OneGuard · MB Makery

OneGuard privacy policy

Effective date: 7 October 2026

1. Who we are

OneGuard ("the app") is published by MB Makery, a small partnership (mažoji bendrija, MB) registered in Lithuania, registered address V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania ("we", "us").

For any question about privacy or this policy, write to support@visata.net.

2. The short version

3. What OneGuard looks at, and why

3.1 Scan and Daily check-up

What it reads: the list of apps installed on your phone and, for each app: its name and package name, which app store installed it, whether it is a system app, whether it has an icon in your app drawer, the permissions it asks for and the ones you have granted, its install and update dates and its version.

Why: to point out apps you installed from outside a known app store that hold sensitive access (for example reading or sending texts, reading the call log, or using the microphone together with precise location). These are OneGuard's own on-phone rules. They are not a malware verdict: this version has no malware-scanning engine.

Daily check-up runs only if you switch it on. It repeats the same check about once a day, when the phone is idle and the battery is not low, and shows a notification only when it finds something new. The notification shows a count, not app names.

What is kept: the result of the latest completed scan (for each app that needs a look: its name, package name and the reasons), the time of the scan and the number of items. Each new completed scan replaces the previous one.

3.2 Spy check

What it reads: which apps use Android's Accessibility features, which apps are active device administrators, which apps have notification access, which apps have no icon in your app drawer, where apps were installed from, which sensitive permissions they hold, and basic signs that the phone is rooted.

It also compares the package names of your installed apps with a list of known monitoring apps that is built into OneGuard: the public "stalkerware-indicators" list by Echap, used under the Creative Commons Attribution 4.0 licence. Only for an installed app whose package name is on that list, OneGuard reads the fingerprint of the app's signing certificate, to check that it really is the listed app. The list is part of the app, so the comparison happens on your phone and nothing is looked up online. The list covers known apps only; a new or renamed monitoring app would not be on it.

Why: these are common signs that someone may be monitoring the phone.

What is kept: only the time of the last check and the number of signs found. The check runs only when you start it.

3.3 Scam guard: texts

This works only after you turn on notification access for OneGuard in Android's settings. OneGuard explains what it reads before it sends you there.

What it reads: with notification access, Android passes OneGuard the notifications of all apps. OneGuard looks only at which app posted each notification and ignores every notification except those from your default text-messaging (SMS) app. For those, it reads the sender as shown in the notification (a name or a number) and the message text.

Why: to warn you about texts that look like scams. OneGuard checks the links inside a text with its own rules, on the phone. A text without a link is never flagged. OneGuard cannot block, delete or answer texts.

What is kept: texts that are not flagged are not kept. For a flagged text, OneGuard keeps the sender, the text, the time and the reasons it was flagged, for the latest 50 flagged texts. If you mark a text "It's safe", it leaves the list and OneGuard keeps only a fingerprint of it (a short code calculated from the text, from which the text cannot be read back; at most 100), so that the same text is not flagged again.

Please note that these texts were written by other people. OneGuard only uses them on your phone to warn you.

3.4 Scam guard: links

A link you type or paste is checked on the phone with OneGuard's rules and is not kept.

3.5 Scam guard: QR codes

Camera: used only while you scan a code, after you allow camera access. Camera frames are read in the phone's memory and discarded; no picture is saved.

Photo: if you pick a photo or screenshot of a code, Android's photo picker gives OneGuard only that photo. It is read in memory and discarded. OneGuard does not keep the photo or its location on your phone.

OneGuard shows what the code contains and checks any web link in it. Nothing is opened, dialled or joined automatically.

3.6 Scam guard: calls

This works only on Android 10 or newer and only after you choose OneGuard as your call screening app in Android's dialog.

What it receives: for incoming calls from numbers that are not in your contacts, Android passes OneGuard the caller's number (unless it is hidden), whether the number was hidden, the result of the network's caller-ID check where the network provides it, and the call direction. OneGuard also reads your SIM card's country code to notice foreign numbers. OneGuard cannot see your contacts or your call history.

Why: to note facts about calls from unknown numbers, such as a hidden number, a failed caller-ID check or a foreign country code. OneGuard declines a call only if you switched on one of its decline rules (all are off by default). A declined call still appears in your phone's call history.

What is kept: the latest 50 screened calls (number, time, the facts noted and whether the call was declined) and your rule settings. "Clear list" erases the list.

3.7 Privacy

The Privacy tab shows which of your apps can use the camera, microphone, location and contacts. It reads the permissions of installed apps when you open it and keeps nothing.

3.8 Settings

Each time you open Settings, OneGuard asks Android which accesses it holds and whether each one is on, and shows them with what each is for. It also lists what OneGuard keeps on your phone. Settings itself keeps nothing.

3.9 Defence check

What it reads: each time you open it, OneGuard reads these settings on your phone: whether Android's Advanced Protection is on (Android 16 and newer), the date of the newest security update, whether a screen lock is set, whether USB debugging and developer options are on, and whether the phone's storage is encrypted. To see whether the bootloader is locked, it creates a temporary key in Android's secure key storage, reads what the phone's secure hardware reports with that key, and deletes the key straight away.

Why: to show how hard the phone is to break into, and which of Android's protections you can switch on. OneGuard cannot detect surveillance by a mobile operator or government-grade spyware, and this check does not look for spyware.

What is kept: nothing. The results are shown on the screen, are not stored and are not sent anywhere. The call-forwarding lines only open your phone's dialer with a code filled in; nothing is dialled until you press call.

3.10 Not in this version

This version has no VPN, no data-breach monitoring, no malware-scanning engine and no paid plan. If we add any of them, we will update this policy first (section 11).

