Data & privacy
Use this page to complete your privacy policy and your Google Play Data safety form.
Data collected
Section titled “Data collected”| Category | Data | When |
|---|---|---|
| Device | Brand, model, manufacturer, OS version, screen size and density | Session start |
| App | Package name, version name/code, requested permissions and their grant status | Session start |
| Identifiers | Random device id generated by the SDK (not the Android ID or advertising id); session id; the user identifier you pass to identify() |
Every event |
| Usage | Screens, taps and long-presses (view id, label, text), Activity/Fragment lifecycle | Continuously |
| Diagnostics | Crash stack traces and thread info; your trace logs | On event |
| Network | URL, method, status, duration, request/response headers and bodies | Each OkHttp call via the interceptor |
| Device integrity | Root, emulator and system-tamper flags, build tags | Once per launch |
| Location | Last known coarse location — only if your app already holds a location permission | Once per launch |
| Dependencies | Your app’s library list and versions | Once per app version |
Remote storage commands
Section titled “Remote storage commands”From the dashboard, authorized team members can send commands to a device during an active session. The SDK polls for them every 30 seconds while the app is in the foreground:
- Capture storage — upload a snapshot of the app’s SharedPreferences files.
- Set — write a value to a SharedPreferences key.
- Clear — remove a key or clear a file (clearing everything with
*is refused).
Firebase, Google Play services, WebView and Google Analytics preference files are excluded.
Controls
Section titled “Controls”| Control | Where | Effect |
|---|---|---|
| Masked properties | Dashboard → application settings | Header names and JSON keys replaced with [MASKED] in network logs |
| Always-removed headers | Built in | Authorization, cimkaApiKey, cimkaAppId are never logged |
maskSensitiveInputs |
cimka_config.json |
EditText text logged as *** (default on) |
cimka_mask tag |
Your code | Exclude a view from click tracking |
| Log type switches | Dashboard | Disable click, screen, crash, network, trace, lifecycle, session, device audit or dependency logs |
| SDK kill switch | Dashboard | Disable the SDK entirely without an app update |
clearUser() |
Your code | Stop attaching the user identifier |
On the server, masked properties and common secret patterns (Bearer …, password=…) are also redacted from trace messages and extras, and from crash messages and stack traces, before anything is stored. Screen names and click text are stored as-is — don’t put personal data in them.
Transport security
Section titled “Transport security”Every request is sent over HTTPS (when baseUrl uses https) and signed with HMAC-SHA256 using your license key, with a timestamp and a one-time nonce, so requests can’t be forged or replayed.