Lonox Browser

Lonox Browser Privacy Policy

Effective date: 26 September 2026

Lonox Browser ("Lonox") is a general-purpose web browser published under the name Lonox Studio.

This Privacy Policy explains how information is handled when you use Lonox Browser for Android. It distinguishes information kept locally on your device, information processed by Lonox Studio's own limited backend services, and information processed by websites or third-party service providers used to provide browser features.

Lonox is a web browser. When you visit a website or use an online service, that website or service will normally receive information needed for Internet communication, such as your IP address and browser/network information, and may process information under its own privacy policy. That website processing is separate from Lonox Studio's anonymous usage-statistics system.

Privacy at a glance

  • Normal browsing information such as history, tabs, bookmarks, settings, and session state is primarily stored on your device.
  • Private browsing reduces normal Lonox persistence for supported browser-state categories, but it does not make you anonymous on the Internet.
  • Isolation is a separate restricted browsing context with additional limits for website permissions and protected content. It is not a VPN or proxy.
  • Lonox sends limited anonymous usage statistics to Lonox Studio when that setting is enabled. The setting is enabled by default and can be turned off in Lonox settings.
  • The Lonox Studio anonymous-usage payload does not contain browsing URLs, browsing history, search queries, tab contents, Android ID, advertising ID, IMEI, hardware serial, account identity, or a persistent installation UUID.
  • Cloudflare necessarily processes network information such as the connecting IP address when delivering Lonox Studio backend requests. That network processing is separate from the application-level anonymous-usage payload.
  • Some Lonox-managed Quick Access links may be commission-capable. Affiliate, redirect, and destination services may process information associated with the request and affiliate link when you use those links.

1. Information stored locally on your device

Normal browsing can create or use local browser information, including:

  • browsing history;
  • open and recently used tab/session state;
  • bookmarks;
  • Quick Access entries;
  • favicons;
  • browser settings and preferences;
  • cookies and website storage;
  • cached website files;
  • download records and downloaded files;
  • local website-protection settings and aggregate blocked-resource statistics;
  • local video/library metadata and playlist information if you use those features; and
  • other browser state needed to restore or operate normal browsing sessions.

This information is primarily stored on your device. Lonox Studio's anonymous usage-statistics system does not receive your normal browsing history, URLs, search queries, page content, tab contents, or bookmarks.

Normal browsing history can contain the URLs you visit. When a search provider includes the search terms in the resulting URL, the locally stored history entry may therefore also contain those terms.

Lonox currently does not provide a Lonox account or Lonox cloud-sync service for this browser data.

Android backup and device transfer

Lonox disables normal Android backup for its configured app-private data and excludes the configured app-private data domains from Android backup/device-transfer rules.

Files you deliberately save into Android's public Downloads collection are separate from Lonox's app-private data. Lonox does not control how Android or another service may handle those public files.

2. Websites, network information, cookies, and site data

Using any web browser requires communication with websites and Internet services. Websites you visit can receive standard network information such as your IP address and may use cookies, local storage, scripts, or other web technologies according to their own practices.

Lonox can store cookies and site data locally so websites can function normally. You can remove supported categories through Lonox's Clear Browsing Data controls.

Lonox Studio does not control how an independent website uses information that you choose to provide to that website. You should review the privacy policy of a website or service when its processing matters to you.

3. Search providers

Lonox supports external search providers. In the current release, Google is the default search provider, with DuckDuckGo and Yahoo available as alternatives.

When you submit a search, the search terms are sent to the search provider you selected so that it can return results. The provider receives and processes the request under its own privacy policy and may receive normal network information such as your IP address.

A resulting search URL can be stored in normal local browsing history.

4. Website permissions: location, camera, and microphone

Websites can request access to certain device capabilities through Lonox.

Location

A website can request location access. Lonox and Android present permission controls before location is made available through the browser engine. If you allow the request, the requesting website may receive location information and process it under its own privacy policy.

A saved location permission decision can persist through the browser engine until it is changed or cleared.

Lonox Studio's anonymous usage-statistics payload does not contain a precise- or approximate-location field.

Device location is different from the IP address used for an Internet connection. A website receives the network connection needed to load the site regardless of whether Android location permission is granted. Device location is a separate capability that a website can request.

Camera and microphone

A website can request camera or microphone access. Lonox requires the relevant browser/Android permission flow before access is allowed.

In the current implementation, website camera and microphone decisions are remembered only for the applicable browser session/process context. A new browser session, app restart, or process restart can require the website to ask again.

Isolation mode applies additional restrictions and can reject website-permission use.

Lonox does not currently provide a dedicated settings list showing every saved website-specific permission. Android app permissions for Lonox can be changed through Android system settings. Website-specific decisions handled by the browser engine can have a separate lifecycle from Android app permissions.

