Privacy Policy
Last updated: October 8, 2026
Data Controller
TrueTo ("TrueTo", "we", "our", "the app") is provided by an independent developer. For the purposes of applicable data protection laws, including the General Data Protection Regulation (GDPR), we act as the data controller for the limited data described in this policy.
Contact: privacy@trueto.app
Overview
TrueTo is an Android app that navigates into other apps to check and change their settings such as read receipts, autoplay, ad personalization, location, and notifications. Users tap a specific action card, and TrueTo navigates to the relevant setting and checks or changes it on their behalf.
This policy explains how we handle information when you use our app. We have written it to be specific and accurate rather than reassuring — if the app collects something, this policy says so.
TrueTo is anonymous by default. Everything in the free tier works without an account. Premium adds an optional account so your subscription and your scan results follow you across devices — the free tier stays anonymous. Creating an account is the one clearly-labeled exception to the no-data posture, and the section If you create an account (optional) below describes exactly what it stores.
Information We Collect
The free tier has no user accounts and does not ask for or collect your name, email address, phone number, or any other contact or identity information.
For anonymous (free-tier) use, the app collects one identifier: a Firebase Installation ID. If the app crashes, it also sends an automatic crash report (see Crash Reporting below). If you turn on usage analytics, the app additionally collects the anonymous scan events described under Usage Analytics below; analytics are off by default.
What the Firebase Installation ID is
The Firebase Installation ID is a random identifier that is automatically generated for each installation of the app. It is not your name, email, phone number, or Google account, and it is not an advertising identifier. On its own it cannot identify you as a person, and unless you create an account it is not linked to any profile.
Why the app needs it
To work correctly, TrueTo needs an up-to-date set of automation instructions — the steps it follows to find and change a setting inside another app. Those steps can break when a target app updates its screens, and a faulty step can be turned off remotely so it does not misbehave on your device. TrueTo therefore downloads its configuration from Google Firebase (Firebase Remote Config and Firebase Cloud Storage). The Firebase software requires the Firebase Installation ID to request this configuration. The identifier is sent to Google Firebase over an encrypted (HTTPS/TLS) connection.
If you create an account (optional)
Premium adds an optional account so your subscription and your scan results follow you across devices — the free tier stays anonymous. If you choose to create one, the TrueTo authentication service — hosted on Google Cloud in the United States (Identity Platform, Firestore, and Cloud Run in the us-central1 region) — stores the following:
- Email address — the email address of the Google account you sign in with. Sign in with Google is the only way to sign in; TrueTo does not ask for or store a password.
- Name and account ID — the display name on your Google account, and the ID that identifies your TrueTo account and its synced data (your Google account ID and the Firebase user ID linked to it). Google sign-in supplies both.
- Subscription status and tier — whether Premium is active and which tier, so your subscription follows your account rather than a single device.
- Your scan results and decisions, synced across your devices. A scan result stores the state or value of a privacy or accessibility setting — a toggle state, or a bounded setting-option label — not personal content. A decision is your keep-or-ignore choice for a given setting. Both sync across the devices you are signed in on. If you remove a decision on one signed-in device, it is removed from your other signed-in devices the next time they sync (unless one of them holds a newer decision for the same setting), and the account keeps a marker of the removal: which check, and when. Synced scan results are not removed this way; they stay with your account until you delete the account.
Some checks report whether an app is signed in to an account or sync service. When you run one of those checks while signed in to that app, the result can include the account name or email address that app displays — for example, the Mozilla account shown at the top of Firefox's settings. If you're signed in to TrueTo, it's stored with your account and synced to your devices like every other check result, and deleted when you delete your account data. If you're not signed in, it stays on your device.
The account record also holds two timestamps: when the account was created and when it was last seen. Each synced scan result records which check ran, the app it ran in (that app's package name), the result, the value the check compares it against, and the time of the scan — so your account holds a record of which supported apps you have scanned and when, kept until you delete your account. All of this is on top of the anonymous Firebase Installation ID described above (which is present whether or not you have an account). The account does not store an inventory of the apps installed on your phone, any behavioral or usage analytics, or the optional free-text reason you can attach to a decision — that note stays on your device and is never synced.
