Open-source project
TrackerControl/tracker-control-android avatar
TrackerControl/tracker-control-android

TrackerControl for Android: local tracker blocking without root

TrackerControl Android: monitor and control trackers and ads.

2,662 stars135 forksJavaGPL-3.0

At a glance

What is it?
TrackerControl is a GPL-3.0 Android app that routes device traffic through a local VPN to detect and block app trackers. It is aimed at unrooted phones, and it does not decrypt TLS.
Who is it for?
TrackerControl suits Android users who want per-app visibility into tracker traffic and are willing to run a local VPN, and it is the wrong tool for anyone who needs iOS blocking or certificate-level inspection of encrypted payloads.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 6 days ago.
What is it written in?
Mainly Java, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 24, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What TrackerControl solves, and for whom

Mobile apps collect behavioural data and send it to companies the user never chose. TrackerControl exists to make that traffic visible and stoppable on an unrooted Android phone. The README describes it as an app that monitors and controls "the widespread, hidden data collection in mobile apps about user behaviour ('tracking')" and says it does so locally on the device, without root and without an external VPN server by default.

The audience is narrow but real: people who keep stock Android, will not root, and still want per-app evidence of which destinations an app contacts. The README also positions the app as educational, noting it aims to inform users about rights under data-protection law such as the EU GDPR. That framing matters, because the product is as much an inspection tool as a blocker.

The project is GPL-3.0 and the last push to the repository was on 2026-09-24. It is not archived.

The local VPN and DNS detection mechanism

TrackerControl uses Android's VPN functionality to analyse network traffic locally. That is the whole architecture: the app becomes the device's VPN interface, inspects traffic as it passes, and logs metadata. No traffic is sent to a TrackerControl server by default.

Detection is DNS-based. The README states that TLS Server Name Indication extraction is disabled by default because reading SNI requires connecting to tracker servers, which would leak the user's IP address. SNI is enabled only in Research mode. The README adds a detail worth reading twice: the SNI itself is read locally from traffic TrackerControl already inspects, so no separate connection is made, and if remote routing over WireGuard is enabled, that connection exits through the VPN tunnel so the tracker sees the provider's IP rather than the device's.

Blocklist matching combines the Disconnect blocklist used by Firefox, the DuckDuckGo Tracker Radar for mobile apps, and an in-house list built from analysing roughly 2,000,000 apps. Custom blocklists are supported. Separately, tracker libraries inside app code are detected using signatures from ClassyShark3xodus and Exodus Privacy. The README distinguishes the two techniques: network analysis gives actual evidence of data sharing, while libraries present in code may never run.

The app also states it protects against DNS cloaking and optionally supports Secure DNS over DNS-over-HTTPS and remote VPN routing through providers such as Mullvad and IVPN.

Installing TrackerControl and enabling the VPN

The README points to four distribution channels: GitHub releases, F-Droid, IzzyOnDroid, and Google Play. Two builds exist and they are not equivalent. The Play Store build is the slim variant with minimal blocking; the F-Droid and GitHub builds are the full variant with all blocking modes. The package identifiers differ, which is how the README distinguishes them: net.kollnig.missioncontrol.fdroid on F-Droid, net.kollnig.missioncontrol on IzzyOnDroid, and net.kollnig.missioncontrol.play on Google Play.

To install the full build from F-Droid, add the repository in your client and install the package by name:

bash
# in an F-Droid client, search for and install:
net.kollnig.missioncontrol.fdroid

After installation, the README's example use section says to follow the in-app steps to enable the VPN, then interact with the apps you want to inspect. Apps must actually run before they share data, so an app you never open will show little or nothing. The README notes that results are shown in a privacy timeline with blocked and allowed tracker connections, per-app controls, and destination countries derived from DNS and IP information.

Blocking mode is changed in Settings. The README's table lists three modes. Minimal uses the DuckDuckGo list only, allows essential services and ambiguous shared IPs, has no granular per-tracker control, auto-excludes known incompatible apps such as browsers from the VPN, and is the default for new installs. Standard uses all tracker sources (X-Ray, Disconnect, DDG) with per-app and per-tracker controls and allows the Content category to reduce breakage. Strict is like Standard but also blocks the Content category and ambiguous mixed shared-IP cases where a tracker hostname and a non-tracker hostname resolve to the same IP.

If you want to build from source rather than install a binary, the repository carries a Gradle wrapper and a rust-toolchain.toml, and the README has a Build Instructions section. The build steps themselves are not reproduced in the README excerpt available here, so read that section in the repository before attempting a build.

