Privacy Policy

Ya Browser Android app · Prepared for version 2.0.1 (code 110) · 22 August 2026

Ringkasan: Ya Browser adalah browser umum berbasis Mozilla GeckoView dengan Secure DNS dan YaAdblock bawaan. Data browsing utama disimpan di perangkat. Analytics penggunaan nonaktif secara default. Iklan reward hanya diminta setelah pengguna memilihnya.

Short version: Ya Browser is a general-purpose Mozilla GeckoView browser with built-in Secure DNS and YaAdblock. Core browsing data stays on the device. Usage analytics is off by default. A rewarded ad is requested only after the user chooses it.

Bahasa Indonesia

1. Tentang Ya Browser

Kebijakan ini berlaku untuk aplikasi Android Ya Browser dengan package com.edlee.yabrowser, dikembangkan oleh Theywe. Ya Browser adalah browser untuk audiens umum dan tidak ditujukan secara khusus untuk anak-anak. Situs dan konten web yang dibuka dipilih oleh pengguna dan tidak disediakan oleh pengembang Ya Browser.

2. Data yang disimpan di perangkat

Riwayat penjelajahan, bookmark, pengaturan browser, status akses YaAdblock, pengecualian YaAdblock per situs, serta sinyal situs yang sering dikunjungi disimpan secara lokal. Peringkat shortcut tidak menyimpan path URL lengkap atau query. Menghapus riwayat juga menghapus sinyal situs otomatis. Data situs Gecko dapat dihapus dari Privasi & Keamanan. File yang diunduh disimpan melalui fasilitas download Android.

3. Secure DNS

Secure DNS aktif secara default. Permintaan DNS diselesaikan melalui Cloudflare, dengan Google sebagai fallback otomatis. Jika Secure DNS dimatikan, Ya Browser menggunakan resolver yang dikonfigurasi Android. Secure DNS bukan VPN dan tidak merutekan trafik aplikasi lain. Provider DNS dapat memproses alamat IP dan domain yang diminta berdasarkan kebijakan mereka sendiri.

4. Layanan keamanan engine GeckoView

GeckoView dapat menghubungi Mozilla Remote Settings (firefox.settings.services.mozilla.com) serta layanan Safe Browsing Mozilla atau Google secara berkala untuk memperoleh data keamanan browser yang ditandatangani. Data ini mencakup daftar phishing dan malware, data intermediate certificate dan pencabutan sertifikat seperti OneCRL/CRLite, serta daftar blokir ekstensi. Bergantung pada pemeriksaan ancaman yang digunakan engine, penyedia dapat menerima alamat IP, versi engine/aplikasi, timestamp koleksi, dan data pencarian daftar ancaman. Ya Browser tidak menerima riwayat browsing dari layanan tersebut.

Ya Browser menonaktifkan telemetry Mozilla, eksperimen, unggahan crash otomatis, dan permintaan unggahan crash on-demand. Pembaruan keamanan engine di atas tetap aktif karena menonaktifkannya akan melemahkan perlindungan phishing/malware, validasi TLS, atau pemblokiran ekstensi berbahaya. Pemeriksaan reputasi file unduhan jarak jauh milik GeckoView dinonaktifkan pada build ini.

5. YaAdblock, iklan reward, dan langganan

YaAdblock memfilter permintaan halaman di GeckoView menggunakan ekstensi bawaan, engine filter yang telah ditinjau dan disertakan di aplikasi, serta perlindungan terhadap pola popup tertentu. YaAdblock tidak mengunduh EasyList, ABPindo, atau daftar filter lain saat aplikasi berjalan; snapshot filter hanya berubah melalui pembaruan aplikasi Ya Browser yang ditandatangani. Keputusan filter, URL yang diblokir, isi halaman, dan pengecualian situs tidak dikirim ke Google Analytics for Firebase.

Pengguna dapat memperoleh satu jam akses dengan memilih iklan reward atau memperoleh akses tanpa batas melalui langganan Google Play. Permintaan iklan hanya dibuat setelah pengguna menekan pilihan reward dan setelah alur persetujuan Google yang berlaku. Akses satu jam hanya diberikan oleh callback reward Google yang berhasil. Google Play memproses pembelian, status langganan, dan pemulihan pembelian.

