Aalvated Browser Privacy Policy
Effective and last updated: 16 July 2026
Aalvated Browser is published by the individual developer identified on its Google Play listing ("Aalvated", "we", or "us"). This policy explains the data handled by the Android app and the limited subscription-verification service. Contact: aalvated@proton.me.
Aalvated does not require an Aalvated account, include advertising or behavioral analytics SDKs, or send crash reports to Aalvated. We do not sell personal data.
Data kept on your device
The app stores browser profiles, settings, browsing history, bookmarks, downloads and download history, cookies, website storage, permissions, open tabs, and saved passwords locally on your device. Privacy and compatibility settings, including language, time zone, user-agent preset, and per-profile Canvas or Audio values, are also stored locally and are not uploaded to Aalvated.
You can clear browsing data and site permissions in the app, delete profiles, clear all app data in Android settings, or uninstall the app. Files saved to a shared Downloads folder can remain after profile deletion or uninstallation and must be deleted with Android's file manager if you no longer want them.
Open-web browsing
When you visit a website, that website and its service providers receive normal browser communications such as your network address, request headers, cookies, information you submit, and data from permissions you choose to grant. A website may request location, camera, microphone, notifications, NFC, or file access; Android and site permission prompts are used where applicable. Aalvated does not operate a proxy or VPN and does not receive your browsing history. Each website's own terms and privacy policy apply.
Subscriptions and purchase verification
If you buy, restore, or refresh an optional subscription, Google Play Billing processes the transaction. Aalvated does not receive your card number, bank account, billing address, or other payment credentials.
To verify paid access, the app sends a Google Play purchase token and a Firebase App Check token over HTTPS to Aalvated's billing service. The raw purchase token is used in memory to query the Google Play Developer API and is not written to the subscription database. The service stores a SHA-256 hash of the token together with product and base-plan identifiers, subscription and acknowledgement status, access limits, test-purchase status, entitlement expiry, verification time, and automatic deletion time. Google Play Real-time Developer Notifications are used to keep this state current.
App integrity, Web Push, and technical data
Firebase App Check with Play Integrity processes app and device attestation material, app metadata, integrity tokens, and related service data to prevent unauthorized access and subscription fraud. Firebase may generate a per-installation identifier. If you allow notifications for a website, Firebase Cloud Messaging processes an app-instance or notification token and technical metadata so that the requested Web Push messages can reach your device.
Google Cloud Run automatically processes HTTPS request metadata for the billing service, which can include IP address, request time, endpoint, response status, user agent, and latency. Request bodies and raw purchase tokens are not intentionally written to application logs. This data is used only to operate, secure, and troubleshoot the service.
Summary of developer-side processing
Data | When and why | Retention
Purchase status and token hash | Optional subscription verification, entitlement, fraud prevention, and support | Deleted 90 days after the later of entitlement expiry or the most recent verification
App/device or installation identifiers and integrity tokens | Subscription security and optional Web Push; processed by Google Play and Firebase | According to the applicable Google service retention period; App Check tokens are short-lived
RTDN message identifier, result, and optional token hash | Prevent duplicate subscription-event processing | Up to 30 days
Billing-service request and operational logs | Security, reliability, and troubleshooting | Up to 30 days
Service providers and disclosure
Google Play, Firebase, and Google Cloud process the data described above as platform providers or service providers. They may use their own service data as described in their terms and privacy notices. We do not disclose app data to advertisers or data brokers. We may disclose information if required by law, to protect users or the service, or as part of a lawful transfer of the app, subject to appropriate safeguards.
Retention, deletion, and security
Automatic retention periods are listed above. Because there is no Aalvated user account, server records are keyed by pseudonymous purchase-token hashes rather than a name or email address. You may contact aalvated@proton.me with a privacy or deletion question; do not email passwords, full payment details, or raw purchase tokens. Google Play subscription cancellation is managed in Google Play and is separate from deleting app data.
Developer-service traffic is encrypted in transit with HTTPS. Access to production systems is restricted, and raw payment credentials are not handled by Aalvated. No security method is perfect, but we use safeguards proportionate to the limited data processed.
Children, international processing, and changes
Aalvated Browser is intended for adults and is not directed to children. Google and its subprocessors may process data in countries other than yours under their applicable contractual safeguards. We may update this policy when features, providers, or legal requirements change. The current version will be published at this same public URL and the date above will be updated.
