Effective August 21, 2026
GreyRecon ("the app", "we") is developed as a single-developer, no-backend Android app. There is no GreyRecon server between you and your network — the app talks directly to your router, the devices on your WiFi, and (only when you choose a specific feature) a small number of third-party APIs using your own credentials.
Scanning your network, classifying devices, and running tools like the subnet calculator or DNS lookup never leaves your phone. The following is stored only in the app's private local storage and never transmitted:
Uninstalling the app deletes all of this. There's no cloud copy to also delete, because none was ever made.
| Permission | What it's for |
|---|---|
| ACCESS_FINE_LOCATION | Required by Android to read WiFi scan results and run Bluetooth Low Energy scans. Not used to track your physical location; never transmitted. |
| ACCESS_WIFI_STATE / ACCESS_NETWORK_STATE | Reads your current subnet so the app knows what range to scan. |
| CHANGE_WIFI_MULTICAST_STATE | Listens for mDNS/UPnP broadcasts (discovery), and supports the MCP foreground service (Pro). |
| BLUETOOTH_SCAN | Optional BLE Scan tool. Results stay on-device. |
| POST_NOTIFICATIONS | "MCP server running" notification (Pro), optional new-device alerts. |
| FOREGROUND_SERVICE | Keeps the optional MCP server (Pro) responsive while backgrounded. |
| INTERNET | Third-party lookups you trigger, and crash reporting. |
Several features are opt-in and require your own API key, entered by you in Settings. GreyRecon never ships with, or shares, its own key — you're talking directly to that provider, under their privacy policy:
None of these keys, or data sent alongside them, pass through any GreyRecon-owned server — there isn't one.
GreyRecon uses Firebase Crashlytics and Firebase Analytics (Google) to find and fix bugs. On a crash, Crashlytics sends a stack trace, device model, OS version, app version, and free memory/storage — enough to fix the bug, not to identify you personally. Firebase Analytics collects basic app-usage signals. This data is processed under Firebase's privacy terms; GreyRecon does not use it for advertising, does not sell it, and carries no ad SDKs.
Any API key you enter is stored using Android's EncryptedSharedPreferences — AES-256 encryption tied to your device's hardware-backed keystore. Keys never leave your device except as part of the specific, user-triggered request described above, sent straight to that provider's API.
GreyRecon Pro (a one-time unlock) is sold and processed entirely through Google Play Billing. We do not receive or store your payment details.
If enabled, the MCP server starts a small HTTP server on your local network only (not the public internet), protected by a token you configure. Anyone with both your local network access and that token can query your scan data — keep the token private.
On-device data is retained until you clear the app's data or uninstall it. Crashlytics/Analytics data is retained by Google per Firebase's standard retention settings. Third-party lookup data is retained per each provider's own policy.
GreyRecon is a technical network-diagnostics tool and isn't directed at children. We don't knowingly collect data from anyone under 13.
If GreyRecon's data practices change, this page will be updated and the effective date will change.
Questions about this policy or your data: emile3983@gmail.com.