Last Updated: August 9, 2026
Introduction
Clarity Check ("the App", "we", "us", "our") is committed to protecting your
privacy. This Privacy Policy explains what data we collect, how we collect it,
how we use it, and who we share it with. Clarity Check is an Android application
distributed through Google Play.
Data We Collect
Account information
- An anonymous user identifier created automatically for you by Firebase
Authentication the first time you open the App. No email or name is required.
- If you choose to sign in with Google from the Settings screen, we additionally
store the email address and display name associated with that Google account.
Signing in is optional and is used to unlock free search credits and to keep
your history across devices.
Information you enter to run a search
We only receive what you type or select in the App:
- Phone numbers you submit for a reverse phone lookup.
- Photos and screenshots you upload for a reverse image search or a dating
profile scan.
- Email addresses you submit for a data breach check.
- Passwords you submit for a password breach check. See "How passwords are
handled" below — your password never leaves your device.
- Names, ages and city or region you enter for a dating profile scan. Cities
are suggested using Google Places autocomplete as you type.
Collected automatically
- Push notification token. A Firebase Cloud Messaging token is generated for
your device and stored against your account so we can send service messages.
- Usage analytics. Google Analytics for Firebase records in-app events such
as which screens are opened and which searches are run, tied to your anonymous
identifier.
We do not collect your contacts, your GPS or precise location, your device
address book, your call logs, your SMS messages, or your advertising identifier.
How Passwords Are Handled
If you use the password breach check, your password is hashed on your device
using SHA-1 and only the first five characters of that hash are sent to the
Pwned Passwords service operated by Have I Been Pwned. That service returns a
list of hash suffixes, and the comparison is completed on your device. Your
password is never transmitted, never reaches our servers, and is never stored —
not in your history, not anywhere. Only the resulting count of how many times
that password has appeared in known leaks is saved.