What TrueTo does NOT collect
Whether or not you create an account, TrueTo does not collect:
- Your phone number, or any contact information beyond the name and email address of the Google account you choose to sign in with and, when you run a check of whether another app is signed in to an account, the account name or email address that app displays (see If you create an account (optional) above)
- Your precise or approximate location
- Your messages, emails, photos, files, contacts, or calendar
- Your browsing history, or an inventory of the apps you have installed — scan results synced to an account, and usage analytics if you opt in, do record which supported apps you scanned
- Behavioral or usage analytics, unless you opt in (see Usage Analytics below) — analytics are off by default and anonymous
- The contents of the screens TrueTo navigates, other than the setting a check reads (which, for a check of whether an app is signed in to an account, can be the account name or email address that app displays) and any debug report you choose to send; or the free-text reason you can attach to a decision (that stays on your device)
- Any advertising identifier
This collection is also disclosed in the Data safety section of TrueTo's Google Play store listing, under "Device or other IDs" (and, for accounts, "Personal info").
Accessibility Service Usage
TrueTo uses Android's Accessibility Service to navigate into apps and change settings on your behalf. Specifically, the service:
- Navigates directly to buried settings screens (reducing multiple taps to one tap)
- Reads UI elements to find the correct settings toggle
- Performs click actions to change settings
The Accessibility Service does not transmit anything off your device. For anonymous use, the data the app sends off-device is the Firebase Installation ID described above, automatic crash reports (see Crash Reporting), and — only if you opt in — anonymous usage analytics (see Usage Analytics), all sent by the Firebase software, not by the Accessibility Service. If you create an account, the app also syncs your account basics, scan results, and decisions to the TrueTo authentication service as described above — including, for a check of whether an app is signed in to an account, the account name or email address that app displays.
Scope Limitation
The Accessibility Service is limited to the apps listed in TrueTo's supported app list — enforced at the OS level by Android's packageNames restriction. TrueTo supports 151 apps, including Spotify, YouTube, Instagram, Chrome, WhatsApp, and Android system settings. The full list of supported apps is visible within the app. The service does not interact with any app outside this list.
What We Do NOT Access
The Accessibility Service:
- Does NOT read your messages, emails, or other personal content, apart from one kind of settings row: when you run a check of whether an app is signed in to an account, it reads the account name or email address that app displays in its own settings (see If you create an account (optional) above)
- Does NOT access passwords, or account information other than the account name or email address described in the item above
- Does NOT monitor your browsing or app usage
- Does NOT perform any actions in the background
- Only activates when you explicitly tap a "Check" or "Fix" action
User Control
You remain in full control:
- The app shows you exactly what it will do before you tap
- Each action requires your explicit tap to execute
- You can revoke the Accessibility Service permission at any time in Android Settings
- No actions run automatically or in the background
- Accounts are optional — you can use TrueTo anonymously, and you can delete your account in-app at any time (see Your Rights)
Debug Reports
If something goes wrong, TrueTo can offer to send a debug report so we can investigate. A debug report is only assembled and sent when you explicitly choose to send one — it never uploads on its own. When a check fails, the app saves a screenshot and the on-screen accessibility layout on your device so a report can be assembled later; these files stay on your device unless you choose to send a report. The report includes a screenshot of the screen where the problem occurred, the on-screen accessibility layout, app logs, and the scan results from that session, so it can contain personal content that happened to be on screen at the time. It is sent directly from the app over an encrypted (HTTPS/TLS) connection to TrueTo's service when you tap Send after reviewing the consent sheet, and stored in Google Cloud Storage (United States), used solely to diagnose and fix the issue you reported. Debug reports are retained for 90 days, then automatically deleted. If you do not send a report, none of this leaves your device.
