HARIS SHIELD

Privacy Policy

A security tool that quietly harvested your data would be worthless. Here is exactly what happens to yours.

Last updated: July 25, 2026

The short version

  • Scan results stay on your computer. We never receive the contents of your phone — no messages, photos, contacts, call logs, or app lists.
  • This website sets no cookies and uses no third-party analytics. No consent banner, because there is nothing to consent to.
  • We do not store your IP address.
  • Some features do contact outside services. They are listed below, and offline mode disables all of them.

What this website collects

We count page views so we can tell which guides are worth writing. The counter runs on our own server — no Google Analytics, no third-party script, no cookie, no fingerprint. For each page view we store the date and time, the page path, the referring website's domain name, and a coarse browser, operating system and device type such as “Chrome / macOS / desktop”.

We deliberately do not store your IP address. It is held in memory only long enough to rate-limit abuse, and is never written to disk. Referring URLs are reduced to a bare domain before storage, so if you arrive from a search engine, the words you searched for never reach us. Query strings are stripped from page paths for the same reason.

These records cannot reasonably be traced back to an individual, and we do not attempt to do so.

What the app sends, and when

Haris Shield analyses your phone on your own computer. The analysis itself is local. However, three features improve their results by consulting outside sources, and you should know about them before you scan:

  • Connection geolocation. When the app finds network connections on your phone, it may look up where those IP addresses are located using ipinfo.io. Those IP addresses — belonging to the servers your phone talked to, not to you — leave your computer.
  • Breach check. If you use the optional breach feature, the email address you enter is sent to Have I Been Pwned to check whether it appears in known data breaches.
  • Threat lists. The app downloads public lists of known-malicious domains. This is a one-way download — nothing about you is sent.

Offline mode turns all of this off. Enable it in the app's settings and Haris Shield will work entirely from its local database with no outbound connections. If you are in a sensitive situation, use offline mode.

If you buy a licence

Payments are handled by Lemon Squeezy, which acts as the merchant of record. They collect your name, email address, payment details and the country used for tax purposes. We never see your card number. Their privacy policy governs that data.

We store your email address and licence key on our own server so the app can confirm your licence is valid. That is the only personal data we hold. Ask us to delete it and we will, though doing so ends the licence.

Repeated failed activations

To stop licence keys being brute-forced, the app reports an anonymous installation identifier when a device has failed activation too many times. It identifies an installation, not a person, and is not linked to your scans.

Your rights

If you are in the EU or UK, you have the right to access, correct, export or delete the personal data we hold about you, and to complain to your national data protection authority. In practice the only such data is your email address and licence key. Write to support@harisshield.com and we will act within 30 days.

Changes

If we change what we collect, we will change this page and update the date at the top. See also our Terms of Service and who we are.