Privacy Policy

CanaryX — Network Capture & Debugging Tool
Package: canary.robin
Developer: Robin Shakya · dev.robinop@gmail.com
Effective: August 25, 2026 · Contains ads: No · In-app purchases: No
CanaryX is a local network debugging tool that intercepts traffic on your device for inspection. All data stays on your device. There are no ads, no analytics, no crash reporting, no backend servers, and no third-party data sharing. The App does not transmit any user data anywhere.

Contents

1. What CanaryX Does

CanaryX is a local network debugging and traffic inspection tool designed for developers, security researchers, and power users. It works by creating a local VPN on your device that routes network traffic through a local on-device proxy. This allows you to inspect HTTP, HTTPS, TCP, and UDP traffic generated by other apps installed on your device — similar to tools like Charles Proxy, Proxyman, or Burp Suite.

Core features include:

The App is designed for developers and security researchers to debug their own apps and network traffic on devices they own or have explicit permission to test.

2. Data We Collect & Store

2.1 Network Traffic

When you start a capture session, CanaryX intercepts and displays network traffic from apps you select. This traffic may include:

Data typeExamplesStored where
HTTP request URLsFull URL, method (GET/POST/etc.), host, path, query parametersDevice RAM
HTTP request headersAuthorization tokens, cookies, User-Agent, Content-Type, custom headersDevice RAM
HTTP request bodyPOST form data, JSON payloads, uploaded file contentsDevice RAM
HTTP response headersSet-Cookie, Content-Type, Cache-Control, server headersDevice RAM
HTTP response bodyAPI JSON responses, HTML pages, image data (if body capture enabled)Device RAM
TCP packet metadataSource IP, destination IP, source port, destination port, packet length, protocolDevice RAM
UDP packet metadataSource IP, destination IP, source port, destination port, packet length, protocolDevice RAM
App identity (UID)The Android UID of the app that generated the traffic, resolved to app nameDevice RAM
Session metadataCapture session start/end time, packet count, HTTP count, selected app filterDevice RAM

All captured traffic is stored in device memory (RAM) only. It is never written to any remote server, database, or cloud service. Captured data is cleared when you tap "Clear Captures", stop the capture session, close the App, or uninstall it. The App retains a maximum of 500 capture items in memory at any time — older items are automatically discarded.

2.2 List of Installed Applications

To allow you to select which apps to capture, CanaryX reads the list of installed applications on your device using PackageManager.getInstalledApplications(). This includes package names, app labels, icons, whether the app is a system app or user app, and the app's UID. This list is used only locally to populate the app selector UI. It is never transmitted, logged, stored persistently, or shared with any server or third party.

2.3 App Settings & Preferences

The following settings are stored locally using Android's SharedPreferences:

These preferences are stored in the App's private storage and are never transmitted anywhere.

2.4 CA Certificate & Private Key

When you generate or install a CA certificate, the following cryptographic material is stored in the App's private storage: CA private key (RSA 2048-bit), CA certificate (X.509 self-signed), and PKCS12 keystore (if exported). This material never leaves the device unless you explicitly export it. Exported files are saved through the Android Storage Access Framework (the user picks the destination) or to the App's external files directory — no legacy shared-storage permissions are required. The CA password is "canaryx".

2.5 Data We Do NOT Collect

CanaryX does not collect, transmit, or share any of the following:

Security notice: CanaryX can see sensitive data flowing through captured apps — including authentication tokens, session cookies, passwords, API keys, and personal information transmitted over HTTP/HTTPS. Use the App only on devices you own and only to inspect traffic you have the right to inspect. Do not use CanaryX to intercept traffic without the consent of the person or entity whose data may be exposed. Misuse of this tool may violate local, national, or international wiretapping and privacy laws.

3. Advertising

CanaryX does not contain any advertisements. No ad SDKs are integrated (no Google AdMob, no Facebook Audience Network, no Unity Ads, no AppLovin, no ironSource, no mediation layers). No advertising identifiers are collected or read (no GAID/AAID). No ad-related tracking is performed. No promotional content is displayed. No in-app purchases are offered.

