Privacy Policy
Last updated: October 01, 2026
This policy describes what GoMobSec Inc. collects when You use the Service, why We collect it, who else sees it, and what You can ask Us to do about it.
We collect and use Your information as described here, and — where the law requires it — only where We have a valid legal basis for doing so. Because the Service analyses mobile applications, some of what We handle is not simply personal data: it is Your application, its source code and its findings. That material is treated separately below, in Customer Application Data.
Interpretation and definitions
Capitalised words have the meanings given here. They have the same meaning whether they appear in the singular or the plural.
- Account
- A unique account created for You to access the Service or parts of it.
- Company
- GoMobSec Inc., referred to as “the Company”, “We”, “Us” or “Our”.
- Cookies
- Small files placed on Your computer, mobile device or other device by a website, containing details of Your browsing history among their many uses.
- Country
- Pakistan.
- Customer Application Data
- The Android package (APK) or iOS application archive (IPA) You upload, and everything derived from it: decompiled source, manifests, resources, extracted network endpoints, and the artefacts produced while the application is run in Our analysis environment.
- Device
- Any device that can access the Service, such as a computer, a cell phone or a digital tablet.
- Personal Data
- Any information that relates to an identified or identifiable individual. We use “Personal Data” and “Personal Information” interchangeably, unless a law uses a specific term.
- Scan Results
- The findings, severity ratings, compliance mappings, network maps and reports produced by analysing Customer Application Data.
- Service
- The GoMobSec platform: this website, the web application and its scanning API, the analysis performed on submitted applications, and the reports We produce.
- Service Provider
- Any natural or legal person who processes data on behalf of the Company. It refers to third-party companies or individuals engaged by the Company to facilitate the Service, to provide it on the Company’s behalf, to perform services related to it, or to help Us analyse how it is used.
- Usage Data
- Data collected automatically, either generated by use of the Service or from the Service infrastructure itself — for example, the duration of a page visit.
- You
- The individual accessing or using the Service, or the company or other legal entity on whose behalf that individual is acting.
Information We collect
Information You give Us
- Account details — Your name, work email address, company name and role, and a password stored only as a one-way hash.
- Sign-in data — where You use single sign-on, the identifier Your identity provider returns to Us. We do not receive Your password for those providers.
- Billing details — invoice and billing contact information.
- Enquiry and campaign details — the name, work email, company, optional phone number and job title You submit through a form on this site, together with a record of the consent You gave and when.
- Correspondence — the content of support tickets, emails and live chat conversations.
Customer Application Data
This is the part of the Service that is unlike an ordinary website. When You submit an application, We:
- receive the APK or IPA file and compute hashes of it;
- decompile and unpack it, producing source code, manifests and resources from Your application;
- run it in an isolated analysis environment, where We may observe network traffic, filesystem activity, cryptographic behaviour and runtime instrumentation;
- store the resulting Scan Results, which routinely contain excerpts of Your source code, file paths, hard-coded values, internal hostnames and API endpoints discovered during the scan.
You are responsible for having the right to submit what You upload. Only upload applications You own or are authorised to test. If an application contains personal data belonging to other people — end-user records, test accounts, embedded credentials — that data will be processed as part of the scan. Where the law requires a written agreement before We process personal data on Your behalf, Our data processing agreement governs that processing and takes precedence over this policy for it.
Customer Application Data is used to perform the scan You asked for, to produce Your reports, and to keep the Service working. It is not used for any other purpose.
Cloud device testing
An ordinary scan runs entirely on Our own infrastructure and the application file never leaves it. There is one feature that is different, and We want it to be unmistakable: if You use the device-testing feature to run Your application on a hosted device and watch it, the complete application file You submit is uploaded to a third-party cloud emulator provider — currently Appetize.io — which runs it and returns a view of the running device. That happens only when You invoke that feature, and only for the file You choose to send to it. Scans that do not use it are unaffected.
Information collected automatically
When You use the Service, We collect Usage Data. This may include Your IP address, browser type and version, the pages You visit, the time and date of Your visit, time spent on those pages, unique device identifiers and other diagnostic data. Where You reach Us through a campaign link, We also record the referring page and any UTM parameters on the URL, so We can tell which campaign a signup came from.
When You submit an application for analysis, We record the IP address and user agent of the submission alongside it. We do this to investigate abuse of a service that costs real compute to run.
Information from third parties
We receive limited information from identity providers when You sign in through them, from referral partners where You arrived through an affiliate link, and from threat intelligence services where We look up an artefact found in an application.
