CanaryX is a local network debugging and traffic inspection tool designed for developers, security researchers, and power users. It works by creating a local VPN on your device that routes network traffic through a local on-device proxy. This allows you to inspect HTTP, HTTPS, TCP, and UDP traffic generated by other apps installed on your device — similar to tools like Charles Proxy, Proxyman, or Burp Suite.
Core features include:
The App is designed for developers and security researchers to debug their own apps and network traffic on devices they own or have explicit permission to test.
When you start a capture session, CanaryX intercepts and displays network traffic from apps you select. This traffic may include:
| Data type | Examples | Stored where |
|---|---|---|
| HTTP request URLs | Full URL, method (GET/POST/etc.), host, path, query parameters | Device RAM |
| HTTP request headers | Authorization tokens, cookies, User-Agent, Content-Type, custom headers | Device RAM |
| HTTP request body | POST form data, JSON payloads, uploaded file contents | Device RAM |
| HTTP response headers | Set-Cookie, Content-Type, Cache-Control, server headers | Device RAM |
| HTTP response body | API JSON responses, HTML pages, image data (if body capture enabled) | Device RAM |
| TCP packet metadata | Source IP, destination IP, source port, destination port, packet length, protocol | Device RAM |
| UDP packet metadata | Source IP, destination IP, source port, destination port, packet length, protocol | Device RAM |
| App identity (UID) | The Android UID of the app that generated the traffic, resolved to app name | Device RAM |
| Session metadata | Capture session start/end time, packet count, HTTP count, selected app filter | Device RAM |
All captured traffic is stored in device memory (RAM) only. It is never written to any remote server, database, or cloud service. Captured data is cleared when you tap "Clear Captures", stop the capture session, close the App, or uninstall it. The App retains a maximum of 500 capture items in memory at any time — older items are automatically discarded.
To allow you to select which apps to capture, CanaryX reads the list of installed applications on your device using PackageManager.getInstalledApplications(). This includes package names, app labels, icons, whether the app is a system app or user app, and the app's UID. This list is used only locally to populate the app selector UI. It is never transmitted, logged, stored persistently, or shared with any server or third party.
The following settings are stored locally using Android's SharedPreferences:
These preferences are stored in the App's private storage and are never transmitted anywhere.
When you generate or install a CA certificate, the following cryptographic material is stored in the App's private storage: CA private key (RSA 2048-bit), CA certificate (X.509 self-signed), and PKCS12 keystore (if exported). This material never leaves the device unless you explicitly export it. Exported files are saved through the Android Storage Access Framework (the user picks the destination) or to the App's external files directory — no legacy shared-storage permissions are required. The CA password is "canaryx".
CanaryX does not collect, transmit, or share any of the following:
CanaryX does not contain any advertisements. No ad SDKs are integrated (no Google AdMob, no Facebook Audience Network, no Unity Ads, no AppLovin, no ironSource, no mediation layers). No advertising identifiers are collected or read (no GAID/AAID). No ad-related tracking is performed. No promotional content is displayed. No in-app purchases are offered.
CanaryX does not use any analytics or crash reporting services: no Google Analytics / Firebase Analytics, no Crashlytics / Bugsnag / Sentry / ACRA, no Mixpanel / Amplitude / Flurry, no usage tracking, session recording, or funnel analytics, no heatmaps or screen recordings. The App does not phone home. There is no backend server. The App operates entirely on-device.
The following Android permissions are declared in the App's AndroidManifest.xml. Each permission is used only for its stated purpose.
| # | Permission | How it is used | Data collected |
|---|---|---|---|
| 1 | INTERNET |
Allows the local on-device proxy to make outgoing network requests on behalf of captured apps. Used for the "Repeat" / "Compose" feature that replays captured HTTP requests, and for the proxy to forward traffic to destination servers. | None stored — traffic passes through the local proxy transparently. |
| 2 | ACCESS_NETWORK_STATE |
Used by the VPN capture service to resolve the UID that owns each network connection (via ConnectivityManager.getConnectionOwnerUid() on API 29+), so captured traffic can be attributed to the originating app. |
None — only queries connection ownership. |
| 3 | VPN_SERVICE (BIND_VPN_SERVICE) |
Creates a local VPN to route device network traffic through the on-device proxy for inspection. The VPN connects to the local proxy running on the device itself (127.0.0.1). No traffic leaves the device through the VPN — the VPN is purely a local routing mechanism. The system VPN consent dialog is shown to the user before the VPN starts. | None — the VPN is local-only. Traffic metadata (IP, port, protocol) is captured in-memory as described in section 2.1. |
| 4 | FOREGROUND_SERVICE |
Allows the capture service to run in the foreground while a capture session is active, so the VPN and local proxy are not killed by the system. | None. |
| 5 | FOREGROUND_SERVICE_SPECIAL_USE |
The capture service uses the specialUse foreground service type because it does not fit the standard categories (media, location, etc.). The subtype is declared as "Network packet capture for debugging." This keeps the VPN tunnel and local MITM proxy alive while the user inspects traffic. The service runs only while you have explicitly started a capture. | None. |
| 6 | POST_NOTIFICATIONS |
Shows a persistent foreground-service notification indicating that a capture session is active (required by Android for foreground services on API 33+). The notification tells the user "VPN Capture Active" with a tap-to-open action. | None — only displays a notification. |
| 7 | QUERY_ALL_PACKAGES |
Lists all installed applications so you can select which app(s) to capture in the app selector. Android's default package-visibility filtering (introduced in API 30) would hide most apps, making per-app capture impossible. The list of installed packages is used only locally to populate the app selector UI and is never transmitted, stored persistently, or shared with any server. This permission requires a justification declaration in the Google Play Console. | Package names, app labels, icons, and UIDs — used only in-memory for the app selector. Never transmitted. |
| 8 | SYSTEM_ALERT_WINDOW(Draw over other apps) |
Displays a floating capture-status indicator overlay so you can see when a capture is active without opening the App. The user must explicitly grant this permission via Android Settings. | None — only draws an overlay, does not read screen content. |
To decrypt HTTPS traffic, CanaryX generates a local Certificate Authority (CA) — a self-signed root certificate with a 2048-bit RSA private key — and optionally installs it as a trusted certificate on your device. This is an optional, user-initiated action — the App will never install a certificate without your explicit consent. A warning dialog is shown before every certificate operation.