5. Private browsing and Isolation

Private browsing

Private browsing is designed to reduce normal Lonox-owned persistence on the device. In Private mode, Lonox does not use its normal persistence paths for browsing history, normal session state, tab previews, favicons, and related normal-tab state.

When the relevant private browser context ends, Lonox asks the browser engine to clear data associated with that private context.

Private mode does not make you anonymous on the Internet. Websites, search providers, Internet/network providers, employers or schools operating your network, and other services involved in a connection may still be able to observe or process activity.

Files you deliberately download while using Private mode can remain in Android's public Downloads storage after the private browsing session ends.

Isolation

Isolation uses a separate privacy context with additional restrictions. In the current version, Isolation can block website permission use and protected-content/DRM playback regardless of the normal protected-content setting.

Isolation is not a VPN, proxy, or Internet-anonymity service.

6. Clear Browsing Data

Lonox's Clear Browsing Data controls are intentionally limited to the categories shown in the app.

The current controls can clear:

  • Browsing history — normal Lonox history records;
  • Cookies & site data — supported cookies, DOM/site storage, and authentication-session data through the browser engine; and
  • Cached files — browser caches.

Clearing browsing history does not by itself delete bookmarks, Quick Access entries, open tabs, downloaded files, or browser settings. Those items have separate lifecycles and controls.

A downloaded file stored in Android's public Downloads collection is separate from app-private browser data.

7. Anonymous usage statistics

Lonox includes a limited anonymous usage-statistics feature to help Lonox Studio measure aggregate app activity and general usage frequency.

In the current release, this setting is enabled by default and can be turned off in Lonox settings.

When an eligible usage event is sent, the application-level payload is limited to:

  • platform (android);
  • release channel;
  • app version;
  • a weekly-active indicator;
  • a monthly-active indicator; and
  • a first-use indicator.

The event itself is also used to increment an aggregate daily-active count.

Lonox Studio's anonymous usage-statistics payload does not include:

  • browsing history;
  • visited URLs or domains;
  • search queries;
  • page titles or page content;
  • tab/session contents;
  • Private-mode activity;
  • your name, email address, or phone number;
  • an advertising ID;
  • Android ID, IMEI, hardware serial, or similar hardware identifier;
  • a persistent Lonox installation UUID; or
  • affiliate-click history.

Lonox keeps limited local timing/state information needed to avoid repeatedly counting the same daily, weekly, monthly, or first-use event. Because this system does not use a persistent installation identifier, clearing app data or reinstalling Lonox can cause a new first-use count.

Infrastructure used for anonymous usage statistics

Lonox uses Cloudflare Workers to receive the usage request and Supabase to maintain aggregate usage counters.

The Lonox application payload does not contain an IP-address field. Cloudflare necessarily processes network metadata, including the connecting IP address, as part of delivering the HTTPS request. The Supabase aggregate usage table does not store the connecting IP address, browsing history, URLs, searches, or a persistent installation identifier.

In the current backend configuration, detailed Cloudflare Worker logs, traces, and telemetry exports are disabled. Cloudflare may still process provider-level operational or network information as part of providing its service.

The Supabase usage database stores aggregate daily counters rather than individual-user browsing histories.

Aggregated usage statistics are retained for up to 24 months and are then automatically deleted under the current retention rule.

Turning off Send anonymous usage statistics stops eligible Lonox Studio usage events from being sent while that setting is off.

8. Local crash reports

Lonox can create sanitized crash reports in app-private local storage to help diagnose application failures.

Lonox's local crash-report system can store limited technical information such as the time of the crash, app/Android version, sanitized device/model information, thread information, exception information, and sanitized stack frames.

The current implementation keeps a limited number of these local reports and does not provide a Lonox Studio crash-report upload path for this local crash-report system. These reports are separate from the anonymous usage-statistics backend.

Third-party components or platform services can have their own diagnostic behavior, as described elsewhere in this policy.

Lonox can display managed Quick Access links on the home screen. The managed list can be updated remotely through a signed configuration so that Lonox can change supported merchant destinations without requiring a new app release.

The Quick Access configuration request is separate from anonymous usage statistics and is not designed to include your browsing history, search queries, tab contents, account identity, or a persistent installation identifier.

Some Lonox-managed Quick Access links may be affiliate or commission links.

Lonox may earn a commission when you use certain Quick Access links.

When a managed commission-capable Quick Access item is shown, Lonox provides an in-app Commission disclosure. User-created Quick Access entries are separate from Lonox-managed commission attribution.

When you open a Quick Access link, the destination website and any affiliate/redirect provider involved in the link can receive normal web-request information and may use cookies or other technologies according to their own privacy policies.

10. Browser protection and security services

Lonox uses browser-engine protection features and filtering rules to help reduce tracking and unsafe browsing.

