# Vendor companion app privacy dataset

Transparent dataset of the vendor bluetooth/wifi pairing apps installed on one Android
device, cross-referenced with the Google Play Store (`en_US`, 2026-10-01).

## Pipeline
1. `apps.txt` — final list of 142 gadget-pairing packages (curated from a 489-package
   device dump: 327 Android system/GMS components filtered, 18 reviewed out — see Exclusions).
2. `node build.mjs` — scrapes Play Store app details, Data-safety labels, permissions, icon and
   privacy-policy snapshot per package (idempotent: raw responses cached in `raw/`), then emits
   `apps.json`, `index.html`, and this README. Slug usage is verified by round-tripping every
   declaration against the raw responses (build fails on any mismatch).

## Files
| file | contents |
|---|---|
| `apps.txt` | final package list (one per line) |
| `apps.json` | the dataset |
| `index.html` | self-contained viewer: app card grid (severity-ranked, unauditable apps hidden behind a toggle), click a card for a full dossier with quotes and Play declarations |
| `icons/` | app icons (512px) |
| `privacy_policies/` | point-in-time policy snapshots |
| `raw/` | unmodified Play API responses + fetch metadata (provenance; also the scrape cache) |
| `build.mjs` | the whole pipeline |

## apps.json format
Header: `schema_version` (2), `generated`, `scrape_locale`, `app_count`. Each app:

| field | meaning |
|---|---|
| `package` | Android package name |
| `name` | Play Store title |
| `category` | Play genre |
| `icon` | local icon copy |
| `url` | Play Store page |
| `installs` | numeric lower-bound installs |
| `privacy_policy_url` | developer-declared policy URL |
| `privacy_policy_archive` | local snapshot (`privacy_policies/`), null = fetch blocked/failed |
| `privacy.declarations` | Data-safety items: `{data, optional, purposes, shared}` — slugs |
| `privacy.practices` | security-practice slugs |
| `privacy` | null if the Play page has no data-safety section |
| `privacy_notes` | policy-review warnings: `{tag, quote, comment?}` — quote is verbatim from the policy |
| `privacy_notes` decode | tags listed under "Policy-review note tags" below |

Slugs decode via the legend below (also embedded in `index.html`).

## index.html severity scoring
Apps are ranked by a weighted count of policy-review notes:
- **×3** — `data_sale`
- **×2** — `sensitive_data`, `location_tracking`, `contacts_upload`, `ads_tracking`, `third_party_share`, `cross_device_profiling`, `no_deletion`, `children_data`
- **×1** — all remaining tags (including `policy_unreadable` / `policy_unavailable`, a transparency penalty)

Grades: Critical ≥15 · Bad 10–14 · Poor 6–9 · Mediocre 3–5 · Caution 1–2 · Clean 0.
Apps whose only findings are unreadable/unavailable policies are marked **Unauditable** instead of Clean.

## Legend — data tags
| tag | Play label | category |
|---|---|---|
| `device_id` | Device or other IDs | Device or other IDs |
| `email` | Email address | Personal info |
| `app_interactions` | App interactions | App activity |
| `crash_logs` | Crash logs | App info and performance |
| `name` | Name | Personal info |
| `user_ids` | User IDs | Personal info |
| `diagnostics` | Diagnostics | App info and performance |
| `precise_location` | Precise location | Location |
| `approximate_location` | Approximate location | Location |
| `photos` | Photos | Photos and videos |
| `other_app_performance` | Other app performance data | App info and performance |
| `phone_number` | Phone number | Personal info |
| `other_info` | Other info | Personal info |
| `fitness_info` | Fitness info | Health and fitness |
| `address` | Address | Personal info |
| `videos` | Videos | Photos and videos |
| `other_actions` | Other actions | App activity |
| `inapp_search_history` | In-app search history | App activity |
| `other_user_content` | Other user-generated content | App activity |
| `purchase_history` | Purchase history | Financial info |
| `health_info` | Health info | Health and fitness |
| `payment_info` | User payment info | Financial info |
| `voice_recordings` | Voice or sound recordings | Audio |
| `contacts` | Contacts | Contacts |
| `emails` | Emails | Messages |
| `installed_apps` | Installed apps | App activity |
| `other_messages` | Other in-app messages | Messages |
| `files_docs` | Files and docs | Files and docs |
| `calendar_events` | Calendar events | Calendar |
| `music_files` | Music files | Audio |
| `other_audio` | Other audio files | Audio |
| `web_browsing` | Web browsing history | Web browsing |
| `sexual_orientation` | Sexual orientation | Personal info |
| `sms_mms` | SMS or MMS | Messages |
| `credit_score` | Credit score | Financial info |
| `political_religious_beliefs` | Political or religious beliefs | Personal info |
| `other_financial` | Other financial info | Financial info |

## Legend — purposes
- `functionality` — App functionality
- `analytics` — Analytics
- `account_mgmt` — Account management
- `personalization` — Personalization
- `ads_marketing` — Advertising or marketing
- `dev_communications` — Developer communications
- `fraud_security_compliance` — Fraud prevention, security, and compliance

## Legend — security practices
- `encrypted_transit` — Data is encrypted in transit: Your data is transferred over a secure connection
- `deletion_request` — You can request that data be deleted: The developer provides a way for you to request that your data be deleted
- `no_deletion` — Data can’t be deleted: The developer doesn’t provide a way for you to request that your data be deleted
- `families_policy` — Committed to follow the Play Families Policy: The developer has committed to follow the Play Families Policy for this app. <a href="https://support.google.com/googleplay/android-developer/answer/9893335" target="_blank">See the policy</a>
- `not_encrypted` — Data isn’t encrypted: Your data isn’t transferred over a secure connection

