iOS and iPadOS Privacy Policy
Last updated: September 9, 2026. This section applies to HTTP Sniffer on iPhone and iPad. The Android-specific policy below applies only to Android. In particular, the iOS app does not enumerate your installed apps, use Google Play Billing, or display an Android-style overlay over other apps.
Local VPN and captured traffic
After you authorize the VPN configuration in iOS and start capture, the app uses a local Network Extension packet tunnel to inspect supported traffic routed through it. Captures can contain URLs, DNS information, timestamps, headers, cookies, tokens, and request or response bodies. Network destinations still receive the traffic you send to them. The local VPN is a debugging tool, not an anonymity or remote VPN service.
Supported HTTPS inspection requires you to install and explicitly trust a local certificate and enable decryption. Some connections cannot be inspected, including services using certificate pinning or unsupported protocols. You can stop the VPN in the app or iOS Settings and remove the certificate and its trust in Settings when no longer needed.
Storage, exports and destinations you choose
Capture records, attachments, rules and preferences are stored in the app's local containers, including an App Group shared with its VPN extension. HTTP Sniffer does not automatically upload captured request or response contents to the developer. If you choose export, Share, Save to Files, replay, forwarding or a Webhook, the selected content is sent to the destination, app or service you configure. An export may include credentials or other personal data: review it before sharing.
The system file picker grants access to the files you select for import or request bodies; the app does not require access to your entire document library. Copies saved to Files, cloud storage or other apps follow those providers' policies. Deleting a capture in HTTP Sniffer does not delete copies already exported.
Background status and appearance
When supported and permitted by your system settings, a Live Activity can show background capture status and elapsed time on the Lock Screen or Dynamic Island. It does not display captured URLs, headers or bodies. You can control Live Activities in iOS Settings. Theme colors and light, dark or system appearance preferences are saved locally.
Advertising, consent and diagnostics
Builds with Google Mobile Ads may send advertising and device information to Google, including IP address, device and app information, ad interactions and diagnostic data, according to Google's documentation and the consent available in your region. Where required, the app uses Google's consent form and Apple's App Tracking Transparency prompt before relevant advertising processing. An advertising identifier is subject to Apple's permission and platform restrictions. iOS does not provide an installed-app inventory to this app.
If the distributed build enables Firebase Analytics, it may transmit app usage events and device or app information after the app's consent gate. Local diagnostic logs can also be generated to troubleshoot failures. Captured traffic contents are not intentionally included in advertising or usage-analytics events. Available advertising privacy choices can be reopened from the app; tracking permission can be changed in iOS Settings.
Membership removes eligible ordinary in-app ads, while low-frequency app-open ads may still be shown to members as disclosed on the purchase screen. Purchasing membership does not revoke choices already given to third-party services.
Provider information: Google Privacy Policy, Google Mobile Ads iOS data disclosures, Firebase privacy information, and Apple Privacy Policy.
Purchases
iOS purchases and subscriptions use Apple's StoreKit and App Store. Apple processes payment details; HTTP Sniffer receives transaction identifiers, product and entitlement information needed to unlock or restore features. We do not receive your full payment-card details. Manage subscriptions in your Apple account and use Restore Purchases in the app when needed.
Retention, choices and contact
You can delete captures and cached files in the app, stop capture, manage VPN and certificate settings, change advertising choices, and remove the app. Local data is retained until deleted, subject to system storage and backup behavior. Files you exported and system or cloud backups may remain until you remove them separately. Third-party advertising, analytics and purchase data is retained under the relevant provider's policies and legal obligations; processing may occur outside your country.
This developer tool is not directed to children under 13. For privacy questions, access or deletion requests concerning information we hold, or concerns about a child's information, contact zhuxiaoit3@gmail.com. Depending on your jurisdiction, you may have rights to access, correct, delete or restrict processing, withdraw consent, or contact your local data protection authority. We publish material policy updates at this same address.
Opening these hosted documents contacts GitHub Pages and may disclose normal web-request information such as IP address and browser details to that hosting provider. See the GitHub Privacy Statement.
Android-specific policy
The following existing disclosures, last updated May 17, 2026, concern the Android distribution. References to installed applications, Google Play, Android permissions and Android-specific controls do not apply to iOS or iPadOS.
Introduction
HTTP Sniffer ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application HTTP Sniffer (the "App"). This App is designed as a learning and testing tool for software developers and testers to analyze and debug network API interfaces, app testing, and bug analysis.
By using our App, you agree to the collection and use of information in accordance with this Privacy Policy.