How We use information
| Purpose | Legal basis |
|---|---|
| To provide the Service: create Your Account, run scans, store findings and produce reports. | Performance of Our contract with You. |
| To bill You, and to keep accounting records We are required by law to keep. | Contract; legal obligation. |
| To keep the Service secure, detect abuse of the free tier, and prevent fraudulent accounts. | Our legitimate interest in protecting the Service and its users. |
| To answer Your support requests, and to send service messages about Your Account — a scan finishing, a limit being reached, a subscription renewing. | Contract; Our legitimate interest in operating the Service. |
| To measure how the site is used, and to improve the product. | Our legitimate interest in improving the Service. |
| To send marketing about products similar to those You have already enquired about or bought. | Our legitimate interest, or Your consent where the law requires it — for example under the law applicable in the EEA and the UK. |
| To show advertising on third-party platforms, and to measure whether it worked. | Your consent where the law requires it; otherwise Our legitimate interest in promoting the Service. |
You can opt out of marketing at any time using the unsubscribe link in any marketing email, or by contacting Us. Withdrawing consent does not affect the lawfulness of anything done on the basis of that consent before it was withdrawn.
Automated analysis and third-party providers
The Service uses artificial-intelligence models to reason about findings — to judge whether a detection is a real vulnerability, to explain its impact, and to write remediation guidance. That means parts of a scan are sent to third-party model providers outside Our infrastructure.
What is sent to a model provider
What leaves for a model provider is finding metadata, not Your application. In practice that is the vulnerability title and severity, the CWE and OWASP mappings, the file paths from Your decompiled application, and short excerpts of the code Our scanners matched, together with the package name and version. We do not upload the application binary, and We do not send whole files.
Be clear about what that still means: excerpts of Your source code and Your file paths do leave Our infrastructure. Before anything is sent, it passes through a redaction engine that replaces credentials — API keys, access tokens, private keys, passwords, session cookies, email addresses and similar secrets — with placeholders. Redaction does not, and cannot, remove the code itself, because the code is what is being analysed.
Which providers
We use Anthropic's API, DeepSeek, and Anthropic's Claude models through AWS Bedrock. Which one handles a given scan depends on how Our deployment is configured: where more than one is available they are tried in that order, and a request that fails falls through to the next.
Turning model analysis off
Where no provider is configured or reachable, analysis falls back to rule-based reasoning running entirely on Our own infrastructure, and no request leaves it. You can also turn model analysis off for a scan, or pin it to that local engine, so that no code excerpt is sent anywhere. Accounts on the free tier always run in that mode.
Threat intelligence
To enrich a scan We also query external threat-intelligence services — VirusTotal, AbuseIPDB and Google's OSV database among them. What We send them is indicators found in Your application: a file hash, an IP address, a domain name, or the name and version of a third-party library. We do not send the application itself. Redaction does not apply to these lookups, and deliberately so — the indicator is the question being asked, so removing it would make the lookup meaningless. They are described separately here for that reason.
What Our providers may retain
We do not use Your Customer Application Data or Scan Results to train machine-learning models of Our own. We do not currently configure provider-side zero-retention or no-training options, so a request We send to a model provider is handled under that provider's standard API terms. Before We offer the Service to a customer whose requirements call for stricter handling, We will put those terms in place or say plainly that We cannot. If it matters to You, ask Us for Our current position and We will confirm it in writing.
Cookies and similar technologies
We use cookies, and browser storage such as localStorage, to keep You signed in, to measure how the site is used, and to measure advertising. Some of these are set by third parties.
These cookies are set when You first load the site, not after You agree to them. There is no cookie banner on gomobsec.ai and no preferences tool, so the analytics and advertising tags below run on Your first visit. Where You are in a jurisdiction that requires consent first — the EEA and the UK, for example — We are relying on the browser-level controls below rather than on consent collected by Us, and We recognise that this does not meet that standard. Blocks marked “essential” are the exception: they are needed for sign-in to work and are not used for tracking.
Cookies set by Us
- Session and authentication cookies (essential) — these keep You signed in and protect Your Account against cross-site request forgery. Without them the Service cannot work, which is why they are not optional.
- Preference storage — remembers choices You have made, such as dismissing a notice, so You are not asked again.
