Files
LibreMediaConverter/PRIVACY.md
T
JMR-devandClaude Opus 5 bb969ece64 Enable R8 and add release, store and F-Droid infrastructure
Turning on R8 immediately surfaced a latent runtime bug: the ffmpeg-kit-next
wrapper references com.arthenica.smartexception.java.Exceptions from
AbstractSession.fail() in eighteen places, but a local .aar carries no
transitive dependencies, so nothing was pulling it in. Debug builds tolerate
this through lazy class loading -- the class is only touched on an error
path -- so it would have shipped as a crash the first time an FFmpeg
conversion failed. Declared explicitly now.

Keep rules cover the JNI boundary. The native library resolves classes and
methods by name, which R8 cannot see, so without them the FFmpeg calls fail
with NoSuchMethodError in release builds only. Workers are kept too, since
WorkManager reconstructs them reflectively from a class name persisted in its
database, and a rename breaks jobs enqueued before the update.

Verified on the produced artifacts rather than assumed: all 22 native
libraries survive minification and every one is still 16 KB aligned inside
the APK. Release is 82 MB against 115 MB for debug; the AAB is 40 MB and Play
splits it per ABI.

The privacy policy lists every permission, including the three WorkManager
adds automatically (WAKE_LOCK, RECEIVE_BOOT_COMPLETED, ACCESS_NETWORK_STATE).
Checking the merged manifest showed those, and a policy that omitted them
would look dishonest to anyone who inspected the app. INTERNET is genuinely
absent, so "files stay on the device" is enforced by the OS rather than a
promise.

CI runs unit tests on every push and builds the FFmpeg AAR only for release
tags, since that is a full cross-compile. Releases attach the FFmpeg
corresponding source next to the APK: GPL-3.0 requires it, and FFmpeg's
instruction to host it "on the same webserver" cannot be satisfied by a Play
listing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-19 22:45:40 -05:00

2.6 KiB

Privacy Policy

Media Converter does not collect any data.

That is the whole policy, but here is what it means concretely.

No data leaves your device

The app has no network access. It does not declare the INTERNET permission, so it is not merely a promise not to transmit anything — the operating system will not let it. Your files are converted on your device and stay there.

No analytics, advertising or tracking

There is no analytics SDK, no crash reporter, no advertising identifier, and no third-party service of any kind.

What the app accesses, and why

Access Why
Files you explicitly pick Read as conversion input. The app uses the system file picker and can only see files you choose. It never scans your storage.
The destination you choose for output Write the converted file. Again, only where you point it.
Notifications Show conversion progress so you can leave the app while a long job runs. Optional; conversions work without it.

The app does not request storage permissions. It uses the Storage Access Framework, which grants access only to the individual files you select.

The full permission list

Inspecting the app will show a few permissions that are not in the table above. They are added automatically by the Jetpack WorkManager library, which runs conversions in the background. Listing them here rather than leaving you to wonder:

Permission Origin What it does here
FOREGROUND_SERVICE, FOREGROUND_SERVICE_MEDIA_PROCESSING, FOREGROUND_SERVICE_DATA_SYNC Ours Keep a conversion running when the app is not in the foreground. Android requires a declared service type for this.
POST_NOTIFICATIONS Ours Show conversion progress. Optional.
WAKE_LOCK WorkManager Stop the device sleeping mid-conversion.
RECEIVE_BOOT_COMPLETED WorkManager Restore an unfinished job queue after a restart.
ACCESS_NETWORK_STATE WorkManager WorkManager can gate jobs on connectivity. This app does not use that feature, and the permission only allows reading whether a network exists — it does not permit any network communication.

Notably absent is INTERNET. Without it the operating system will not allow the app to open a network connection at all, so "your files stay on your device" is enforced by Android rather than resting on our word.

Where files are stored

Conversions are written to the app's private cache while they run, then copied to the location you choose. The temporary copy is deleted afterwards. Uninstalling the app removes everything in its private storage.

Contact

Report issues at the project's repository.