Privacy Policy

CloudEx Inc. ("we", "us", or "our") operates the "Network Tools Pro" app (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices available to you. By using the Service, you are deemed to have agreed to the practices described in this Policy.

1. Our Core Principle

Network Tools Pro is a network diagnostics app that brings together ping, traceroute, DNS lookup, a port scanner, Whois, a website check, a Wi-Fi analyzer, an IP calculator, a LAN scanner, and more. There is no account and no sign-in. The targets you look up and their results, the list of devices on your LAN, and your Wi-Fi and network details are processed and stored on your device. We never view, collect, or transmit any of them to our servers. Specifically, we do not have access to any of the following:

  • The targets you enter (host names, IP addresses, URLs) and the results of each tool
  • The DNS queries that pass through the DNS changer (which site names were looked up)
  • The list of devices found on your LAN, and the names and notes you give them
  • Your Wi-Fi name (SSID), the list of nearby Wi-Fi networks, your IP addresses, and other network details
  • Your saved results, the devices you add to Wake on LAN, and your monitoring targets

Your saved results and device lists leave your device only when you share, copy, or export them yourself, and through Android backup (Section 5.2). In rare cases, a crash report sent when the app crashes may contain something being processed at that moment, such as a host name, in the text of the error (Section 5.1). Also, because this is a network diagnostics app, many features communicate with the targets you specify or with outside servers used for diagnostics. Sections 2 and 3 explain exactly which communications take place, when, and with whom.

2. How the App Communicates

2.1 Tools You Run

  • Ping, port scanner, and website check: Send ICMP, TCP connections, or HTTP(S) requests to the target you enter. The port scanner reads the greeting (service information) that open ports return, and the website check reads the redirects (up to 10 steps), the certificate, and the headers.
  • Traceroute: Asks each router on the way to the target to reply, pings each of them, and looks up the name of each one's IP address (reverse lookup). By default, to show who runs each public (global) address along the route, it sends those IP addresses to the Team Cymru lookup service. Private addresses, such as those inside your home, are not sent. You can turn this lookup off with "Show who runs each hop" in the traceroute settings.
  • DNS lookup: Asks the DNS server you choose (your device's DNS, a public DNS, or a server you specify) about the name you enter. When you look up a domain name with a single record type and get an answer, the app automatically sends the same name and type to Cloudflare (1.1.1.1), Google (8.8.8.8), Quad9 (9.9.9.9), and your device's DNS as well, to compare their speed and answers. There is no setting to turn this comparison off. When you run "Compare DNS", the app asks the eight public DNS providers and your device's DNS.
  • Whois: Sends the domain name or IP address you enter to the IANA Whois server and to the Whois servers it refers to, such as domain registries, registrars, and regional internet registries. For a domain name, only its last part (such as .com) is sent to IANA.
  • Wake on LAN (Premium): Sends a wake-up signal (magic packet) to your LAN's broadcast address, or to a host and port you specify. If you enter a SecureOn password, it is included in the signal. You can also send it from a home screen shortcut. For devices with an IP address entered to check that they woke up, the app pings that address when you open the Wake on LAN screen and after sending the signal (for up to 2 minutes) to see whether the device is awake.

As with any internet connection, these communications reveal your IP address to the servers and devices you contact and to the networks along the way. Host names are converted to IP addresses, and IP addresses are looked up for their names, by the DNS configured on your device's network. Some of these communications, such as Whois and plain DNS (UDP), are not encrypted by design. Please use the port scanner and the LAN scanner only on networks and devices that you manage or have permission to test.

