See exactly where your apps send your data. Embergard traces every connection — and blocks the ones that shouldn't be there.
🌍 6 servers · 4 countries · 1 calculator app
📍 You
US Server
US Server
US Server
🇨🇳 Unknown
🇷🇺 Ad network
🇩🇪 EU
🇮🇪 EU
Your calculator app sends data to 6 servers across 4 countries
Dangerous
Questionable
EU-safe
You
📱
Data Flow Breakdown
What your calculator sends where
11:52🔒 ● ● ▊
📊
Data Trace
● 4 Active Flows
👤
Contacts → US (Virginia) Flurry Analytics · Tracking SDK
📍
Location → US (California) AppsFlyer · Attribution tracker
🆔
Device ID → China Unknown SDK · No privacy policy
📊
Usage patterns → Russia Ad network · Behavioral profiling
✅
Summary: 3 of 4 flows unnecessary A calculator needs none of this.
🏠📊📋⚙️
Where each data flow goes
👤
Contacts→US — Virginia
Flurry Analytics (Yahoo). Purpose: user profiling. Not needed for a calculator.
📍
Location→US — California
AppsFlyer. Purpose: ad attribution. Sends GPS coordinates every 30 seconds.
🆔
Device ID→China — unknown
Embedded tracking SDK with no privacy policy. Creates persistent fingerprint.
📊
Usage→Russia — ad network
Behavioral profiling. Tracks every tap, scroll, and screen duration.
3 of 4 data flows are UNNECESSARY for a calculator
A loan calculator needs exactly zero of these data types to function.
🔬
Deep Packet Inspection
Seeing what the app really sends
Embergard doesn't just see where data goes — it inspects every packet to see what is being sent. On-device, no VPN required, no cloud processing.
11:52🔒 ● ● ▊
🔬
Packet Inspector
● 6 connections
🔍
DNS Queries: 4 domains 2 tracker · 1 ad network · 1 legitimate
🔗
TLS: 6 outbound 3 to known tracking servers
📋
HTTP Headers UA · Device fingerprint · Ad ID sent in clear
📦
Payload: base64 contacts Full contact list encoded + lat/long + UUID
📊
Data volume: 2.3 MB/hr 47× expected for a calculator
🏠🔬📋⚙️
Full packet-level breakdown
Layer
Detail
Verdict
DNS
ads.flurry.com — resolves to 3 US IPs
Tracker
DNS
attr.appsflr.com — AppsFlyer attribution
Tracker
DNS
track.xiaomark.cn — no privacy policy
Unknown
DNS
api.loan.calc — legitimate app API
Safe
TLS
3/6 connections to known tracking servers
Risk
Header
User-Agent includes device model + OS build
Fingerprint
Header
X-Device-Id: UUID persistent
Identifier
Header
X-Advertising-Id: tracking ID
Tracking
Payload
Base64-encoded contact list (247 entries)
Exfil
Payload
Lat/long coordinates with 3m accuracy
Location
Volume
2.3 MB/hr — expected: ~49 KB/hr
47× normal
2.3 MBsent in 1 hour47× expected for a calculator
Embergard's on-device DPI engine sees every packet.
No VPN required. No cloud processing. All analysis runs locally on your phone.
📡
Protocol Analysis
HTTPS doesn't hide what you send
People think HTTPS means privacy. It doesn't — it only encrypts the transport. Embergard sees the data before the app encrypts it, because inspection happens on your device.
11:52🔒 ● ● ▊
📡
Protocol Analysis
● 4 protocols
🌍
DNS — 4 queries Unencrypted. Your ISP sees these too.
🔒
HTTPS — 6 connections Encrypted transport. Data visible before encrypt.
📡
gRPC — 2 streams Binary protocol. Harder to audit without DPI.
📊
WebSocket — 1 persistent Always-on connection. Sends telemetry every 30s.
