private IP address assigned by our capture server. No ISP-assigned IP, MNO identifier, IMSI, ICCID, IMEI, SIM/eSIM metadata, or any network-layer information capable of identifying the originating device's physical location, carrier, or subscriber identity is present in — or derivable from — the captured data.

Consequently, even in the event of a lawful interception order, data breach, or unauthorised access to stored PCAP files, it is technically impossible to:

  • Determine the geographic location of the scanned device
  • Identify the ISP, carrier, or mobile network operator
  • Associate the captured traffic with a specific subscriber or SIM/eSIM
  • Perform reverse GeoIP lookup to the device's real IP address

This architecture provides analysis anonymity by design — not as a policy choice, but as an inherent technical constraint of the Layer 3 tunnel encapsulation model.

2.4 Technical data

  • IP address of the connection to our servers — for security and abuse prevention only, retained in logs for 90 days
  • User-Agent and platform version — for compatibility
  • Access logs — timestamps of API calls; no request body content

2.5 Data we do not collect

  • Payment card details — In-App Purchases are processed entirely by Apple and Google
  • Social media profiles or contact lists
  • Precise device location (GPS)
  • Content of communications inside PCAP files (bodies, media, encrypted payloads)
  • Advertising identifiers (IDFA, GAID)
  • Any biometric data

3. How we use your data

PurposeData usedLegal basis
Provide the analysis servicePCAP files, Device UIDContract performance
Generate forensic reportsAnalysis results, metadataContract performance
Manage scan creditsDevice UID, purchase receipts from Apple/GoogleContract performance
Security monitoringIP, access logsLegitimate interest
Service improvementAnonymised aggregate statistics (no PII)Legitimate interest
Legal complianceRelevant data as requiredLegal obligation

4. Legal basis for processing (GDPR)

  • Contract performance (Art. 6(1)(b)) — necessary to provide the service you requested
  • Legitimate interest (Art. 6(1)(f)) — security, fraud prevention, service improvement
  • Legal obligation (Art. 6(1)(c)) — compliance with lawful requests, financial records

The mobile app requires no consent-based processing because we do not collect personal data by default.

5. Data retention

DataRetentionDeletion method
PCAP files24 hours after report deliverySecure overwrite (DoD 5220.22-M)
Analysis reportsUntil you delete your device profileDatabase deletion
Device UID + credit balanceUntil you delete the app / reset deviceDatabase deletion
Access logs90 daysAutomatic rotation
Purchase receipts7 years (tax law)Encrypted archive

Automatic deletion: All PCAP files are automatically and permanently deleted by a scheduled job 24 hours after report delivery. This window allows you to request the C-Level extended analysis if the initial report warrants further investigation. After 24 hours the PCAP is irrecoverably destroyed. A deletion certificate is available upon request for chain-of-custody documentation.

6. Data security

6.1 Encryption

  • In transit: TLS 1.3 for all connections. Dual certificate pinning (ISRG Root X1 + Secure Path CA) in the mobile app.
  • Tunnel: WireGuard ChaCha20-Poly1305 for all captured traffic.
  • At rest: AES-256 for stored PCAP files during the 24-hour retention window.

6.2 Infrastructure

  • ISO 27001 certified data centres in Germany (EU)
  • No US cloud dependency — 100% European infrastructure
  • Air-gapped analysis environments
  • Regular penetration testing

6.3 Access control

  • Role-based access control (RBAC)
  • Multi-factor authentication for all operator accounts
  • Employee access logged and audited
  • Background checks for staff with data access

7. Your rights (GDPR)

Under GDPR, you have the following rights. Because we do not identify you by name or email, exercising most rights requires you to provide your Device UID so we can locate your data.

RightDescriptionHow to exercise
AccessRequest a copy of your dataEmail DPO with your Device UID
RectificationCorrect inaccurate dataEmail DPO with your Device UID
ErasureDelete your profile and dataUninstall the app, or email DPO
PortabilityExport data in machine-readable formatEmail DPO (JSON export)
RestrictionLimit how we process your dataEmail DPO
ObjectionObject to legitimate-interest processingEmail DPO

To exercise your rights, contact dpo@securepath.biz. We respond within 30 days as required by GDPR.

8. International data transfers

Your data is processed in the European Union. We do not transfer analysis data (PCAP or reports) outside the EU. Where transfer of technical metadata is unavoidable (e.g. Apple / Google IAP receipt verification), we rely on the EU–US Data Privacy Framework and Standard Contractual Clauses.

9. Website cookies

The smartscanforensic.com website uses only strictly necessary cookies:

CookiePurposeDuration
ssf_langPreferred display language override1 year
Cloudflare Turnstile cf_chl_*CAPTCHA anti-abuse for the claim formSession

We do not use Google Analytics, Meta Pixel, advertising trackers, cross-site tracking or fingerprinting. The mobile app itself sets no cookies.

10. Third parties

ServicePurposeData sharedLocation
Apple Inc.iOS distribution & In-App PurchasesPurchase receipts, app installsUS / EU (Apple Data Privacy Framework)
Google LLCAndroid distribution & In-App PurchasesPurchase receipts, app installsUS / EU (Data Privacy Framework)
CloudflareCDN, CAPTCHA (Turnstile), DDoS protectionRequest IP, headers, Turnstile tokenGlobal (EU primary)
SMTP2GoTransactional email (support replies only)Recipient email address, message contentEU / NZ
Hetzner Online GmbHServer hosting (Germany)Encrypted server infrastructure onlyGermany (EU)

All processors are GDPR compliant with Data Processing Agreements in place.

11. Children's privacy

SmartScan is not intended for individuals under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us immediately at dpo@securepath.biz.

12. Policy changes

We may update this policy to reflect new features, legal or regulatory changes, or security improvements. Material changes will be notified via in-app notification at next launch, at least 30 days before taking effect. Continued use after changes constitutes acceptance.

13. Contact us

Data Protection Officer
Email: dpo@securepath.biz
Response time: 30 days maximum

General inquiries
Email: privacy@securepath.biz

Supervisory authority
If unsatisfied with our response, you may lodge a complaint with:
Information Commissioner's Office (ICO) — https://ico.org.uk/make-a-complaint/


© 2026 SmartScan by Secure Path Ltd. All rights reserved.
This privacy policy is provided for informational purposes and does not constitute legal advice.

SmartScan by Secure Path Ltd

Forensic mobile intelligence — for the people who need to know.

SmartScan by Secure Path Ltd. Registered in England and Wales. 100% European infrastructure — no US cloud dependency.

Product

  • How it works
  • Engines
  • Threats
  • C-Level Report
  • FAQ

Guides

  • Phone spyware signs
  • Spyware database
  • No-root detection
  • High-risk protection
  • Anti-stalkerware check
  • Triada: the Android trojan a factory reset won't fix
  • Unwanted subscriptions on your phone bill: why

Download

  • App Store
  • Google Play

Legal

  • Privacy policy
  • Terms of service
  • Refund policy

Language

  • English
  • Deutsch · Home
  • Italiano · Home
  • Español
  • Português BR
  • العربية

© 2026 Secure Path Ltd. All rights reserved.

SmartScan by Secure Path Ltd · London, United Kingdom