Privacy Policy
Our commitment: SmartScan is built by security professionals who understand the sensitivity of forensic data. We collect only what is strictly necessary, encrypt everything, and delete data promptly. Your privacy is not a policy — it is an architectural constraint.
Table of contents
1. Who we are
Secure Path Ltd ("we", "us", "our") operates the SmartScan Forensic mobile applications for iOS and Android, distributed through the Apple App Store and Google Play Store, and this website at smartscanforensic.com.
| Detail | Information |
|---|---|
| Company name | Secure Path Ltd |
| Registration | England & Wales |
| Data Protection Officer | dpo@securepath.biz |
| ICO registration | C1895044 |
| iOS bundle | ltd.securepath.smartscanforensic |
| Android package | com.securepath.smartscan |
2. Data we collect
2.1 Device identity
SmartScan does not require registration, email, name, phone number or any personal identifier. On first launch, the mobile app generates a random Device UID locally on your device. This identifier is:
- generated by the app on-device using cryptographic random
- never linked to your Apple ID, Google Account, phone number or email
- the only identifier stored on our servers to track your scan credits
- the value you paste into the "Claim your free scan" form on this website
You may optionally provide your Apple ID or Google Account through the platform's native In-App Purchase system when buying scan credits — this identifier is handled by Apple/Google and never shared with us in plain form; we only receive a purchase receipt token used to verify the transaction.
2.2 Analysis data (PCAP)
Important: PCAP files may contain sensitive network traffic. We analyse them for spyware indicators only. We do not access, store, or analyse payload content beyond what is necessary for threat detection.
- PCAP / PCAPNG files captured during the scan window (10 to 30 minutes, configurable)
- Metadata — file size, capture start/end timestamps, analysis duration
- Results — detected threats, confidence scores, IOCs, MITRE ATT&CK mapping
2.3 Network anonymisation architecture (WireGuard tunnel)
SmartScan captures traffic through a WireGuard VPN tunnel operating at Layer 3 (Network Layer) of the OSI model. Understanding this architecture is critical to evaluating the privacy characteristics of captured data:
| OSI layer | What SmartScan sees | What SmartScan CANNOT see |
|---|---|---|
| 1 (Physical) | Nothing — no access to radio/cellular/Wi-Fi physical layer | Carrier signal, cell tower ID, IMEI, IMSI, SIM/eSIM ICCID |
| 2 (Data link) | Nothing — WireGuard operates above this layer | MAC addresses, ARP tables, Ethernet frames, Wi-Fi BSSID |
| 3 (Network) | Only the WireGuard tunnel IP (10.x.x.x) assigned by our server |
Real device IP, ISP public IP, NAT gateway, GeoIP location |
| 4 (Transport) | TCP/UDP ports and session metadata (within the tunnel) | Source port mappings from the ISP's NAT/CGNAT |
| 5–7 (Session / App) | DNS queries, TLS handshakes (SNI), HTTP metadata — all routed through the tunnel | Any traffic that does not traverse the WireGuard tunnel |
Encapsulation process:
- The device establishes a WireGuard tunnel to our capture server.
- All device traffic is encapsulated in ChaCha20-Poly1305 encrypted UDP packets.
- On arrival at the capture server, traffic is decapsulated — the outer headers (real IP) are discarded.
- The PCAP records only the inner packet, with the tunnel-assigned private IP as source.
- The original device IP, ISP identity and geographic location never enter the PCAP file.
Forensic-legal implication: The PCAP files generated during a SmartScan analysis contain exclusively traffic from within the WireGuard tunnel interface, bearing only the ephemeral private IP address assigned by our capture server. No ISP-assigned IP, MNO identifier, IMSI, ICCID, IMEI, SIM/eSIM metadata, or any network-layer information capable of identifying the originating device's physical location, carrier, or subscriber identity is present in — or derivable from — the captured data.
Consequently, even in the event of a lawful interception order, data breach, or unauthorised access to stored PCAP files, it is technically impossible to:
- Determine the geographic location of the scanned device
- Identify the ISP, carrier, or mobile network operator
- Associate the captured traffic with a specific subscriber or SIM/eSIM
- Perform reverse GeoIP lookup to the device's real IP address
This architecture provides analysis anonymity by design — not as a policy choice, but as an inherent technical constraint of the Layer 3 tunnel encapsulation model.
2.4 Technical data
- IP address of the connection to our servers — for security and abuse prevention only, retained in logs for 90 days
- User-Agent and platform version — for compatibility
- Access logs — timestamps of API calls; no request body content
2.5 Data we do not collect
- Payment card details — In-App Purchases are processed entirely by Apple and Google
- Social media profiles or contact lists
- Precise device location (GPS)
- Content of communications inside PCAP files (bodies, media, encrypted payloads)
- Advertising identifiers (IDFA, GAID)
- Any biometric data
3. How we use your data
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the analysis service | PCAP files, Device UID | Contract performance |
| Generate forensic reports | Analysis results, metadata | Contract performance |
| Manage scan credits | Device UID, purchase receipts from Apple/Google | Contract performance |
| Security monitoring | IP, access logs | Legitimate interest |
| Service improvement | Anonymised aggregate statistics (no PII) | Legitimate interest |
| Legal compliance | Relevant data as required | Legal obligation |
4. Legal basis for processing (GDPR)
- Contract performance (Art. 6(1)(b)) — necessary to provide the service you requested
- Legitimate interest (Art. 6(1)(f)) — security, fraud prevention, service improvement
- Legal obligation (Art. 6(1)(c)) — compliance with lawful requests, financial records
The mobile app requires no consent-based processing because we do not collect personal data by default.
