Hidden Apps Privacy Policy / 숨겨진 앱 찾기 개인정보처리방침

Hidden Apps Privacy Policy / 숨겨진 앱 찾기 개인정보처리방침

Last updated / 최종 업데이트: September 4, 2026 / 2026년 9월 4일

Provider / 제공자: Coolpisoo
Contact / 문의: coolpisoo@gmail.com


English

1. Overview

Hidden Apps (soo.project.findhidden) helps you review installed apps, launcher visibility, permissions, installation sources, recent changes, and other caution signals. The app is a review tool. It does not guarantee that a device or app is safe and does not replace Android or Google Play Protect.

This policy explains which information the app uses, what stays on your device, when Google and Cloudflare process limited information, and how you can control or delete app data.

2. Installed-app information processed on your device

When you agree to the in-app notice and start a scan, Hidden Apps accesses the list of installed apps and related metadata needed for its core security-review feature. This can include:

  • app label and package name;
  • app version, first-install time, last-update time, and installation source;
  • requested and currently granted permissions;
  • launcher, enabled, disabled, and archived state that Android makes available;
  • active special access, such as Accessibility, device administrator, and display-over-other-apps;
  • signing-certificate information; and
  • for selected apps only, the SHA-256 hash calculated locally from the installed APK.

The app also asks Google Play services whether Verify Apps is enabled and for the harmful-app list that Play Protect makes available to the app.

The installed-app list, APK files, APK hashes, scan findings, messages, photos, contacts, and other personal content are not uploaded to a Coolpisoo server. Hidden Apps does not read messages, photos, or contacts for the scan. The broad installed-app visibility permission is used only for the user-initiated security-review feature. Developer-app promotions do not check which apps are installed; their buttons open fixed product pages in the app store for that distribution build.

3. Information stored locally

The following information can be stored on your device:

  • your consent and app settings;
  • the last completed scan baseline;
  • the local change history;
  • identifiers for apps you chose to ignore;
  • rescan-reminder state; and
  • local ad-frequency and house-ad rotation state.

The app automatically limits change history to the most recent 90 days and 500 events. A record for an app that is no longer installed is removed from the comparison baseline after 30 days. An ignored app is automatically removed from the ignored list if the app is removed, reinstalled, updated, or its reviewed security identity changes.

Scan baselines, change history, ignored-app identities, monitoring state, local ad-frequency state, house-ad rotation state, and downloaded threat lists are excluded from Android cloud backup and device-to-device transfer by the app's backup rules. Remaining local records stay until an automatic limit applies or you delete them in the app, clear the app's storage, or uninstall the app. Withdrawing consent stops scans and rescan reminders. The app also provides a separate control for deleting locally stored scan data.

4. Signed threat-list updates, Play Integrity, and Cloudflare

After you accept the in-app notice, Hidden Apps may automatically request a signed threat-list update when the feature is configured and a network is available. The app checks after consent and then approximately every three days. Each downloaded response is limited to 1 MB. If the update is unavailable or invalid, the app uses its bundled local list.

To protect this update endpoint, Google Play Integrity creates a one-time token. Google may process the app package name, app version, app signing certificate, Play recognition and license status, request hash, and device-integrity information. The app requests that app-access-risk information not be included. The token is sent over HTTPS to a Coolpisoo Cloudflare Worker, which asks Google to decode it and checks only the access conditions needed to return the signed list. Installed-app information and scan results are not included in this request.

The Worker application does not store the raw token or verdict. For abuse prevention, it converts the connection IP address in memory to a secret-keyed HMAC rate-limit key and does not store or log the raw IP in application code. The HMAC key is processed by Cloudflare's rate-limiting service. Separately, the Worker's Durable Object stores worldwide aggregate decode-attempt counts in at most 25 hourly buckets. Google and Cloudflare infrastructure may process or retain network and service metadata under their own terms and privacy policies.