Information We Collect
⚠️ CRITICAL DISCLOSURE - INSTALLED APPLICATIONS INFORMATION
THIS APP COLLECTS AND ACCESSES YOUR DEVICE'S INSTALLED APPLICATIONS LIST
This is a core and essential functionality of HTTP Sniffer as a network debugging tool. Here's exactly what we collect and why:
What Installed Application Information We Collect:
Complete list of all installed applications on your device, including:
- Application names (e.g., "Chrome", "Facebook", "WhatsApp")
- Package names (e.g., "com.android.chrome", "com.facebook.katana")
- Application icons and logos
- Application version information
- Installation status and metadata
Why We Need This Information:
- Core Functionality: As an HTTP/HTTPS network traffic analyzer and debugger, you must be able to select which specific applications you want to monitor
- User Interface: Display a list of your installed apps so you can choose which ones to debug
- Network Monitoring: Enable targeted network traffic capture for selected applications
- Developer Tool: Allow developers and testers to analyze network behavior of specific apps
How This Information Is Used:
- Local Processing (by HTTP Sniffer): The installed applications list is processed and displayed locally on your device for app selection
- User Selection: Enables you to select target applications for network monitoring
- Third-Party SDK Transmission: Integrated third-party SDKs (Google AdMob, Firebase Analytics) collect and transmit your installed application list to Google's servers for advertising, analytics, and fraud prevention purposes
- Background Collection: Third-party SDKs may collect this data even when the app is not actively in use
Third-Party SDK Access to Installed Applications:
IMPORTANT: The following third-party SDKs integrated in our app collect and transmit your installed applications information to their servers:
- Google AdMob SDK (Ad-supported version only):
- Collects installed applications list for ad targeting and personalization
- Used for fraud detection and prevention
- Subject to Google's Privacy Policy
- Firebase Analytics SDK:
- May collect installed applications list for analytics purposes
- Used for fraud detection and app quality monitoring
- Subject to Google's Privacy Policy
- Google Play Services:
- May access installed applications for various Google services
- Subject to Google's Privacy Policy
You cannot opt-out of the installed applications access as it is essential for the core functionality of this HTTP debugging tool. If you do not agree to this data collection, please do not install or use this app.
1. Information Collected Automatically
Device and System Information
- Device model, operating system version, and hardware specifications
- Memory usage, CPU instruction set type
- Screen resolution and display density
- Network connection type (WiFi/mobile data)
- App version and build information
- System language and locale settings
Application Usage Data
- App launch events and session duration
- Feature usage statistics (VIP purchases, tool usage)
- User interactions within the app
- Crash reports and error logs for debugging purposes
2. Network Traffic Data (Core Functionality)
As an HTTP debugging tool, our App collects and processes:
HTTP/HTTPS Request and Response Data
- Request and response headers
- Request and response body content
- URL paths and query parameters
- HTTP methods and status codes
- Timestamps of network requests
Important: This network traffic data is stored locally on your device only and is never uploaded to our servers or shared with third parties.
3. Third-Party Services Data Collection
Google AdMob (Ad-supported version only)
When using the ad-supported version of our App, Google AdMob may collect:
- Installed applications list - Used for ad targeting, personalization, and fraud prevention
- Advertising ID (GAID)
- Device identifiers
- IP address (for approximate location)
- Ad interaction data (views, clicks, completions)
- App usage patterns for ad personalization
Note: The installed applications list collected by AdMob is used to:
- Deliver personalized advertisements based on your app usage patterns
- Detect and prevent advertising fraud
- Improve ad relevance and performance
- This data is subject to Google's Privacy Policy and data handling practices
Firebase Analytics and Crashlytics
We use Firebase services to improve app quality:
- Installed applications list - May be collected for analytics, fraud detection, and app quality monitoring
- App performance metrics
- Crash reports and diagnostic information
- User engagement analytics
- Custom events for feature usage tracking
Note: Firebase may use installed applications data to:
- Detect fraudulent activity and abuse
- Improve analytics accuracy
- Monitor app quality and performance
- This data is subject to Google's Privacy Policy
Google Play Billing
For in-app purchases:
- Purchase transaction data
- Billing information (processed by Google Play)
- Subscription status and history
How We Use Your Information
Core App Functionality
- Network Debugging: Process HTTP/HTTPS traffic for analysis and debugging
- App Selection: Display installed applications for monitoring selection - THIS REQUIRES ACCESS TO YOUR COMPLETE INSTALLED APPLICATIONS LIST
- Data Storage: Store captured network data locally for your analysis
- Target Monitoring: Enable you to select specific apps for network traffic analysis
Installed Applications List Usage
We use your installed applications list for:
