This policy describes how NetBlade handles data in its three editions: Android (com.netblade.tools), iPhone and iPad, and Windows (Microsoft Store). NetBlade is developed by Innovatek Software (Innovatek di Cafaro Carmelina). No account is needed and we collect no personal data for our own purposes: we have no server that receives your scans, your devices or your credentials. Where the editions behave differently, the difference is spelled out below. The three editions are independent apps: they share no data and do not communicate with one another.
Scan data
Local network scans (devices, ports, Wi‑Fi, SNMP, diagnostic tools) run and are processed only on your device. Saved results stay in the app's local storage and are never sent to us: Innovatek Software receives no data about your networks.
Exports (CSV, JSON, PDF) and sharing happen only when you ask for them, to the destination you choose.
Local storage, credentials and backup
Android: app data (saved scans, recognised devices, networks, event history) lives in a local database. SNMP credentials you enter to query your own equipment are stored in that database unencrypted, because they must stay usable for later queries; for SSH the app saves host, port and username, never the password; Windows credentials are encrypted with a key held in the Android Keystore and left out of every backup. The database is included in the standard Google backup, which stays in your own Google account, encrypted, and is not accessible to us; you can turn it off in your device's backup settings. The backup file you can export by hand from the app (.nbak) is not encrypted and contains the SNMP credentials: keep it somewhere you consider safe.
iPhone and iPad: app data lives in a local database included in the device backup (iCloud or computer), which stays in your own Apple account, encrypted. Credentials — SNMP communities and keys, Windows accounts, and the SSH or FTP passwords you choose to remember — are kept only in the iOS Keychain, tied to this device: they are not in the database, not in the device backup and not in the backup file you can export from the app (.nbak).
Windows: data lives in a database in the app's private folder (LocalState), which Windows removes together with the app. Passwords — Windows accounts used to read PCs, SNMP, SSH, mail server, webhook secrets — are encrypted with Windows data protection (DPAPI) for your user account on that PC: not even a copy of the folder makes them readable elsewhere. The operating log stays in the same folder and is sent to no one.
What the app does on your network
On Windows, with the credentials you register, NetBlade reads the PCs and devices on your network (WMI and WinRM, SMB, SNMP, SSH) and, if you turn it on, does so on a schedule from an agent that runs while you are signed in to Windows. Remote actions on a PC (a restart or a command, for example) start only when you start them. Use these features only on networks and machines you are entitled to administer.
System permissions
iOS asks for the "local network" permission the first time: without it the app cannot see a single device. On Android, the location permission (or, from Android 13, "nearby Wi‑Fi devices") is what allows Wi‑Fi scan results to be read, that is network names and access-point identifiers; on iOS, location is required by the system only to read the name of the Wi‑Fi network you are connected to. There is never background location access.
On Android, if you use the map features, the app saves the coordinates associated with a saved network or scan to show it on the map: they stay in the local database. Maps are drawn with OpenStreetMap, which receives the requests for the map tiles to display.
On Windows the app asks to start with Windows so the background agent can run; you can turn this off in Settings › Apps › Startup. You may deny any permission: the features that do not depend on it stay available.
External services
A few tools, and only when you start them yourself, query public third-party services: ipinfo.io (and ipwho.is on iOS) for public-IP information and the geolocation of an IP address; speed.cloudflare.com for the speed test; crt.sh for a domain's certificates; internetdb.shodan.io to see which ports of your public IP are exposed to the internet; services.nvd.nist.gov (National Vulnerability Database) for the known vulnerabilities of a recognised program, on Android and iOS; api.pwnedpasswords.com (Have I Been Pwned) to check whether a password has leaked. In that last case the password never leaves the device: only the beginning of its cryptographic hash is sent (k‑anonymity), which cannot be traced back to the password.
The vulnerability check on Android and iOS is optional and sends only the name and version of recognised programs. On Windows it sends nothing: once a day the app downloads a public, digitally signed list of vulnerabilities from feed.netblade.app and the comparison with your programs happens on the PC. The download carries no information about your inventory.
On Windows, if you ask for it, the app downloads PsExec straight from Microsoft's site (live.sysinternals.com) into its own folder, for remote actions. Email alerts and reports leave from the mail server you configure, to the addresses you choose; webhooks go to the addresses you enter. We are not in between.
Each service receives only what that single request needs — the IP address, the domain, the program name or the partial hash — along with the IP address the connection comes from. Scans of your local network never go through any external service.
Advertising (Android only)
On Android the free version shows ads through Google AdMob. To serve and measure ads, Google may process device identifiers (including the advertising ID) and technical data, as described in Google's privacy policy (policies.google.com/privacy). If you are in the European Economic Area, the United Kingdom or Switzerland, the app collects your consent through Google's form before any ad is requested, and you can change or withdraw it at any time from Settings › Privacy options. The iPhone and Windows editions contain no advertising and no advertising SDK, and do not track you.
Purchases and subscriptions
Purchases are handled entirely by the store: Google Play Billing on Android, Apple (StoreKit) on iPhone and iPad, the Microsoft Store on Windows (NetBlade Pro monthly or yearly subscription, with a free trial the first time). We never receive or store payment data and we do not know who bought. There is no server of ours behind the subscription: the app asks the store, on the device, whether the subscription is active.
Your rights
Since the app's data lives only on your devices, you can delete it at any time by clearing the app's data or uninstalling it. For any privacy request (access, rectification, erasure) write to info@innovateksoftware.com.
The netblade.app website uses Google Analytics to measure visits, and only after you accept it in the cookie banner — until then no analytics cookie is set. The three apps themselves use no analytics and send us nothing.