Untuk memverifikasi dan mempertahankan akses langganan, aplikasi mengirim package aplikasi, ID produk, dan purchase token melalui HTTPS ke alamat tetap layanan verifikasi Ya Browser yang dijalankan di Cloudflare Workers. Worker meneruskan token tersebut ke Google Play Developer API. Purchase token mentah hanya diproses sementara di memori dan tidak dicatat atau disimpan. Cloudflare D1 menyimpan hash SHA-256 satu arah dari token saat ini dan linked token jika tersedia, package aplikasi, serta data entitlement terbatas—produk/paket dasar, status, waktu kedaluwarsa, status perpanjangan dan acknowledgement, penanda pembelian uji, serta waktu verifikasi/event—untuk memproses aktivasi, perpanjangan, pembatalan, dan notifikasi Google Play secara aman. Layanan ini tidak menerima riwayat browsing, URL, query pencarian, bookmark, isi halaman, atau keputusan filter.

Perangkat menyimpan status langganan terverifikasi terakhir, waktu verifikasi, dan waktu kedaluwarsa Play untuk ketahanan saat jaringan atau layanan verifikasi sementara tidak tersedia. Akses offline berakhir pada batas yang lebih awal antara waktu kedaluwarsa Play atau 30 hari sejak verifikasi berhasil terakhir. Di sekitar pergantian token perpanjangan, aplikasi dapat mempertahankan akses paling lama 15 menit setelah waktu kedaluwarsa yang sebelumnya terverifikasi sambil memeriksa ulang Google Play; jembatan ini tetap, tidak dapat diperpanjang berulang, dan dicabut setelah status baru berhasil diverifikasi.

Google dan Cloudflare dapat memproses alamat IP serta metadata request yang diperlukan untuk menyediakan dan mengamankan layanan mereka berdasarkan kebijakan masing-masing. Untuk membatasi penyalahgunaan endpoint verifikasi, Worker mengubah alamat IP menjadi HMAC-SHA256 menggunakan secret server; IP mentah tidak disimpan. Bucket hash rate-limit berumur sekitar 24 jam dan dihapus ketika traffic verifikasi berikutnya menjalankan pembersihan.

Google Mobile Ads SDK dapat mengumpulkan atau membagikan alamat IP, interaksi produk dan iklan, informasi diagnostik, serta identifier perangkat/akun untuk periklanan, analytics, dan pencegahan penipuan. Data tersebut dienkripsi saat transit. Ya Browser meminta perlakuan publisher non-personalized untuk seluruh permintaan iklan, menonaktifkan identifier first-party publisher opsional milik Google, dan tetap menerapkan sinyal consent/limited ads yang lebih ketat jika diwajibkan.

6. Rekomendasi beranda

Beranda secara berkala meminta feed rekomendasi terkurasi dan thumbnail dari yabrowser.my.id. Permintaan ini tidak menyertakan riwayat, bookmark, URL yang dikunjungi, judul halaman, atau istilah pencarian. Feed valid terakhir disimpan dalam preferensi privat aplikasi dan thumbnail disimpan dalam cache yang dapat dibersihkan. Kartu komersial atau afiliasi harus diberi label bersponsor.

