Effective Date / Last Updated: September 2026
Shake Robber App, engineered and managed by dulldusk.com, treats user privacy with paramount gravity.
1. Data Controller Identification & Contact
For the execution of global data frameworks, dulldusk.com functions as the primary Data Controller.
2. Personal Data Categories & Functional Mapping
To deliver automated antitheft tracking, Shake Robber requires local permissions. Below is the handled category matrix:
| Data Category | Technical Source & Pipeline | Primary Operational Use Case |
|---|---|---|
| Visual Data | Device Camera Hardware | Captures photos of unknown handlers upon execution of shake gestures or failed locking actions. |
| Spatial Geolocation | GPS Frameworks & Location Services | Affixes precise and approximate location metadata points to localized incident logs. |
| Identity & Google Account Data | Google Account Manager & OAuth 2.0 | Accesses your target email identity and the https://www.googleapis.com/auth/drive.file scope strictly to read, write, and sync application security backups in your personal Google Drive storage. |
3. Legal Bases for Processing (GDPR / LGPD)
- User Explicit Consent (Art. 6(1)(a) GDPR / Art. 7 LGPD).
- Legitimate Interests (Art. 6(1)(f) GDPR).
4. Purpose Limitation, Data Minimization, & Data Protection
- Purpose Limitation rule application.
- Data Minimization framework verification.
- Data Retention standard mapping.
Data Security & Safeguards for Sensitive Data
We implement strict technical and organizational protection mechanisms to secure sensitive user metrics:
- Transit Encryption: All data transmitted through API connections (such as Google Drive API endpoints) is fully encrypted in transit using industry-standard protocols (HTTPS / TLS 1.2+).
- Local Sandbox Isolation: Photos, location logs, and tokens are saved strictly inside Android's application-isolated local sandbox, preventing access by other apps.
- Credential Security: Google OAuth 2.0 access tokens are managed using standard Android credential frameworks. No user tokens, credentials, or metrics are ever transmitted to or stored on developer-owned servers.
5. Google Play Services & Cloud APIs
- Google Play operational endpoints.
- Google Drive sandboxed pipeline processing and restricted per-file scope usage.
- Google API Limited Use Compliance statement.
6. International Data Transfers
Because there is no developer cloud backend infrastructure, cross-border migrations do not take place.
7. User Rights (GDPR, CCPA/CPRA, LGPD)
- Right to Deletion / Erasure.
- Right to Access & Portability.
- CCPA/CPRA Non-Commercial Sharing assurance.
- Complaint Procedures metrics mapping.
8. Children's Privacy (COPPA & GDPR)
The app does not intentionally gather or process data from users under thirteen.
9. Additional Regulatory Disclosures
Geo-blocking Regulation (EU) 2018/302
Offered without unjustified regional discrimination elements.
Digital Services Act (DSA) Contact
Direct monitoring requests should route to dulldusk@gmail.com.
EU Consumer Rights
Purchase processing safeguards are completely managed by Google.
10. Policy Updates
Updates take effect immediately upon being posted to this URL partition path.
11. Contact Information
Please route any operational privacy concerns directly via support email lines.