1. Who we are
AI Storage Cleaner is published by NextWave Infotech ("we", "us", "our"), which acts as the data controller (and, under some laws, the "business" or "data fiduciary") for the limited personal data described in this policy.
| Controller | NextWave Infotech |
|---|---|
| Registered address | 408, Elita Square, Utran, Surat, Gujarat 394105, India |
| Privacy contact | support@nextwaveinfotech.com |
| Grievance Officer (India, DPDP Act) | [name] — support@nextwaveinfotech.com |
We are not required to appoint a Data Protection Officer, because we carry out no large-scale or systematic monitoring of individuals. Any privacy matter can be raised directly with the contact above.
2. Summary
- No account, no sign-up, no login. We do not know who you are.
- Your content never leaves your device. Photos, videos, files, contacts and calendar entries are read and processed entirely on your device.
- No advertising, no analytics, no attribution or crash-reporting SDK, no profiling.
- We do not track you across apps or websites, so the app never asks for App Tracking Transparency permission on iOS.
- We do not sell or "share" your personal information, and never have.
- No purchases, no subscriptions, no paywall. The app is free and its features are unlimited.
- The only data that leaves your device is a push notification token and a configuration request, both handled by Google Firebase.
We would rather be precise than absolute. An app that talks to a push-notification service does not collect "nothing at all", and this policy says exactly what that involves — see section 5.
3. What our store privacy labels say
Both stores require us to summarise our data practices. Those summaries and this policy are consistent with each other.
Google Play — Data safety
| Declaration | Our answer |
|---|---|
| Does the app collect or share user data? | Yes — minimally. Only a device/installation identifier for push notifications. |
| Data type collected | Device or other IDs — push registration token and installation identifier, plus the IP address inherent in any network request. |
| Purpose | App functionality (delivering notifications you enabled) only. |
| Is data shared with third parties? | Processed by Google Firebase as our service provider. Not sold, not shared for advertising. |
| Photos, videos, files, contacts, calendar, app list | Not collected. Accessed on-device only, never transmitted. |
| Is data encrypted in transit? | Yes. |
| Can users request deletion? | Yes — uninstalling or disabling notifications ends it entirely. See section 9. |
Apple App Store — App Privacy
| Category | Our answer |
|---|---|
| Data used to track you | None. We do not track, and we do not present the App Tracking Transparency prompt. |
| Data linked to you | None. We hold nothing that identifies you. |
| Data not linked to you | Identifiers — a push token / installation identifier, used solely for App Functionality. |
| Photos, Contacts, Calendars | Accessed with your permission for on-device processing; not collected and never sent off the device. |
4. What the app processes on your device
Everything below is read and processed locally, to make a feature you asked for work. None of it is collected by us, transmitted off your device, or stored on any server we control.
| Data | Why the app reads it | Where it is kept | Sent to us? |
|---|---|---|---|
| Photos and videos | Find duplicate, similar, blurry and screenshot images, large or old videos and messaging-app media; show previews; compress; and delete what you select. | A local scan index and thumbnail cache inside the app's own storage. | No |
| Files and storage usage | Measure free space and find cached or junk files you choose to clean. | Not retained beyond the scan. | No |
| Contacts | Find duplicate and incomplete contacts, and merge, delete or hide the ones you select. | In memory while in use; entries you hide are stored in a local database. | No |
| Calendar entries | List old or bulk events so you can delete the ones you select. Event details may include the calendar account name (often an email address), shown on screen. | A local cache. | No |
| Installed apps and usage Android | Show your apps with their size and when you last used them, so you can spot apps you no longer need, and begin an uninstall that you confirm. | A local cache. | No |
| Device model and OS version | Apply the correct storage-permission behaviour for your OS version. Not used to identify or track you. | Not retained. | No |
| Vault contents and PIN | Hide selected photos, videos and contacts behind a PIN you choose — see section 12. | The app's private storage on your device. The PIN is stored only as a salted cryptographic hash, never as the digits you typed. | No |
The app does not access your location, microphone, camera, call logs, SMS messages, health data, browsing history, biometrics, or any online account.
5. What does leave your device
Two things only, both provided by Google Firebase:
a) Push notifications — Firebase Cloud Messaging
If you allow notifications, Firebase issues your installation a registration token and an associated installation identifier, so we can send reminders such as "your storage is filling up". These identify an app installation on a device, not you, and contain none of your photos, contacts, calendar entries or files. Turning notifications off in your device settings stops this.
b) App configuration — Firebase Remote Config
The app asks Firebase for its current configuration — feature settings, support links, and the latest available version. This is a download; your personal content is never included in the request.
To deliver these two services, Google processes technical data such as your IP address and an installation identifier, under its own terms: firebase.google.com/support/privacy. An IP address can constitute personal data, which is why we disclose it here rather than claiming that nothing at all is transmitted.
Two further cases are worth naming, because they involve your device talking to someone else — though neither sends us anything:
- Opening a link. Tapping a support, policy or store link opens it in your browser or store app, and that destination sees an ordinary visit from your device.