4. Analytics & Crash Reporting

CanaryX does not use any analytics or crash reporting services: no Google Analytics / Firebase Analytics, no Crashlytics / Bugsnag / Sentry / ACRA, no Mixpanel / Amplitude / Flurry, no usage tracking, session recording, or funnel analytics, no heatmaps or screen recordings. The App does not phone home. There is no backend server. The App operates entirely on-device.

5. Permissions

The following Android permissions are declared in the App's AndroidManifest.xml. Each permission is used only for its stated purpose.

#PermissionHow it is usedData collected
1 INTERNET Allows the local on-device proxy to make outgoing network requests on behalf of captured apps. Used for the "Repeat" / "Compose" feature that replays captured HTTP requests, and for the proxy to forward traffic to destination servers. None stored — traffic passes through the local proxy transparently.
2 ACCESS_NETWORK_STATE Used by the VPN capture service to resolve the UID that owns each network connection (via ConnectivityManager.getConnectionOwnerUid() on API 29+), so captured traffic can be attributed to the originating app. None — only queries connection ownership.
3 VPN_SERVICE (BIND_VPN_SERVICE) Creates a local VPN to route device network traffic through the on-device proxy for inspection. The VPN connects to the local proxy running on the device itself (127.0.0.1). No traffic leaves the device through the VPN — the VPN is purely a local routing mechanism. The system VPN consent dialog is shown to the user before the VPN starts. None — the VPN is local-only. Traffic metadata (IP, port, protocol) is captured in-memory as described in section 2.1.
4 FOREGROUND_SERVICE Allows the capture service to run in the foreground while a capture session is active, so the VPN and local proxy are not killed by the system. None.
5 FOREGROUND_SERVICE_SPECIAL_USE The capture service uses the specialUse foreground service type because it does not fit the standard categories (media, location, etc.). The subtype is declared as "Network packet capture for debugging." This keeps the VPN tunnel and local MITM proxy alive while the user inspects traffic. The service runs only while you have explicitly started a capture. None.
6 POST_NOTIFICATIONS Shows a persistent foreground-service notification indicating that a capture session is active (required by Android for foreground services on API 33+). The notification tells the user "VPN Capture Active" with a tap-to-open action. None — only displays a notification.
7 QUERY_ALL_PACKAGES Lists all installed applications so you can select which app(s) to capture in the app selector. Android's default package-visibility filtering (introduced in API 30) would hide most apps, making per-app capture impossible. The list of installed packages is used only locally to populate the app selector UI and is never transmitted, stored persistently, or shared with any server. This permission requires a justification declaration in the Google Play Console. Package names, app labels, icons, and UIDs — used only in-memory for the app selector. Never transmitted.
8 SYSTEM_ALERT_WINDOW
(Draw over other apps)
Displays a floating capture-status indicator overlay so you can see when a capture is active without opening the App. The user must explicitly grant this permission via Android Settings. None — only draws an overlay, does not read screen content.

6. Certificate Authority (CA) Installation

To decrypt HTTPS traffic, CanaryX generates a local Certificate Authority (CA) — a self-signed root certificate with a 2048-bit RSA private key — and optionally installs it as a trusted certificate on your device. This is an optional, user-initiated action — the App will never install a certificate without your explicit consent. A warning dialog is shown before every certificate operation.

6.1 User CA Installation (No Root Required)

The CA can be installed as a user certificate via Android's certificate installer. On Android 7+ (Nougat / API 24+), most apps ignore user-installed certificates by default (this is a platform security feature), so HTTPS capture may not work for all apps without additional steps. The user CA password is "canaryx". A warning dialog is shown before installation explaining what the CA does, Android 7+ limitations, and how to remove it.

6.2 System CA Installation (Root Required — Optional)

On rooted devices (where the su binary is available), the CA can be installed as a system certificate, which makes all apps trust it — including apps that ignore user-installed certificates. This is an advanced feature that requires root access and a writable system partition, modifies the system certificate store (/system/etc/security/cacerts), and may not survive a reboot on Android 14+ (APEX-managed certificate stores). This feature is entirely optional and not required for the App to function. A detailed warning dialog is shown before any system CA operation, explaining the risks and recommending the safer user CA alternative. The App executes su commands only when the user explicitly taps the "Install System CA" button — it never calls su automatically or in the background.