7. Laporan situs YaAdblock

Formulir yabrowser.my.id/report-adblock menerima URL situs, jenis gangguan, negara, versi Ya Browser dan Android, catatan, serta email opsional yang pengguna pilih untuk kirim. Aplikasi mengisi awal URL dan versi hanya melalui fragmen lokal yang tidak dikirim ke Cloudflare Pages, Turnstile, referrer, atau access log; halaman segera menghapus fragmen itu dari address bar. Data baru dikirim setelah pengguna memeriksa formulir, menyetujui pernyataan, dan menekan Kirim. Sebelum disimpan, kredensial dan fragmen URL dibuang, nama host dinormalisasi, serta nilai parameter query sensitif yang umum—seperti token, password, session, dan kode otorisasi—disamarkan. Laporan disimpan privat di layanan Cloudflare Worker/D1 yang terpisah dari billing dan tidak ditampilkan sebagai daftar publik. Sistem memakai HMAC untuk mengelompokkan laporan identik tanpa membuat URL menjadi daftar publik; laporan lalu dapat ditandai ditinjau, duplikat, berhasil direproduksi, diperbaiki, diverifikasi, atau ditolak. Ekspor fixture regresi hanya memakai ID perbaikan acak dan origin sintetis .invalid, tanpa URL laporan, host, catatan, email, atau hash jaringan. Setelah laporan tersimpan, Cloudflare Email Service mengirim notifikasi minimal ke email developer yang hanya berisi ID dan waktu laporan; URL, catatan, serta email pengguna tidak disalin ke notifikasi. Kegagalan email tidak menghapus atau menolak laporan yang sudah tersimpan. Cloudflare Turnstile memproses sinyal anti-penyalahgunaan. Alamat IP mentah tidak disimpan oleh Ya Browser; layanan menyimpan HMAC-SHA256 IP untuk membatasi lima laporan per jam. Laporan memasuki masa penghapusan setelah 90 hari dan biasanya dihapus saat pembersihan harian berikutnya (sekitar paling lama 91 hari), atau lebih cepat saat traffic yang diterima memicu pembersihan. Jangan kirim password, token, atau data rahasia.

8. Analytics penggunaan opsional

Berbagi penggunaan dan diagnostik nonaktif secara default. Firebase Analytics tidak diinisialisasi sampai pengguna memilih Izinkan di Privasi & Keamanan. Setelah opt-in, Ya Browser hanya mengirim event produk terbatas seperti mesin pencari yang dipilih, titik awal pencarian, tindakan tab baru/bookmark/bagikan, status umum rekomendasi, serta kategori error aplikasi. Firebase juga dapat memproses event aplikasi/sesi standar, app-instance ID, metadata aplikasi/perangkat, dan wilayah geografis kasar.

Ya Browser tidak mengirim URL atau domain yang dikunjungi, judul atau isi halaman, riwayat, isi bookmark, nama download, istilah pencarian, permintaan DNS, keputusan filter YaAdblock, purchase token, atau user ID buatan aplikasi ke Analytics. Pengumpulan advertising ID untuk Analytics, personalisasi iklan, dan pelaporan layar otomatis dinonaktifkan. Event Analytics khusus Ya Browser tidak dikirim dari tab privat.

Pengguna dapat mematikan berbagi penggunaan kapan saja. Aplikasi menghentikan pengumpulan, menolak penyimpanan Analytics, dan mereset data Analytics lokal beserta app-instance ID.

9. Situs web, pencarian, dan izin

Situs yang dibuka dapat menerima request web biasa, alamat IP, cookies, dan data yang diperlukan untuk menampilkan halaman. Mesin pencari menerima query yang pengguna kirim. Situs dapat meminta lokasi, kamera, mikrofon, pemilihan file, notifikasi, atau izin lain; Ya Browser meminta keputusan pengguna melalui kontrol Android/Gecko jika berlaku. Situs dan layanan pihak ketiga memiliki kebijakan privasi sendiri.

10. Retensi, keamanan, dan penghapusan

Data lokal tetap berada di perangkat sampai pengguna menghapusnya, membersihkan data aplikasi, atau menghapus aplikasi. Hash token dan catatan entitlement backend disimpan selama diperlukan untuk memvalidasi dan mengelola siklus langganan, mencegah pemrosesan notifikasi duplikat, serta menjaga keamanan layanan; purchase token mentah tidak disimpan. Bucket HMAC IP untuk rate-limit berumur sekitar 24 jam dan dihapus oleh proses pembersihan pada traffic verifikasi berikutnya; jika endpoint tidak menerima traffic, penghapusan dapat terjadi lebih lambat. Permintaan terkait data backend dapat dikirim ke alamat kontak di bawah. Tidak ada browser atau fitur jaringan yang dapat menjamin keamanan atau anonimitas penuh. Ya Browser tidak menjual data pribadi dan tidak mengoperasikan server untuk mengumpulkan riwayat penjelajahan pengguna.

