Privacy policy
1. About the developer and the app
Shutterguard (“the app”) is an iPhone privacy tool made by an independent developer in Taiwan. It helps people check hotels, fitting rooms, clinics and public restrooms for possible hidden cameras.
Contact: yanru.studio@icloud.com, or GitHub at github.com/lawliet0813/shutterguard.
2. Core commitment
All processing happens on your device. The app never uploads scan history, images, Bluetooth device lists, location or any personal identifiers to any server.
3. Data
3.1 Data we collect from you
None. No account, email address or name is required.
3.2 Data created and stored only on your device
| Data | Purpose | Protection |
|---|---|---|
| Scan history | Shown on the History screen | iOS Data Protection (CompleteUnlessOpen) |
| Thumbnails of candidate reflections (200 × 200) | Shown in details and history | iOS Data Protection (Complete) |
| Full evidence images (Pro, full frame plus annotated copy) | Let Pro users review the lit frame and the marked spots | iOS Data Protection (Complete) |
| Scan diagnostics (Pro sweep mode: measurement files and small crops of candidate spots) | Kept for 7 days in the release version; deleted together with photos when you clear photos | iOS Data Protection (Complete) |
| Settings and status (onboarding, Pro status, preferences) | Remember your settings | Managed by iOS |
| “My environment” Bluetooth baseline (device name, manufacturer ID, CoreBluetooth identifier) | Exclude your own regular devices from scoring | Managed by iOS |
| StoreKit purchase records | Verify the one-time Pro / Pro+ purchases | Managed by Apple |
3.3 Third-party tracking and analytics
None. The app contains no third-party SDKs, ad modules or analytics.
4. Permissions
4.1 Camera (required)
- Free (photo mode): takes two still photos, flash on and flash off, and compares them to find lens-like reflections.
- Pro (sweep mode): during each pass (about 5 seconds) the flash pulses quickly and the app analyzes the live camera preview for spots that brighten in step with the flash. Confirming a spot up close takes about another 5 seconds.
- Infrared check: uses the front camera to look for infrared light in a dark room.
- All processing is on the device. Nothing is uploaded. No video is recorded or saved; the live preview is analyzed in memory only. What stays on the phone is listed in 3.2.
- LiDAR depth (supported models): used during detection to estimate the size and distance of a reflection. Depth data is processed in memory only, never written to history, exported or uploaded.
4.2 Bluetooth (Pro)
- Scans nearby Bluetooth Low Energy devices, filters known harmless ones, and flags possibly suspicious signals. Used only during Pro scans. The free version does not use Bluetooth or ask for the permission.
- Only publicly broadcast data is read: advertised name, signal strength, a randomized identifier (not the hardware MAC address), manufacturer ID and service UUIDs. Manufacturer IDs are matched against an offline table on the phone.
- For a few unnamed devices very close by (at most 5, for at most 3 seconds each), the app briefly connects to read the public device name, then disconnects. It does not pair, write to the device, or send any of your data.
4.3 Location (Pro, optional)
- Used only if you turn on arrival reminders. Geofence matching runs on the device. To find nearby venues, the app queries Apple Maps (MapKit), which sends an approximate location to Apple, not to the developer.
- If enabled, iOS may wake the app in the background to show a local notification when you arrive. No movement history is kept. A scan record may store the venue name and coordinates, which you can delete at any time.
4.4 Motion (magnetometer, Pro)
Reads the magnetometer to build a baseline of the room's magnetic field. Shown for reference only and not scored. Processed on the device.
4.5 Microphone (Pro, optional)
Analyzes the 17 to 22 kHz ultrasonic range in real time. Audio is never recorded or saved. Used only when a Pro user turns this check on.
4.6 Local network (Pro, optional)
Sends standard Bonjour service queries on the Wi‑Fi network you are connected to, looking for camera streaming services. It does not connect to those devices or transfer any content. Used only when a Pro user turns this check on.
5. Things the app never does
- Upload images, Bluetooth lists or location to the developer.
- Track device or advertising identifiers.
- Share data with ad networks or analytics services.
- Record audio or video in the background, or keep using the camera, Bluetooth or magnetometer after the app closes (except iOS geofencing for Pro arrival reminders).
- Sync history to iCloud on its own. iCloud device backups, if you use them, are managed by Apple.
6. Your choices
- Delete everything: in Settings, delete all records (history, photos and the Bluetooth baseline), or delete the app.
- Clear photos only: in Settings, clear photos. This also removes scan diagnostics but keeps text records.
- Export: Pro users can export history as a JSON file. File paths to images are not included.
7. Children
The app is not designed for children under 13 and collects no identifying information. See the App Store page for the age rating.
8. Third-party services
The only third-party service is Apple StoreKit 2, used for the one-time Pro / Pro+ purchases under Apple's privacy policy. The app never receives your payment details or Apple Account.
9. Security
Images use iOS Data Protection (Complete); the history database uses CompleteUnlessOpen. There is no cloud storage and no developer server. Network use is limited to Apple frameworks (StoreKit, and MapKit for Pro reminders) and local Bonjour queries for the Pro Wi‑Fi check.
10. Changes
Significant changes will update the date above and be noted in the app's release notes. If a change adds new data collection, the app will ask for your consent again.