Privacy policy
1. Who we are
This policy describes the data practices of the Webora mobile application ("Webora", "the app", "we", "us"). Webora is a web browser. Your browsing data stays on your device — no accounts, no cloud sync, no analytics, no behavioural tracking SDKs.
2. What data Webora handles
The app stores the following on your device only, in app-private SQLite:
| Category | Examples | Where it lives | Cleared by |
|---|---|---|---|
| Browsing history | URLs, page titles, timestamps | Local SQLite | Settings → Clear browsing history, or uninstall |
| Bookmarks | URLs, titles | Local SQLite | In-app delete or uninstall |
| Open tabs | URLs, titles, scroll state | Local SQLite | Closing the tab or uninstall |
| Site cookies & WebView storage | Set by the websites you visit | Android WebView storage | Browser data clear, system settings, or uninstall |
| Settings | Theme, search engine, ad-blocker, page width, cursor, personalised-ads preference | Local SQLite | Reset to default or uninstall |
Incognito tabs do not write history, are not persisted across launches, and use a separate cookie store.
We do not transmit any of the above to any server.
3. What goes over the network
Webora is a browser, so the obvious answer is "anything you ask it to load." Beyond that, the app itself initiates a small number of background requests:
3.1 Search suggestions
When you type in the address bar, Webora sends your partial query to the suggestion
endpoint of your currently selected search engine — for example
Google's suggestqueries.google.com, DuckDuckGo's duckduckgo.com/ac,
or Bing's www.bing.com/osjson.aspx. These requests are made directly from your
device to the search provider. Webora does not see them.
3.2 Favicons
For pages you visit, the app fetches favicon images via Google's S2 favicon service:
https://www.google.com/s2/favicons?domain=<host>&sz=64. This causes
Google to see which hostnames you visit as favicons are requested. If you do not want
this, you can block www.google.com/s2/favicons via the Block ads &
trackers toggle.
3.3 Over-the-air updates (optional)
Webora uses Expo's OTA update system to deliver bug-fix JavaScript bundles without a
full Play Store release. On launch the app contacts u.expo.dev to check
for an update. The check sends Expo your installation ID, runtime version and channel.
No personal data is sent.
3.4 Sites you visit
When you load a page, that page's host (and any third-party hosts it embeds) see what an ordinary web browser would see — your IP address, the page you requested, the HTTP headers, etc. With Desktop mode on, Webora sends a desktop user-agent. With Block ads & trackers on, Webora blocks many known ad and tracker domains before any request leaves your device.
3.5 AdMob (advertising)
See §10 for details. AdMob requests are sent to Google's ad-serving infrastructure
(*.googleadservices.com, *.googlesyndication.com) whenever an
ad slot is on screen.
4. Permissions
The app requests the following Android permissions:
| Permission | Purpose |
|---|---|
INTERNET | Load web pages, fetch favicons, contact AdMob |
ACCESS_NETWORK_STATE | Detect offline state to show the right error UI |
VIBRATE | Subtle haptic feedback on button presses |
AD_ID | Read the Android Advertising ID so AdMob can serve relevant ads. Reset / opt out via Android Settings → Privacy → Ads. |
The app does not request the microphone, camera, location, contacts, calendar, SMS, accounts, accessibility services, or storage permissions.
5. Children
Webora is rated for 13+. AdMob is configured with
tagForChildDirectedTreatment: false and maxAdContentRating: T
(Teen) so the ads served are filtered accordingly.
6. Third-party services we use
| Service | Purpose | Data shared |
|---|---|---|
| Google AdMob | Show in-app ads (§10) | Advertising ID, IP address, app version, language, coarse location derived from IP, time of impression |
| Google Favicon Service | Display favicons next to URLs | Hostname of each page you visit |
Expo Updates (u.expo.dev) | Deliver bug-fix JS bundles between Play releases | App installation ID, runtime version, channel |
We do not use: analytics SDKs, crash reporting, attribution / install tracking, social-login SDKs, push-notification systems, or payment SDKs.
7. Data retention & deletion
All app data is on-device. It lives until you clear it from in-app settings, clear app data via Android Settings, or uninstall. See our data deletion page for step-by-step instructions. AdMob retains advertising data according to Google's privacy policy.
8. Changes to this policy
If we make material changes (e.g. a new feature that touches the network in a new way, or we change ad providers), we will update this document and bump the Effective date at the top. The current version is always available at this URL and linked from inside the app under Settings → About → Privacy policy.
9. Contact
Questions, requests, or reports: hasana3n@gmail.com.
10. In-app advertising (Google AdMob)
Starting with v2.0, Webora shows ads inside the app to sustain ongoing development. The ad provider is Google AdMob.
Where ads appear
- A small anchored adaptive banner at the bottom of the Home, Bookmarks, History, and Settings screens, sitting above the floating navigation dock.
- One native advanced ad tile blended into the speed-dial grid on Home. Labelled "Ad" / "Sponsored" in its corner, as required by AdMob policy.
Ads are never shown on the actual web-browsing surface, in the tab switcher, in sheets / modals, or anywhere else inside the app.
What AdMob receives
When an ad slot is on screen, the Google AdMob SDK sends a request to Google's ad-serving infrastructure containing:
- Your Advertising ID (or
0000…0000if you have opted out of personalised ads in Android settings) - Your IP address (Google uses this to derive coarse location)
- The app package (
com.webora.browser) and version - Device language, time-zone, and screen size
- The fact that an ad slot was requested in Webora
Webora does not send AdMob your browsing history, your bookmarks, the URL of the page you are currently viewing, or any content from the WebView.
Personalised vs non-personalised ads
By default, Webora requests non-personalised ads from AdMob. You can opt in to personalised ads via Settings → Privacy → "Allow personalised ads". You can also globally opt out at the Android OS level via Settings → Privacy → Ads → "Opt out of Ads Personalization".
Resetting / limiting your Advertising ID
The Advertising ID can be reset or disabled at any time from
Android Settings → Privacy → Ads. Resetting issues a fresh ID; disabling
causes apps to receive 0000…0000 as if you had opted out completely.
Google's policies
AdMob is governed by Google's privacy policy and ad-personalisation help.