Xewa Browser
Your privacy

Privacy Policy

This notice sets out what the Xewa Browser app (com.xewa.browser) records, the reasons for it, who receives it, and the controls you hold over it.

In brief

01Who runs Xewa, and what this covers

Xewa Browser (the “App”, “we”, “us”) is an Android web browser built and published by its developer, enerdziion, who acts as the data controller for everything described below.

What follows applies to the Xewa Browser Android app alone. It doesn't extend to the outside websites you reach through the browser, or to the third-party services linked in Section 9 — each of those is governed by its own policy, not this one.

02What we collect

You don't register, and we don't ask for directly identifying details — no name, email address, phone number or contacts. What we do gather, mostly on its own, is listed below; it exists to run the App and its advertising and measurement features:

WhatDetailsWhy we use itWho gets it
App-instance IDuid A random value created on the device the first time the App runs and kept locally — not derived from any hardware or account identifier. Tell one install apart from another, attach analytics to it, and gauge retention. Our servers
Advertising IDGoogle Advertising ID (GAID) The resettable ad identifier exposed by Google Play services. Serving and measuring ads, and restoring your attribution after a reinstall. Google (AdMob), our servers
Install referrer & campaignPlay Install Referrer The referrer string Google Play hands over describing how you arrived at the App (source, campaign). Attribution — seeing which campaign brought the install. Our servers
Install timestampinstall When the App was first installed on the device. Keeping attribution fresh, plus analytics. Our servers
Device & app info Android and app version, device model and maker, language/region, and whether you're currently connected. Compatibility, analytics and ad delivery. Our servers, Google
Push tokenFCM registration token A token from Firebase Cloud Messaging that lets a notification reach your device. Delivering push notifications — only where you've allowed the permission. Google (Firebase), our servers
Ad interaction & revenue Ad views, taps, and an estimate of the revenue each impression earns. Judging how ads perform and what they bring in. Google (AdMob), our servers
Usage events Actions inside the App — opening a feature, starting the proxy — carrying the fields above. Product analytics and troubleshooting. Our servers
Browsing data Your history, cookies, cache, open tabs and downloaded files. Running the browser itself. Kept on the device only (see Section 8)

We don't deliberately collect precise (GPS) location — the App asks for no location permission at all — and your history and the contents of the pages you open are never pulled onto our servers.

03What we do with it

Legal bases (EEA/UK). Personalised advertising and push notifications rest on your consent; measurement, analytics, security and non-personalised advertising rest on our legitimate interests; and anything the law demands rests on legal obligation. You can take back consent at any point (Section 16).

04Ads and your consent

The App is paid for by advertising served through Google AdMob and the Google Mobile Ads SDK. To place and measure those ads, Google and its advertising partners may handle your advertising ID and device information, as explained in Google's “How Google uses information from sites or apps that use our services”.

Where the law calls for it — for instance in the European Economic Area, the United Kingdom and Switzerland — the App shows a Google-certified consent form through the User Messaging Platform (UMP) before any personalised ad appears, so you can accept or refuse. If you refuse, or consent doesn't apply, the ads you see are non-personalised (contextual) as far as that is supported.

Controls you have over ads

Note: some builds ship with advertising switched off; it comes on only once a live ad account is configured. The practices above apply whenever ads are running.

05Install attribution

At install time, Google Play may pass along a referrer string (through the Google Play Install Referrer API) showing how you came to the App — say, the campaign or source. We file this alongside your app-instance ID and install timestamp so we can judge how well our marketing is doing.

So that attribution survives a reinstall, we may keep a little attribution data (such as your campaign/referrer) on our servers, keyed to your advertising ID, and read it back when you install again. With no advertising ID available — for example after you opt out — that recovery simply doesn't happen. Calls to our servers are signed to block tampering.

06Notifications

Grant the notifications permission and we use Firebase Cloud Messaging (Google) to send push notifications. That needs a device registration token, which we store so messages can be addressed to your device. Switch notifications off any time in the Android system settings for the App, or decline the permission when asked — the App works fine either way.

