Privacy Policy

NFC Tag Tools

Read, Write, Automate — without the confusion. Honest NFC: everything stays on your device by default. We never clone secure cards.

Effective Date: October 02, 2026 Application: NFC Tag Tools (com.winterfieldintelligence.nfctools) Developer: Winterfield Intelligence

1 Introduction

Welcome to NFC Tag Tools (“we”, “our”, or “us”), developed and published by Winterfield Intelligence. This Privacy Policy explains how data is handled when you download, install, and use NFC Tag Tools (Package ID: com.winterfieldintelligence.nfctools).

The app reads, writes and automates standard NDEF NFC tags entirely on your phone. There are no accounts, no analytics, no advertising SDKs, and no Winterfield Intelligence servers receiving your data — in full compliance with this Policy and Google Play Developer Program Policies, including the User Data policy.

2 No User Account & No Login Required

NFC Tag Tools does not require registration, login, or account creation.

  • You can use every feature immediately without providing personal information.
  • We do not collect names, email addresses, phone numbers, or passwords.
  • We do not create or maintain online user accounts for this app.

3 How NFC Is Handled (Honesty Engine)

To fix false expectations, the app includes a Compatibility Engine with plain-language results — never error codes:

  • Writable tags (NTAG213/215/216, MIFARE Ultralight, Topaz, NDEF Formattable): full read / write / copy allowed.
  • Protected tags (MIFARE Classic, DESFire, MIFARE Plus, FeliCa, IsoDep secure element, bank / access / transport / hotel / amiibo): the app shows Read-Only ID (UID, ATQA, SAK, ATS) and explains it cannot be imported, copied or emulated for security reasons. Copy/Emulate buttons are disabled with a tooltip.
  • The app never claims to clone UIDs, copy secure cards, open doors, or act as a payment / hotel / amiibo card. No root or private-key bypass is attempted.
  • Scanning is foreground-only by default with a prominent Pause NFC toggle. When Paused, the app ignores all tags (e.g. glucose-monitor sensors, contactless cards in a phone case). No background NFC service runs by default and nothing persists after uninstall.
Note: Tag IDs you scan are stored only in your on-device History (see §4) so you can reuse them. They are never uploaded anywhere.

4 Information Stored on Your Device

A. Scan history (auto-save). UID, tag type, tech list, NDEF records decoded human-readable, and timestamps live in an app-private Room database so your list never disappears when the app closes.

B. Profiles you save. Tag profiles (records + byte size) and task profiles (automations, optional UID link) are kept on-device with auto-backup to files you choose.

C. Settings. Pause state, foreground-only, sound/vibrate, auto-save, HCE payload, and theme live in DataStore preferences.

D. Exports you explicitly create. Only when you tap Export/Share is a .txt / .csv / .json dump written via the Storage Access Framework to a location you choose or the share target you pick. We never create, upload, or keep copies of it.

Note: All of the above stays on your device. It is never uploaded to, transmitted to, or stored on any external server by Winterfield Intelligence, because the app contains no sync, analytics, or advertising code.

5 Device Permissions

Permissions are requested in-context with a rationale, only when a feature you added needs them. Denying a permission simply skips the steps that need it.

  • NFC — reading/writing NDEF tags and HCE emulation (foreground dispatch only).
  • Vibrate — haptic confirmation on scan/write.
  • Notifications (post) — “Executed by Tag: …” confirmations and write results (Android 13+ asks at runtime).
  • Bluetooth Connect/Scan — Bluetooth toggle / pair tasks (Android 12+ shows a permission flow instead of silent fail).
  • Nearby Wi-Fi Devices / Location (up to Android 13 limits) — Wi-Fi tasks and reading SSIDs; location is used only to resolve the Wi-Fi name when Android requires it.
  • Internet — only for HTTP GET / webhook / MQTT tasks and links you add; requests go directly to addresses you typed.
  • Camera / Files / Media — only if you add flashlight, file, or media-control tasks. Media tasks use the system MediaSession API (works with Spotify/YouTube) and do not collect listening history.

The app does not request SMS read/send, contacts harvesting, microphone recording, or Accessibility access. Calls/SMS always open the system dialer/composer for you to confirm — no silent sending.

6 Tag Emulation (HCE) — Limits

Emulation uses Android Host Card Emulation for standard NDEF only (Text, URL/URI, Phone, SMS, Email, vCard, Wi-Fi). It is explicitly stated in-app that:

  • UID emulation, door-badge, payment, hotel-key, transport, and amiibo emulation with private keys are not possible and not attempted.
  • Emulating a protected profile is blocked with the same Protected message as reading.
  • iOS cannot emulate (CoreNFC reads NDEF only) — stated before you try.

7 Network Use You Configure

The app has no background network activity of its own. Network is used only when you add a step that needs it — a webhook URL you type, or opening a link — in which case that request goes directly to the address you specified, under that service's policy.

8 Data Sharing, Selling & Third-Party Access

We do not sell, rent, trade, or share any user data with third parties.

NFC Tag Tools contains no behavioral tracking, advertising identifiers, analytics scripts, crash-reporting SDKs, or social SDKs that profile activity across apps or websites. We do not track your IP address or device identifiers.

9 Children's Privacy (COPPA & Google Play Families Policy)

NFC Tag Tools is a general-audience utility.

  • We comply fully with the Children’s Online Privacy Protection Act (COPPA) and Google Play Families Policies.
  • We do not knowingly collect any personal information from children under the age of 13 (or under 16 where applicable law requires).
  • Because the app has no accounts, personal-data forms, analytics, or ads, no children's personal data is ever obtained.

10 Data Retention & User Control / Deletion

Because everything is stored locally on your device, you hold full control at all times:

  • Delete history & profiles: anytime inside the app (History Clear, profile Delete, per-record Delete).
  • Clear App Data: Android Settings > Apps > NFC Tag Tools > Storage > Clear Data.
  • Uninstall: uninstalling permanently removes all locally stored data. Uninstall Cleanup Guarantee: no residual background service or plugin remains (foreground dispatch only).
  • Exported dumps: .txt / .csv / .json files you saved or shared remain wherever you put them until you delete them yourself.

There is no server-side copy to delete, because none exists.

11 Security

History, profiles, and files live in app-private storage and the app sandbox, which no other app can read. By keeping everything on-device with no login servers, the attack surface is minimal. Tag Lock / Password features warn with double-confirm because locking is permanent.

No method of electronic storage is 100% secure, so please also protect your device with a screen lock and keep Android up to date.

12 Changes to This Privacy Policy

We may update our Privacy Policy from time to time to reflect changes in legal requirements or app features. Any updates will be posted on this page with a revised “Effective Date” at the top of the policy. The same updated text ships inside the app.

13 Contact Us

If you have any questions, suggestions, or concerns regarding this Privacy Policy or NFC Tag Tools, please contact us:

📞 Phone
🏢 Publisher
Winterfield Intelligence
📱 Application
NFC Tag Tools (com.winterfieldintelligence.nfctools)