4. What we receive

From the app: nothing. This version of OneGuard cannot send data to us.

If you write to us: we receive your email address and what you write, and use them only to answer you. We keep that correspondence only as long as we need it to answer you and to deal with any follow-up, and then delete it, unless the law requires us to keep it longer.

Google Play: when you install OneGuard from Google Play, Google handles your download under its own privacy policy (https://policies.google.com/privacy). Google gives app publishers statistics about their apps, such as numbers of installs, and, for users who chose to share usage and diagnostics data with Google, reports of crashes and freezes. Google prepares these reports; we use them only to fix problems in OneGuard.

5. Where your data is stored and how it is protected

Everything OneGuard keeps is stored in its private storage on your phone. Android prevents other apps from reading it. OneGuard tells Android to leave its data out of backup: it is not copied to Google's cloud backup, and it is not copied to a new phone in a phone-to-phone transfer. On a new phone, OneGuard starts empty.

OneGuard does not add its own encryption to what it keeps. It relies on Android's app separation and, where your phone uses it, Android's storage encryption. Anyone who can unlock your phone and open OneGuard can see the flagged texts and the screened calls.

6. How long things are kept

What Kept until
Latest scan result (apps that need a look, reasons, time, count) The next completed scan replaces it
Last spy check (time and number of signs) The next spy check replaces it
Flagged texts (sender, text, time, reasons) Only the latest 50 are kept; older ones drop off. Or until you mark them safe or erase OneGuard's data
Fingerprints of texts marked safe Only the latest 100 are kept
Screened calls (number, time, notes, declined or not) Only the latest 50 are kept; or until you tap "Clear list"
Settings (light or dark appearance, daily check-up on or off and its schedule, call rules, whether you have seen the welcome screen) Until you change them or erase OneGuard's data
Camera frames, QR photos, typed links, the Privacy tab, the Defence check's readings, the access list in Settings Not kept

Erasing OneGuard's data (section 7) or uninstalling OneGuard removes everything in this table.

7. How to erase your data

To stop OneGuard reading something, switch off its notification access, choose another call screening app (or none), or turn off camera or notifications for OneGuard in Android's settings. Each row in OneGuard's Settings opens the matching Android screen.

Because we never receive this data, we cannot erase it for you and cannot recover it.

8. Permissions and special access, one by one

Permission or access What it allows What OneGuard uses it for When it is given
See all installed apps (QUERY_ALL_PACKAGES) Read the list of installed apps, their permissions and their signing certificates Scan, Daily check-up, Spy check (including the comparison with the list of known monitoring apps), Privacy At install; Android does not ask
Request app removal (REQUEST_DELETE_PACKAGES) Open Android's uninstall dialog for an app The "Remove app" button in Results and Spy check. Android always asks you to confirm At install; Android does not ask
Camera (CAMERA) Use the camera Scanning QR codes Asked when you tap "Scan with camera"
Notifications (POST_NOTIFICATIONS, Android 13+) Show notifications Daily check-up alerts Asked when you switch on Daily check-up
Notification access (special access) Read notifications of other apps Scam guard texts (only notifications of your default SMS app are used) You turn it on in Android's settings
Call screening app (Android role) Receive incoming calls from numbers not in your contacts before they ring Scam guard calls You choose OneGuard in Android's dialog
Read whether Advanced Protection is on (QUERY_ADVANCED_PROTECTION_MODE, Android 16 and newer) Read whether Android's Advanced Protection is switched on. It cannot change it Defence check At install; Android does not ask
Device settings and the phone's secure hardware (no permission needed) Read the security update date, whether a screen lock is set, USB debugging, developer options and storage encryption; create a temporary key in Android's secure key storage to read what the phone's secure hardware reports about the bootloader, then delete it Defence check. Nothing is stored or sent Each time you open the Defence check
Run at start-up, keep the phone awake briefly, foreground service, view network state (RECEIVE_BOOT_COMPLETED, WAKE_LOCK, FOREGROUND_SERVICE, ACCESS_NETWORK_STATE) Let scheduled work run reliably Added by Android's WorkManager library, which runs the Daily check-up. "View network state" only lets the library see whether a network is connected; it does not give internet access At install; Android does not ask

OneGuard does not request: internet access, access to files or photos in your phone's storage (including "All files access"), contacts, call log, SMS, location, microphone, Accessibility services, or the advertising ID.

9. Children

OneGuard is meant for adults and is not directed at children. This version does not send anyone's personal data to MB Makery or another recipient, children included.

10. Your rights under the GDPR

Controller. MB Makery is the controller for personal data we process ourselves, which today is only correspondence you send us. Data that OneGuard handles only on your phone never reaches us, and we cannot see it.

Legal bases (Article 6 GDPR).

Your rights. You have the right to access, correct and erase your personal data, to restrict or object to its processing, to data portability, and to withdraw any consent you gave. For data that exists only on your phone you can exercise these rights directly, as described in section 7. For anything else, write to support@visata.net; we will answer within one month.

Automated assessments. OneGuard's checks (for example "needs a look" or a flagged text) are automatic, are shown only to you and do not produce legal or similarly significant effects. You decide what to do.

Transfers. This version of the app sends no data anywhere, so no data is transferred outside the European Economic Area.

Complaints. You can complain to the Lithuanian supervisory authority, the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, https://vdai.lrv.lt), or to the data protection authority of the EU country where you live or work.

11. Changes to this policy

When we change this policy we will publish the new version at the same address, with a new effective date. The "Privacy policy" link in OneGuard's Settings and the link on Google Play both point to that address. Before any feature that sends data off your phone is switched on, we will update this policy and explain the change in the app first.

12. Contact

MB Makery, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania, support@visata.net.