## Quick stats
- 107/142 apps (75%) declare collecting at least one data type
- 49/142 (35%) declare sharing data with third parties
- 127 declare security practices; 1 policy archives unavailable

Most-declared collected data:
- `email` (Email address): 74
- `device_id` (Device or other IDs): 72
- `name` (Name): 68
- `crash_logs` (Crash logs): 68
- `app_interactions` (App interactions): 66
- `user_ids` (User IDs): 57
- `diagnostics` (Diagnostics): 48
- `precise_location` (Precise location): 44
- `photos` (Photos): 42
- `approximate_location` (Approximate location): 42
- `phone_number` (Phone number): 39
- `other_app_performance` (Other app performance data): 32
- `other_info` (Other info): 29
- `address` (Address): 24
- `videos` (Videos): 21
- `fitness_info` (Fitness info): 20
- `other_actions` (Other actions): 17
- `purchase_history` (Purchase history): 16
- `other_user_content` (Other user-generated content): 15
- `inapp_search_history` (In-app search history): 14
- `payment_info` (User payment info): 12
- `contacts` (Contacts): 12
- `voice_recordings` (Voice or sound recordings): 11
- `emails` (Emails): 10
- `health_info` (Health info): 10
- `installed_apps` (Installed apps): 9
- `other_messages` (Other in-app messages): 8
- `files_docs` (Files and docs): 7
- `calendar_events` (Calendar events): 7
- `music_files` (Music files): 5
- `other_audio` (Other audio files): 4
- `web_browsing` (Web browsing history): 3
- `sexual_orientation` (Sexual orientation): 3
- `sms_mms` (SMS or MMS): 2
- `credit_score` (Credit score): 2
- `political_religious_beliefs` (Political or religious beliefs): 1
- `other_financial` (Other financial info): 1

## Policy-review notes
Privacy policies were reviewed (LLM-assisted, human-curated) for warning-worthy clauses.
Every note carries a **verbatim quote** from the policy text — auditable against
`raw/policy_text/<pkg>.txt`. Tags:

| tag | meaning |
|---|---|
| `data_sale` | data sale |
| `ads_tracking` | ads/tracking |
| `third_party_share` | third-party share |
| `location_tracking` | location tracking |
| `contacts_upload` | contacts upload |
| `sensitive_data` | sensitive data |
| `cross_device_profiling` | cross-device profiling |
| `no_deletion` | no deletion |
| `indefinite_retention` | indefinite retention |
| `law_enforcement` | law enforcement |
| `international_transfer` | international transfer |
| `auto_consent` | auto consent |
| `children_data` | children data |
| `liability_shift` | liability shift |
| `arbitration` | arbitration |
| `vague_policy` | vague policy |
| `account_required` | account required |
| `policy_unreadable` | policy unreadable |
| `policy_unavailable` | policy unavailable |
| `other` | other |

Notes for apps without archived policies (bot-blocked fetches) are marked `policy_unavailable`.

## Exclusions (21)
| package | reason |
|---|---|
| `scadica.aq` | review drop — app search utility, no gadget pairing |
| `com.rupiapps.cameraconnectcast` | review drop — third-party (not vendor) camera companion |
| `org.staacks.alpharemote` | review drop — third-party (not vendor) camera companion |
| `com.emanuelef.remote_capture` | review drop — network capture tool (PCAPdroid) |
| `com.pcapdroid.mitm` | review drop — network capture tool (PCAPdroid MITM plugin) |
| `com.machiav3lli.fdroid` | review drop — F-Droid store client |
| `com.fujixweekly.FujiXWeekly` | review drop — film recipe browser |
| `com.heb12.heb12` | review drop — bible reader |
| `dev.imranr.obtainium` | review drop — APK installer |
| `dev.petabyt.camcontrol` | review drop — FOSS camera file manager |
| `app.alextran.immich` | review drop — photo backup app |
| `no.nordicsemi.android.mcp` | review drop — BLE scanning tool (nRF Connect) |
| `com.mixplorer.silver` | review drop — file manager |
| `dev.zwander.installwithoptions` | review drop — APK installer |
| `org.kde.kdeconnect_tp` | review drop — desktop integration |
| `com.topjohnwu.magisk` | review drop — root manager |
| `com.termux` | no gadget pairing — terminal emulator |
| `com.nothing.cmf.watch` | not listed on Play Store |
| `com.google.android.glasses.core` | not listed on Play Store |
| `com.icatch.activeon.app` | not listed on Play Store |
| `fi.eye.android` | not listed on Play Store |

## Caveats
- Policy-review notes were extracted by **LLM reviewers, not lawyers** — take them with a grain of salt; every note carries a verbatim quote so claims can be checked against the source text.
- All privacy policies were collected and interpreted **from a US standpoint** (Play listings `en_US`, US-served policy pages, US-framed reviewer interpretation); terms shown may differ for users in other regions.
- Data-safety labels are **developer self-declarations**, not audits — they state what vendors
  *declare*, not verified ground truth.
- Policy snapshots are point-in-time (2026-10-01); 1 fetches failed (bot-blocked 403s,
  dead links, connection failures) — the declared URL is still recorded.
- Installs are Play-reported lower bounds.