07The proxy

The App carries an optional proxy. Turn it on and your browsing traffic travels through third-party SOCKS5 proxy servers on its way to the sites you open. It sits off by default and runs only while you've enabled it.

Please read before switching it on

With the proxy running, whoever operates that proxy server can see which destinations you reach and any traffic that isn't encrypted. Anything served over HTTPS stays encrypted end to end, but connection metadata — the destination server, for one — is visible to the proxy operator.

We don't keep the contents of your proxied browsing on our servers. Third-party proxy operators are outside our control, and we can't vouch for how they log or secure traffic. Switch the proxy on only if you're comfortable with that.

08What stays on your device

Your history, cookies, cache, open tabs, saved settings and downloaded files all sit locally on the device and are never uploaded to us. The App also carries on-device ad- and tracker-blocking (“Ad-control”) that filters content right in the browser.

You can wipe this data from inside the App or through the Android settings for the App. Uninstalling clears locally stored data off your device (anything already sent to Google or to our servers is covered by Sections 9 and 12).

09Who else is involved

The App leans on the following third parties, each with a privacy policy of its own:

10Permissions the App asks for

INTERNET / ACCESS_NETWORK_STATE
Fetch web pages and check whether you're online.
AD_ID
Reach the advertising ID for ads and attribution (Sections 4–5).
POST_NOTIFICATIONS
Display push notifications, only where you allow it (Section 6).
USE_FULL_SCREEN_INTENT / WAKE_LOCK
Deliver time-sensitive notifications dependably.
WRITE_EXTERNAL_STORAGE
Store files you download (on older Android versions).
USE_BIOMETRIC
Optional biometric lock for App features, handled on-device by Android.
VIBRATE
Haptic feedback.

11When we share

We don't sell your personal information for money. Sharing happens only as this policy lays out: with the providers in Section 9 to run the App and its advertising, and where the law requires, where we need to enforce our terms, or to protect the rights, safety and security of our users and the public.

Bear in mind that some laws — California's CCPA/CPRA among them — may treat the use of advertising identifiers for cross-context behavioural advertising as a “sale” or “sharing.” Section 16 explains how to opt out.

12How long we keep it

We hold the data we collect only for as long as the purposes above need it — usually around 24 months for analytics and attribution — and then delete or aggregate it. Advertising data in Google's hands follows Google's own retention rules. Whatever is stored on your device stays there until you clear it or uninstall.

13Keeping it safe

We apply sensible technical and organisational safeguards, including encryption in transit (HTTPS) and signed requests to our servers. That said, no way of transmitting or storing data is ever perfectly secure, so we can't promise absolute security.

14Where data is processed

We and our providers may process information in countries other than your own, including wherever Google operates. Where the law requires, such transfers are backed by appropriate safeguards — the European Commission's Standard Contractual Clauses, for instance.

15Children

The App isn't aimed at children under 16, and we don't knowingly collect their personal information. If you think a child has given us data, get in touch and we'll remove it.

16Your rights

Depending on where you live, you may be entitled to access, correct, delete, restrict or object to how we process your information, to move your data elsewhere, and to withdraw consent. In the EEA/UK you can also complain to your data protection authority. In California and similar U.S. states you can ask to know or delete your information and to opt out of “sale”/“sharing” for cross-context behavioural advertising.

Since we tag data mostly by pseudonymous identifiers rather than your name, we may ask you for your advertising ID or app-instance ID so we can find the right records to act on.

To use any of these rights, write to enerdziion@gmail.com. The advertising controls in Section 4 are also available straight from your device at any time.

17Updates

This policy may change over time. When it does, we'll move the “Last updated” date above, and for anything significant we'll flag it more prominently in the App or on this page. Carrying on with the App after a change means you accept the revised version.

18Reach us

Got a question or request about this policy or your data? Here's how to reach the developer: