Privacy Policy
WHO-SEE-MY-PHONE (WSMP) · Published by OWESI STUDIO
Effective date
Last updated: 9 July 2026
Who we are
WHO-SEE-MY-PHONE (WSMP) is published by OWESI STUDIO, based in Lahore, Pakistan. For the purposes of the EU/UK General Data Protection Regulation, OWESI STUDIO is the data controller for the limited information described below. You can reach us at info@owesistudio.com for any privacy question or request.
Overview
WSMP helps you detect unauthorized access attempts on a device you own or are authorized to monitor. The app can capture photos, store incident records on your device, show notifications, display ads, and optionally upload incidents to your own Google Drive account if you enable that feature.
We do not operate a server that receives your incident photos or incident records. Everything the app captures stays on your device unless you explicitly export it or turn on sync to your own Google Drive.
Information the app processes
Depending on the features you enable, the app may process:
- intruder photos captured by the device camera
- incident records such as event type, time, and device unlock attempts
- app settings such as camera facing, photo quality, monitoring toggles, notification preferences, and sync preferences
- optional local app-lock settings such as an in-app PIN and biometric preference
- if you enable Google Drive sync, your Google account email address and the authorization needed to upload files to your own Google Drive
- an advertising identifier and limited technical and network information required by Google Mobile Ads and Google Play services
The app does not read your contacts, messages, call logs, location, or files outside its own storage. It does not collect a history of which apps you open.
How information is used
The app uses this information only to provide and support its features, including detecting unlock attempts, capturing intruder photos, storing and showing incident history, protecting access to the app, optionally syncing incidents to your own Google Drive account, and showing ads through Google Mobile Ads.
Legal bases for processing (EU/UK users)
Where the GDPR applies, we rely on:
- your consent, for optional features you switch on such as Google Drive sync, biometric unlock, and personalized advertising
- performance of a contract, to deliver the core monitoring features you installed the app to use
- legitimate interests, to keep the app secure, stable, and free of abuse
You may withdraw consent at any time by turning the relevant feature off inside the app.
Camera and photo handling
The camera is used only for the security features you enable inside the app. It is never used continuously and never in the background without an active, visible foreground-service notification.
Captured photos are encrypted on your device using a key held in the Android Keystore and stored in app-private storage, where other apps cannot read them. The developer does not run a server that receives your incident photos. If you enable Google Drive sync, incident photos are uploaded only to your own Google Drive account.
Device admin, notifications, and background operation
If you grant Device Admin permission, the app can receive failed device unlock events reported by Android. This is what allows an intruder photo to be captured after a wrong PIN or pattern.
The app may also request notification, boot, foreground-service, vibration, wake-lock, and biometric-related permissions so monitoring and alerts can work as intended on your device. These permissions are used only for the app's stated security features. While monitoring is active, Android displays an ongoing foreground-service notification.
Google Drive sync
Google Drive sync is optional and off by default. If enabled, incidents are uploaded to a folder in your own Google Drive account using the restricted drive.file scope, which means the app can only see files it created itself.
The app uses Google sign-in and Google Drive authorization to connect your account, and stores your account email locally so it can show which account is connected. The developer does not operate a remote server for storing your incidents. Turning off sync stops future uploads. Content already stored in your Google Drive remains subject to your Google account settings until you delete it.
Advertising and the advertising identifier
The app displays ads through Google Mobile Ads (AdMob). To do this, Google may access your device's advertising identifier (Android Advertising ID) together with limited network and device information, and may use it to measure ad performance and to serve personalized or non-personalized ads.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the app asks for your consent choices before serving personalized ads, and you can change those choices at any time. You can also reset or delete your advertising identifier in your Android settings under Settings > Privacy > Ads.
Google's handling of this data is governed by Google's own privacy policy at https://policies.google.com/privacy and https://policies.google.com/technologies/ads
Sharing and disclosure
The developer does not sell your personal data and does not share it with data brokers. The app does not send intruder photos or incident records to the developer's own server. Data may be shared only when you explicitly export or share a photo or report, when you enable sync to your own Google Drive account, when third-party services are used to provide the features you turned on, or when disclosure is required by law.
International transfers
The app itself does not transfer your incident data across borders, because that data stays on your device or in your own Google Drive account. Where Google processes data for ads, sign-in, or Drive on servers outside your country, those transfers are governed by Google's own safeguards and privacy terms.
Storage and retention
Incident records remain on your device until you delete them, clear app data, or uninstall the app. You can also remove incident items from inside the app. When the number of stored incidents exceeds the limit you configure, the oldest incidents are removed automatically. If cloud sync is enabled, copies stored in your Google Drive remain there until you delete them from Drive.
Deleting your data
Because the app does not store your data on our servers, you are in full control of deletion:
- delete individual incidents from inside the app
- clear all incidents from the app's settings
- disconnect Google Drive to stop future uploads, and delete the app's folder from your Google Drive to remove uploaded copies
- uninstall the app, or use Android's “Clear storage” option, to remove every local record, photo, PIN, and setting
If you need help deleting anything, contact info@owesistudio.com.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, to withdraw consent, and to data portability. Residents of California may additionally have the right to know what personal information is collected and to opt out of its sale; we do not sell personal information.
Because incident data never leaves your device or your own Google Drive, you can exercise most of these rights directly inside the app. For anything else, contact info@owesistudio.com and we will respond within 30 days. EU/UK users also have the right to lodge a complaint with their local data protection authority.
Security
Incident photos are encrypted with a key stored in the Android Keystore and kept in app-private storage. An optional PIN, hashed with salted PBKDF2 and protected by a brute-force lockout, can be required to open the app. We limit access to the minimum needed for functionality. No method of storage or transmission is guaranteed to be completely secure.
Children's privacy
The app is not directed to children and is intended for device owners or authorized users who want to monitor access to their own devices. We do not knowingly collect personal information from children under 13 (or the minimum age required in your country). If you believe a child has provided us with personal information, contact info@owesistudio.com and we will delete it.
Your choices
You can disable monitoring toggles, remove Device Admin access, turn off cloud sync, disconnect your Google account, delete incidents, clear app data, reset permissions, change your advertising consent, or uninstall the app at any time. You can also choose whether to enable biometric unlock and whether to keep cloud sync active.
Contact
For privacy questions or requests, contact OWESI STUDIO at info@owesistudio.com.
Policy updates
This policy may be updated when app features, service providers, or legal requirements change. When we make a material change we will update the effective date above and, where required, notify you in the app. The latest published version is the version linked in our Google Play listing.