Cookies set by third parties
| Cookie | Set by | What it is for | Lasts |
|---|---|---|---|
_ga, _ga_0C3VQH47NC, _ga_281ED0EGG8 | Google Analytics 4 | Distinguishes one visitor from another and keeps a session together, so a visit can be counted once. Two of the three are measurement IDs configured in the site and in Tag Manager. | 399 days |
_gcl_au | Google Ads | Records which advertisement a visit came from, so the conversion that follows can be attributed to it. | 89 days |
_fbp | Meta | The same attribution for advertising on Meta, and the signal that lets Meta show a later advertisement to the same browser. | 89 days |
FPID, FPLC | FirstPromoter | Identifies the partner or referral link that brought a visitor to the site, so a commission can be credited if they later become a customer. | 399 days / session |
The following also load on a normal visit, and may set or read identifiers even where they do not leave a cookie behind:
- Google Tag Manager — a container that loads most of the tags above. Because the tags arrive through the container rather than through Our own code, the list can change without a code change on Our part.
- Microsoft Clarity — records how visitors interact with pages, including clicks and scrolling, so We can see where the interface is confusing. It is configured to mask the values typed into form fields.
- FirstPromoter — attributes a visit to the partner or referral link that produced it.
- Tidio — the live chat widget. It loads on the marketing pages. It is deliberately not loaded on our paid-advertising landing pages.
- Google Fonts — serves the typefaces used on the site, which means Your browser makes a request to Google when a page loads.
- Loom — only where a page contains a product video, and only once You press play. Nothing is requested from Loom before that.
Controlling cookies
You can instruct Your browser to refuse all cookies or to indicate when one is being sent, and You can delete the cookies already stored. If You refuse cookies, parts of the Service may not work — in particular, You will not be able to stay signed in.
For the advertising cookies specifically, You can opt out of personalised advertising through Google Ads Settings and through Meta’s ad preferences. You can also opt out of Microsoft Clarity through the controls described in Microsoft’s privacy statement.
How We share information
We do not sell Your Personal Data. We share it only in these situations:
- With Service Providers who process data on Our behalf under contract — the model providers, threat-intelligence services, the cloud device testing provider, analytics and advertising platforms, the live chat provider, Our payment processor and Our hosting providers. Each is permitted to use the data only to provide its service to Us.
- With advertising and analytics partners — Google, Meta and Microsoft receive identifiers and information about how You use the site, so that We can measure and target advertising. Under California law this may count as “sharing” for cross-context behavioural advertising, and You have the right to opt out of it, as described in Your rights.
- For business transfers — if the Company is involved in a merger, acquisition or sale of assets, Your Personal Data may be transferred. We will give notice before that happens and before it becomes subject to a different policy.
- With Our affiliates — companies that control, are controlled by, or are under common control with Us, who must honour this policy.
- Where the law requires it — to comply with a legal obligation, to respond to a valid request from a public authority, to protect and defend the rights or property of the Company, to prevent or investigate possible wrongdoing in connection with the Service, to protect the personal safety of users or the public, or to protect against legal liability.
- With Your consent — for any other purpose, where You have agreed to it.
If You use the Service through an organisation — an employer, for example — the administrators of that organisation can see activity within its workspace, including scans and reports. That visibility comes from Your organisation’s account, not from Us disclosing Your data to it.
International transfers
Your information, including Personal Data, is processed at the Company’s operating offices and wherever the parties involved in the processing are located. This means it may be transferred to — and maintained on — computers outside Your state, province, country or other jurisdiction, where the data protection laws may differ from those where You live.
Where the law requires it, We ensure such transfers are covered by appropriate safeguards, and put supplementary measures in place where they are needed. We take the steps reasonably necessary to ensure Your data is treated securely and in accordance with this policy, and We do not transfer Personal Data to an organisation or a country without adequate controls in place for its security.
How long We keep information
We keep Personal Data only as long as it is needed for the purposes in this policy. Where We can, We shorten that period, or reduce identifiability by deleting, aggregating or anonymising the data. Unless stated otherwise, the periods below are maximums — We may delete sooner once the data is no longer needed.
