Privacy Policy for AGDM Root Checker
AGDM Soft ("AGDM", "we", "us") provides the AGDM Root Checker Android application (the "App"). This Policy explains what the App processes, what leaves the device, why it is processed, how long it is retained, and how users can remove data.
1. Release 1 service model
Release 1 is offered through a Google Play subscription. It has no advertising, advertising SDK, advertising-ID use, or free trial. The App does not create an AGDM account and does not request a user's name, email address, phone number, contacts, photos, media, or message contents during normal operation.
2. On-device security checks and installed-app monitoring
Most checks run locally. Depending on Android version, device capabilities, optional access, and the feature selected, the App may examine security configuration, root indicators, boot state, installed-app metadata and signing certificates, network/VPN/proxy state, per-app traffic totals, Wi-Fi security information, battery/heat information, and APK files or folders explicitly selected by the user.
Before the first device scan, the App shows a disclosure and asks for affirmative consent. If consent is declined, neither the scan nor background Integrity verification starts. After consent, a user-started scan or a scheduled scan explicitly enabled by the user may compare visible installed apps with built-in security indicators. Package names, signing certificates, installed-app lists, APK contents, traffic totals, and proxy/VPN candidate lists are not uploaded to AGDM.
The App keeps only an aggregate installed-app scan metric in its private local history: scan time, number of visible apps checked, indicator-match count, acknowledged monitoring-tool match count, and local scan duration. It does not read message contents or network-traffic contents.
With optional Usage Access enabled in Android Settings, the App queries recorded traffic totals and app-usage statistics to display Android-reported last-use times for apps matching known indicators. Android may omit these values. These usage records stay on the device unless included in a report the user explicitly exports or shares; they are not uploaded to AGDM.
3. Google Play Integrity and AGDM verification service
After consent, a scan can ask Google Play to create a Play Integrity token. Beginning with App version 1.0.26 (27), the App first sends the following over HTTPS to the AGDM primary managed service on Google Cloud Run at agdm-rootchecker-backend-swzwtl5vwa-ew.a.run.app. If that service has a network failure or returns HTTP 5xx, the App can retry the same request against the independent AGDM fallback at api.agdm-rootchecker.com on Hostinger. HTTP 4xx responses are not bypassed:
- the Play Integrity token and an opaque expected nonce;
- a random per-request identifier;
- the App package name, version name/code, and installer package name.
Closed-test versions up to 1.0.25 (26) can also contain a client timestamp, request hash, random App-install identifier, locally derived security-signal digest, and build type. These compatibility fields are not used or persisted by the production verifier. They are no longer separate outbound fields beginning with version 1.0.26 (27).
The AGDM service sends the token to Google Play Integrity for decoding, validates package, nonce, app-recognition, and device-integrity results, and returns the result to the App. It does not keep request bodies or successful request/response records in a database, cache, file, or application log. In particular, it does not persist raw tokens, nonces, per-request identifiers, install identifiers, digests, package/version/installer fields, or decoded verdicts.
The backend's abuse-prevention state for the raw connection IP is held in process memory without geolocation. Request records expire after 24 hours plus approximately one minute for cleanup; the IP entry disappears when no current records remain, or earlier if the process restarts. Continued requests can keep the entry active.
Technical security logs and IP addresses
The memory-only rule above applies to the backend's raw-IP abuse-prevention state, not to all infrastructure logs. Minimized application security logs can contain the event time and type, method, category or reason, a masked network address and a per-process HMAC fingerprint of the IP. These are pseudonymous identifiers, not a guarantee of anonymity. Hostinger application logs are limited to seven days; Google Cloud application logs to 30 days. VPS operating-system security logs can contain full source IP addresses for network events. The system journal is configured for seven-day retention with daily file rotation. UFW firewall and rsyslog text logs rotate weekly and keep the current file plus four archives. Older copies of these files can remain in provider backups until backup rotation removes them.
Hostinger application logs contain no raw IP, request body, token, nonce, successful verdict, or purchase token and are limited to seven days. Minimized Google Cloud application logs can contain an event type, reason, masked network, and a short per-process HMAC fingerprint, but no raw IP, request body, token, nonce, or successful Integrity verdict; the Google Cloud _Default bucket retains them for 30 days. Cloud Run infrastructure request logs are excluded from the _Default sink so raw request IPs and URLs are not retained there.
4. Google Play Billing
Google Play offers and processes subscriptions, displays the localized price, and handles payment details. The App uses Google Play Billing to query purchases and acknowledge a completed purchase. To prevent a modified client from granting itself access, the App sends the subscription product ID and Google Play purchase token over HTTPS to the same Cloud Run primary or Hostinger fallback described above. The backend sends the token to the Google Android Publisher API, returns only the entitlement state, expiry time, base-plan ID, acknowledgement state, and verification time, and does not persist the token or response in an AGDM database or application log. The App stores the verified entitlement locally and can use it offline for no more than 72 hours.