5. Advertising and consent

The app contains ads. After you accept the app's data notice, it asks Google's User Messaging Platform to determine whether an advertising consent choice is required. The app requests or preloads an ad only when Google reports that ads may be requested. Depending on your region and choices, Google Mobile Ads and the User Messaging Platform may automatically collect or share information such as IP address, app interactions, diagnostic information, advertising identifiers, and other device/account identifiers for advertising, fraud prevention, security, and measurement.

Installed-app information, APK hashes, and scan results are not provided to the advertising SDKs. An eligible completed scan may show one full-screen paid ad or clearly labeled promotion, limited by the app to at most once in a rolling 24-hour period. You can reopen Google's available advertising privacy choices from the app.

6. Optional web search

If you choose the web-search action on an app detail screen, Hidden Apps places that app's package name in a Google search URL and opens your browser. The package name is then processed by your browser and search provider under their policies. No web search occurs automatically.

7. Notifications

Rescan notifications are off by default. If you opt in and grant Android's notification permission, the app schedules a reminder starting seven days after the last completed scan and repeats it every seven days until another scan is completed. You can turn these reminders off in the app or in Android notification settings. Notification scheduling data stays on the device.

8. Security and sharing

Network requests made by the app use HTTPS. Downloaded threat lists are accepted only after signature, hash, size, version, and validity checks. Coolpisoo does not sell installed-app information or scan results and does not share them with advertising providers.

No method of storage or transmission is completely secure. Keep Android and Google Play services up to date and review important findings using trusted system or store information.

9. Your choices and deletion

You can:

  • decline the initial notice and exit without running a scan;
  • withdraw consent to stop scans and reminders;
  • turn rescan reminders off separately;
  • delete the local baseline, change history, and ignored-app data;
  • change available Google advertising privacy choices; and
  • clear app storage or uninstall the app to remove the app's local copy of its data.

For questions or a deletion issue that cannot be resolved with the in-app controls, contact coolpisoo@gmail.com. Coolpisoo does not hold a server-side copy of installed-app scan data to identify or delete.

10. Third-party policies

11. Changes to this policy

This policy may be updated when the app, providers, or legal requirements change. The updated date at the top identifies the current version. If a change materially affects installed-app processing, the app will require a renewed in-app notice when appropriate.


한국어

1. 개요

숨겨진 앱 찾기(soo.project.findhidden)는 기기에 설치된 앱의 표시 여부, 권한, 설치 출처, 최근 변화와 주의 신호를 사용자가 검토하도록 돕는 앱입니다. 기기나 앱의 안전을 보장하지 않으며 Android 또는 Google Play 프로텍트를 대신하지 않습니다.

이 방침은 앱이 어떤 정보를 사용하는지, 어떤 정보가 기기에만 저장되는지, Google과 Cloudflare가 제한적으로 정보를 처리하는 경우와 사용자가 데이터를 제어·삭제하는 방법을 설명합니다.

2. 기기에서 처리하는 설치 앱 정보

사용자가 앱 안의 안내에 동의하고 검사를 시작하면 핵심 보안 검토 기능을 위해 설치된 전체 앱 목록과 다음 관련 정보를 확인할 수 있습니다.

  • 앱 이름과 패키지명
  • 앱 버전, 최초 설치 시점, 마지막 업데이트 시점과 설치 출처
  • 앱이 요청한 권한과 현재 허용된 권한
  • Android가 제공하는 런처 표시, 사용·사용 중지 및 보관 상태
  • 접근성, 기기 관리자, 다른 앱 위에 표시 등 현재 허용된 특별 접근
  • 앱 서명 인증서 정보
  • 선별된 앱에 한해 설치 APK에서 기기 안에서 계산한 SHA-256 해시

또한 Google Play 서비스에 앱 검사 기능 사용 여부와 Play 프로텍트가 앱에 제공하는 유해 앱 목록을 요청합니다.