5. Data retention
| Data | Retention | Deletion method |
|---|---|---|
| PCAP files | 24 hours after report delivery | Secure overwrite (DoD 5220.22-M) |
| Analysis reports | Until you delete your device profile | Database deletion |
| Device UID + credit balance | Until you delete the app / reset device | Database deletion |
| Access logs | 90 days | Automatic rotation |
| Purchase receipts | 7 years (tax law) | Encrypted archive |
Automatic deletion: All PCAP files are automatically and permanently deleted by a scheduled job 24 hours after report delivery. This window allows you to request the C-Level extended analysis if the initial report warrants further investigation. After 24 hours the PCAP is irrecoverably destroyed. A deletion certificate is available upon request for chain-of-custody documentation.
6. Data security
6.1 Encryption
- In transit: TLS 1.3 for all connections. Dual certificate pinning (ISRG Root X1 + Secure Path CA) in the mobile app.
- Tunnel: WireGuard ChaCha20-Poly1305 for all captured traffic.
- At rest: AES-256 for stored PCAP files during the 24-hour retention window.
6.2 Infrastructure
- ISO 27001 certified data centres in Germany (EU)
- No US cloud dependency — 100% European infrastructure
- Air-gapped analysis environments
- Regular penetration testing
6.3 Access control
- Role-based access control (RBAC)
- Multi-factor authentication for all operator accounts
- Employee access logged and audited
- Background checks for staff with data access
7. Your rights (GDPR)
Under GDPR, you have the following rights. Because we do not identify you by name or email, exercising most rights requires you to provide your Device UID so we can locate your data.
| Right | Description | How to exercise |
|---|---|---|
| Access | Request a copy of your data | Email DPO with your Device UID |
| Rectification | Correct inaccurate data | Email DPO with your Device UID |
| Erasure | Delete your profile and data | Uninstall the app, or email DPO |
| Portability | Export data in machine-readable format | Email DPO (JSON export) |
| Restriction | Limit how we process your data | Email DPO |
| Objection | Object to legitimate-interest processing | Email DPO |
To exercise your rights, contact dpo@securepath.biz. We respond within 30 days as required by GDPR.
8. International data transfers
Your data is processed in the European Union. We do not transfer analysis data (PCAP or reports) outside the EU. Where transfer of technical metadata is unavoidable (e.g. Apple / Google IAP receipt verification), we rely on the EU–US Data Privacy Framework and Standard Contractual Clauses.
9. Website cookies
The smartscanforensic.com website uses only strictly necessary cookies:
| Cookie | Purpose | Duration |
|---|---|---|
ssf_lang | Preferred display language override | 1 year |
Cloudflare Turnstile cf_chl_* | CAPTCHA anti-abuse for the claim form | Session |
We do not use Google Analytics, Meta Pixel, advertising trackers, cross-site tracking or fingerprinting. The mobile app itself sets no cookies.
10. Third parties
| Service | Purpose | Data shared | Location |
|---|---|---|---|
| Apple Inc. | iOS distribution & In-App Purchases | Purchase receipts, app installs | US / EU (Apple Data Privacy Framework) |
| Google LLC | Android distribution & In-App Purchases | Purchase receipts, app installs | US / EU (Data Privacy Framework) |
| Cloudflare | CDN, CAPTCHA (Turnstile), DDoS protection | Request IP, headers, Turnstile token | Global (EU primary) |
| SMTP2Go | Transactional email (support replies only) | Recipient email address, message content | EU / NZ |
| Hetzner Online GmbH | Server hosting (Germany) | Encrypted server infrastructure only | Germany (EU) |
All processors are GDPR compliant with Data Processing Agreements in place.
11. Children's privacy
SmartScan is not intended for individuals under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us immediately at dpo@securepath.biz.
12. Policy changes
We may update this policy to reflect new features, legal or regulatory changes, or security improvements. Material changes will be notified via in-app notification at next launch, at least 30 days before taking effect. Continued use after changes constitutes acceptance.
13. Contact us
Data Protection Officer
Email: dpo@securepath.biz
Response time: 30 days maximum
General inquiries
Email: privacy@securepath.biz
Supervisory authority
If unsatisfied with our response, you may lodge a complaint with:
Information Commissioner's Office (ICO) — https://ico.org.uk/make-a-complaint/
© 2026 SmartScan by Secure Path Ltd. All rights reserved.
This privacy policy is provided for informational purposes and does not constitute legal advice.