Crash Reporting
TrueTo uses Google's Firebase Crashlytics to collect automatic crash reports. If the app crashes, a report containing the stack trace, relevant app state, device model, OS version, and app version is sent over an encrypted (HTTPS/TLS) connection to Google's Crashlytics service, where we use it to diagnose and fix the crash. Crash reports also carry an anonymous Crashlytics installation identifier used only to count how many users a crash affects — per Google, it does not uniquely identify you or your device.
Crash reports contain no screen content, no personal content, and no account information, and they are not linked to your account if you have one. You can turn crash reporting off at any time in Settings → Privacy; turning it off stops future crash reports.
Usage Analytics
Usage analytics are opt-in only. The app collects no usage analytics unless you turn them on — either at the one-time ask shown after your first scan, or later in Settings → Privacy. Analytics are off by default, and declining costs you nothing: every feature works exactly the same whether analytics are on or off.
When you turn them on, the app records a small set of events about how a scan ran — never the content of your screens. Specifically:
- When a scan starts and finishes, and how long it took
- Which checks ran, and whether each one passed or failed
- Which supported app was scanned
- When you change your analytics consent
The common thread is that these events describe setting states — whether a check passed or failed, and how a scan ran. They never include the content of the screens TrueTo navigates, your messages, photos, personal data, or anything you type.
Usage analytics are anonymous. They are not linked to any account (including a Premium account) and are tied only to an anonymous app-installation identifier. The data is processed by Google Firebase Analytics, consistent with the other Firebase services described in this policy, and is never sold or shared.
You stay in control. You can switch usage analytics off at any time in Settings → Privacy. Switching them off stops collection and also clears the analytics identifier on your device, along with any buffered analytics data that has not yet been sent.
Subscription Billing
TrueTo offers an optional paid subscription. Payment is processed by Google Play Billing, which is built into the Google Play Store on your device.
What Google Play handles
Google Play handles the entire transaction. It collects and stores your payment information (credit card, billing address, etc.) under its own privacy policy. TrueTo never sees, stores, or transmits your payment details.
What TrueTo sees
When you subscribe, TrueTo reads the following from Google Play Billing on your device:
- Product ID: the subscription you purchased
- Subscription state: active, in free trial, expired, paused, on hold, or canceled
Google Play Billing does not give TrueTo your name, email address, payment method, or billing address. For anonymous use, the app reads subscription state at runtime from Google Play Billing on your device. Google Play also notifies the TrueTo authentication service of subscription events. For a subscription that is not linked to a TrueTo account, that service checks the purchase token with Google Play and keeps a hashed copy of it, with the product ID, the time it was first seen, and any account ID the app attached to the purchase. That record is removed if the subscription is later linked to an account, and otherwise stays. If you have a TrueTo account, TrueTo already holds the name and email address from your Google sign-in, and your subscription status and tier are also stored with your account (on the TrueTo authentication service described above) so that Premium follows you across the devices you sign in on, rather than living on a single device. To link the subscription to your account, that service also receives the Google Play purchase token (from the app, and from Google Play's subscription notifications), checks it with Google Play, and keeps a hashed copy with your account ID. Uninstalling the app removes any local copy from the device; your subscription itself is managed in Google Play (see Terms of Service for cancellation and refund details), and your account-side subscription record is removed when you delete your account. If the subscription still exists in Google Play at that point, a later Google Play notification about it creates the record for an unlinked subscription described above, with your old account ID.
Legal Basis for Processing
For users in the European Economic Area and the United Kingdom, our legal basis under the GDPR for processing the Firebase Installation ID is legitimate interest (Article 6(1)(f)): delivering up-to-date automation configuration, and being able to remotely disable a faulty automation step so the app behaves safely and reliably on your device. The data involved is a single anonymous identifier; we do not build profiles, target advertising, or track behavior.
If you create an account, we process your account data — your email, name, account ID, subscription status and tier, and your synced scan results and decisions — to provide the Premium features you signed up for. Our legal basis is performance of a contract (Article 6(1)(b)): you create the account voluntarily, and we need this data to authenticate you, deliver your subscription across devices, and sync your scan results. You can withdraw at any time by deleting your account.
