HUSH

HUSH BROWSER / HELP & PRIVACY

Privacy policy

What Hush Browser handles, what stays on your device, and when information leaves it.

Last updated: 4 September 2026

1. Who this policy covers

This policy applies to Hush Browser (also shown as Hush), Android package com.apptoace.hushbrowser, its optional reading-assistant service and this website. The Hush Browser developer is responsible for these services. For privacy questions or requests, contact mrtckr.developer@gmail.com. Hush does not require a Hush account.

2. Data on your device

Hush processes website addresses and page content to display pages and block matching requests. Normal browsing history (URL, title and visit time), bookmarks, cookies, website storage, cache, preferences and protection counters are stored locally. Hush does not upload your complete browsing history or vault to a developer-operated account or cloud-sync service.

Private tabs use a separate browser profile and are not added to normal browsing history. Their site data is cleared when the private session ends; abandoned private profiles are removed on a later app start. Private tabs do not hide your IP address from websites or your network. Downloads and files you export remain outside the private session.

3. Device protection and DNS

When you enable protection for all apps, Hush uses Android VpnService to route DNS lookups to a local filter on your device. Blocked names are answered locally. Allowed lookups are sent to your selected DNS resolver. Ordinary browsing traffic is not routed through a remote Hush VPN server, and this feature does not change your public IP address.

DNS providers can receive queried domain names, your IP address and connection metadata. Choices include Cloudflare (the default), Google, Quad9 and the network’s own resolver.

DNS encryption can fall back. If the chosen DNS-over-HTTPS service cannot be reached, the current app can use the network’s resolver without encryption and displays a fallback status. Selecting the network resolver also uses unencrypted DNS. DNS protection does not encrypt all device traffic.

4. Optional reading assistant

If the reading assistant is available and enabled, opening it starts a summary request. The current page’s URL, title and extracted text, your questions and conversation context are sent over HTTPS to the Hush service hosted by Cloudflare and then to OpenAI to generate a response. Long page text is limited before sending. Content from signed-in pages may include personal information; do not use this feature for content you do not want sent to these services.

The app sends a random installation identifier to the Hush service for rate limiting. Cloudflare processes connection metadata, including your IP address. The proxy can use a hash of the IP address if an installation identifier is unavailable. The identifier is not an advertising ID. The assistant is unavailable in private tabs and can be turned off in Settings. Conversation state is held in app memory and cleared when the assistant is closed; that does not undo server-side processing.

5. Personal files and permissions

Files you select for the private vault are encrypted on the device using AES-GCM. Vault files, thumbnails and unlock material are held in app-private storage; Hush does not upload them. Original files you import may remain in their original location, and exported copies are no longer protected by the vault. If you forget your vault code, we cannot recover the encrypted files.

Network access loads pages, DNS results, filter updates and assistant responses. Android’s VPN permission enables local device-wide DNS filtering. Notification and foreground-service permissions support ongoing protection and downloads. System file pickers grant access to the files you choose; older Android versions may request storage access for downloads. The current app does not request contacts, precise location, microphone or camera permissions. Android app backup and device-transfer backup are disabled in the app configuration.

6. Usage analytics and crash reports

The release app uses Google Analytics for Firebase to understand app usage and Firebase Crashlytics to diagnose crashes and unresponsive sessions. Collection is enabled by default in the release app. These services process app-instance and installation identifiers, app/session activity, app version, device model, operating-system version and diagnostic information. Analytics can derive approximate location from network information; Hush does not request device location permission for this purpose. Crash reports can include exception messages, stack traces, relevant application state and recent Analytics events. Data is sent to Google/Firebase over encrypted connections.

Advertising-ID collection, advertising storage, ad-user-data consent and ad-personalization signals are disabled in the app configuration. Automatic screen reporting is disabled. Hush does not add visited URLs, search queries, page text, AI conversations, passwords or vault contents as Analytics event parameters or Crashlytics custom keys/logs. We do not assign an account-based Analytics user ID. Private browsing does not disable app-level usage or crash reporting. Debug and store-screenshot builds do not include these SDKs.

Provider information: Firebase privacy and security and Google Privacy Policy.

7. Other recipients and services

Websites you visit and the search engine you choose receive the requests you make to them. Hush retrieves filter lists from EasyList, the Adblock Plus mirror and AdGuard’s repository on GitHub; those hosts receive the network information needed to serve downloads. Their own policies apply to their services.

Cloudflare hosts this website and the reading-assistant proxy. OpenAI processes reading-assistant requests. Email providers process support messages you send. These providers may process data outside your country. We use data to provide requested features, respond to inquiries, protect the services and meet legal obligations. We do not sell personal data or use browsing activity for advertising profiles. The release app uses Google Analytics for Firebase and Firebase Crashlytics as described below. This site does not include analytics scripts or advertising SDKs.

Provider information: Cloudflare, Cloudflare DNS, Google Public DNS, Quad9, OpenAI API data practices, GitHub.

8. Retention and deletion

  • History: entries older than 90 days are pruned when the app runs its cleanup. You can delete history earlier.
  • Local data: bookmarks, preferences, counters and vault contents remain until you remove them or clear the app’s storage/uninstall it. Cookies may also expire according to the website. Clearing browsing data does not erase the vault or exported files.
  • Assistant: the Hush proxy does not maintain a conversation database. It processes requests and streams responses; operational logs may contain request metadata and limited upstream error details. Current Cloudflare Workers log retention is up to 7 days, depending on the plan. Provider security and legal retention may differ.
  • OpenAI: its API policy states that inputs and outputs are not used to train models by default and may generally be retained for up to 30 days for service and abuse monitoring, subject to applicable exceptions and legal requirements. See the linked provider policy.
  • Firebase: Crashlytics retains crash reports and associated identifiers for 90 days before starting deletion from live and backup systems. Analytics event/user retention depends on the configured Analytics property settings; aggregated reports can follow different retention rules. Clearing local app data does not erase reports already sent to these providers. Because Hush has no account, we may not be able to link every installation identifier to an email-based deletion request.
  • Support: we receive your email address, message and any attachments you choose to send. We keep correspondence as needed to resolve the request, handle related follow-ups and meet applicable legal or security obligations. You may request deletion by email.

See the data deletion guide for step-by-step instructions. We cannot remotely delete files that exist only on your device or erase a third-party website’s records.

9. Security and your choices

Hush uses on-device vault encryption and HTTPS for the assistant service. Browsing can still use HTTP if you allow an exception, and DNS fallback can be unencrypted as described above. No software can guarantee complete security, anonymity or that every ad and tracker will be blocked.

You can disable the assistant, stop device-wide protection, change the DNS provider, close private tabs and clear local data. Depending on applicable law, you may request access, correction or deletion of information held by the developer, object to certain processing, or contact your local data-protection authority. Email us with enough information to identify the request; never send a vault code or password.

10. This website and support

This site has no account, contact form, advertising pixels or analytics scripts. Fonts and assets are served from this site. Cloudflare necessarily processes web requests and may handle network/security metadata to deliver and protect the site. Clicking an email link opens your email app; nothing is submitted until you send the message.

11. Children and updates

Hush does not ask for your age or create age profiles. If you believe a child has sent personal information to our support service or through the reading assistant, contact us so we can address the request under applicable law.

We may update this policy when the app or its data practices change. The updated policy and its date will appear here; material changes may also be communicated within the app. Contact: mrtckr.developer@gmail.com.