2.2 Automatic and Other Communications

  • Connection quality on the home screen: While the home screen is shown, the app pings (ICMP) Cloudflare's 1.1.1.1 every 2 seconds to show your connection's response time. No data of yours is included, but by the nature of the connection Cloudflare receives your IP address. It stops when you leave the home screen. There is no setting to turn this measurement off.
  • Public IP address and provider: When you open the Connection info screen (and when the network changes or you refresh while it is open), the app asks Cloudflare (1.1.1.1) over HTTPS for your device's public IP address, then sends that IP address to the Team Cymru lookup service to find your provider's name. If you turn off "Look up the public IP" in the settings (it is on by default), these lookups are never made. The home screen measurement and the DNS features that use Cloudflare are separate from this setting.
  • Automatic LAN scan: When you open the Devices tab (the first time after the app starts, or after you move to a different network), a LAN scan starts automatically (Section 2.3).
  • List of our other apps: When you open the Settings tab (which introduces our other apps) or the "Our other apps" list, the app downloads their names, descriptions, and images from our content server (static files hosted on Cloudflare Pages). The request contains no personal data from the app. Your region, language, and which apps you have installed are determined only on your device and are not sent. As with any request to a web server, the server receives your device's IP address and the standard device information that Android adds to such requests (such as the Android version and device model). Tapping an app in the list opens its page on Google Play, together with information showing that the referral came from this app.
  • Google Play: At startup and when you return to the app, it checks the status of your Premium purchase with Google Play. When certain conditions are met, it also calls Google Play's in-app review (a request to rate the app) and in-app updates (a notice about a new version).
  • Crash reports: When the app crashes, Firebase Crashlytics sends diagnostic information to Google (Section 5.1).
  • Showing this policy: When you open this policy in the app, it is loaded from our website (networktoolspro.cloud-ex.biz). As with any web page, the server receives your IP address and browser information.

2.3 LAN Scanner

The LAN scanner asks each address on the network your device is connected to (your own subnet; on networks larger than /22, the /24 range that contains your own address; with Premium, a range you specify, up to /16) to reply, using ICMP and TCP connections. To find device names, it also uses mDNS and SSDP (UPnP) multicast, NetBIOS name queries, queries to each device, and reverse lookups of IP addresses. Reverse lookups go to your router (or a DNS server on your LAN), and, if no answer is found, to the DNS configured on your device's network. For UPnP devices, the app reads the description from the address that the device itself announces (normally a device on your LAN).

The list of devices found is never sent to us or to any other third party. Manufacturer names are looked up in a list bundled with the app (the IEEE OUI list), so no communication is made for that. On Android 10 and later, the MAC address of another device is known only when the device announces it itself (for example, via NetBIOS or AirPlay).

2.4 Monitoring (Premium)

When you turn monitoring on, the app uses an Android system feature (WorkManager) to check, at the interval you choose (15 minutes to 3 hours), whether your targets reply, using ping (ICMP) or a TCP connection. If your list of targets is empty when you turn it on, the app adds your router (gateway) and Cloudflare's 1.1.1.1. If you turn on "New device alert", it also runs a LAN scan on the chosen Wi-Fi. When a target goes down, comes back, or becomes slow, or when a new device is found, you are notified with a notification on your device.

3. The DNS Changer (Premium) and Use of a VPN

The DNS changer sends the DNS queries of your whole device (the lookups that turn a site's name into an IP address) to the DNS provider you choose. To do this without root, it uses Android's VpnService (the system VPN feature). It runs only when you turn it on and allow it in Android's VPN confirmation dialog.