If you opt in to usage analytics, our legal basis for processing the anonymous scan events is your consent (Article 6(1)(a)). Analytics are off until you turn them on, and you can withdraw your consent at any time in Settings → Privacy, which stops collection and clears the analytics identifier and any buffered data on your device.
Subscription product ID and subscription state read from Google Play Billing on your device are non-personal operational data.
Data Sharing with Third Parties
We do not sell your data, and we do not share it for advertising.
The Firebase Installation ID is processed by Google through Firebase Remote Config and Firebase Cloud Storage. Google acts as our service provider (data processor) for the purpose of delivering app configuration, and processes this data under the Firebase Data Processing and Security Terms and Google's privacy policy.
If you create an account, your account data (email, name, account ID, subscription status and tier, and synced scan results and decisions) is stored and processed on Google Cloud in the United States — using Google Cloud Identity Platform, Firestore, and Cloud Run — which acts as our service provider (data processor) under the same Google data-processing terms linked above. Debug reports you choose to send are sent directly from the app to TrueTo's service on Google Cloud and stored in Google Cloud Storage (United States).
Beyond Google (for Firebase configuration delivery, crash reporting, opt-in usage analytics, account and authentication services, debug-report intake, and Google Play Billing), TrueTo:
- Uses no advertising networks or advertising SDKs
- Runs no behavioral or usage analytics inside the app unless you opt in — analytics are off by default, anonymous, and limited to the scan events listed under Usage Analytics above
- Sends crash and diagnostic data to no one other than Google's Crashlytics service, as automatic crash reports (see Crash Reporting above)
- Uses no social media integrations
- Stores no inventory of your installed apps (each synced scan result does name the app it ran in), and stores on-screen content in the cases described above: a check's result, which can include the account name or email address another app displays, and a debug report you explicitly choose to send
Data Retention
For anonymous use, the Firebase Installation ID exists on your device only while the app is installed; uninstalling the app removes it. The identifier is processed on Google's infrastructure under the Firebase terms linked above. Crash reports, and usage analytics events if you opted in, that the app has already sent are held by Google's Crashlytics and Firebase Analytics services; uninstalling the app does not remove them. To ask about them, see Contact below. TrueTo holds no name, email, or account for anonymous users; the record kept for a subscription not linked to an account is described under Subscription Billing above.
If you create an account, your account data (email, name, account ID, subscription status and tier, and synced scan results and decisions) is retained on the TrueTo authentication service (Google Cloud, United States) until you delete your account. Deleting your account removes that data from the service and across all of your signed-in devices, with the exceptions that follow. Debug reports are retained for 90 days, then automatically deleted. A debug report sent while you were signed in is stored with your account ID, and deleting your account does not remove it sooner. If a subscription bought with the account still exists in Google Play, a later Google Play notification about it leads the service to keep your old account ID with a hashed purchase token, the product ID and the time (see Subscription Billing above); that record stays unless the subscription is later linked to an account. The service's logs also record your account ID with subscription events and errors, and deleting your account does not remove entries already written.
For step-by-step instructions on removing your data, see How to Delete Your Data.
Data Security
TrueTo protects your privacy through technical design:
- Anonymous by default: The free tier needs no account. It collects an anonymous installation identifier, automatic crash reports unless you turn them off, and, if you opt in, usage analytics; accounts are opt-in
- Encrypted in transit: All communication with Google Firebase, Google Cloud, and Google Play services uses encrypted (HTTPS/TLS) connections
- Account data scope: If you create an account, it holds your email, name, account ID, subscription status and tier, and synced scan results and decisions; a scan result names the app it ran in, and the result of a check of whether an app is signed in to an account can include the account name or email address that app displays. It holds no inventory of your installed apps and no usage analytics
- Google sign-in: Authentication uses Sign in with Google; we never store a password
- Limited accessibility scope: The Accessibility Service only interacts with apps listed in TrueTo's supported app list
- User-initiated only: All settings actions require explicit user interaction; nothing runs in the background
Marketing Website Analytics
The TrueTo marketing website (trueto.app) uses Cloudflare Web Analytics to measure aggregate website traffic.
