Last updated: 2026-07-19
CPU-Y ("the app") is a device-information and hardware-diagnostics utility. This policy explains what the app accesses and what it does (and does not) do with that information.
CPU-Y does not collect or upload the device information it reads. CPU, battery, sensor, Wi-Fi and other hardware data is shown to you on your own device and is never sent to us or stored off-device. There are no accounts.
Three third-party SDKs do send limited data off-device, and none of them receive your hardware readings:
All of the following are read on-device and displayed only in the app's UI (or an on-device notification/widget you enable). None of it is uploaded, logged off-device, or shared with anyone.
| Data / capability | Why | Leaves device? |
|---|---|---|
| CPU, RAM, storage, battery, thermal, GPU, display, camera specs | Show live/static hardware info | No |
| Sensors (live values) | Sensor list + readings screen | No |
Wi-Fi info / scan (ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, ACCESS_WIFI_STATE) | Show connected Wi-Fi name (SSID), channel, signal, link speed | No |
Cellular network type (READ_PHONE_STATE) | Show mobile network type/operator | No |
Bluetooth on/off + scan (BLUETOOTH_SCAN, BLUETOOTH_CONNECT; BLUETOOTH/BLUETOOTH_ADMIN on Android ≤11) | "Nearby devices" Bluetooth scanner tool. Scanning is declared neverForLocation — it is not used to derive your location | No |
Microphone (RECORD_AUDIO) | Microphone hardware test — live input-level meter only | No (audio never recorded or saved) |
Live network throughput (ACCESS_NETWORK_STATE, TrafficStats) | Show real-time download/upload speed | No |
Local network probing (INTERNET) | "Network mapper" discovers hosts on your local Wi-Fi (LAN) | No external servers contacted |
Vibration (VIBRATE), flashlight, biometric availability (USE_BIOMETRIC), brightness | Hardware self-tests. Biometric is checked for availability only — no fingerprint/face data is read, requested or stored | No |
Audio routing (MODIFY_AUDIO_SETTINGS) | Earpiece test — routes the test tone to the earpiece speaker | No |
NFC (NFC) | NFC hardware test — detects a tag while that test screen is open | No |
List of installed apps (QUERY_ALL_PACKAGES) | "App Analyzer" tool — groups the apps on your device by target/min SDK, installer, category and system/user. Only app metadata (package name, label, SDK level) is read — never app content | No |
Per-app network usage (PACKAGE_USAGE_STATS, "Usage access") | "Data usage" tool — shows how much mobile/Wi-Fi data each app has used, read from Android's own accounting | No |
Draw over other apps (SYSTEM_ALERT_WINDOW) | Optional floating live-stats window, enabled by you in Settings and stoppable from its notification | No |
Ongoing status-bar monitors (FOREGROUND_SERVICE, FOREGROUND_SERVICE_SPECIAL_USE, POST_NOTIFICATIONS) | Optional notifications for live network speed and/or battery temperature/current, toggled by the user | No |
The microphone is used only to display a real-time loudness meter during the microphone test; no audio is recorded, stored, or transmitted. The app itself requests location permission only because Android requires it to read the connected Wi-Fi name (SSID) and scan results, and the app does not use it for your geographic location. However, when you grant location permission, the bundled advertising SDK (Start.io) may access your approximate and precise location and share it for ad targeting — see Advertising below. You can decline or revoke location permission at any time; the app still works, only the Wi-Fi name is hidden.
The app displays ads through Start.io (formerly StartApp). To serve and measure ads, that SDK may collect and share with Start.io a device advertising ID, limited technical/diagnostic data (e.g. device model, OS version, IP address), and — when you have granted location permission — your approximate and precise location, used for ad targeting. This is standard for mobile advertising and is governed by Start.io's own privacy policy: https://www.start.io/policy/privacy-policy/. We (the developer) do not receive or store your personal data from this. You can reset or opt out of ad personalization via your device's Settings › Privacy › Ads (advertising ID).
The app shows a banner above the bottom bar, and occasionally a full-screen ad when you open a screen from the Home or More tab. Full-screen ads are rate-limited — never during the first few actions after you open the app, and at most one every few minutes however long you browse. The SDK's launch ("splash") and return-to-app formats are switched off, so an ad never greets you when you open the app or come back to it. Ads are not shown at all on the benchmark, stress-test, throttle, FPS or storage-speed screens, so they cannot affect the measurements the app reports.
The app uses Firebase Crashlytics (Google) to report crashes and errors, and Firebase Analytics to attach basic usage/device context to those reports. When the app crashes or logs a handled error, a report is sent containing technical diagnostics such as the stack trace, device model, OS version, app version, and a random installation identifier.
These reports never contain the hardware readings the app shows you — no CPU/battery/sensor values, no Wi-Fi name (SSID), no BSSID/MAC, no serial number or IMEI, and no location. This data is used solely to find and fix bugs, and is governed by Google's privacy policy: https://policies.google.com/privacy.
We (the developer) do not sell your data. Third-party data sharing is limited to the SDKs described above: Start.io (advertising identifier, technical data, and — with your permission — approximate and precise location, to serve and measure ads) and Firebase Crashlytics / Analytics (crash diagnostics and basic usage/device context, to fix bugs). The hardware information the app reads from your device is never shared with either of them, or with anyone else.
The only things the app persists on your device are your own settings (theme, accent, language, temperature unit, refresh rate, monitor/widget toggles, onboarding flag, and hardware-test pass/fail marks) via Android's local storage. This never leaves the device and is removed when you uninstall the app.
CPU-Y is a general-purpose utility and is not directed at children.
If this policy changes, the updated version will be posted at this URL with a new "last updated" date.