OAPKH

Privacy Policy

OAPKH is the Android client for a self-hosted build distribution server. The app talks to the servers of the organizations you join, and to Google only for the two services described below. We, the developer, operate no servers, run no analytics, and never receive your data.

Last updated 26 September 2026

Who holds your data

The app does nothing on its own. Everything it shows comes from an OAPKH server that someone in your organization installed and administers, on infrastructure they control. That organization is the data controller for your account, and its own policies govern how your data is kept and for how long.

As the developer of the app, we have no access to any organization's server, database, storage or notification service. No data reaches us.

What the app sends to your organization's server

  • Account details — your email address and password when you sign in, and the display name and password you choose when you accept an invite. The OAPKH server stores passwords only as Argon2 hashes.
  • A notification registration — if you allow notifications and your organization has set them up, a Firebase Cloud Messaging token and the platform name ("android"). Signing out deletes the token and removes the registration from the server.
  • What you do in the app — the projects you follow, and when you last opened each one, so the app can show you what is new. If you are a developer or an admin, also the builds, changelogs, tags and settings you upload or change. The server keeps an activity log of uploads, edits, access changes and verification checks, which your team can see.
  • APK verification checks — when you check an APK, only its SHA-256 hash, package name and version code are sent. The file itself never leaves your phone.

What stays on your device

  • Session tokens, encrypted with a key held in the Android Keystore and stored in the app's private storage.
  • The organizations you have joined, your preferences, and a cache of recently viewed projects and builds, so the app opens quickly.
  • Downloaded APKs, kept in the app's own storage rather than your shared Downloads folder. Only the three most recent are kept.

The app opts out of Android's cloud backup, and uninstalling the app erases all of its data. None of it ever reaches us.

Google services

  • Firebase Cloud Messaging delivers build notifications. It runs on your organization's own Firebase project, not ours. To route messages, Google processes the notification token and a Firebase installation ID on your organization's behalf.
  • The Google code scanner, part of Google Play services, reads an invite QR code if you choose to scan one. The app never receives the camera image, only the text of the code, which is why it needs no camera permission. Google may collect diagnostic information about the scanner, such as device and app details and performance metrics, under Google's Privacy Policy.

The app contains no analytics SDK, no crash reporting, no advertising and no tracking of any kind.

Security

  • The app connects to servers only over HTTPS. Unencrypted connections are blocked.
  • Session tokens are encrypted at rest on your device, as described above.
  • Download links for builds are signed by your server and expire after five minutes.

Permissions and why

  • Internet — to reach your organization's server.
  • Install unknown apps — to install a build you chose to download. Only ever at your request, and only for that file.
  • Notifications — optional, for new builds on projects you follow. Decline it and the rest of the app works unchanged.

Firebase Cloud Messaging adds three permissions of its own, used only to deliver notifications: receiving messages from Google's messaging service, checking whether the device is online, and briefly keeping the device awake to handle an incoming notification.

The app asks for no location, contacts, photos, microphone, camera or advertising ID.

Keeping and deleting your data

On your device, data is kept until you sign out of that organization or uninstall the app. Signing out (Account → Sign out) removes that organization's session and notification registration from the phone and from the server.

On your organization's server, your organization decides how long data is kept. To close your account, ask your administrator. An administrator can deactivate an account, which ends its access at once; erasing the account and its data is done by whoever operates that server.

We cannot deactivate or delete an account for you, because accounts live on servers we have no access to. For anything else, contact us below.

Children's privacy

OAPKH is a tool for software teams and is not directed at children. Accounts exist only on servers run by organizations, which issue them to their own members.

Changes to this policy

If this policy changes, the revised version is posted on this page with a new date above.

Contact Us

If you have any questions about this Privacy Policy, feel free to reach out.