Privacy Policy
# Privacy Policy
## NDEF Commander
**Last Updated: September 2026**
## Overview
NDEF Commander (“the App”) is an application developed by Dangerous Things (“we”, “us”, or “our”) for reading, editing and writing data on NFC tags and implants, and for running actions when a tag is scanned. We are committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
**The short version:** Your data stays on your device. We cannot access your tags, scan results or rules. The only request the App makes on its own is a check for app updates, which carries no personal information.
## Information We Collect
### Information Stored Locally (On Your Device Only)
The following data is stored exclusively on your device and is never transmitted to us:
- **Scan Results** - The contents, UIDs and memory layout of tags you scan. These are held in memory only and are cleared when the App restarts.
- **Scan Action Rules** - Rules you create, including any UIDs, text, web addresses, phone numbers, email addresses and app names they contain. These are saved on your device so they survive a restart.
- **Appearance Settings** - Your theme, colour-vision palette and animation speed.
We cannot access this data. It remains entirely on your device.
### Information Transmitted by the App
**App Updates** - Each time the App starts, it checks with our update provider, Expo (expo.dev), for a newer version of the App. The request includes a random installation identifier created by the App, the platform, the App’s version details, and identifiers of the update currently installed. Like any internet request, it also reveals your IP address to Expo. It contains no tag data, rules, or account information. Expo uses it to deliver updates and may provide us with aggregate statistics, such as how many installations have received an update. Expo’s handling of this data is described in its privacy policy at Privacy policy — Expo.
**Actions You Configure** - Scan action rules can send data off your device, but only where you direct them to:
- An HTTP action sends a request to the web address you enter, including any tag details you place in it with variables such as `{TAG-ID}` or `{NDEF-TEXT}`. That data goes to the server you choose and never passes through Dangerous Things.
- Open, dial, SMS, email, launch and “system default” actions hand the address, number, message or tag record to the app on your device that handles it, such as your browser or messaging app.
- Copy actions place text on your clipboard, where other apps on your device may be able to read it.
**Tags You Write** - Data you write to a tag is stored on the tag itself, where any NFC reader can read it unless the tag is locked or otherwise protected.
**Dangerous Things Website** - Tapping the dangerousthings.com link opens our website in your browser. The link carries no tracking parameters.
### Information We Do NOT Collect
- We do not collect location data
- We do not collect contacts, call logs, or messages
- We do not collect your tag contents, scan history, or scan action rules
- We do not use third-party analytics, crash reporting, or advertising SDKs
## How We Use Information
### Local Data
- Scan results are used to display and edit tags, and are cleared when the App restarts.
- Scan action rules and appearance settings are saved so the App behaves the same after a restart.
- Speak actions are read aloud by the text-to-speech engine installed on your device.
- When you use **Choose File** or **Paste**, the App reads only the file or clipboard item you select, in order to build a tag record. Paste keeps a temporary copy in the App’s private cache.
- To offer apps in pickers, the App reads the list of launchable apps installed on your device. This list is used on your device only.
## Data Storage and Security
### Local Storage
- Data is protected by Android’s application sandboxing
### Data Sharing
We do not sell, trade, or share your personal information with third parties.
The only external communication is:
- **App Updates** - The automatic update check with Expo, our update provider, described above.
- **Actions You Configure** - Requests and hand-offs you set up in scan action rules.
- **Dangerous Things Website** - When you choose to open our website.
## Data Retention
### Local Data
Scan results remain until you restart the App. Scan action rules, appearance settings and the update installation identifier remain on your device until you:
- Delete them in the App (scan action rules)
- Clear app data
- Uninstall the App
## Your Rights
You have complete control over your data:
- **Access** - All your data is stored locally on your device and is visible in the App
- **Deletion** - Delete rules in the App, or remove everything by clearing app data or uninstalling the App
- **Control** - Scan actions are off by default. While they are off, the App does not respond to tags scanned outside it
## Children’s Privacy
NDEF Commander is not directed at children under 13. We do not knowingly collect information from children under 13. Dangerous Things implants require a minor surgery and are intended for adults.
## Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Updating the “Last Updated” date at the top of this policy
- Posting the new policy in the App and on our website
Your continued use of the App after changes constitutes acceptance of the updated policy.
## Permissions Explained
NDEF Commander requests the following Android permissions:
| Permission | Purpose |
|—|—|
| NFC | Required to read and write NFC tags and implants |
| Internet | Used to check for App updates, and to send HTTP requests you configure in scan action rules |
| Network state | Used to check whether a connection is available before looking for updates |
| Storage (Android 12 and earlier only) | Declared by the App’s file library; the App reads only files you choose |
We do not request permissions for camera, microphone, contacts, or location.
## Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
**Dangerous Things**
- Email: privacy@dangerousthings.com
- Website: https://dangerousthings.com
- Support: support@dangerousthings.com
## Summary
| What | Collected? | Shared? |
|—|—|—|
| Tag contents and scan history | No | No |
| Scan action rules | No | No |
| App update check* | Yes | With Expo only |
| Analytics/usage data | No | No |
| Advertising data | No | No |
| Device identifiers | No | No |
| Location | No | No |
**Your data. Your device. Your privacy.**
\* A random installation identifier and version details, sent to Expo when the App checks for updates. It contains no personal information, and it is reset when you clear the App’s data or reinstall it.
I think this is the first app on Android that can write to alternate sectors such as those found on the NTAGI2C 2k. Are you xSIID folks excited?
This one was a bit of a rushed side quest. Once it hits the playstore, it’ll be in closed testing. Want to participate? Go here.





