BlogPlugins
Services
WordPress designPro WordPress design & buildSpeed optimisationSpeed + Core Web VitalsWordPress maintenanceMonthly maintenance plansModern CMS maintenanceNext.js, Headless, JamstackKeyword researchTarget the right keywordsCustom CMSPlatforms built for you
Paid service

WordPress maintenance plans

Daily backups, 24/7 monitoring, and managed updates — from $49/mo.

Learn more →
Academy
1Basic course$50 · Beginners2Pro course$150 · Best seller3Advanced course$200 · EnterpriseBrowse all courses →
WorkTestimonials
Extras
1Ask AIAsk the AI for free2Name GeneratorFree business-name generator3Speed TestFree website speed checker4حساب العمر بالهجري والميلاديأداة حساب العمر بشكل مفصل
Sign inGet a quote →
Sign inAccess your client portal
BlogPlugins
Services
WordPress designSpeed optimisationWordPress maintenanceModern CMS maintenanceKeyword researchCustom CMS
Academy
1Basic course2Pro course3Advanced courseBrowse all courses
WorkTestimonials
Extras
1Ask AI2Name Generator3Speed Test4حساب العمر بالهجري والميلادي
CartClient portal
Get a quote →
Home/Network Discovery

Windows application

Privacy Policy

Last updated: 26 August 2026

This policy describes what the application accesses, what it stores, and what it sends over the internet. It is deliberately specific, because the application inspects a local network and you are entitled to know exactly where that information goes.

Summary

The application does not create an account, does not contain analytics, telemetry or advertising, and does not send your network inventory anywhere. The devices it finds are held in memory for the duration of the session and are never written to disk or transmitted.

You may optionally sign in to your own equipment so that the application can read the details a device only reveals to an operator. Those credentials are yours, they are sent only to the device you entered them for, and they are never transmitted to us or to anyone else. They are kept on your own computer, sealed so that only your Windows account can read them, and you can switch that off or erase them at any time.

Discovery only ever reads. The single exception is installing firmware, which writes to a device and restarts it: it happens only to a device you chose, with a file you chose, after you press the button that says so. The file is read from your computer and sent to that device. No copy of it is sent anywhere else, and nothing about the device is either.

Information the application accesses

To discover equipment on the network you are connected to, the application reads:

  • IPv4 addresses, MAC addresses, host names and open TCP ports of devices on the local network or on a scan range you configure
  • Device identity that equipment broadcasts about itself — vendor, model, firmware version, uptime, signal level and SSID — obtained from vendor discovery protocols, mDNS, the Windows neighbour cache, HTTP responses and read-only SNMP
  • Where a device has not identified itself from any of those, one further read-only request to the status address its make publishes, purely to tell one make from another. It is only ever sent to a device that would otherwise be listed as unknown, and it carries nothing about you
  • The list of network adapters present on your computer

This information is kept in memory only. Closing the application discards it. It is not written to disk, and it is not sent to us or to any third party.

Information stored on your computer

Only your preferences are saved:

  • Light or dark theme
  • Custom scan scopes you add (a name and an IPv4 range)
  • The discovery preferences: the firmware check after scans, auto-rescan with its interval, and live readings with theirs

These are stored in plain JSON at %LOCALAPPDATA%\ALNAKIB\NetworkDiscovery\settings.json in the portable build, or in the equivalent per-package location when installed from the Microsoft Store. Removing the application removes them.

Device sign-in details

If you sign in to a device, the username and password you enter are held in memory for that session so that you are not asked again for every device.

A credential is filed against that device's address and against its hardware address, so the same equipment is recognised when a later scan reaches it by a different route and gives it a different address. Settings also lets you keep one credential per vendor, used for any device of that make you have not signed in to individually. Nothing else is recorded with them.

They are written to disk while Remember device sign-ins is on in Settings, which it is unless you turn it off. When it is on they are sealed with the Windows Data Protection API and written to credentials.dat beside the settings file. That sealing ties the file to the Windows account that wrote it: another account on the same computer cannot open it, and neither can the same file copied to another computer.

Switching the setting off deletes the file, and from then on credentials are held in memory only and discarded when the application closes. Forget, next to that setting, discards everything held both in memory and on disk. Removing the application removes the file with the rest of its data.

Credentials are sent only to the device they belong to, over that device's own interface, and to no other destination. They are never included in a firmware check or any other internet request.

Information sent over the internet

The application makes outbound requests only when you invoke a feature that needs one. Each request necessarily discloses your public IP address to the operator of that service, as any internet request does.

