This policy describes how NetBlade for Android (com.netblade.tools, on Google Play) handles data. NetBlade is developed by Innovatek Software (Innovatek di Cafaro Carmelina). No account is needed and we collect no personal data for our own purposes: we have no server that receives your scans, your devices or your credentials. It is independent of the NetBlade apps for other platforms: they share no data and do not communicate with one another.
Scan data
Local network scans (devices, ports, Wi‑Fi, SNMP, diagnostic tools) run and are processed only on your phone. Saved results stay in the app's local storage and are never sent to us: Innovatek Software receives no data about your networks.
Exports (CSV, JSON, PDF) and sharing happen only when you ask for them, to the destination you choose.
Local storage, credentials and backup
App data (saved scans, recognised devices, networks, event history) lives in a local database on the phone. SNMP credentials you enter to query your own equipment are stored in that database unencrypted, because they must stay usable for later queries. For SSH the app saves host, port and username, never the password.
The Windows credentials you enter to read your PCs are kept apart: they are encrypted with a key generated inside the Android Keystore, which cannot be exported from the phone, and they are left out of every backup.
The database is included in the standard Google backup and in device-to-device transfer: that backup stays in your own Google account, encrypted, and is not accessible to us. You can turn it off in your device's backup settings. The backup file you can export by hand from the app (.nbak) is not encrypted and contains the SNMP credentials: keep it somewhere you consider safe.
What the app does on your network
With the credentials you enter, NetBlade reads the Windows PCs (SMB and WinRM) and Linux machines (SSH) on your network. If you turn on scheduled inventory or monitoring, they run in the background only on the network the phone is connected to, and their alerts are notifications on the phone: nothing is sent anywhere. Use these features only on networks and machines you are entitled to administer.
System permissions
The location permission (or, from Android 13, "nearby Wi‑Fi devices") is what allows Wi‑Fi scan results to be read, that is network names and access-point identifiers. There is never background location access.
If you use the map features, the app saves the coordinates associated with a saved network or scan to show it on the map: they stay in the local database. Maps are drawn with OpenStreetMap, which receives the requests for the map tiles to display.
You may deny any permission: the features that do not depend on it stay available.
External services
A few tools, and only when you start them yourself, query public third-party services: ipinfo.io for public-IP information and the geolocation of an IP address; speed.cloudflare.com for the speed test; crt.sh for a domain's certificates; internetdb.shodan.io to see which ports of your public IP are exposed to the internet; services.nvd.nist.gov (National Vulnerability Database) for the known vulnerabilities of a recognised program; api.pwnedpasswords.com (Have I Been Pwned) to check whether a password has leaked. In that last case the password never leaves the phone: only the beginning of its cryptographic hash is sent (k‑anonymity), which cannot be traced back to the password.
The vulnerability check is optional and sends only the name and version of recognised programs.
Each service receives only what that single request needs — the IP address, the domain, the program name or the partial hash — along with the IP address the connection comes from. Scans of your local network never go through any external service.
Advertising
The free version shows ads through Google AdMob, including the optional videos that unlock the advanced features for 24 hours. To serve and measure ads, Google may process device identifiers (including the advertising ID) and technical data, as described in Google's privacy policy (policies.google.com/privacy). If you are in the European Economic Area, the United Kingdom or Switzerland, the app collects your consent through Google's form before any ad is requested, and you can change or withdraw it at any time from Settings › Privacy options. The in-app purchase removes the ads.
Purchases
Purchases are handled entirely by Google Play Billing. We never receive or store payment data and we do not know who bought: the app asks Google Play, on the phone, what has been purchased.
Your rights
Since the app's data lives only on your devices, you can delete it at any time by clearing the app's data or uninstalling it. For any privacy request (access, rectification, erasure) write to info@innovateksoftware.com.