11. Kontak dan perubahan

Pertanyaan privasi dapat dikirim ke dewirahm7@gmail.com. Kebijakan ini akan diperbarui jika praktik data aplikasi berubah secara material.


English

1. About Ya Browser

This policy applies to the Android application Ya Browser, package com.edlee.yabrowser, developed by Theywe. Ya Browser is a general-audience browser and is not specifically directed to children. Websites and web content are selected by the user and are not supplied by the Ya Browser developer.

2. Data kept on the device

Browsing history, bookmarks, browser settings, YaAdblock access state, per-site YaAdblock exceptions, and frequently visited site signals are stored locally. Shortcut ranking does not retain full URL paths or queries. Clearing history also clears automatic-site signals. Gecko site data can be cleared from Privacy & Security. Downloaded files are stored through Android's download facilities.

3. Secure DNS

Secure DNS is enabled by default. DNS requests are resolved through Cloudflare, with Google as an automatic fallback. If Secure DNS is turned off, Ya Browser uses Android's configured resolver. Secure DNS is not a VPN and does not route traffic from other apps. DNS providers may process the requesting IP address and requested domain under their own policies.

4. GeckoView engine security services

GeckoView may periodically contact Mozilla Remote Settings (firefox.settings.services.mozilla.com) and Mozilla or Google Safe Browsing services to obtain signed browser-security data. This data includes phishing and malware lists, intermediate-certificate and certificate-revocation data such as OneCRL/CRLite, and extension blocklists. Depending on the engine threat check, providers may receive the IP address, engine/application version, collection timestamps, and threat-list lookup data. Ya Browser does not receive browsing history from these services.

Ya Browser disables Mozilla telemetry, experiments, automatic crash upload, and on-demand crash-upload requests. The engine security updates above remain enabled because disabling them would weaken phishing/malware protection, TLS validation, or malicious-extension blocking. GeckoView remote download-reputation checks are disabled in this build.

5. YaAdblock, reward ads, and subscriptions

YaAdblock filters page requests in GeckoView using a built-in extension, a reviewed filter engine bundled with the application, and protection against certain popup behavior. YaAdblock does not download EasyList, ABPindo, or another filter list at runtime; filter snapshots change only through a signed Ya Browser application update. Filter decisions, blocked URLs, page content, and site exceptions are not sent to Google Analytics for Firebase.

Users can obtain one hour of access by choosing a rewarded ad or obtain unlimited access through a Google Play subscription. An ad request is made only after the user presses the reward option and after any applicable Google consent flow. One-hour access is granted only by Google's successful earned-reward callback. Google Play processes purchases, subscription status, and purchase restoration.

To verify and maintain subscription access, the app sends its package name, product ID, and purchase token over HTTPS to the fixed address of Ya Browser's verification service running on Cloudflare Workers. The Worker forwards that token to the Google Play Developer API. The raw purchase token is processed transiently in memory and is never logged or stored. Cloudflare D1 stores one-way SHA-256 hashes of the current token and any linked token, the app package name, and limited entitlement fields—product/base plan, state, expiry, renewal and acknowledgement status, test-purchase flag, and verification/event timestamps—to securely process activation, renewal, cancellation, and Google Play notifications. The service does not receive browsing history, URLs, search queries, bookmarks, page content, or filtering decisions.

The device stores the last verified subscription status, verification time, and Play expiry for resilience while the network or verification service is temporarily unavailable. Offline access ends at the earlier of the Play expiry or 30 days after the last successful verification. Around a renewal-token transition, the app may preserve access for at most 15 minutes after the previously verified expiry while it rechecks Google Play; this bridge is fixed, cannot be repeatedly extended, and is cleared after a new status is verified.

Google and Cloudflare may process the IP address and request metadata needed to provide and secure their services under their respective policies. To limit abuse of the verification endpoint, the Worker converts the IP address to an HMAC-SHA256 value with a server secret; the raw IP is not retained. Rate-limit hash buckets age out after approximately 24 hours and are deleted when subsequent verification traffic runs cleanup.