  • Only DNS queries go through the VPN: The VPN that the app sets up has a single route, to the address of a placeholder DNS server inside your device. Everything other than DNS, such as web browsing and app data, does not go through the VPN, and the app never sees or records its contents. Anything that reaches the VPN other than DNS queries (to UDP port 53) is discarded. The DNS changer is not used to reroute any traffic other than DNS, or to collect your data.
  • Where queries go: The DNS queries it picks up are sent to the provider you choose (Cloudflare, Google Public DNS, Quad9, Cloudflare for Families, OpenDNS, CleanBrowsing Family, Control D, IIJ Public DNS, or a server you specify), and the answers are returned to the app that asked. By default, queries are encrypted (DoH or DoT); if you specify only IP addresses yourself, they are sent as plain, unencrypted DNS. If you turn off "Encrypt (DNS over HTTPS / TLS)", or when an encrypted query fails to get an answer (and for about 30 seconds after that), queries are sent to the same provider as plain, unencrypted DNS (providers and custom servers without a plain DNS address, such as IIJ Public DNS, are still queried encrypted). With DoH, the provider also receives the standard device information that Android adds to such requests (such as the Android version and device model). Queries never pass through our servers. How a provider handles the queries it receives is governed by that provider's privacy policy. When you tap "Speed test", the app sends a few fixed names, such as example.com, to the eight providers to measure their speed.
  • Apps kept outside the VPN: The app's own traffic, and DNS queries from the apps you choose under "Apps to bypass", do not go through the DNS changer. The screen for choosing apps to bypass reads the list of apps shown in your launcher on your device. Only the package names of the apps you choose are stored, and the list is never sent anywhere.
  • Query log: "Recent queries" on the screen shows the queries that went through the DNS changer (time, name, type, time taken, part of the answer, and the route used). Up to 500 are kept only in your device's memory; they are never saved to a file or sent to us or anyone else. They are cleared when you clear them or when the app's process ends.
  • Notification and automatic restart: If notifications are allowed, a notification shows that the DNS changer is active. The app turns the DNS changer back on after your device restarts or the app is updated only when "Turn on again after restart" is on, the DNS changer was on before, and the VPN permission is still valid. If you set the app as the always-on VPN in Android's settings, Android starts the DNS changer. You can stop the DNS changer at any time from the app, the Quick Settings tile, or the notification, and you can withdraw the VPN permission in Android's settings. It stops automatically when another VPN starts.

4. Location Permission and Wi-Fi Information

Android gives the name (SSID) and access point identifier (BSSID) of the connected Wi-Fi, and the list of nearby Wi-Fi networks, only to apps that have the location permission. Network Tools Pro requests the location permission (ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION) only to read Wi-Fi names and nearby Wi-Fi networks.

  • The app has no code that gets your device's location (latitude and longitude). Because Android requires location to be turned on for the Wi-Fi name to be readable, the app only checks whether it is on.
  • The app does not request location access while you are not using it (background location).
  • Before asking for the permission, the app explains why. If you do not allow it, the other tools still work; only the Wi-Fi name and similar details are not shown.
  • The Wi-Fi name may be stored on your device to keep device lists separate for each network, to remember which Wi-Fi to watch for monitoring, and when you save a result. It is never sent to us.

5. Information We Collect

5.1 Information Collected Automatically

  • Crash reports: Via Firebase Crashlytics. When the app crashes, it sends the stack trace, device model, OS version, app version, and an identifier that Firebase issues for each installation of the app (the Firebase installation ID), among other details, to Google. Basic information about app sessions (app starts) is also sent so that crash rates can be calculated. We do not add the targets you enter, your results, or your network details to crash reports (in rare cases, the text of the error that caused a crash may contain something being processed at that moment, such as a host name). There is no setting in the app to turn this off.
  • Purchase information: Your one-time "Premium" purchase is made and verified through Google Play Billing. Verification takes place between your device and Google Play and does not pass through our servers. We never receive any payment information such as credit card numbers. For refunds and similar procedures, we may check the order information that Google Play provides to developers.
  • Support enquiries: If you email us, we use what you send and your email address to reply. When you write a support or feedback email from the app, the app version, Android version, and device model are added to the message to help us check (feedback also includes the ratings you chose; you can review and edit everything before sending). The email is sent from your own email app.