Where TrackerControl breaks down

The README carries its own disclaimer: use of the app is at your own risk, no app can offer 100 percent protection against tracking, and analysis results shown in the app may be inaccurate. That is unusually direct, and it should shape expectations. A DNS-based detector sees hostnames, not payloads. If an app sends data to a first-party domain that is also used for legitimate functions, or if it obfuscates destinations, the classification can be wrong in either direction.

The shared-IP problem is the clearest structural limitation. Strict mode blocks ambiguous cases where a tracker hostname and a non-tracker hostname resolve to the same IP, which the README presents as a deliberate trade-off. Blocking those addresses can break unrelated functionality. Minimal mode takes the opposite position and allows them. There is no mode that resolves the ambiguity; the user picks which failure they prefer.

Because TrackerControl does not intercept SSL, it cannot see inside encrypted connections. That is a privacy choice stated in the README, and it also caps what the tool can prove. It will not tell you what fields an app transmitted.

Finally, the VPN itself is the constraint. Only one VPN can be active on Android at a time, so running TrackerControl conflicts with any other VPN use unless you route through a supported provider as the README describes. On iOS the README says a feature-reduced version is in the making with tracker analysis only and no blocking, so there is no iOS blocking option today.

How it differs from certificate-pinning interception tools

The obvious alternative class is tools that install a user CA certificate and man-in-the-middle TLS, such as mitmproxy paired with an Android proxy setup, or apps built on similar interception. Those tools decrypt traffic, so they can show request bodies, headers and exact parameters. TrackerControl cannot, by design.

The difference is not a missing feature; it is a different threat model. Interception requires trusting a certificate on the device, and on modern Android many apps refuse to trust user certificates, so interception fails on exactly the apps people most want to inspect. TrackerControl avoids that class of failure by never decrypting, which is why it works on unrooted devices. The README states this contrast directly: unlike similar solutions, TrackerControl does not intercept SSL connections, minimising privacy risks and allowing usage on unrooted devices.

A second alternative is host-file ad blocking through a local DNS filter. That blocks by hostname too, but it typically has no per-app granularity and no notion of which app contacted which destination. TrackerControl's per-app and per-tracker controls are the practical difference.

Licence and the cost of keeping up

TrackerControl is GPL-3.0. If you redistribute a modified build, the licence's source-availability terms apply to your version, and the project's own distribution channels already ship separate package identifiers per store. This is a description of the licence file in the repository, not legal advice; read the LICENSE file and the GPL-3.0 text if you plan to fork or repackage.

The upgrade cost is mostly on the blocklist side, not the app side. Detection quality depends on three external sources plus an in-house list, and on signatures borrowed from ClassyShark3xodus and Exodus Privacy. When those upstream sources change format or coverage, the app has to follow. The repository's recent releases are dated 2026-08-05, 2026-07-27 and 2026-07-27, all carrying version numbers in the same numeric style, which suggests a steady release cadence rather than a frozen artifact.

For a user, upgrading means replacing the APK or letting the store or F-Droid client update it. The README does not document rollback or a downgrade path, and it does not describe a migration step between blocking modes, so treat a mode change as a fresh configuration decision rather than an upgrade.

Editorial conclusion

TrackerControl suits Android users who want per-app visibility into tracker traffic and are willing to run a local VPN, and it is the wrong tool for anyone who needs iOS blocking or certificate-level inspection of encrypted payloads. Before adopting it, verify which distribution you are installing (Play Store slim versus F-Droid or GitHub full), because blocking modes differ between them, and check the current release on the project's own release page rather than a third-party mirror.

Frequently asked questions

How do I find hidden trackers on Android with TrackerControl?

Install the app, follow the in-app steps to enable its local VPN, then open and use the apps you want to inspect, because the README states apps must actually run to share data with tracking companies. TrackerControl then shows a privacy timeline of blocked and allowed tracker connections, with per-app controls and destination countries.

Can someone track my Android location without me knowing?

TrackerControl does not answer that question about a person tracking your device; it reports which apps contact tracking companies and lets you block those connections. The README notes that no app can offer 100 percent protection against tracking and that results shown in the app may be inaccurate.

Can I track a family member on an Android phone with TrackerControl?

No. TrackerControl monitors and controls tracking performed by apps on the device it is installed on; it is not a person-location or family-tracking tool, and the README describes no such feature.

How do I tell if someone is tracking my Android phone?

TrackerControl shows which apps contact tracking companies, so it can reveal app-level tracking, but the README does not claim to detect a person tracking your device. It also warns that analysis results shown in the app may be inaccurate.

Official sources

  1. License: GPL-3.0
  2. Project website
  3. README
  4. Releases
  5. TrackerControl/tracker-control-android on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/trackercontrol-tracker-control-android.svg)](https://hysenlabs.com/projects/trackercontrol-tracker-control-android)