The Google Mobile Ads SDK may automatically collect or share IP address, product and ad interactions, diagnostic information, and device/account identifiers for advertising, analytics, and fraud prevention. This data is encrypted in transit. Ya Browser requests non-personalized publisher treatment for every ad request, disables Google's optional publisher first-party identifier, and still honors any more restrictive consent or limited-ads signal where required.

6. Home recommendations

Home periodically requests a curated recommendation feed and thumbnails from yabrowser.my.id. The request does not include browsing history, bookmarks, visited URLs, page titles, or search terms. The last valid feed is kept in private app preferences and thumbnails are kept in recoverable cache. Commercial or affiliate cards must be labelled as sponsored.

7. YaAdblock site reports

The yabrowser.my.id/report-adblock form accepts a website URL, issue type, country, Ya Browser and Android versions, notes, and an optional email that the user chooses to send. The app prefills the URL and version only in a local fragment that is not sent to Cloudflare Pages, Turnstile, referrers, or access logs; the page immediately removes that fragment from the address bar. Data is sent only after the user reviews the form, accepts the disclosure, and presses Send. Before storage, URL credentials and fragments are removed, the host is normalized, and values of common sensitive query parameters—such as tokens, passwords, sessions, and authorization codes—are redacted. Reports stay private in a Cloudflare Worker/D1 service that is isolated from billing and are never published as a public list. The service uses HMAC to group identical submissions without creating a public URL list; reports may then be marked triaged, duplicate, reproduced, fixed, verified, or rejected. Regression-fixture exports use only a random fix ID and a synthetic .invalid origin, without the reported URL, host, notes, email, or network hash. After a report is stored, Cloudflare Email Service sends a minimal notification to the developer email containing only the report ID and receipt time; the submitted URL, notes, and user email are not copied into the notification. An email failure does not delete or reject an already stored report. Cloudflare Turnstile processes anti-abuse signals. Ya Browser does not retain raw IP addresses; the service stores an HMAC-SHA256 IP value to limit submissions to five per hour. Reports become eligible for deletion after 90 days and are normally removed during the next daily cleanup (within about 91 days), or sooner when accepted traffic triggers cleanup. Do not submit passwords, tokens, or secrets.

8. Optional usage analytics

Usage and diagnostic sharing is off by default. Firebase Analytics is not initialized until the user chooses Allow in Privacy & Security. After opt-in, Ya Browser sends only a limited set of product events such as the selected search engine, search entry point, new-tab/bookmark/share actions, generic recommendation status, and broad app-error categories. Firebase may also process standard app/session events, an app-instance ID, app/device metadata, and a coarse geographic region.

Ya Browser does not send visited URLs or domains, page titles or content, browsing history, bookmark contents, download names, search terms, DNS requests, YaAdblock filter decisions, purchase tokens, or an app-defined user ID to Analytics. Analytics advertising-ID collection, ad personalization, and automatic screen reporting are disabled. Ya Browser custom Analytics events are suppressed in private tabs.

The user can turn usage sharing off at any time. The app stops collection, denies Analytics storage, and resets local Analytics data and the Analytics app-instance ID.

9. Websites, search, and permissions

Opened websites may receive normal web requests, IP address, cookies, and data required to render the page. Search providers receive queries the user submits. Websites can request location, camera, microphone, file selection, notifications, or other permissions; Ya Browser asks through Android/Gecko controls where applicable. Websites and third-party services have their own privacy practices.

10. Retention, security, and deletion

Local data remains on the device until the user deletes it, clears app data, or uninstalls the app. Backend token hashes and entitlement records are retained for as long as needed to validate and manage the subscription lifecycle, prevent duplicate notification processing, and secure the service; raw purchase tokens are not retained. HMAC IP rate-limit buckets age out after approximately 24 hours and are removed by cleanup on subsequent verification traffic; if the endpoint receives no traffic, deletion can occur later. Requests concerning backend data can be sent to the contact address below. No browser or network feature can guarantee complete security or anonymity. Ya Browser does not sell personal data and does not operate a server that collects users' browsing history.

11. Contact and changes

Privacy questions can be sent to dewirahm7@gmail.com. This policy will be updated when the application's data practices materially change.