When

Where

What is sent

You run the internet speed test

speed.cloudflare.com

Test traffic only. No network or device information.

A MikroTik device's firmware is checked

upgrade.mikrotik.com

The RouterOS branch number (6 or 7) and an application user-agent. No device identity.

A Ubiquiti airMAX / airFiber device's firmware is checked

fw-update.ui.com

The product code carried in that device's firmware string (for example XW) and an application user-agent. No address, name, serial or MAC.

You open a device's web interface, a changelog or a vendor download page

The address you clicked

Handled by your default browser, subject to its own privacy behaviour.

Firmware checks run when you press Check for updates, and after a scan if you leave the "Firmware check after scans" setting enabled. You can switch that setting off, in which case no vendor feed is contacted unless you ask for it.

Installing firmware sends the image you chose from your computer to the device you chose, over that device's own authenticated interface, and asks the device to install it. Nothing is fetched from the internet for this and no copy of the file goes anywhere but to that device. MikroTik equipment is given its packages over the file service RouterOS itself provides and is then restarted, which is how RouterOS installs them.

The image is read and checksummed on your computer first, and nothing is written to the device until it has accepted the image and reported what it read from it. Afterwards the device is re-read to confirm the version it came back on.

Signing in to a device is a request to that device on your own network, not to the internet. Nothing about it leaves your network.

While Live readings is on, the application re-reads each device you have signed in to on a timer, so that signal, link quality and rate stay current. Those are the same requests, to the same devices, made no more often than the interval you set in Settings, and never to more than a few devices at once. Nothing is read while an image is being written to a device, or while you are signing in to one. Switching it off stops them.

What the application does not do

  • No user accounts, sign-in, or licence servers
  • No analytics, crash reporting, telemetry or advertising identifiers
  • No collection of documents, browsing history, location, contacts or any personal file
  • No transmission of discovered device data to us or to anyone else
  • No transmission of your device credentials to us or to anyone else; they go to the device you entered them for and nowhere else
  • No modification of the devices it finds, other than a firmware installation you ask for. Discovery is read-only and signing in reads a device's own status and changes nothing on it; installing firmware writes to the device you chose and restarts it, and is the only thing here that alters any equipment

Children

The application is a network administration utility. It is not directed at children and collects nothing from them.

Security

Vendor firmware feeds are contacted over HTTPS. The speed test uses HTTPS. Local discovery protocols are the plaintext protocols the equipment itself defines, and carry no credentials.

Signing in uses whichever interface your device provides. Network equipment typically presents HTTPS with a self-signed certificate, which the application accepts because a device's own certificate cannot be verified against a public authority; the connection is encrypted and is confined to the address you chose. Some equipment offers only plain HTTP, in which case the exchange is as protected as using that device's own web interface from a browser — which is to say, it relies on your local network.

Sending packages to a MikroTik uses FTP, because that is the file service RouterOS provides and the one its own tools use. FTP carries the username and password in the clear, so that exchange is only as private as the network it crosses. If that is not acceptable on your network, copy the packages to the router with WinBox and restart it yourself instead; the application is not required for that part.

Stored credentials are sealed with the Windows Data Protection API as described above and are never held in plain text on disk.

Changes

If a future version accesses or transmits anything not described here, this policy will be updated before that version is released.

Contact

Questions about this policy: [email protected]

100% secure paymentsSSL encryption · PCI-DSS Level 1
14-day money-backOn digital products
Fast Arabic supportWhatsApp · replies in minutes
Trusted since 2013240+ sites optimized

A digital studio specializing in high-performance WordPress design, development, and maintenance. Serving ambitious brands since 2013.

VISAMASTERCARDAPPLE PAYGOOGLE PAYPAYPALSTRIPE

Services

  • WordPress design
  • Speed optimisation
  • Custom CMS
  • Maintenance plansPaid

Store & Academy

  • Plugins & tools
  • Basic course
  • Pro course
  • Advanced course
  • All courses
  • Cart

Company

  • About us
  • Work
  • Testimonials
  • Book a consultation
  • Account / Sign in
  • Contact

Contact us

Email[email protected]
Phone+964 773 971 6668
OfficeBaghdad, Iraq

Newsletter

Weekly tips on speed, security, and best practices in development.

© 2026 Alnakib — Digital Studio. All rights reserved.
Privacy policyTerms of useRefund policyNetwork Discovery privacy Sign in
Need help? Chat with us