5.2 Information Stored Only on Your Device

  • Settings and recent targets: Settings for each tool, the recent targets for each tool (8 each), your DNS lookup and DNS changer settings (such as servers you specify and apps to bypass), the status of your Premium purchase, and similar data.
  • Saved results: Only results you save with the Save button, up to 500. Depending on the result, they may contain targets, IP addresses, the Wi-Fi name, the list of nearby Wi-Fi networks, the list of LAN devices, your public IP address and provider, Whois results, and so on.
  • LAN device lists: For each network, the IP address, MAC address (when known), the name the device announces, its type, its manufacturer, when it was first and last seen, and the names and notes you give it.
  • Wake on LAN devices (Premium): The name, MAC address, destination, port, when a signal was last sent, and, if you enter them, the IP address to check and the SecureOn password. The SecureOn password is stored without encryption.
  • Monitoring (Premium): Your targets, the most recent results for each target (up to 32 checks), the Wi-Fi chosen for new device alerts, and similar data.
  • List of our other apps: The most recently downloaded list and a cache of its images.
  • Exports (Premium): When you export saved results or a device list as CSV, the app creates a temporary file for sharing. The file goes only where you choose to send it.
  • Android backup: If backup is turned on in your device settings, Android may include the data above (including Wake on LAN SecureOn passwords) in the backup it saves to your own Google account, and may copy it to a new phone when you transfer your data directly. Caches (images and exported files) and some on-device records, such as the record of review requests, are excluded. This is handled by Android; we have no access to it.
  • When you uninstall: Uninstalling the app or clearing its data deletes all the data stored on your device. Backups saved to your Google account are managed by Android.

5.3 Information We Explicitly Do Not Collect

  • The targets you enter, the results of each tool, your DNS queries, and your LAN device lists (except in the rare cases described for crash reports in Section 5.1)
  • Your device's location (latitude and longitude)
  • Your name, email address, phone number, or contacts (the app has no account or sign-up; except when you email us)
  • Device identifiers such as the IMEI, Android ID, or advertising ID, and this device's MAC address
  • A history of the websites you visit, or the contents of any communication other than DNS
  • The list of apps installed on your device (it is read on your device only to choose apps to bypass and to introduce our other apps, and is never sent)

5.4 Permissions the App Requests and Their Purposes

A network diagnostics app needs several OS permissions. Network Tools Pro uses them only for the stated purposes:

  • Internet (INTERNET) — Used for each tool's communications, the public IP lookup, forwarding by the DNS changer, downloading the list of our other apps, Google Play purchase verification, in-app reviews and in-app updates, crash reports, and showing this privacy policy in the app.
  • Network state (ACCESS_NETWORK_STATE) — Reads the type of the connected network, your IP addresses, the gateway, DNS, Private DNS, and whether a VPN is active.
  • Wi-Fi state and changes (ACCESS_WIFI_STATE / CHANGE_WIFI_STATE) — Shows the Wi-Fi signal strength, frequency, and speed, and scans for nearby Wi-Fi networks in the Wi-Fi analyzer. The app never changes your Wi-Fi connection or settings.
  • Multicast reception (CHANGE_WIFI_MULTICAST_STATE) — Used only during a LAN scan, to receive the replies that devices send over mDNS and SSDP.
  • Location (ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION) — Used only to read Wi-Fi names and nearby Wi-Fi networks (Section 4). The app never gets your device's location.
  • Notifications (POST_NOTIFICATIONS, Android 13+) — Used for monitoring alerts (a target went down, came back, or became slow; a new device joined) and to show that the DNS changer is active. The app asks when you turn on monitoring or the DNS changer. If you do not allow it, the features still work; you just will not see the alerts.
  • VPN (BIND_VPN_SERVICE) — Used for the DNS changer (Section 3). You allow it in Android's confirmation dialog the first time you turn it on.
  • Run at startup (RECEIVE_BOOT_COMPLETED) — Turns the DNS changer back on after your device restarts or the app is updated (only with Premium, when "Turn on again after restart" is on, the DNS changer was on before, and the VPN permission is still valid).
  • Keep awake (WAKE_LOCK) — Used by an Android system feature (WorkManager) while a scheduled monitoring (Premium) check is running.
  • Google Play billing (com.android.vending.BILLING) — Used to make and verify the one-time Premium purchase.

6. How We Use Information

The limited information we collect is used only for the following purposes:

  • Providing and operating the Service
  • Verifying your Premium purchase
  • Diagnosing and fixing crashes
  • Responding to support inquiries
  • Complying with applicable laws

We do not use your information for delivering ads, measuring ads, or analyzing app usage.