The CA can be installed as a user certificate via Android's certificate installer. On Android 7+ (Nougat / API 24+), most apps ignore user-installed certificates by default (this is a platform security feature), so HTTPS capture may not work for all apps without additional steps. The user CA password is "canaryx". A warning dialog is shown before installation explaining what the CA does, Android 7+ limitations, and how to remove it.
On rooted devices (where the su binary is available), the CA can be installed as a system certificate, which makes all apps trust it — including apps that ignore user-installed certificates. This is an advanced feature that requires root access and a writable system partition, modifies the system certificate store (/system/etc/security/cacerts), and may not survive a reboot on Android 14+ (APEX-managed certificate stores). This feature is entirely optional and not required for the App to function. A detailed warning dialog is shown before any system CA operation, explaining the risks and recommending the safer user CA alternative. The App executes su commands only when the user explicitly taps the "Install System CA" button — it never calls su automatically or in the background.
The CA private key and certificate are stored in the App's private storage (not accessible to other apps). They are never transmitted to any server. When you export the CA, the following files are offered for saving via the Android Storage Access Framework: CanaryXCA.crt (PEM certificate, public key only) and CanaryXCA.p12 (PKCS12 keystore, private key + certificate, password-protected). A warning dialog is shown before export, advising the user to store the file securely and never share it.
You can uninstall the CA at any time. For user CA: go to Android Settings → Security → Credential storage → Trusted credentials → User → Remove "CanaryXCA". For system CA (root): use the "Uninstall System CA" button in the App (a confirmation dialog is shown first).
The App declares android:usesCleartextTraffic="true" and uses a network_security_config.xml file. This is necessary because the App's core function is to inspect HTTP (cleartext) traffic. The configuration allows cleartext traffic for all domains (required for HTTP capture), trusts both system and user CA stores (so the CanaryX CA is accepted by the local proxy), and affects only the CanaryX app process — it does not modify the certificate validation behavior of other installed apps.
android:allowBackup="false" — ADB backup is disabled to prevent captured data and CA keys from being extracted.android:dataExtractionRules — Device-to-device transfer is disabled (Android 12+).android:fullBackupContent="false" — Cloud backup is disabled.The App includes a RootUtils class that can execute commands as root (su). This is used only for the optional "Install as System CA" feature. The App checks for root availability only when the Certificate screen is opened, executes su commands only when the user explicitly taps "Install System CA" or "Uninstall System CA", never runs root commands in the background or without user action, and does not require root to function — the App is fully usable without root.
CanaryX does not share any data with any third party. No data is sent to any server. No analytics, advertising, or tracking integrations. No data is sold or licensed to third parties. No data is shared with affiliated companies. No data is disclosed to law enforcement unless legally compelled.
You can delete all data at any time:
CanaryX is a developer tool and is not directed at children under the age of 13 (or the minimum age in your jurisdiction). The App does not knowingly collect personal information from children, does not offer content specifically for children, is not marketed to children, and is classified as a "Tools" app on Google Play. If you believe a child has provided us with personal information, please contact us so we can delete it.
Depending on your jurisdiction, you may have rights regarding your personal data: the right to access (this policy documents everything), the right to deletion (clear captures in-app or uninstall), the right to object (stop using the App and uninstall), the right to portability (use the export features in the App), and the right to withdraw consent (clear App data to reset the consent screen). Since CanaryX stores all data locally on your device and does not transmit it to any server, you can exercise these rights directly by clearing captures in-app or uninstalling the App. No request to a server is needed.
This Privacy Policy applies only to CanaryX. The App may display links to external websites (e.g., in the About dialog or Privacy Policy link). We are not responsible for the privacy practices or content of those external sites. We recommend reviewing the privacy policies of any third-party sites you visit.
CanaryX uses the following open-source libraries, each governed by their own licenses. These libraries do not collect user data through CanaryX:
| Library | Purpose | Collects data? |
|---|---|---|
| BouncyCastle (bcprov-jdk18on, bcpkix-jdk18on) | Cryptography — CA certificate generation, PKCS12 keystore, SSL | No |
| OkHttp | HTTP client — local proxy networking, request replay | No |
| Gson | JSON parsing — serialize/deserialize capture data and rewrite rules | No |
| Kotlin Coroutines | Asynchronous programming — background proxy operations | No |
| AndroidX Core / AppCompat | Android compatibility utilities | No |
| Material Components for Android | UI components — Material 3 Expressive design | No |
| Jetpack Compose | UI toolkit — loading indicators | No |
| AndroidX RecyclerView | Scrollable list of captured items | No |
| AndroidX Preference | Settings screen | No |
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective date" at the top of this page. For significant changes, we may also notify you through the App (e.g., re-showing the consent screen). We encourage you to review this policy periodically.
If you have any questions, concerns, or requests regarding this Privacy Policy or the App's data practices, please contact:
Robin Shakya
dev.robinop@gmail.com