🏠📡📋⚙️
Protocol-by-protocol breakdown
DNS (Unencrypted)
Trackers
2
Ad network
1
Legitimate
1
HTTPS Connections (6 outbound)
Trackers
3
Legitimate
1
Unknown
2
HTTPS only hides data in transit. Embergard inspects data before the app encrypts it — because inspection happens on your device, not in the cloud.
Unencrypted DNS queries to tracking domains are visible to your ISP, your carrier, and anyone on the same Wi-Fi. Embergard can block these before they leave your phone.
HTTPS doesn't hide WHAT you send — only the transport.
Embergard sees app-level data before it's encrypted. No VPN needed. No cloud processing.
🇪🇺
EU Data Residency
Your data stays in Europe
Embergard processes everything on-device. The only data that leaves your phone goes to EU-based servers — and only what you explicitly allow.
09:15🔒 ● ● ▊
🪵
Embergard
● EU Protected
🇪🇺
EU Data Residency All Embergard data stays in EU data centers.
🛡️
No US CLOUD Act EU jurisdiction only. No US government access.
📋
GDPR by Design Privacy by architecture, not afterthought.
🔒
Zero-Knowledge We can't see your data even if we wanted to.
🏠🛡️📋⚙️
Your threat data stays in Europe. Period.
No US jurisdiction, no CLOUD Act exposure, no third-party data sharing.
⚠️
Data Exfiltration Alert
Caught in real-time
Embergard monitors every outgoing connection. When an app tries to send data where it shouldn't, you get an instant alert — and Embergard blocks it.
14:32🔒 ● ● ▊
🪵
Embergard
● Alert
⚠️
New Data Flow Detected App attempting data exfiltration.
📱
Flash Loan Calculator App: com.flash.loan.calc
🌐
Destination: 45.33.xx.xx US-based · Known tracking server
📦
Data: Fingerprint + Location + Contacts 3 data types in single request.
🛡️
Blocked. Data flow quarantined. All 3 data types intercepted. App sandboxed.
🏠🛡️📋⚙️
What Embergard blocked
Flash Loan Calculator attempted to send your device fingerprint, GPS location, and full contact list to a known tracking server at 45.33.xx.xx (US).
Embergard detected this was unnecessary for the app's core function (a calculator) and automatically quarantined the data flow.
The app has been sandboxed — it can still calculate loans, but cannot send any data externally.
⚖️
Safe Apps Comparison
Same function, different risk
Two calculator apps. One sends your data to 4 countries. The other respects your privacy. Embergard shows you the difference.
🚨 Flash Loan Calculator
72
Risk score
External flows6
Countries4
Trackers5
Unnecessary4 of 4
US CLOUD ActExposed
✅ Simple Loan Calc
8
Risk score
External flows0
CountriesEU only
Trackers0
UnnecessaryNone
US CLOUD ActSafe
Same function. Radically different privacy.
Embergard helps you choose the app that respects you.
🛡️
The P1 Privacy Promise
Your data is yours
Embergard's privacy principles
🔐
P1: Consent-firstYour data never leaves your device without your explicit consent. No background uploads, no silent tracking, no "improving our services" data grabs.
📱
On-device analysisAll threat detection runs locally on your phone. Pattern matching, behavioral heuristics, and signature-based scanning — without sending a single byte to the cloud.
🔒
Zero-knowledge architectureWe can't see your data even if we wanted to. Your threat intelligence is encrypted before it ever touches our servers — and those servers are in the EU.
🇪🇺
European infrastructureAll Embergard infrastructure runs in EU data centers. No US jurisdiction, no CLOUD Act exposure, no Patriot Act access. GDPR isn't a compliance exercise — it's our architecture.
🌍
Data sovereigntyAs shown on this page: most apps exfiltrate your data to countries with weak privacy laws. Embergard reverses this — your data stays where you are, under the laws that protect you.
You are the product of no one. Your data is yours.
🪵🔥 Simulated demo. No real data flows. Showing how Embergard traces and protects.