- Sharing. If you use a share option, your device's own share sheet hands the content to the destination you pick. We are not involved and receive nothing.
6. What we never do
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under US state privacy laws.
- We show no advertising and integrate no advertising network.
- We include no analytics, attribution, or crash-reporting SDK, and build no profile of you.
- We do not track you across other companies' apps or websites, and therefore never present the iOS App Tracking Transparency prompt.
- We carry out no automated decision-making producing legal or similarly significant effects.
- We do not upload, back up, or index your photos, videos, files, contacts or calendar entries.
- We never ask for, and cannot access, your passwords or any online account.
7. Permissions, and why each is requested
You may decline any permission. Declining only disables the feature that needs it — the rest of the app keeps working, and you can change your mind at any time in your device settings.
iOS
| Permission | Purpose |
|---|---|
| Photo Library (read) | Scan for duplicate, similar and large photos and videos, show previews, compress and delete what you select. |
| Photo Library (add) | Save a compressed copy back to your library, and restore items you unhide from the Vault. |
| Contacts | Find duplicate and incomplete contacts and merge, delete or hide the ones you choose. |
| Calendars (full and write-only access) | List old or bulk events and delete the ones you select. |
| Notifications | Send storage reminders and show cleaning progress. |
Android
| Permission | Purpose |
|---|---|
READ_MEDIA_IMAGES, READ_MEDIA_VIDEO, READ_MEDIA_VISUAL_USER_SELECTED | Read photos and videos so they can be scanned, previewed, compressed or deleted. |
READ_EXTERNAL_STORAGE (Android 12 and older only) | The same purpose on older versions, where the media-specific permissions above do not exist. |
WRITE_EXTERNAL_STORAGE | Declared by the video-compression component so a compressed video can be saved on older Android versions. On Android 10 and newer it grants nothing; the app writes only through the system media store and its own private folder. |
READ_CONTACTS, WRITE_CONTACTS | Find duplicate or incomplete contacts and merge, delete or hide the ones you choose. |
READ_CALENDAR, WRITE_CALENDAR | List and delete the calendar entries you choose. |
QUERY_ALL_PACKAGES, PACKAGE_USAGE_STATS | Show installed apps with their size and last-used time so you can identify apps you no longer use. Usage access is optional and is requested only when you open that feature. |
REQUEST_DELETE_PACKAGES | Start the system uninstall prompt for an app you selected. Android performs the uninstall, and only if you confirm it. |
CLEAR_APP_CACHE | Clear cached junk data to reclaim space. |
POST_NOTIFICATIONS | Show storage reminders and cleaning progress. |
FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNC, WAKE_LOCK | Keep a long scan or compression running reliably while you wait. |
RECEIVE_BOOT_COMPLETED | Re-register your scheduled reminders after the device restarts. |
INTERNET, ACCESS_NETWORK_STATE, C2D_MESSAGE (push receipt) | Required only for the two Firebase functions described in section 5. |
VIBRATE | Haptic feedback when you tap. |
8. Legal bases for processing (EU / UK GDPR)
| Purpose | Legal basis |
|---|---|
| Reading your photos, videos, files, contacts, calendar entries and app list so the cleaning features work | Consent (Art. 6(1)(a)), given through the operating-system permission prompt and withdrawable at any time in your device settings. The processing itself happens on your device. |
| Deleting, compressing, merging or hiding the items you selected | Performance of a contract (Art. 6(1)(b)) — carrying out the action you asked the app to perform. |
| Sending push notifications | Consent (Art. 6(1)(a)), given via the notification prompt and withdrawable in device settings. |
| Fetching app configuration and checking for a newer version | Legitimate interests (Art. 6(1)(f)) — operating, securing and maintaining the app. We consider the impact low, because no personal content is transmitted. |
Where you withdraw consent we stop the related processing. Withdrawal does not affect anything already done, and cannot restore data you have already deleted.
9. Retention, and how to delete everything
We hold none of your personal content on any server, so there is nothing on our side to retain, export or erase.
Data the app creates on your device — its scan index, thumbnail cache, settings, local databases, Vault contents and your hashed Vault PIN — remains there until you remove it. To erase all of it:
- Android Settings → Apps → AI Storage Cleaner → Storage → Clear storage, or uninstall the app.
- iOS Delete the app from your Home Screen or App Library.
Your push token is retained by the messaging service only while the app remains installed with notifications enabled; it is invalidated when you uninstall the app or turn notifications off.
10. Recipients and international transfers
We disclose your personal data to no third party for that party's own purposes. Our only recipient is a service provider (processor):
| Recipient | Service | Data involved |
|---|---|---|
| Google (Firebase Cloud Messaging, Firebase Remote Config) | Push notification delivery and app configuration | Push registration token, installation identifier, IP address, basic device and app metadata |
We may also disclose information where legally required — for example in response to a valid legal request, or to establish or defend legal claims. Given how little we hold, in most cases we would have nothing meaningful to produce.
