Cyber Ask Mobile Apps — Privacy Policy
Last updated: 10 July 2026
This Privacy Policy explains how Cyber Ask Ltd ("we", "us", "our") processes information in our Android applications. It applies to the apps listed below and is intended to support Play Store privacy disclosures.
1. Apps Covered by This Policy
- CE+ Validation (Android) - one-time device compliance validation for Cyber Essentials Plus assessments.
- CyberAsk Scanner (Android) - mobile client for Tenable Nessus / Tenable.io environments configured by your organisation.
If future Cyber Ask mobile apps are added, this page may be updated to include them.
2. Shared Privacy Principles Across All Apps
- We do not sell personal data.
- We do not use in-app advertising SDKs.
- We do not use behavioural profiling for marketing.
- Data is processed only for the app's operational security purpose.
- Where network transfer is required, we require encrypted transport (HTTPS/TLS).
3. App-Specific Data Processing
3.1 CE+ Validation
The CE+ Validation app collects technical metadata required to validate a device against Cyber Essentials Plus controls.
| Data Category | Specific Data Points | Purpose |
|---|---|---|
| Device Identification | Manufacturer, Brand, Model | CE+ device inventory validation |
| Operating System | OS version, API level, Security Patch level | Verify OS currency requirements |
| Security Configuration | Root status (su binaries), Encryption status, Screen lock status, Auto-lock timeout | Verify CE+ security controls on-device |
| System Status | Last boot time, Auto-update enabled | CE+ patching and update compliance |
| Administrative Status | MDM enrolment status | Device management compliance check |
| User-Provided Data | Unique validation code provided by your organisation | Link result to the correct assessment |
- Personal identifiers such as name, email address, or phone number
- Location data
- Contacts, calendars, photos, media files, or documents
- Browsing history
- Microphone or camera content
3.2 CyberAsk Scanner (Nessus Frontend)
CyberAsk Scanner lets you connect to a Nessus or Tenable endpoint that you configure. It processes connection settings and security data from your own environment.
- User-provided settings: base URL, API access key, API secret key, scanner ID, and connection preferences.
- Server-returned data: scan lists, scan status/details, hosts, vulnerabilities, plugins, groups, agents, scanners, templates, and report export output that you request.
- Local files: exported reports can be stored in app-specific storage on your device and shared by user action.
- Optional security preference: app lock using biometric or device credential.
- No Cyber Ask account is required for core app use
- No advertising IDs, ad SDK tracking, or marketing analytics
- No contacts, SMS, precise location, microphone, or camera data
- No backend proxy by Cyber Ask for Nessus credentials or scan results in normal operation
4. Permissions We Request
| App | Permission | Purpose |
|---|---|---|
| CE+ Validation | Device state/security metadata access as required by Android APIs | Read compliance-related technical posture for CE+ checks |
| CyberAsk Scanner | Internet | Connect to the Nessus/Tenable URL you configure |
| CyberAsk Scanner | Post notifications (Android 13+) | Notify when requested report exports are ready |
5. Data Use, Sharing, and Retention
- CE+ Validation: metadata is used to produce a compliance result and sent to the endpoint configured by your organisation or assessor.
- CyberAsk Scanner: API calls are made directly to the endpoint you configure; app settings are stored locally on your device.
- No sale of data: we do not sell personal data.
- No ad sharing: we do not share app data with advertising networks.
- Retention: local data remains until you delete it, clear app storage, or uninstall; server-side retention is controlled by your organisation and provider policies.
6. Security
- Encrypted transport (HTTPS/TLS) for network transmission.
- CyberAsk Scanner stores sensitive connection settings in encrypted on-device storage.
- Optional biometric/device-credential app lock is available for CyberAsk Scanner.
- No system can be guaranteed 100% secure; users remain responsible for securing their devices and credentials.
7. Children's Privacy
These apps are specialist security and compliance tools for professionals and organisational users. They are not intended for children under 13, and we do not knowingly collect data from children through these apps.
8. Your Rights and Choices
Depending on jurisdiction, you may have rights to access, rectify, erase, or restrict personal data processing. For data held in your organisation's Nessus/Tenable environment or compliance endpoint, requests should be made to your organisation's administrator or provider. For policy questions about our apps, contact us directly.
9. Contact Us
Cyber Ask Ltd
Website: https://www.cyberask.co.uk
Email: [email protected]
Phone: +44(0)7346 808791
Registered in England & Wales. Company No. 15113248.
10. Changes to This Policy
We may update this Privacy Policy as our mobile apps evolve or legal requirements change. We will update the "Last updated" date on this page when changes are published.
See Also
For the Cyber Ask Ltd website privacy policy (covering cyberask.co.uk), please see: Cyber Ask Ltd Website Privacy Policy.