Privacy Policy

Device Trust Scan is an audit tool. It reads the state of your device, keeps the results on that device, and makes exactly one external request — described in section 3 below.

Last updated: August 10, 2026

1. Who processes the data

The data controller for Device Trust Scan (bundle identifier sv.Startnap) is O. & S. STEFANOU LIMITED, 3 Michalaki Paridi, Nicosia (Kaimakli), Nicosia 1041, Cyprus. Questions about this policy: support@trustscandevice.online, tel. +357 95 584591.

2. What data is processed

The app works without an account. There is no server behind it, so there is nothing for us to hold. The following is created and kept on your iPhone:

  • Audit results — the status of each of the 28 checks and the resulting cyber rating.
  • Your answers to manual checks — the settings iOS does not allow apps to read, which you confirm yourself.
  • Email addresses you add for breach monitoring.
  • Notification and reminder settings.

All of it is stored locally and in the shared app group group.sv.Startnap, which is what allows the Home Screen widget to display your current score. None of it is transmitted to us.

3. Sharing with third parties

Read this one

When you run a breach check, the email address you entered is sent to the XposedOrNot service (api.xposedornot.com) as part of the request. The address is transmitted in the request itself, in clear text over HTTPS.

The connection is ephemeral: no cookies are set and no cache is kept. XposedOrNot processes the address under its own terms — see the XposedOrNot privacy policy.

There are no other transfers of any kind. No data is shared with advertisers, data brokers or analytics providers, because none are present in the app.

4. What the app does not do

  • Does not collect analytics or telemetry — there are no analytics, advertising or tracking SDKs in the build.
  • Does not create accounts and does not operate its own servers.
  • Does not read the contents of your mail, messages, photos or passwords.
  • Does not scan other apps and does not detect malware.
  • Does not sell or share personal data with anyone.

5. Permissions and why they are needed

Location
Required purely because iOS only reveals the security parameters of the current Wi-Fi network to apps that hold location permission. Coordinates are neither stored nor transmitted, and the app does not track your movements.
Notifications
Used to alert you about a newly discovered breach involving a saved address, and for reminders to run the audit again.
Background App Refresh
Used to periodically re-check saved addresses so a new breach is not missed.

Every permission can be refused. Refusing one disables the related checks; the rest of the audit keeps working.

6. Storage and deletion

Data lives exactly as long as the app is installed. Deleting the app erases all of it, including the app group used by the widget.

You can also delete data without removing the app — remove saved addresses and reset your answers to the manual checks. Step-by-step instructions are on the data deletion page.

7. Your rights

Under the GDPR and comparable laws you have the right to access, rectify and erase your data, to object to processing, to restrict it, to data portability, and to lodge a complaint with a supervisory authority.

Because the data never leaves your device, you exercise most of these rights directly in the app. For anything else, write to support@trustscandevice.online; we reply within 72 hours.

8. Children

The app is not directed at children under 13 and does not knowingly collect their data. If you believe a child has provided data, contact us at support@trustscandevice.online.

9. Changes to this policy

If this policy changes, the revision date at the top of the page changes with it, and material changes are announced in the app before they take effect.