Privacy Policy

WHO-SEE-MY-PHONE (WSMP) · Published by OWESI STUDIO

Effective date

Last updated: 9 July 2026

Who we are

WHO-SEE-MY-PHONE (WSMP) is published by OWESI STUDIO, based in Lahore, Pakistan. For the purposes of the EU/UK General Data Protection Regulation, OWESI STUDIO is the data controller for the limited information described below. You can reach us at info@owesistudio.com for any privacy question or request.

Overview

WSMP helps you detect unauthorized access attempts on a device you own or are authorized to monitor. The app can capture photos, store incident records on your device, show notifications, display ads, and optionally upload incidents to your own Google Drive account if you enable that feature.

We do not operate a server that receives your incident photos or incident records. Everything the app captures stays on your device unless you explicitly export it or turn on sync to your own Google Drive.

Information the app processes

Depending on the features you enable, the app may process:

The app does not read your contacts, messages, call logs, location, or files outside its own storage. It does not collect a history of which apps you open.

How information is used

The app uses this information only to provide and support its features, including detecting unlock attempts, capturing intruder photos, storing and showing incident history, protecting access to the app, optionally syncing incidents to your own Google Drive account, and showing ads through Google Mobile Ads.

Legal bases for processing (EU/UK users)

Where the GDPR applies, we rely on:

You may withdraw consent at any time by turning the relevant feature off inside the app.

Camera and photo handling

The camera is used only for the security features you enable inside the app. It is never used continuously and never in the background without an active, visible foreground-service notification.

Captured photos are encrypted on your device using a key held in the Android Keystore and stored in app-private storage, where other apps cannot read them. The developer does not run a server that receives your incident photos. If you enable Google Drive sync, incident photos are uploaded only to your own Google Drive account.

Device admin, notifications, and background operation

If you grant Device Admin permission, the app can receive failed device unlock events reported by Android. This is what allows an intruder photo to be captured after a wrong PIN or pattern.

The app may also request notification, boot, foreground-service, vibration, wake-lock, and biometric-related permissions so monitoring and alerts can work as intended on your device. These permissions are used only for the app's stated security features. While monitoring is active, Android displays an ongoing foreground-service notification.

Google Drive sync

Google Drive sync is optional and off by default. If enabled, incidents are uploaded to a folder in your own Google Drive account using the restricted drive.file scope, which means the app can only see files it created itself.

The app uses Google sign-in and Google Drive authorization to connect your account, and stores your account email locally so it can show which account is connected. The developer does not operate a remote server for storing your incidents. Turning off sync stops future uploads. Content already stored in your Google Drive remains subject to your Google account settings until you delete it.

Advertising and the advertising identifier

The app displays ads through Google Mobile Ads (AdMob). To do this, Google may access your device's advertising identifier (Android Advertising ID) together with limited network and device information, and may use it to measure ad performance and to serve personalized or non-personalized ads.

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the app asks for your consent choices before serving personalized ads, and you can change those choices at any time. You can also reset or delete your advertising identifier in your Android settings under Settings > Privacy > Ads.

Google's handling of this data is governed by Google's own privacy policy at https://policies.google.com/privacy and https://policies.google.com/technologies/ads

Sharing and disclosure

The developer does not sell your personal data and does not share it with data brokers. The app does not send intruder photos or incident records to the developer's own server. Data may be shared only when you explicitly export or share a photo or report, when you enable sync to your own Google Drive account, when third-party services are used to provide the features you turned on, or when disclosure is required by law.

International transfers

The app itself does not transfer your incident data across borders, because that data stays on your device or in your own Google Drive account. Where Google processes data for ads, sign-in, or Drive on servers outside your country, those transfers are governed by Google's own safeguards and privacy terms.

Storage and retention

Incident records remain on your device until you delete them, clear app data, or uninstall the app. You can also remove incident items from inside the app. When the number of stored incidents exceeds the limit you configure, the oldest incidents are removed automatically. If cloud sync is enabled, copies stored in your Google Drive remain there until you delete them from Drive.

Deleting your data

Because the app does not store your data on our servers, you are in full control of deletion:

If you need help deleting anything, contact info@owesistudio.com.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, to withdraw consent, and to data portability. Residents of California may additionally have the right to know what personal information is collected and to opt out of its sale; we do not sell personal information.

Because incident data never leaves your device or your own Google Drive, you can exercise most of these rights directly inside the app. For anything else, contact info@owesistudio.com and we will respond within 30 days. EU/UK users also have the right to lodge a complaint with their local data protection authority.

Security

Incident photos are encrypted with a key stored in the Android Keystore and kept in app-private storage. An optional PIN, hashed with salted PBKDF2 and protected by a brute-force lockout, can be required to open the app. We limit access to the minimum needed for functionality. No method of storage or transmission is guaranteed to be completely secure.

Children's privacy

The app is not directed to children and is intended for device owners or authorized users who want to monitor access to their own devices. We do not knowingly collect personal information from children under 13 (or the minimum age required in your country). If you believe a child has provided us with personal information, contact info@owesistudio.com and we will delete it.

Your choices

You can disable monitoring toggles, remove Device Admin access, turn off cloud sync, disconnect your Google account, delete incidents, clear app data, reset permissions, change your advertising consent, or uninstall the app at any time. You can also choose whether to enable biometric unlock and whether to keep cloud sync active.

Contact

For privacy questions or requests, contact OWESI STUDIO at info@owesistudio.com.

Policy updates

This policy may be updated when app features, service providers, or legal requirements change. When we make a material change we will update the effective date above and, where required, notify you in the app. The latest published version is the version linked in our Google Play listing.