This page is written to be shown to users, in plain language, and to stay accurate to the actual engine (:core:safeguard, :core:safeguard.adguard, :core:safeguard.rescue).
The short version
AppSquach reviews security-related characteristics of the apps installed on your phone and gives each one a simple rating so you can decide whether it deserves a closer look.
A high rating does not mean an app is malicious. AppSquach cannot promise to find every harmful app. Always read the reasons AppSquach shows before removing anything.
What AppSquach looks at
For every installed app, AppSquach considers a combination of:
Powerful Android access it currently holds — an enabled accessibility service, notification access, device-administrator control, permission to appear over other apps, or a battery-optimisation exemption. AppSquach reads whether other apps hold these; it does not run an accessibility service of its own.
Where the app came from — a recognised app store, another store, a file/browser download, side-loading, or the system image.
Whether it behaves like a normal app — for example, an app with powerful access but no icon and no way to open it is unusual.
Permission combinations that don't fit the app's apparent purpose — for example, a "flashlight" or "cleaner" that asks for contacts, SMS, the call log, or the microphone.
Launcher and keyboard behaviour — an app that has quietly become your Home screen, or a keyboard that isn't a recognised one, is called out so you can switch back.
Clusters of advertising / tracking SDK components — one is meaningless; a large cluster inside a single-purpose "utility" is context.
Recent changes — AppSquach remembers the last scan, so it can tell you an app just gained accessibility access rather than only that it has it.
For the optional "an ad just popped up — find the source" feature, and only if you have granted Android's Usage Access permission after seeing the in-app explanation, AppSquach also reads roughly the last 90 seconds of which apps came to the foreground, uses it to rank the likely source, and then discards it. That window is never stored or sent anywhere.
How the rating is decided
AppSquach does not add up points into a "threat score". A set of context-aware rules each look at the facts and either stay silent or contribute a plain-language reason with a severity. The app's rating is the highest severity any rule produced.
Rating (Phone Safety)
Meaning
Nothing stands out
No notable signals.
Good to know
One expected capability worth being aware of.
Worth a look
Something you may want to check and confirm you recognise.
Please review
A combination of things a person would likely want to look at sooner.
There is no "virus", "malware", "infected", "hacked" or "keylogger" rating, by design.
Protected apps
Core Android components, System UI, Settings, the permission controller, the package installer, Google Play services and store, your current launcher, known manufacturer system services, and AppSquach itself are treated as protected and are never offered for removal.
What AppSquach does with a finding
Shows you the app, its rating, and the reasons.
Lets you Keep it (so AppSquach stops flagging it, unless it materially changes) or Lock it.
Lets you start a removal — which always opens Android's own uninstall confirmation; AppSquach never removes an app itself, and re-checks that the app is not protected against fresh data first.
Optionally lets you send a paired family helper a review request for that one app.
Limits you should know about
AppSquach can only see what Android lets a normal app see. Some capabilities can only be inferred from an app's declared permissions, not its actual behaviour — AppSquach marks these clearly and weights them low.
Results can be wrong in both directions: a legitimate app may be flagged, and a harmful app may not be.
AppSquach is a review aid, not antivirus, and not a guarantee of safety.