6.3 CA Key Storage & Export

The CA private key and certificate are stored in the App's private storage (not accessible to other apps). They are never transmitted to any server. When you export the CA, the following files are offered for saving via the Android Storage Access Framework: CanaryXCA.crt (PEM certificate, public key only) and CanaryXCA.p12 (PKCS12 keystore, private key + certificate, password-protected). A warning dialog is shown before export, advising the user to store the file securely and never share it.

6.4 CA Uninstallation

You can uninstall the CA at any time. For user CA: go to Android Settings → Security → Credential storage → Trusted credentials → User → Remove "CanaryXCA". For system CA (root): use the "Uninstall System CA" button in the App (a confirmation dialog is shown first).

7. Network Security Configuration

The App declares android:usesCleartextTraffic="true" and uses a network_security_config.xml file. This is necessary because the App's core function is to inspect HTTP (cleartext) traffic. The configuration allows cleartext traffic for all domains (required for HTTP capture), trusts both system and user CA stores (so the CanaryX CA is accepted by the local proxy), and affects only the CanaryX app process — it does not modify the certificate validation behavior of other installed apps.

8. Data Storage & Security

8.1 Local Storage

8.2 Backup & Transfer Protection

8.3 Root Access

The App includes a RootUtils class that can execute commands as root (su). This is used only for the optional "Install as System CA" feature. The App checks for root availability only when the Certificate screen is opened, executes su commands only when the user explicitly taps "Install System CA" or "Uninstall System CA", never runs root commands in the background or without user action, and does not require root to function — the App is fully usable without root.

9. Data Sharing

CanaryX does not share any data with any third party. No data is sent to any server. No analytics, advertising, or tracking integrations. No data is sold or licensed to third parties. No data is shared with affiliated companies. No data is disclosed to law enforcement unless legally compelled.

10. Data Deletion

You can delete all data at any time:

11. Children's Privacy

CanaryX is a developer tool and is not directed at children under the age of 13 (or the minimum age in your jurisdiction). The App does not knowingly collect personal information from children, does not offer content specifically for children, is not marketed to children, and is classified as a "Tools" app on Google Play. If you believe a child has provided us with personal information, please contact us so we can delete it.

12. Your Rights (GDPR / CCPA / DPDP)

Depending on your jurisdiction, you may have rights regarding your personal data: the right to access (this policy documents everything), the right to deletion (clear captures in-app or uninstall), the right to object (stop using the App and uninstall), the right to portability (use the export features in the App), and the right to withdraw consent (clear App data to reset the consent screen). Since CanaryX stores all data locally on your device and does not transmit it to any server, you can exercise these rights directly by clearing captures in-app or uninstalling the App. No request to a server is needed.

13. Third-Party Links

This Privacy Policy applies only to CanaryX. The App may display links to external websites (e.g., in the About dialog or Privacy Policy link). We are not responsible for the privacy practices or content of those external sites. We recommend reviewing the privacy policies of any third-party sites you visit.

14. Open Source Libraries

CanaryX uses the following open-source libraries, each governed by their own licenses. These libraries do not collect user data through CanaryX:

LibraryPurposeCollects data?
BouncyCastle (bcprov-jdk18on, bcpkix-jdk18on)Cryptography — CA certificate generation, PKCS12 keystore, SSLNo
OkHttpHTTP client — local proxy networking, request replayNo
GsonJSON parsing — serialize/deserialize capture data and rewrite rulesNo
Kotlin CoroutinesAsynchronous programming — background proxy operationsNo
AndroidX Core / AppCompatAndroid compatibility utilitiesNo
Material Components for AndroidUI components — Material 3 Expressive designNo
Jetpack ComposeUI toolkit — loading indicatorsNo
AndroidX RecyclerViewScrollable list of captured itemsNo
AndroidX PreferenceSettings screenNo

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Effective date" at the top of this page. For significant changes, we may also notify you through the App (e.g., re-showing the consent screen). We encourage you to review this policy periodically.

16. Contact

If you have any questions, concerns, or requests regarding this Privacy Policy or the App's data practices, please contact:

Robin Shakya
dev.robinop@gmail.com