Transfers. Google operates globally, so the limited technical data above may be processed in countries other than your own, including the United States. Where those transfers are subject to the EU or UK GDPR, they rely on the safeguards Google puts in place, such as the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Your photos, contacts, calendar entries and files are not transferred anywhere, because they never leave your device.
11. Your rights
Depending on where you live, you may have rights to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to processing, to receive it in a portable form, and to withdraw consent.
An honest note on what we can actually do for you. Because the app has no accounts and we keep no server-side record identifying you, we normally have no personal data about you to produce, correct, or erase. In practice you exercise the strongest form of these rights yourself, and instantly: revoke a permission, turn off notifications, or uninstall the app. You are welcome to contact us regardless, and we will respond as the applicable law requires — but we may be unable to link any data to you, and where that is so we will explain it rather than ask you for identifying information we do not otherwise need.
EU, UK and Switzerland
You may exercise the rights above and lodge a complaint with your supervisory authority. EU authorities are listed by the EDPB; in the UK, the ICO; in Switzerland, the FDPIC.
United States (California and other states)
We do not sell personal information and do not share it for cross-context behavioural advertising, so there is no opt-out for us to offer. We do not knowingly collect sensitive personal information in order to infer characteristics about you. You have the right to know, delete and correct, and the right not to be discriminated against for exercising those rights. Authorised agents may submit requests on your behalf via the contact below. In the twelve months preceding this policy's date, the only category of personal information involved was identifiers and device/internet activity, in the narrow form described in section 5, collected solely to deliver notifications and configuration.
India
Under the Digital Personal Data Protection Act, 2023 you may access, correct, complete, update and erase your personal data, nominate another person to exercise your rights on your behalf, and raise a grievance with our Grievance Officer (section 1) before approaching the Data Protection Board of India.
Brazil, Canada, Australia, South Korea, Japan and elsewhere
If you are covered by the LGPD, PIPEDA, the Australian Privacy Principles, PIPA, APPI or a comparable law, you may exercise the equivalent rights that law grants you by contacting us, and may complain to your national regulator — for example the ANPD, the Office of the Privacy Commissioner of Canada, or the OAIC.
How to exercise any right: email support@nextwaveinfotech.com, telling us the country you are writing from and what you would like us to do. We aim to respond within 30 days and will tell you if we need longer.
12. The Vault
Items you hide in the Vault are moved into the app's private storage area on your device and placed behind a PIN you choose. The PIN is stored only as a salted cryptographic hash — the digits you type are never written to storage. Vault contents are not uploaded, and we cannot see them.
Please understand the Vault's limits. It is a privacy convenience that keeps hidden items out of your gallery and contact list. It is not a security product:
- Vault contents are moved, not encrypted. They rely on your device's own security and app sandboxing, so someone with deep access to an unlocked or compromised device could reach them.
- Uninstalling the app, or clearing its data, permanently deletes everything in the Vault. Unhide anything you want to keep before you uninstall.
- If you forget your PIN we cannot reset it or recover the contents.
13. Deletion is permanent
The app deletes photos, videos, files, contacts and calendar entries at your instruction, using your device's own operating system.
- Deletion is generally permanent. Depending on your device and OS version, deleted photos and videos may remain in a system "Recently Deleted" or "Trash" album for a limited period; other files, contacts and calendar entries usually cannot be recovered. Contacts synced to a cloud account may be recoverable from that account's own trash for a limited time.
- We cannot recover anything for you, because we never hold a copy.
- Please review your selection before confirming, and back up anything important first.
14. Children
The app is a general-purpose utility and is not directed to children. We do not knowingly collect personal data from children under 13, or under the higher age of digital consent applicable in your country (up to 16 in parts of the EU). If you believe a child has provided us with personal data, contact us and we will delete anything we hold.
15. Security
Because your content stays on your device, the principal protections are your device's own: your screen lock, app sandboxing, and full-disk encryption where your device provides it. The limited data described in section 5 is encrypted in transit to Google's services, and your Vault PIN is stored only as a salted hash.
No method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security. What we can state precisely is that we operate no server holding your content, so there is no central store of your photos, contacts or files for an attacker to breach. Please also read the Vault limits in section 12.
16. Changes to this policy
We may update this policy as the app changes or as the law requires. The "Last updated" date at the top always reflects the current version. Where a change materially affects your rights or how your data is handled, we will give prominent notice in the app or on its store listing before it takes effect, and will seek your consent again where the law requires it. Continuing to use the app after an update means you accept the revised policy.
17. Contact and complaints
| support@nextwaveinfotech.com | |
| Controller | NextWave Infotech, 408, Elita Square, Utran, Surat, Gujarat 394105, India |
| Grievance Officer (India) | [name] — support@nextwaveinfotech.com |
If you are not satisfied with our response, you may complain to your local data protection authority — see section 11 for where to go in your region.