Privacy policy
Last updated 10 October 2026.
NotFusion collects no data. Nothing you do in the app is sent to the developer or to anyone other than Sophos.
What the app keeps on your phone
- Your Sophos API client ID and client secret, in the iOS Keychain or Android's Keystore-backed secure storage. The secret is locked behind Face ID, Touch ID or your fingerprint when the phone has one set up, and behind the phone's passcode when it doesn't. They are not synced to other devices or restored onto a new phone.
- Details of each credential profile that are not secret: the label you give it, whether it is a tenant, partner or organization credential, and the tenants it can see.
- A cache of what the app last showed you, such as alerts, cases, endpoints and policies, so screens open quickly and work offline. It sits in the app's cache folder, which iPhone backups leave out. It is deleted when you remove the profile, and anything in it older than a limit you choose (24 hours unless you change it) is deleted rather than shown.
- A log of the changes you made through the app: profile, tenant, action, item, result and time. It keeps no reasons and none of the text you send to Sophos, such as comments, close reasons and isolation reasons. It stays on your phone unless you export it from Settings.
The access token Sophos issues is held in memory only and never saved.
Where the app sends data
Only to your own Sophos account, over HTTPS:
id.sophos.com, to exchange your credential for an access tokenapi.central.sophos.comand your region'sapi-*.central.sophos.comhost, for tenants, alerts, endpoints and policiesapi.central.sophos.comagain while your phone reports no connection: a request with no credential in it, every 15 seconds while the app is open, to find out when Sophos can be reached again. The app doesn't check its connection through anyone else.api.taegis.sophos.com, for Sophos Fusion cases
NotFusion has no server. It contains no analytics, advertising or crash reporting code and shares nothing with anyone.
Deleting your data
Settings, Remove all profiles deletes the credentials, the cache and the log. On iPhone, deleting the app does not delete the credentials from the Keychain, so remove the profiles first.
If your phone is lost, delete the API credential in Sophos Fusion. That stops it working on every device.
Changes and questions
This page is the policy, and the date at the top says when it last changed. For questions, see the support page.