Legal
Privacy Policy
In short: Noo talks to one place only — the Nextcloud server you tell it to use. We do not operate any servers that receive your data, we do not use analytics, advertising, crash-reporting or tracking services, and we do not collect, store, sell, share or have access to your personal information.
1. Definitions
In this policy, “Noo”, “the App” means the Noo Nextcloud client application for Android and any other platform on which it is published; “we”, “us” and “the developer” mean the individual developer of the App; “you” means the person using the App; “Your Server” means the Nextcloud instance whose address you enter into the App, whether operated by you or by another party of your choosing; and “Personal Data” has the meaning given in applicable data-protection law, including Regulation (EU) 2016/679 (GDPR), the UK GDPR and the California Consumer Privacy Act, to the extent they apply.
2. We do not collect your data
The developer does not collect, receive, record, store, transmit, process, sell, rent, license, disclose or otherwise have access to any Personal Data or any other information about you or your use of the App. The App contains no code that sends information to the developer or to any server operated by the developer. Because we hold no such data, we are not a controller or a processor of your Personal Data in respect of the App, and there is no data we are able to disclose, delete, correct or hand over to any third party, including in response to a legal request.
Specifically, the App does not contain or use:
- analytics, telemetry, usage statistics or behavioural measurement of any kind;
- advertising networks, advertising identifiers or attribution services;
- crash-reporting or error-reporting services;
- social-media, marketing, A/B-testing or “growth” SDKs;
- fingerprinting, cross-app tracking or profiling;
- in-app purchases, subscriptions or accounts with the developer.
3. Your Nextcloud server
The App is a client. Its only network communication is with Your Server, at the address you provide, in order to perform the actions you ask for: signing in, listing and transferring files, showing activity, managing shares and trash, and synchronising files you have chosen to keep available offline. This communication uses the standard Nextcloud and WebDAV interfaces and goes directly from your device to Your Server; it does not pass through the developer or any intermediary operated by the developer.
What Your Server logs, stores and does with that traffic is governed by the privacy policy and practices of whoever operates Your Server. We have no control over, and accept no responsibility for, those practices. If you use a server run by someone else, please consult them.
The App permits unencrypted (HTTP) connections so that you can reach servers on a private network. Whether to use HTTP or HTTPS is your choice; we strongly recommend HTTPS for any server reachable over the internet, because unencrypted traffic can be read by others on the network.
If you add several accounts, the App communicates with each account’s server only when you use that account, and never shares information between them.
4. No third-party services
The App does not connect to any service other than Your Server. In particular:
- Fonts and assets. The typefaces used by the App are bundled inside the App package. The App does not download fonts, images, icons, configuration or code from any third-party host at runtime.
- No remote configuration. The App does not fetch feature flags, update manifests or any other instructions from the developer.
- No embedded web content from others. Sign-in uses your device’s browser to open the login page of Your Server (see section 6); no third-party web content is loaded.
- Open-source libraries. The App is built with open-source libraries that run locally on your device. They are not permitted by us to, and to our knowledge do not, transmit data to their authors.
If the App is distributed through an app store (for example Google Play), the store operator may collect information about your download and installation under its own policy. That collection is independent of the App and outside our control.
5. Data stored on your device
To work, the App keeps some information locally on your device. This information remains on your device, is not transmitted to the developer, and is removed when you remove the account, clear the App’s storage or uninstall the App.
| Data | Purpose | Where it lives |
|---|---|---|
| Server address, username and an app-specific access token for each account | Keep you signed in | The device’s secure credential storage (Android Keystore-backed storage) |
| Preferences: theme, accent colour, bottom bar, tab order, action bar, swipe actions, lock and sync settings | Remember how you set the App up | App-private storage |
| Cached file lists, thumbnails and previews | Speed and offline browsing | App-private cache |
| Files you marked for offline use and files you download | Offline access; saving to your device | App-private storage, or your device’s Downloads folder when you save a file there |
The App does not read your contacts, location, calendar, messages, call history, microphone or camera, and it does not scan or index your device’s other files. It reads a local file only when you pick it to upload or share it to the App.
6. Authentication and app lock
Sign-in
Noo signs in using Nextcloud’s Login Flow v2. You enter only a server address; you authenticate on Your Server’s own web page in your browser, and Your Server issues the App an app-specific token. The App never sees, collects or stores your account password, and you can revoke the token at any time from the security settings of Your Server.
Biometric and device lock
The optional login lock, hidden-file lock and account-switch lock use your device’s own authentication (fingerprint, face, PIN, pattern or password) through the operating system. The operating system performs the check and tells the App only whether it succeeded. The App does not receive, store or transmit your biometric data, your PIN or your device credentials.
7. Permissions
On Android the App requests only the permissions needed for the features you use:
| Permission | Why |
|---|---|
| Internet | To communicate with Your Server. |
| Network state | To know whether you are offline, so the App can avoid pointless requests and show offline files. |
| Biometric | To support the optional device-based lock. |
| Foreground service (data sync) and Notifications | To keep an upload, download or sync running, and to show its progress with a cancel option, when the App is not on screen. |
| Write external storage (Android 9 and earlier only) | To save downloads on old devices that require it. |
You can withhold or revoke any permission in your system settings; features that depend on it may stop working.
8. Sharing and file handoff
When you use Noo’s sharing features, such as creating a share link, adding a person to a share, or sending a file directly, that action is carried out on Your Server. Anyone you share with can then access the content under Your Server’s rules. When you hand a file to another app through the system share sheet or file picker, that other app receives the file and is governed by its own privacy policy. You are responsible for what you choose to share and with whom.
9. This website
This website (noo.ayushya.dev) is separate from the App. It is a static site: it has no accounts, forms, cookies, analytics or advertising, and it does not set tracking identifiers. The interactive demos run entirely in your browser and send nothing anywhere; any preferences you toggle in them are not stored.
To display its typefaces, the website loads fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). Your browser therefore sends your IP address and standard request headers to Google when you visit, subject to Google’s own privacy policy. The site is hosted on Cloudflare, which, like any web host, processes technical request data (such as IP address and user agent) to deliver pages and protect against abuse, under its own policy. We do not receive this data in any identifiable form beyond what the host’s standard dashboard may aggregate. None of this applies to the App.
10. Children
The App is a general-purpose file client and is not directed at children. Because we collect no Personal Data from anyone, we also collect none from children. Accounts on Your Server, and any age requirements that apply to them, are determined by whoever operates Your Server.
11. Your rights
Depending on where you live, you may have rights over your Personal Data, such as access, correction, deletion, portability, restriction and objection, and the right to complain to a supervisory authority. Since we hold no Personal Data about you, there is nothing for us to provide or erase; to exercise these rights over data held on Your Server, contact whoever operates it. You are always in control of data on your own device: you can delete any of it by removing an account, clearing the App’s storage, or uninstalling the App.
We do not sell or share Personal Data, as those terms are defined by the California Consumer Privacy Act, and we do not engage in targeted advertising or automated decision-making.
12. Changes to this policy
If the App changes in a way that affects this policy, for example if it ever needed to connect to a service other than Your Server, we will update this page and its effective date before that change is released, and we will describe the change in the App’s release notes. Continued use of the App after an update means you accept the revised policy. Previous versions are available on request.
13. Contact
Questions about this policy can be sent to the developer through the contact details published at ayushya.dev.