Aalvated Browser 隐私政策
生效及最后更新日期:2026 年 7 月 16 日
Aalvated Browser 由 Google Play 商店页面中列明的个人开发者发布(下称“Aalvated”或“我们”)。本政策说明 Android 应用及有限的订阅验证服务如何处理数据。联系邮箱:aalvated@proton.me。
应用不要求注册 Aalvated 账号,不包含广告或行为分析 SDK,也不会向 Aalvated 发送崩溃报告。我们不出售个人数据。
保存在设备上的数据
应用会在你的设备本地保存浏览器配置、设置、浏览历史、书签、下载文件及下载记录、Cookie、网站存储、站点权限、标签页和保存的密码。语言、时区、用户代理预设以及按配置生成的 Canvas/Audio 值等隐私与兼容性设置也只保存在本地,不会上传至 Aalvated。
你可以在应用内清除浏览数据和站点权限、删除配置,也可以在 Android 设置中清除全部应用数据或卸载应用。保存到公共“下载”目录的文件在删除配置或卸载后可能仍然存在,需要时请使用 Android 文件管理器删除。
访问开放互联网
访问网站时,网站及其服务商会收到正常的浏览器通信,例如网络地址、请求头、Cookie、你提交的信息以及你主动授予权限后产生的数据。网站可以请求位置、摄像头、麦克风、通知、NFC 或文件访问;适用时应用会显示 Android 系统及站点权限提示。Aalvated 不提供代理或 VPN,也不会收到你的浏览历史。第三方网站受其自身条款和隐私政策约束。
订阅与购买验证
当你购买、恢复或刷新可选订阅时,交易由 Google Play 结算处理。Aalvated 不会收到你的银行卡号、银行账户、账单地址或其他支付凭据。
为验证付费权限,应用会通过 HTTPS 将 Google Play 购买令牌和 Firebase App Check 令牌发送到 Aalvated 结算服务。原始购买令牌仅在内存中用于查询 Google Play Developer API,不会写入订阅数据库。服务器保存购买令牌的 SHA-256 哈希,以及产品和基础方案、订阅及确认状态、权限上限、测试购买状态、权益截止时间、验证时间和自动删除时间。Google Play 实时开发者通知用于更新这些状态。
应用完整性、网页推送与技术数据
Firebase App Check 和 Play Integrity 会处理应用与设备证明材料、应用元数据、完整性令牌及相关服务数据,用于阻止未授权访问和订阅欺诈。Firebase 可能生成按安装区分的标识符。如果你允许某个网站发送通知,Firebase Cloud Messaging 会处理应用实例或通知令牌及技术元数据,以便把你请求的网页推送送达设备。
Google Cloud Run 会自动处理结算服务的 HTTPS 请求元数据,其中可能包括 IP 地址、请求时间、接口路径、响应状态、用户代理和延迟。我们不会有意把请求正文或原始购买令牌写入应用日志。这些信息仅用于运行、保护和排查服务。
开发者侧处理摘要
数据 | 使用场景和目的 | 保留期限
购买状态和令牌哈希 | 可选订阅验证、权益、反欺诈和支持 | 在权益截止或最近一次验证两者中较晚的日期之后 90 天删除
应用/设备或安装标识符及完整性令牌 | 订阅安全和可选网页推送;由 Google Play 和 Firebase 处理 | 按相应 Google 服务的保留期限处理;App Check 令牌有效期较短
实时通知消息标识、结果及可选令牌哈希 | 防止重复处理订阅事件 | 最长 30 天
结算服务请求和运行日志 | 安全、可靠性和故障排查 | 最长 30 天
服务提供商与披露
Google Play、Firebase 和 Google Cloud 作为平台或服务提供商处理上述数据,并可能按其条款和隐私声明使用服务数据。我们不会向广告商或数据经纪商披露应用数据。依法必须披露、为保护用户或服务,或应用发生合法转让时,我们可能在采取适当保护措施的前提下披露必要信息。
保留、删除与安全
自动保留期限见上表。由于没有 Aalvated 用户账号,服务器记录使用假名化的购买令牌哈希作为键,而不是姓名或邮箱。你可以通过 aalvated@proton.me 咨询隐私或删除问题;请勿通过邮件发送密码、完整支付资料或原始购买令牌。在 Google Play 中取消订阅与删除应用数据是两项不同操作。
开发者服务使用 HTTPS 加密传输,生产系统访问受到限制,Aalvated 不处理原始支付凭据。任何安全措施都无法保证绝对安全,但我们会针对有限的数据处理采取相称的保护。
儿童、跨境处理与政策变更
Aalvated Browser 面向成年人,并非为儿童设计。Google 及其子处理商可能依据适用的合同保障在你所在国家或地区之外处理数据。当功能、服务商或法律要求发生变化时,我们可能更新本政策;最新版会继续发布在同一个公开 URL,并更新页面顶部日期。