Current protection-related components include:

  • tracking/content blocking;
  • EasyList and EasyPrivacy filtering data;
  • Global Privacy Control;
  • local-network/device-access protections; and
  • Safe Browsing through the browser engine.

Lonox enables Global Privacy Control through the browser engine. Global Privacy Control is a browser privacy-preference signal sent to visited websites. Whether and how a website recognizes or honors that signal depends on the website and applicable law.

Lonox keeps limited protection-related state locally, including aggregate blocked-resource counts and registered-domain protection mode/state. Lonox's local protection statistics can include aggregate counts of blocked resources categorized as ads, trackers, fingerprinting, and cryptomining. These statistics are stored locally and are not part of Lonox Studio's anonymous usage-statistics backend. Private and Isolation blocked-resource activity is not added to the persistent lifetime protection statistics.

Safe Browsing

Lonox uses the GeckoView browser engine's Safe Browsing functionality, which can communicate with Google Safe Browsing services to support malicious-site and related security checks.

The exact provider request can depend on the browser-engine/runtime mechanism, cached threat data, and the security check being performed. Lonox therefore does not claim that every visited URL is sent in full to Google, and it also does not claim that no URL-derived information can ever reach the Safe Browsing provider.

Safe Browsing provider traffic is separate from Lonox Studio's anonymous usage-statistics backend.

11. Mozilla GeckoView and Mozilla-operated services

Lonox uses Mozilla GeckoView as its browser engine.

GeckoView can communicate with Mozilla-operated or other provider services for browser-engine functions such as configuration, content-signature infrastructure, Remote Settings and related attachment delivery, network/connectivity detection, and security services.

These browser-engine/provider communications are separate from Lonox Studio's anonymous usage-statistics system.

The exact services used can change with browser-engine/runtime updates. Mozilla's own privacy notices and service documentation may apply to Mozilla-operated processing.

12. QR scanning and Google Code Scanner / ML Kit

Lonox uses Google Code Scanner / ML Kit components for QR-code scanning.

Lonox receives the decoded result needed to offer browser actions, such as opening a detected web address. Lonox does not maintain a separate QR-scan history or camera-frame store for this feature.

Google Code Scanner auto-zoom is disabled in the current Lonox configuration.

Google's Code Scanner documentation states that image processing for this scanner flow occurs on the device and that Google does not store the scan result or image data as part of the scanner flow.

Google Play services / ML Kit can still process technical service, diagnostic, usage, device/app, and device or per-installation identifier information described in Google's applicable SDK disclosures. That provider-side processing is separate from Lonox Studio's own anonymous usage-statistics system.

When you use Voice Search, Lonox launches the speech-recognition service available through Android/the device and receives the transcript returned by that service.

Depending on your device and speech provider, audio or related speech-recognition information may be processed on the device or by the provider's servers under that provider's privacy terms.

Lonox Studio does not operate the speech-recognition service itself.

By default, the returned transcript is placed into the editable address/search field. If the optional Voice Search auto-submit behavior is enabled, the transcript can instead be submitted through Lonox's normal URL/search flow.

If the transcript is submitted as a web search, it is then sent to the selected search provider in the same way as typed search input.

14. Protected content and DRM

Some websites use protected-content technologies such as EME/DRM for licensed media.

Lonox provides a browser-wide Protected content control. Lonox's Protected content approval state does not store a website origin, hostname, URL, tab ID, Private-context ID, or browsing-history record as part of that approval state.

Lonox does not operate its own DRM license server or custom DRM license transport. Actual protected playback can involve Gecko, Android, and the relevant content/DRM provider. Depending on the site, device, and provider, protected playback may involve license-server requests, provisioning, or device-specific DRM credentials.

Those provider communications are separate from Lonox Studio's anonymous usage statistics.

Private browsing does not create a new durable Protected content approval, although an already-established browser-wide approval can be reused according to the current Protected content state.

In the current implementation, Isolation blocks protected content.

15. Downloads and media playback

Files you choose to download can be written to Android's public Downloads storage. Such files can remain on the device independently of Lonox's app-private browsing data and can remain after a Private browsing session ends.

Lonox may keep local download state needed to manage downloads. A limited retry/replay request envelope used by the download system is protected with Android Keystore-backed AES-GCM encryption. This specific protection must not be interpreted as a claim that all Lonox local browser data is encrypted at the application level.

Media and background playback are primarily handled by the browser engine and Android media/audio facilities. Lonox Studio does not use its anonymous usage-statistics backend to collect the media title or page being played.

