← Back

Data Trace

See exactly where your apps send your data. Embergard traces every connection — and blocks the ones that shouldn't be there.

🌍 6 servers · 4 countries · 1 calculator app
📍 You
US Server
US Server
US Server
🇨🇳 Unknown
🇷🇺 Ad network
🇩🇪 EU
🇮🇪 EU

Your calculator app sends data to 6 servers across 4 countries

Dangerous
Questionable
EU-safe
You
11:52🔒 ● ● ▊
📊
Data Trace
● 4 Active Flows
👤
Contacts → US (Virginia)
Flurry Analytics · Tracking SDK
📍
Location → US (California)
AppsFlyer · Attribution tracker
🆔
Device ID → China
Unknown SDK · No privacy policy
📊
Usage patterns → Russia
Ad network · Behavioral profiling
✅
Summary: 3 of 4 flows unnecessary
A calculator needs none of this.
🏠📊📋⚙️
Where each data flow goes
👤
Contacts → US — Virginia
Flurry Analytics (Yahoo). Purpose: user profiling. Not needed for a calculator.
📍
Location → US — California
AppsFlyer. Purpose: ad attribution. Sends GPS coordinates every 30 seconds.
🆔
Device ID → China — unknown
Embedded tracking SDK with no privacy policy. Creates persistent fingerprint.
📊
Usage → Russia — ad network
Behavioral profiling. Tracks every tap, scroll, and screen duration.

3 of 4 data flows are UNNECESSARY for a calculator

A loan calculator needs exactly zero of these data types to function.

Embergard doesn't just see where data goes — it inspects every packet to see what is being sent. On-device, no VPN required, no cloud processing.

11:52🔒 ● ● ▊
🔬
Packet Inspector
● 6 connections
🔍
DNS Queries: 4 domains
2 tracker · 1 ad network · 1 legitimate
🔗
TLS: 6 outbound
3 to known tracking servers
📋
HTTP Headers
UA · Device fingerprint · Ad ID sent in clear
📦
Payload: base64 contacts
Full contact list encoded + lat/long + UUID
📊
Data volume: 2.3 MB/hr
47× expected for a calculator
🏠🔬📋⚙️
Full packet-level breakdown
LayerDetailVerdict
DNSads.flurry.com — resolves to 3 US IPsTracker
DNSattr.appsflr.com — AppsFlyer attributionTracker
DNStrack.xiaomark.cn — no privacy policyUnknown
DNSapi.loan.calc — legitimate app APISafe
TLS3/6 connections to known tracking serversRisk
HeaderUser-Agent includes device model + OS buildFingerprint
HeaderX-Device-Id: UUID persistentIdentifier
HeaderX-Advertising-Id: tracking IDTracking
PayloadBase64-encoded contact list (247 entries)Exfil
PayloadLat/long coordinates with 3m accuracyLocation
Volume2.3 MB/hr — expected: ~49 KB/hr47× normal
2.3 MB sent in 1 hour 47× expected for a calculator

Embergard's on-device DPI engine sees every packet.

No VPN required. No cloud processing. All analysis runs locally on your phone.

People think HTTPS means privacy. It doesn't — it only encrypts the transport. Embergard sees the data before the app encrypts it, because inspection happens on your device.

11:52🔒 ● ● ▊
📡
Protocol Analysis
● 4 protocols
🌍
DNS — 4 queries
Unencrypted. Your ISP sees these too.
🔒
HTTPS — 6 connections
Encrypted transport. Data visible before encrypt.
📡
gRPC — 2 streams
Binary protocol. Harder to audit without DPI.
📊
WebSocket — 1 persistent
Always-on connection. Sends telemetry every 30s.
🏠📡📋⚙️
Protocol-by-protocol breakdown

DNS (Unencrypted)

Trackers
2
Ad network
1
Legitimate
1

HTTPS Connections (6 outbound)

Trackers
3
Legitimate
1
Unknown
2

HTTPS only hides data in transit. Embergard inspects data before the app encrypts it — because inspection happens on your device, not in the cloud.

Unencrypted DNS queries to tracking domains are visible to your ISP, your carrier, and anyone on the same Wi-Fi. Embergard can block these before they leave your phone.

HTTPS doesn't hide WHAT you send — only the transport.

Embergard sees app-level data before it's encrypted. No VPN needed. No cloud processing.

Embergard processes everything on-device. The only data that leaves your phone goes to EU-based servers — and only what you explicitly allow.

09:15🔒 ● ● ▊
🪵
Embergard
● EU Protected
🇪🇺
EU Data Residency
All Embergard data stays in EU data centers.
🛡️
No US CLOUD Act
EU jurisdiction only. No US government access.
📋
GDPR by Design
Privacy by architecture, not afterthought.
🔒
Zero-Knowledge
We can't see your data even if we wanted to.
🏠🛡️📋⚙️

Your threat data stays in Europe. Period.

No US jurisdiction, no CLOUD Act exposure, no third-party data sharing.

Embergard monitors every outgoing connection. When an app tries to send data where it shouldn't, you get an instant alert — and Embergard blocks it.

14:32🔒 ● ● ▊
🪵
Embergard
● Alert
⚠️
New Data Flow Detected
App attempting data exfiltration.
📱
Flash Loan Calculator
App: com.flash.loan.calc
🌐
Destination: 45.33.xx.xx
US-based · Known tracking server
📦
Data: Fingerprint + Location + Contacts
3 data types in single request.
🛡️
Blocked. Data flow quarantined.
All 3 data types intercepted. App sandboxed.
🏠🛡️📋⚙️
What Embergard blocked

Flash Loan Calculator attempted to send your device fingerprint, GPS location, and full contact list to a known tracking server at 45.33.xx.xx (US).

Embergard detected this was unnecessary for the app's core function (a calculator) and automatically quarantined the data flow.

The app has been sandboxed — it can still calculate loans, but cannot send any data externally.

Two calculator apps. One sends your data to 4 countries. The other respects your privacy. Embergard shows you the difference.

🚨 Flash Loan Calculator

72
Risk score
External flows6
Countries4
Trackers5
Unnecessary4 of 4
US CLOUD ActExposed

✅ Simple Loan Calc

8
Risk score
External flows0
CountriesEU only
Trackers0
UnnecessaryNone
US CLOUD ActSafe

Same function. Radically different privacy.

Embergard helps you choose the app that respects you.
Embergard's privacy principles
🔐
P1: Consent-firstYour data never leaves your device without your explicit consent. No background uploads, no silent tracking, no "improving our services" data grabs.
📱
On-device analysisAll threat detection runs locally on your phone. Pattern matching, behavioral heuristics, and signature-based scanning — without sending a single byte to the cloud.
🔒
Zero-knowledge architectureWe can't see your data even if we wanted to. Your threat intelligence is encrypted before it ever touches our servers — and those servers are in the EU.
🇪🇺
European infrastructureAll Embergard infrastructure runs in EU data centers. No US jurisdiction, no CLOUD Act exposure, no Patriot Act access. GDPR isn't a compliance exercise — it's our architecture.
🌍
Data sovereigntyAs shown on this page: most apps exfiltrate your data to countries with weak privacy laws. Embergard reverses this — your data stays where you are, under the laws that protect you.

You are the product of no one.
Your data is yours.

🪵🔥 Simulated demo. No real data flows. Showing how Embergard traces and protects.

← Back to Embergard