FAQ

The analysis found nothing. Is my phone safe? #

No. It means nothing matched the indicators and heuristics available today. Spyware that has never been documented — especially sophisticated, state-sponsored tools — will not be detected, and neither will new, simpler threats that have gone unnoticed so far. Keep the acquisition and scan it again in the future, when new indicators are published. Read more in risks and warnings.

There are also other factors relevant to your privacy that the app does not check: access to your cloud accounts, phone tracking features, and so on.

The analysis found something. What now? #

Do not panic, and do not delete anything: the acquisition is evidence. Contact a support helpline operating in your country, or people you trust with this. They may ask you to Export or Share the encrypted acquisition for a deeper look. Keep in mind that the preliminary result might be a false positive: do not take it for granted; treat it as a signal that should be double-checked by somebody more technical.

Does Bugbane send my data anywhere? #

No. Acquisitions and analysis results stay on your device, encrypted. The only network traffic is the periodic download of updated indicators, done through an Oblivious HTTP relay so the update server never sees your IP address. Sharing an acquisition happens only when you decide to, and the archive is encrypted.

Which Android versions are supported? #

Android 11 or newer. On older devices, use AndroidQF or MVT from a trusted computer.

Is it safe to enable Wireless Debugging? #

Only on a trusted network, and only while you use it. Turn it off after each acquisition — the app reminds you. If your device is missing the fix for CVE-2026-0073 (Android 14–16), Bugbane warns you: in that case update your system, or use a personal hotspot. Details in risks and warnings.

Why do I have to tap “Build number” seven times? #

That is how Android unlocks Developer Options, which contain the Wireless Debugging interface Bugbane uses to collect data. It is a standard Android feature, not a modification of your device. Disable Developer Options again after each session.

I lost the export passphrase. Can I recover it? #

No, as it is shown only once and Bugbane does not store it. Export the acquisition again: you get a new archive with a new passphrase.

I forgot my acquisition password. What happens? #

Acquisitions already stored on the device cannot be opened anymore; there is no recovery. New acquisitions keep working. You can remove or change the password in the app settings, but only while you still know it (or can unlock with your screen lock, depending on your setup). If you want to reset the app, you can do so from the Android settings; that allows you to repeat the onboarding procedure and set a new password.

What is the difference between Export and Share? #

Both produce the same encrypted archive with a one-time passphrase. Export saves it to a file you choose. Share hands it directly to another app (Signal, email, …) without saving it first. In both cases, send the passphrase through a different channel than the archive.

Can I scan an old acquisition again? #

Yes. Open it in the Acquisitions tab and tap “Run Analysis”: the scan uses the most recent indicators the app has. This is the main reason to keep acquisitions: today’s data can reveal a past compromise once new indicators come out.

My question is not here #

Write to bugbane@osservatorionessuno.org, or open an issue on GitHub.