Google Play Real-time Developer Notifications can be delivered through Google Cloud Pub/Sub to two independent AGDM push subscriptions. An unacknowledged notification, which can contain a purchase token, is retained by Pub/Sub for no more than 24 hours. Each backend verifies the Google-signed OIDC identity, processes the notification in memory, and does not create a server-side user or entitlement database. Google processes Play and Cloud data under the Google — Privacy Policy.
5. Local storage and retention
- App-private data: settings, consent state, scan history, aggregate scan metrics, reports, and deferred-verification state remain until removed through available App/Android controls, App storage is cleared, or the App is uninstalled. Android backup and device transfer are disabled for this data.
- AGDM Integrity and entitlement requests: request data is processed for the request and is not retained in AGDM application storage or successful-request logs.
- Abuse-prevention IP state: memory only; each request record expires after 24 hours plus approximately one minute for cleanup. New requests can keep the IP entry active.
- Hostinger minimized application logs: no more than seven days.
- Google Cloud minimized application logs: 30 days in the
_Defaultbucket; Cloud Run infrastructure request logs are excluded. - Google Cloud mandatory audit/system logs: the locked
_Requiredbucket retains provider administration and system-event records for 400 days. These records are not AGDM request bodies and do not contain Play Integrity or purchase tokens. - Pub/Sub RTDN messages: acknowledged messages are removed by Google; unacknowledged messages are retained for no more than 24 hours.
- Hosting backups: Hostinger rotates full daily and weekly VPS backups according to the provider's schedule. These copies can contain files already deleted from the live server; that content remains until the provider removes the particular backup during rotation. A fixed calendar deadline for removal from all provider backups is not guaranteed here.
- User exports: files explicitly exported or shared remain wherever the user saved or sent them and must be deleted there by the user.
6. Deletion and user choices
The App creates no AGDM account, so there is no AGDM account to delete. Users can remove local history where the App provides that action, clear App storage in Android settings, delete exported files from their destination, or uninstall the App. See the AGDM Root Checker data-deletion instructions.
Because successful Integrity and entitlement requests are not retained as AGDM records, AGDM cannot retrieve them later by install ID, request ID, package name, or purchase token. Temporary abuse-prevention state, minimized logs, and unacknowledged Pub/Sub messages expire automatically under the periods above. Questions or deletion requests can be sent to agdmsoft@gmail.com; AGDM will respond within 30 calendar days. Hostinger rotates full daily and weekly VPS backups according to the provider's schedule. These copies can contain files already deleted from the live server; that content remains until the provider removes the particular backup during rotation. A fixed calendar deadline for removal from all provider backups is not guaranteed here.
7. Service providers and disclosures
- Google Play Integrity and Google Play Billing: token decoding, app/device recognition, subscriptions, and payments.
- Google Cloud Run, Cloud Logging, and Pub/Sub: primary managed verification and entitlement processing, minimized operational logs, and delivery of subscription notifications in the European region selected by AGDM.
- Hostinger: independent fallback verification and entitlement processing on a VPS in Germany; separately stored daily backups observed in Lithuania.
AGDM does not sell user data, use it for advertising, or use a general analytics/advertising processor. Information may be disclosed when required by applicable law or reasonably necessary to protect users, the service, or legal rights, limited to information AGDM actually has.
8. Security
The App uses HTTPS and disables cleartext traffic. Release builds disable the App's HTTP body logger. The primary managed service runs on Google Cloud Run with route-level validation, per-IP rate limiting, and an operator endpoint that is not public. The independent Hostinger fallback terminates HTTPS through Caddy and forwards requests to a backend bound only to loopback. Tokens and nonces are excluded from logs, success records are not logged, persistent logs are minimized and access-controlled, and retention is limited as described above. No transmission or storage method is completely secure.
9. Permissions and special access
Android permissions and special access are used only for user-facing security features that require them. Denying optional access can make a related check unavailable or less complete. Granting access does not mean local installed-app or device results are uploaded: automatic off-device transmission is limited to the Integrity and subscription-entitlement flows in Sections 3 and 4 unless the user explicitly exports or shares a file.
10. Children
The App is a device-security utility and is not directed to children. It creates no user profile and uses no advertising.
11. Changes
AGDM may update this Policy when the App, backend, legal requirements, or service providers change. The effective date and published text will be updated. A material change in off-device processing requires a corresponding review of the Google Play Data Safety declaration and, where appropriate, a renewed in-App disclosure.
12. Contact
Privacy questions and requests: agdmsoft@gmail.com
Deleting data or uninstalling does not cancel your subscription. Manage or cancel it separately in Google Play.