| What | Examples | Kept for |
|---|---|---|
| Account information | Name, email, company, role, sign-in history. | The life of the Account, plus up to 24 months after closure. |
| Customer Application Data and Scan Results | Uploaded APK/IPA files, decompiled sources, findings, reports and network captures. | Until You delete the project or scan, plus up to 30 days in backups. Retained longer only where a legal obligation or a legal claim requires it. |
| Billing records | Invoice, amount, currency, period and the payment processor’s identifiers. Card details are held by the processor and never reach Us. | As required by tax and accounting law, currently 7 years. |
| Campaign and enquiry records | Name, work email, company, optional phone and job title, the form You submitted, and the consent record that goes with it. | Up to 24 months from the last contact. |
| Support correspondence | Tickets and email threads, including chat transcripts. | Up to 24 months from ticket closure. |
| Usage and analytics data | IP addresses, device and browser identifiers, pages viewed, and server logs. | Up to 24 months from collection. |
We may keep data longer than the periods above where:
- the law requires it — financial records for a tax authority, for example;
- it is necessary to establish, exercise or defend a legal claim;
- You ask Us to keep something specific;
- it exists in a backup scheduled for routine deletion, which We do not restore except for security, disaster recovery or legal compliance.
When a retention period ends, We delete the data or render it anonymous. In some cases We convert Personal Data into aggregate statistical data that cannot be linked back to You; that aggregate data may be kept indefinitely. You can ask Us how long a specific category of Your data will be kept by contacting Us.
Deleting Your data
You can delete projects, scans and other content from within the Service while signed in. You can also ask Us to give You access to, correct, or delete any Personal Data You have provided, by contacting Us at support@gomobsec.ai. Deleting Your Account removes Your Personal Data and Your Customer Application Data, subject to the retention obligations above. We may need to keep certain records where We have a legal obligation or another lawful basis to do so, and We will tell You which, and why, if that applies.
Security
The security of Your Personal Data matters to Us, and protecting it is the product We sell. Passwords are stored only as bcrypt hashes. Access to production systems is restricted and authenticated. Secrets are stripped from scan data before it is sent to any third-party service. Data is encrypted in transit.
No method of transmission over the Internet, and no method of electronic storage, is completely secure, and We cannot guarantee absolute security. What We can tell You is what We do, and that We will notify You and the relevant authority without undue delay where a breach affecting Your Personal Data meets the threshold for notification.
Your rights
Depending on where You live, You may have some or all of the following rights. We do not charge for handling a request made within the limits the law allows, and We answer within the period the applicable law sets.
- Access — a copy of the Personal Data We hold about You.
- Correction — correction of data that is inaccurate or incomplete.
- Deletion — deletion of Your Personal Data, subject to the retention obligations above.
- Restriction and objection — a limit on how We use Your data, or an objection to a use based on Our legitimate interests.
- Portability — a machine-readable copy of the data You gave Us.
- Withdraw consent — where We rely on consent, withdraw it at any time. This does not affect processing carried out before You withdrew it.
- Complain — lodge a complaint with Your local data protection authority. If You are in the EEA or the UK, You may complain to the authority in the country where You live or work.
California. If You are a California resident, You have the right to know what Personal Information We collect, to delete it, to correct it, and to opt out of its sale or sharing. We do not sell Personal Information for money. We do disclose identifiers and internet activity to Google, Meta and Microsoft for advertising measurement and targeting, which California law may treat as “sharing” for cross-context behavioural advertising. To opt out of that, use the browser and advertising controls in Cookies and similar technologies, or contact Us and We will handle it for You. We will not discriminate against You for exercising any of these rights.
To exercise any right, contact Us at support@gomobsec.ai. We may need to verify Your identity before acting, and where Your request concerns an organisation’s account We may direct it to that organisation’s administrator, who controls the data in it.
Children
The Service is not directed at, and We do not knowingly collect Personal Information from, anyone under the age of 16. If You are a parent or guardian and believe Your child has given Us Personal Information, contact Us. If We learn that We have collected Personal Information from anyone under 16, We will take steps to remove it from Our servers as soon as reasonably possible.
Some countries and states set a higher age at which a person can consent to the processing of their own Personal Information. Where We rely on consent and the law that applies to a user sets an age above 16, We may require the consent of that user’s parent or guardian before collecting and using their Personal Information.
Links to other websites
The Service may contain links to websites We do not operate. If You follow one, You will be directed to that third party’s site. We strongly advise You to review the privacy policy of every site You visit. We have no control over, and assume no responsibility for, the content, privacy policies or practices of any third-party site or service.
Changes to this policy
We may update this policy from time to time. We will notify You of a material change by email or by a prominent notice in the Service before it takes effect, and We will update the “Last updated” date at the top of this page. Changes take effect when they are posted here, so please review this page periodically.
Contact Us
If You have any questions about this policy, or want to exercise a right described in it, contact Us at support@gomobsec.ai.