- Essential Functionality: Display all your installed apps so you can select which ones to monitor
- User Interface: Show app names and icons in the selection interface
- Network Filtering: Enable targeted network traffic capture for selected applications
- Local Processing: All processing happens on your device; data is not uploaded
Third-party SDKs use installed applications list for:
- Google AdMob (Ad version only):
- Ad targeting and personalization based on your app usage patterns
- Fraud detection and prevention
- Ad performance optimization
- Firebase Analytics:
- Usage analytics and fraud detection
- App quality monitoring
- Performance analysis
App Improvement
- Performance Monitoring: Identify and fix crashes and performance issues
- Feature Analytics: Understand which features are most valuable to users
- Quality Assurance: Improve app stability and user experience
Advertising (Ad-supported version only)
- Personalized Ads: Display relevant advertisements based on your interests and installed apps
- Ad Performance: Measure ad effectiveness and optimize ad delivery
- Revenue Generation: Support free app distribution through advertising
Data Storage and Security
Local Storage
- All network traffic data is stored locally on your device
- Data is stored in the app's private directory, accessible only by the app
- You can clear this data at any time through the app's cache management features
Data Transmission
- Network traffic data is never transmitted to external servers
- Analytics and crash data is transmitted securely using HTTPS encryption
- Ad-related data is handled by Google's secure infrastructure
Data Retention
- Local network data: Retained until manually deleted by user
- Analytics data: Retained according to Firebase's data retention policies
- Ad data: Retained according to Google AdMob's policies
Data Sharing and Disclosure
We Do Not Share
- Your captured network traffic data
- Personal identification information
- Sensitive authentication data (passwords, tokens, cookies)
- Private communications or personal files
Third-Party Sharing
We may share limited, non-personal data with:
Google Services
- Firebase Analytics: Anonymized usage statistics for app improvement
- AdMob: Device and usage data for ad personalization (ad version only)
- Play Billing: Purchase data for transaction processing
Legal Requirements
We may disclose information if required by law or to:
- Comply with legal processes
- Protect our rights and property
- Ensure user safety
- Investigate potential violations of our terms
Your Privacy Rights and Choices
Data Control
- Clear Local Data: Delete all captured network traffic through app settings
- Manage Cache: Control storage of temporary files and attachments
- Export Data: Share or backup your captured data as needed
Advertising Controls (Ad-supported version)
- Reset Advertising ID: Reset your device's advertising identifier in system settings
- Opt-out of Personalized Ads: Disable ad personalization in Google settings
- Upgrade to VIP: Remove ads entirely by purchasing VIP membership
Analytics Controls
- Crash Reporting: Cannot be disabled as it's essential for app stability
- Usage Analytics: Anonymized and cannot be individually controlled
Children's Privacy
Our App is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us so we can delete such information.
International Data Transfers
Your information may be transferred to and processed in countries other than your own, including the United States, where Google's servers are located. These countries may have different data protection laws than your country of residence.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new Privacy Policy in the app
- Updating the "Last Updated" date at the top of this policy
- Providing in-app notifications for significant changes
Your continued use of the App after any modifications indicates your acceptance of the updated Privacy Policy.
Prohibited Uses and Disclaimer
Prohibited Actions
You are strictly prohibited from:
- Using this app for any illegal activities such as malicious attacks on network data, creating plugins, or stealing data
- Debugging and modifying network data of other hosts, IPs, and apps without official authorization
- Reverse engineering this app (including decompiling, modifying installation packages, or signature information)
- Distributing unauthorized versions of this app
Disclaimer
We are not liable for any damages resulting from:
- Violations of this agreement or related service terms
- Third-party damages caused by your violations
- Service interruptions due to force majeure events
- System interruptions due to technical issues or government orders
Risk Acknowledgment
You acknowledge that:
- Cache generated during app operation may contain sensitive information (passwords, cookies, etc.)
- You should clean up data regularly or close the app during sensitive operations
- You must comply with local laws regarding network analysis tools
Contact Us
Consent
By using our App, you consent to our Privacy Policy and agree to its terms and conditions. If you do not agree with this policy, please do not use our App.
Note: This Privacy Policy is designed to be transparent about our data practices while ensuring compliance with privacy regulations including GDPR, CCPA, and Google Play policies. We are committed to protecting your privacy while providing valuable network debugging tools for developers and testers.