7. Third-Party Services

Network Tools Pro uses the following third-party services. Each service has its own privacy policy.

  • Firebase Crashlytics (Google LLC) — crash diagnostic data (including Firebase Installations and Firebase Sessions)
  • Google Play Billing (Google LLC) — the one-time Premium purchase; payment is completed on Google Play
  • Google Play In-App Review and In-App Updates (Google LLC) — let you rate the app and install updates without leaving it; handled by Google Play
  • Cloudflare (Cloudflare, Inc.) — the target of the home screen measurement (1.1.1.1), the public IP lookup, the DNS lookup speed comparison, the DNS options available in DNS lookup and the DNS changer (Cloudflare and Cloudflare for Families), and a default monitoring target
  • Cloudflare Pages (Cloudflare, Inc.) — hosts the static list of our other apps
  • Team Cymru — a lookup service that finds the provider (AS number) for an IP address; used for the public IP lookup and to show who runs each traceroute hop
  • Public DNS services (Google Public DNS, Quad9, OpenDNS, CleanBrowsing Family, Control D, IIJ Public DNS) — used when you choose them in DNS lookup, Compare DNS, or the DNS changer, when you tap "Speed test" in the DNS changer, and for the DNS lookup speed comparison (Google Public DNS and Quad9)
  • IANA and Whois servers (domain registries, registrars, regional internet registries, and others) — used when you run Whois

The hosts contacted by ping, the port scanner, the website check, Wake on LAN, monitoring, and similar tools are the targets you enter or the devices on your LAN. They are not third parties chosen by us, and how they handle data is governed by their own operators' policies.

Network Tools Pro uses no advertising SDK and no advertising ID, and does not share your data with advertising networks. It also does not use Google Analytics or any other app usage analytics tool.

8. Data Retention

  • Crash reports: retained for 90 days, then deleted.
  • Support emails: retained for 12 months after the last reply, then deleted (except where legally required).
  • Data on your device: kept until you delete it, uninstall the app, or clear the app's data. Saved results are limited to 500, and the oldest are deleted when that limit is exceeded. Monitoring keeps only the most recent 32 results for each target. The DNS changer's recent queries are kept only in memory and are cleared when you clear them or when the app's process ends.
  • Information that reaches third-party services (such as Cloudflare, Team Cymru, DNS providers, and Whois servers), such as your IP address and the names you look up, is retained according to each service's own policy.

9. International Data Transfers

We are based in Japan. The servers used for crash diagnostics, hosting the list of our other apps, the public IP and provider lookup, DNS, and Whois may be located in various countries. When you use these features, the information described in Sections 2 and 3 (such as your IP address and the names and targets you look up) may be processed outside your country of residence. Each service handles it according to its operator's own privacy policy.

10. Your Rights

Depending on where you reside (e.g., the EEA, UK, California, Japan), you may have the right to request access to, correction of, or deletion of the limited information we hold. You can:

  • Turn off "Look up the public IP" in the settings to stop public IP lookups with Cloudflare and Team Cymru
  • Turn off "Show who runs each hop" in the traceroute settings to stop lookups with Team Cymru
  • Turn off the DNS changer and monitoring at any time, and withdraw the VPN permission in Android's settings
  • Withdraw the location and notification permissions in your device settings at any time
  • Delete saved results (Saved tab), clear recent hosts and device names (Settings), or remove a device from the list ("Forget"); or uninstall the app or clear its data to erase all the data stored on your device
  • Contact us at the address below to make a request regarding the information we hold

11. Children's Privacy

Network Tools Pro is not directed to children under the age of 13 (or the minimum age applicable in your region). If we inadvertently collect information from such a child, we will delete it promptly upon being contacted.

12. Changes to This Policy

This Privacy Policy may be updated from time to time. The latest version is always published at this URL together with its effective date. We will also notify you within the app of significant changes as appropriate.

13. Contact

For questions about privacy, data requests, or to report concerns, please email us at .

CloudEx Inc. (Japan)

Effective Date: October 6, 2026