설치 앱 목록, APK 파일, APK 해시, 검사 결과, 메시지, 사진, 연락처와 그 밖의 개인 콘텐츠는 Coolpisoo 서버로 전송하지 않습니다. 검사 과정에서 메시지, 사진 또는 연락처를 읽지 않습니다. 전체 앱 목록 접근 권한은 사용자가 직접 실행하는 보안 검토 기능에만 사용합니다. 개발자의 다른 앱을 홍보할 때는 설치 여부를 조회하지 않고 버튼을 누르면 해당 배포 버전의 앱 마켓에 있는 정해진 상품 페이지를 엽니다.

3. 기기에 저장하는 정보

다음 정보는 사용자 기기에 저장될 수 있습니다.

  • 동의 및 앱 설정
  • 마지막 완료 검사의 비교 기준
  • 기기 내 변화 기록
  • 사용자가 무시하기로 한 앱의 식별 정보
  • 재검사 알림 상태
  • 광고 노출 횟수 제한과 자체 광고 순서 상태

변화 기록은 최근 90일, 최대 500건으로 자동 제한됩니다. 제거된 앱의 비교 기록은 30일 뒤 비교 기준에서 삭제됩니다. 무시한 앱이 제거·재설치·업데이트되거나 검토한 보안 식별 정보가 달라지면 해당 앱은 무시 목록에서 자동으로 빠집니다.

검사 비교 기준, 변화 기록, 무시한 앱 정보, 관련 알림 상태, 광고 노출 횟수 제한, 자체 광고 순서 및 내려받은 탐지 목록은 앱의 백업 규칙에 따라 Android 클라우드 백업과 기기 간 전송에서 제외됩니다. 남은 기기 내 기록은 자동 보존 한도가 적용되거나 앱 안에서 삭제하거나, 앱 저장공간을 삭제하거나, 앱을 제거할 때까지 보관됩니다. 동의를 철회하면 검사와 재검사 알림이 중지됩니다. 저장된 검사 데이터만 별도로 삭제할 수도 있습니다.

4. 서명된 탐지 목록, Play Integrity 및 Cloudflare

사용자가 앱 안의 안내에 동의한 뒤 기능이 설정되어 있고 네트워크를 사용할 수 있으면 서명된 탐지 목록을 자동으로 확인할 수 있습니다. 동의 후 확인하고 이후 약 3일마다 갱신합니다. 한 번에 받는 응답은 최대 1MB로 제한합니다. 갱신할 수 없거나 파일이 올바르지 않으면 앱에 포함된 기기 내 목록을 사용합니다.

이 갱신 주소를 보호하기 위해 Google Play Integrity가 일회성 토큰을 만듭니다. Google은 이 앱의 패키지명·버전·서명 인증서, Play 인식 및 라이선스 상태, 요청 해시와 기기 무결성 정보를 처리할 수 있습니다. 앱은 앱 접근 위험 정보가 포함되지 않도록 요청합니다. 토큰은 HTTPS로 Coolpisoo의 Cloudflare Worker에 전달되고, Worker는 Google에 토큰 해석을 요청한 뒤 서명된 목록을 받을 수 있는 조건만 확인합니다. 설치 앱 정보와 검사 결과는 이 요청에 포함되지 않습니다.

Worker 앱 코드는 원본 토큰과 판정값을 저장하지 않습니다. 남용 방지를 위해 접속 IP를 메모리에서 비밀키 기반 HMAC 제한 키로 바꾸며 원본 IP는 앱 코드에서 저장하거나 기록하지 않습니다. HMAC 키는 Cloudflare의 요청 제한 서비스에서 처리됩니다. 이와 별도로 Worker의 Durable Object는 전 세계 전체 해석 시도 횟수를 최대 25개의 시간대별 묶음으로 저장합니다. Google과 Cloudflare 인프라는 각 회사의 약관 및 개인정보처리방침에 따라 네트워크·서비스 정보를 처리하거나 보관할 수 있습니다.