What Cloudflare Web Analytics collects:
- Page URLs visited and referrer sources (including UTM campaign parameters)
- Approximate geographic location (country/region level)
- Browser type and operating system
- Device type (desktop/mobile)
Cloudflare Web Analytics does not use cookies or store personal data. IP addresses are not logged. Data is processed by Cloudflare, Inc. For more details, see Cloudflare's privacy policy.
The Android app does not use this analytics setup. The visitor data described here applies only to the trueto.app website, not to the app on your device.
Website Email Signup
The trueto.app website has an optional email signup form. If you submit it, your browser sends the email address you typed, and on some pages a short label naming the page you signed up on (for example, "home" or "beta"), directly to Kit (formerly ConvertKit), the email service we use to send the emails you signed up for. Nothing is sent to Kit unless you submit the form. Emails sent through Kit carry an unsubscribe link in the footer; use it to stop them. To ask about that address or request its deletion, see Contact below. Signing up does not create a TrueTo account, and the Android app does not use this form.
How to Delete Your Data
For anonymous use, the app collects an anonymous installation identifier, plus the crash reports and opt-in usage analytics described above. The most direct way to delete the identifier is to uninstall the app, which removes the Firebase Installation ID from your device. You can also clear the app's storage. If you have an account, you can delete it in-app, which erases your account data across all of your devices. Full step-by-step instructions, and a description of exactly what is deleted and what is kept, are on the How to Delete Your Data page.
Your Rights Under GDPR
If you are in the European Economic Area or the United Kingdom, you have rights over your personal data, including the rights of access, rectification, erasure, restriction, data portability, and objection.
If you have an account, you can exercise these rights directly. You can delete your account in-app, which erases your email, name, account ID, subscription link and tier, and all synced scan results and decisions across every device you are signed in on, except as described under Data Retention above. You can also use "Download my data" in the app to export your account data. Because account data is linked to the email you provided, we can identify and act on it on request at privacy@trueto.app.
For anonymous (free-tier) use, TrueTo collects an anonymous installation identifier (plus the crash reports and opt-in usage analytics described above) and holds no name, email, or account, so we cannot link that identifier to a specific person or look it up on request. In practice, the most reliable way to exercise your right to erasure is to delete your data by uninstalling the app or clearing its storage (this removes the identifier from your device; crash reports and analytics events already sent are covered under Data Retention above). If you have any question about your rights, contact us at privacy@trueto.app and we will help to the extent the data allows.
Supervisory Authority
If you are located in the European Economic Area and believe we have violated your data protection rights, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU data protection authorities is available at: European Data Protection Board - Members
Children's Privacy
TrueTo is not directed to children. The free tier has no accounts and collects no name, email, contacts, or other information that could identify a user of any age; the installation identifier it collects is anonymous and is not used to profile or track anyone. Optional accounts require an email address and are intended for adults — they are not directed to or intended for children under 13 (COPPA) or under 16 (GDPR).
International Data Transfers
The Firebase Installation ID is processed by Google, which operates data centers in multiple countries. Your data may therefore be processed outside your country of residence. Google applies safeguards for international transfers as described in the Firebase Data Processing and Security Terms and Google's privacy policy. Subscription transactions are handled entirely by Google Play under the same framework.
If you create an account, your account data is stored and processed in the United States on Google Cloud (Identity Platform, Firestore, and Cloud Run in the us-central1 region). If you are located outside the United States and create an account, your account data will be transferred to and processed in the United States; Google applies the international-transfer safeguards described in the Google terms linked above.
Changes to This Policy
We may update this policy from time to time. Updates will be posted at this URL with a new "Last updated" date.
Contact
Questions about this privacy policy? Contact us at privacy@trueto.app