Effective date: July 21, 2026
Applies to: the “Lucia Cipher – hostile scan” app distributed on Google Play (package com.lucia.dpc)
Data controller: LUKE LTD (“we”, “us”)
Contact: hey@luke.vn
Lucia Cipher is one app with two modes. This policy describes both, because
what the app does with data is very different in each:
- Device Guard (free mode) — what you get when you install the app from
Google Play. A device-integrity scanner you run yourself. In this mode we
do not collect any personal data, and your scan results stay on your phone. - Lucia Cipher (managed mode) — activates only if the device is enrolled
with an organization through the Zeno companion app and the app becomes the
device administrator. In this mode the app collects device data, sends it to
our servers, and shares it with the organization that enrolled the device.
The app never switches modes silently. Enrollment requires a deliberate
setup flow in the Zeno companion app, with its own disclosure that must be
accepted before management begins.
1. Free mode — Device Guard
1.1 What stays on your phone
Everything the scanner produces stays on the device:
- Scan results and findings — stored only in the app’s local storage.
- Scan history journal — a local timeline of past scans. Never uploaded
in free mode. - Settings and preferences — including whether Continuous watch is on.
- Local install ID — a random identifier computed once on first launch
for the in-app Diagnostics screen. It stays on the device.
You can erase all of this at any time with Settings → Reset and disable,
or by uninstalling the app.
1.2 What the app sends over the network
Free mode makes two kinds of network requests, both to servers we operate:
- Rule-database sync. The app periodically downloads the current
database of hostile-app and tampering signatures. This is a download; no
device identifiers are sent on this path. - Aggregated scan-severity reports (only while Continuous watch is on).
The app reports the overall severity grade of background scans together
with app-version and rules-version metadata, so we can measure how well
the rule database performs. These reports do not include your name,
your list of installed apps, your scan history, your location, or device
hardware identifiers such as IMEI or serial number.
We do not sell this data, use it for advertising, or share it with third
parties. In free mode there is no account, no sign-up, and nothing that
links network traffic to you as a person.
1.3 Permissions the free mode uses, and why
| Permission | Why the app asks for it |
|---|---|
| Notifications (asked at runtime) | To alert you when a scan finds something and to show the “Continuous watch is on” status. Never used for marketing. Declining only silences alerts. |
| Battery-optimization exemption (asked at runtime, optional) | Some manufacturers aggressively stop background apps. Without the exemption, Continuous watch stops shortly after you leave the screen. Declining only disables Continuous watch. |
| Phone state — read once (asked at runtime) | Read a single time on first launch to compute the stable local install ID shown in Diagnostics. The IMEI is not transmitted in free mode. You can decline. |
See all installed apps (QUERY_ALL_PACKAGES) | The core of the scanner: it enumerates installed packages and compares each app’s signing certificate and declared permissions against the rule database (root tooling, overlay abuse, risky permission holders). It reads only manifest metadata and signing certificates — never app content, files, or messages — and the list of your apps is not uploaded in free mode. |
| Internet / network state / Wi-Fi state (read-only) | To download rule updates and, if Continuous watch is on, send the aggregated severity reports described above. Wi-Fi state is checked only to defer network work to an unmetered connection; the app does not read network names (SSIDs). |
| Foreground service (incl. data-sync and special-use subtypes) | Required by Android to keep Continuous watch running visibly, with a persistent notification. |
| Wake lock | Held for the few seconds a scan runs so the system doesn’t suspend it mid-scan. Released immediately after. |
| Start at boot / exact alarms | If Continuous watch was on before a reboot, these re-arm it afterward. Unused otherwise. |
1.4 Permissions that are declared but NOT used in free mode
Because free and managed mode ship in a single app, the app’s store entry
lists permissions that free mode never exercises. In free mode:
- Camera, location (fine/coarse/background), Bluetooth, phone numbers, and phone-call permissions are never requested — no system prompt is ever
shown for them, so they cannot be granted. - Device-management permissions (device administrator binding and the
Android Device Policy permissions covering camera toggle, Wi-Fi,
app control, lock credentials, VPN, wallpaper, and similar) are inert.
Android only activates them for an app that has been made the device’s
administrator, which cannot happen without the enrollment flow described
below.
The in-app Settings → Permissions screen lists all of these under
“Reserved” so you can verify their status on your own device at any time.
2. Managed mode — Lucia Cipher (after enrollment)
Managed mode exists for organizations — for example an employer, a device
lessor, or a financing provider — that manage devices they issue or finance.