16. Third-party services and user-directed communications

Depending on the feature you use, information may be processed by third parties that are separate from Lonox Studio, including:

  • websites you choose to visit;
  • your selected search provider;
  • Mozilla/Gecko browser-engine services;
  • Google Safe Browsing;
  • Google Code Scanner / ML Kit / Google Play services;
  • the speech-recognition provider available on your device;
  • content and DRM/license providers;
  • Cloudflare;
  • Supabase;
  • Quick Access affiliate/redirect providers and destination merchants; and
  • Android/Google Play platform services.

These services can have their own privacy policies, retention rules, infrastructure, and legal obligations. Lonox Studio does not control the independent processing performed by websites or providers acting for their own purposes.

If you choose to open, share, or hand off a link or other content to another Android app, Android and the selected app receive the information necessary to perform that action. The selected app's own privacy practices then apply.

Where a provider processes information on behalf of Lonox Studio, that provider may process the information necessary to provide the relevant service.

17. International processing

Internet and cloud services can process information in more than one country.

Lonox's current backend architecture uses Cloudflare for edge Worker processing and Supabase for the aggregate usage database. Cloudflare Worker request processing can occur on Cloudflare's global network and is not limited to India.

Other websites and service providers you choose to use may process information in other countries according to their own infrastructure and privacy terms.

18. Data retention and deletion

Different categories of information have different lifecycles.

  • Normal browser data stored locally remains subject to Lonox/Android controls and the lifecycle of the app and device.
  • Clear Browsing Data removes only the categories described in Section 6.
  • Downloaded files in Android's public Downloads storage are separate and may remain until you delete them.
  • Local sanitized crash reports are kept in a bounded local store.
  • Aggregate anonymous-usage rows are retained for up to 24 months under the current backend retention rule.
  • Third-party websites and service providers apply their own retention rules to information they process.

Because Lonox's aggregate usage system does not use an account or persistent installation identifier, Lonox Studio generally cannot identify which aggregate counter contribution came from a particular person after it has been aggregated.

Support and privacy correspondence

If you contact Lonox Studio, we may retain your message and related information as needed to respond to your request, maintain appropriate support records, address disputes or abuse, or comply with applicable legal obligations. Retention can vary depending on the nature of the communication and applicable requirements.

If we become aware that personal information was provided by a child, the child-specific handling described in the Children's Privacy section applies.

19. Security

Lonox uses technical measures appropriate to the functions described in this policy, including HTTPS for Lonox-owned backend communications and Android security facilities for specific protected local data.

No application, device, network, or Internet service can be guaranteed to be completely secure. This policy therefore does not promise absolute security.

Lonox does not claim that its entire local browser database is protected by application-level whole-database encryption.

20. Children's Privacy

Lonox is a general-purpose web browser and is not specifically directed to children.

Lonox's own anonymous usage statistics do not include names, contact information, account identifiers, browsing history, URLs, search queries, or a persistent installation identifier.

If we become aware that a child has provided personal information directly to Lonox Studio through a support or contact channel, we will use that information only as reasonably necessary to address the communication and will delete it when it is no longer reasonably necessary for that purpose, unless retention is required by applicable law.

A parent or guardian may also contact us using the privacy contact listed in this policy regarding personal information a child has provided.

21. Your choices and privacy rights

You can control several privacy-related functions directly in Lonox or Android, including:

  • turning Lonox anonymous usage statistics off;
  • clearing supported browsing-data categories;
  • changing website permissions;
  • choosing a search provider;
  • using Private or Isolation browsing contexts where available;
  • removing or editing Quick Access items; and
  • deleting local downloaded files through Android/file-management tools.

Depending on where you live, applicable law may also give you rights relating to personal information, such as requesting access, correction, deletion, restriction, objection, portability, or information about processing.

You may contact lonox.support@gmail.com to make a privacy inquiry.

Some rights depend on the type of information involved and applicable law. For example, Lonox Studio may not be able to identify an individual contribution inside aggregate usage counters because the usage system is intentionally not tied to an account or persistent installation identifier.

22. Information you send directly to us

If you contact Lonox Studio by email or another support channel, we receive the information you choose to include in that communication, such as your email address, message, and any files or technical details you voluntarily provide.

When you contact Lonox Studio by email, the email service provider used for the support mailbox also processes the message and related email metadata as necessary to provide the email service, under its own applicable privacy terms.

Please avoid sending sensitive information that is not needed for your support request.

Information provided directly through support/contact channels is separate from Lonox's anonymous usage-statistics system.

23. Changes to this Privacy Policy

Lonox may be updated over time, and privacy-relevant features, providers, or legal requirements can change.

If this Privacy Policy is changed, the updated policy will be published with a revised effective date. Where appropriate or required, material changes may also be communicated through the app, store listing, website, or another reasonable channel.

24. Contact

For privacy questions, requests, or concerns about Lonox Browser, contact:

Lonox Studio Email: lonox.support@gmail.com