5. 광고와 동의

이 앱에는 광고가 포함됩니다. 앱의 데이터 안내에 동의한 뒤 Google User Messaging Platform을 통해 광고 동의 선택이 필요한지 확인합니다. Google이 광고 요청을 허용하는 경우에만 광고를 요청하거나 미리 불러옵니다. 지역과 사용자의 선택에 따라 Google Mobile Ads와 User Messaging Platform은 광고, 부정 사용 방지, 보안 및 측정을 위해 IP 주소, 앱 이용 동작, 진단 정보, 광고 식별자와 그 밖의 기기·계정 식별자를 자동으로 수집하거나 공유할 수 있습니다.

설치 앱 정보, APK 해시와 검사 결과는 광고 SDK에 제공하지 않습니다. 조건을 충족한 검사가 끝난 뒤 전체 화면 유료 광고 또는 광고라고 명확히 표시한 자체 홍보가 나올 수 있으며, 앱은 이를 최근 24시간 동안 최대 한 번으로 제한합니다. 앱에서 Google이 제공하는 광고 개인정보 선택 화면을 다시 열 수 있습니다.

6. 사용자가 선택하는 웹 검색

앱 상세 화면에서 웹 검색을 선택하면 해당 앱의 패키지명을 Google 검색 주소에 넣어 브라우저를 엽니다. 이후 패키지명은 브라우저와 검색 서비스의 방침에 따라 처리됩니다. 웹 검색은 자동으로 실행되지 않습니다.

7. 알림

재검사 알림은 기본적으로 꺼져 있습니다. 사용자가 알림 받기를 선택하고 Android 알림 권한을 허용하면 마지막 완료 검사 7일 후부터 알림을 예약하고, 다시 검사할 때까지 7일마다 알립니다. 앱 안 또는 Android 알림 설정에서 끌 수 있습니다. 알림 예약 정보는 기기에만 저장됩니다.

8. 보안과 공유

앱의 네트워크 요청은 HTTPS를 사용합니다. 내려받은 탐지 목록은 서명, 해시, 크기, 버전 및 유효기간 검증을 모두 통과해야 사용합니다. Coolpisoo는 설치 앱 정보나 검사 결과를 판매하지 않으며 광고 제공자에게 공유하지 않습니다.

어떤 저장 또는 전송 방식도 완전한 보안을 보장할 수 없습니다. Android와 Google Play 서비스를 최신 상태로 유지하고 중요한 결과는 신뢰할 수 있는 시스템·스토어 정보로 다시 확인하세요.

9. 사용자의 선택과 삭제

사용자는 다음을 할 수 있습니다.

  • 최초 안내에 동의하지 않고 검사를 실행하지 않은 채 종료
  • 동의를 철회하여 검사와 재검사 알림 중지
  • 재검사 알림만 별도로 끄기
  • 기기 내 비교 기준, 변화 기록과 무시한 앱 정보 삭제
  • 제공되는 Google 광고 개인정보 선택 변경
  • 앱 저장공간 삭제 또는 앱 제거로 앱이 보관한 기기 내 데이터 사본 삭제

앱 안의 기능으로 해결되지 않는 삭제 문제나 문의 사항은 coolpisoo@gmail.com으로 연락해 주세요. Coolpisoo는 사용자를 식별하여 삭제할 수 있는 설치 앱 검사 데이터 사본을 서버에 보관하지 않습니다.

10. 제3자 방침

11. 방침 변경

앱 기능, 제공자 또는 법적 요구사항이 달라지면 이 방침을 변경할 수 있습니다. 맨 위의 최종 업데이트 날짜로 현재 버전을 확인할 수 있습니다. 설치 앱 처리에 중요한 변화가 있으면 필요한 경우 앱 안에서 새 안내에 다시 동의하도록 요청합니다.