It activates only after the device is enrolled with that organization
through the Zeno companion app. During enrollment you are shown a dedicated
disclosure describing the management capabilities, and enrollment does not
proceed without acceptance. After enrollment, the app becomes the device
administrator and its branding changes from “Device Guard” to
“Lucia Cipher” so the mode change is visible.
2.1 Data collected in managed mode
Once enrolled, the app collects the following and transmits it to our
servers:
- Device identifiers: IMEI, hardware serial number, device model,
manufacturer, and OS version — used to bind the device to its enrollment
record so policy commands reach the right device. - Hardware attestation data: certificates produced by the device’s
secure hardware, used to verify the device’s integrity and identity. - Status telemetry (“heartbeat”): periodic reports of device state —
online/offline status, battery level, network connectivity type, applied
policy level, and policy-compliance status. - Command results: confirmations that management commands (lock, unlock,
policy changes) were received and executed, with timestamps. - App inventory and state: which apps are installed, hidden, suspended,
or blocked, to the extent the organization’s policy manages them. - SIM information: SIM identifiers used for SIM-swap detection, where
the organization enables that protection. - Location data: once a device is enrolled, Lucia Cipher collects the device’s precise and approximate location so the enrolling organization can locate a lost or stolen device, run live location sessions during device recovery, respond to individual locate requests, and apply geofencing policies. Location may be collected in the background — including when the app is closed or not in use — so a lost or stolen device can still be found and geofence policies keep working. During a live location session the app runs a visible foreground service (Android’s location foreground-service type) with a persistent notification, so active tracking is always indicated on the device. Location is sent only to the enrolling organization’s Lucia Cipher dashboard; it is never sold, never used for advertising, and never shared with third parties. If the organization enables none of these features, location is not collected. The free Device Guard mode never collects location.
- Scan results: the device-integrity scan results and history that were
previously local-only may be reported to the organization’s dashboard.
On-device network filtering (VPN): on enrolled devices, the organization may activate a local VPN service (Android’s VpnService / BIND_VPN_SERVICE) to enforce its network policy — blocking DNS lookups and connections to addresses the organization has denied. All filtering happens on the device itself: traffic is not routed through any external server, and Lucia Cipher does not record browsing history, visited URLs, or the content of network traffic. Android displays the system VPN indicator while the filter is active.
2.2 What managed mode still does NOT collect
Even in managed mode, the app does not capture or transmit:
- camera photos, video, or frames (camera policy is an on/off switch only);
- the content of your notifications, messages, or emails (the notification
listener suppresses or surfaces notifications locally; content is not sent
off-device); - browsing history or Wi-Fi network names;
- your files, photos, or documents.
2.3 How managed-mode data is used and shared
- Shared with the enrolling organization. The organization that enrolled
the device sees the data described in §2.1 in its management dashboard and
uses it to administer its device policy (locking, unlocking, compliance,
loss prevention). For that data, the organization determines the purposes
of processing; we operate the service on its behalf. - Stored on our servers. We host the management backend and store
enrollment records, telemetry, and command history for the organization. - Service providers. We use hosting and infrastructure providers to run
the service; they process data only on our instructions. - Legal requirements. We may disclose data where required by law or
valid legal process.
We do not sell this data and do not use it for advertising.
2.4 Retention
Managed-mode data is retained while the device remains enrolled. After a
device is unenrolled or released, its telemetry and command history are
deleted or anonymized within 90 days, except where the enrolling
organization or the law requires a longer audit retention.
3. Security
- All network traffic uses TLS.
- Device identity in managed mode is anchored in hardware-backed keys
(Android Keystore / secure element) where the device supports it. - Credentials and sensitive values stored on the device use Android’s
encrypted storage facilities.
4. Your choices and rights
In free mode: you can revoke Notifications, the battery exemption, or
phone-state access at any time in Android settings; each revocation only
disables the matching feature. Settings → Reset and disable wipes the
local journal and preferences. Uninstalling removes all local data.
In managed mode: the device is administered by the enrolling
organization. Requests to access, correct, or delete managed-mode data, or
to unenroll the device, should be directed to that organization’s
administrator — we support them in fulfilling such requests. Where data
protection law (such as GDPR or CCPA/CPRA) grants you rights against us
directly, you can exercise them via the contact below.
Children: the app is not directed at children under 13, and we do not
knowingly collect personal information from them.
5. Changes to this policy
If we make material changes — in particular, if the app starts using a
permission in a new way — the app re-displays its in-app disclosure for
acceptance, and this page’s effective date is updated.
6. Contact
LUKE LTD
Số 92A-94 Bạch Đằng, phường Tân Sơn Hòa, Thành phố Hồ Chí Minh, Việt Nam
hey@luke.vn