Privacy Policy
Androsaurus helps users manage GitHub-hosted Android projects, edit source code, build signed APK/AAB artifacts with GitHub Actions, and prepare Google Play drafts.
Summary
Androsaurus processes project and account information only to perform actions you request. Source code stays on your device and in your GitHub account, and builds run in your GitHub Actions environment. Androsaurus does not include advertising SDKs, analytics, or crash-reporting services, and Pix-kit does not sell personal data.
1. Information Androsaurus handles
Depending on the features you choose, Androsaurus may handle:
- Your GitHub fine-grained personal access token, account identity, repositories, branches, commits, pull requests, workflow runs, and repository content you choose to fetch or change.
- Local project workspaces, edited files, synchronization state, cached APK/AAB artifacts, build reports, logs, screenshots, and Google Play listing metadata.
- Release-signing material including a keystore, key alias, passwords, and certificate fingerprints.
- The package name, installed state, and SHA-256 signing-certificate fingerprints of the exact launchable Android app that a selected APK may replace. Androsaurus uses Android's narrow launcher-app visibility query and does not request QUERY_ALL_PACKAGES.
- Local review-prompt scheduling data, including first-use time, successful-build count and recent opaque operation identifiers, prompt-attempt count, and the next eligible prompt time.
- A Google Play service-account JSON key that you explicitly import for publishing actions.
- Google Play subscription state and the purchase token supplied to the Billing Library while a purchase is validated or acknowledged. Androsaurus does not store or log the purchase token.
- The normalized GitHub owner/repository name selected for free usage and the UTC time of its latest successful build.
2. Local storage and credential protection
Workspaces, settings, cached artifacts, the free-project lock, and the most recently verified Premium state are stored in the app's private storage. Android cloud backup and device-transfer backup are disabled for Androsaurus app data.
GitHub credentials, Google Play publishing credentials, and on-device signing material are protected with Android platform security and app-private storage. The Google Play service-account file is size-limited and validated before it is saved. A portable signing-backup ZIP is created only when you explicitly request it. Unlike the encrypted on-device backup, that exported ZIP is not encrypted and must be kept in private, encrypted storage under your control.
3. GitHub and GitHub Actions
Androsaurus contacts GitHub to carry out actions you request and to safely resume, reconcile, or verify operations already started. These actions include listing or creating repositories, fetching files, committing changes, managing branches or pull requests, configuring Actions secrets, and starting or inspecting builds.
Android builds run in the GitHub Actions environment of the selected repository. Source code, build logs, artifacts, and repository history are then handled under your GitHub account and GitHub's terms and privacy policy. Androsaurus does not operate a separate Pix-kit source-code build server.
4. Google Play publishing
If you configure Google Play publishing, Androsaurus uses the service-account credential you provide to communicate directly with Google Play APIs. The app sends an AAB, Store Listing text, images, and release metadata only when you explicitly prepare a Google Play draft.
Google Play Console declarations, review, testing, and final publication remain under your control.
5. Google Play Billing and subscriptions
Google Play processes payments for Androsaurus Pro. Androsaurus never receives or stores your full card or bank details. The app grants Premium access only when Google Play reports the subscription as purchased; a pending purchase does not unlock Premium.
Active purchases are synchronized automatically with the current Google Play account when Androsaurus opens or returns to the foreground. Initial purchases are acknowledged through Google Play Billing. You can view, change, pause, resubscribe, or cancel through the Manage subscription link, which opens Google Play.
The current release stores a short-lived Premium verification result locally and does not use a Pix-kit subscription backend.
When local eligibility conditions are met, Androsaurus may ask Google Play to present its standard in-app review flow. Google Play decides whether the prompt appears and handles any rating or review. Androsaurus does not receive the rating or review text and stores only local scheduling and prompt-attempt state.
6. Permissions
- Internet: connects to GitHub, GitHub Actions, Google Play Billing, Google Play in-app review, and Google Play publishing APIs.
- Notifications and foreground data sync: keeps user-started fetch, push, build, import, install, and publishing operations visible while they run.
- Wake lock: uses a bounded partial wake lock while tracking a GitHub build so device sleep does not interrupt that foreground operation.
- Package visibility, install, and uninstall: inspects the exact package and signing certificate of the app a selected APK may replace. It opens Android's package installer or, after an explicitly confirmed signing mismatch, Android's uninstall confirmation. Androsaurus never installs or uninstalls an application silently, and Android keeps the final confirmation.
- Document access: uses Android's system picker when you choose files to import or destinations for exported artifacts.
7. Data sharing and third-party services
Androsaurus sends data only to services required for the features you choose, principally GitHub, GitHub Actions, Google Play Billing, the Google Play Android Publisher API, Google Play in-app review, and Android system services. Pix-kit does not sell or rent this data and does not use it for cross-app advertising.
Those providers process information under their own terms and privacy policies.
8. Retention and deletion
- Disconnecting GitHub removes the saved GitHub token and related account settings from the app.
- Clearing a repository cache removes that local workspace and its cached build artifacts from the device.
- Clearing app data or uninstalling Androsaurus removes app-private settings, local workspaces, the free-project lock, the entitlement cache, and unexported artifacts.
- Temporary build and import files are deleted after the operation.
- Commits, pull requests, GitHub Actions logs and artifacts, exported files, and Google Play records remain with their provider or destination until you delete them there.
9. Children's privacy
Androsaurus is a professional software-development tool and is not directed to children under 13. If you believe a child has provided personal information through the app, contact us so we can help address the issue.
10. Security
Androsaurus uses app-private storage, AndroidKeyStore-backed protection where supported, least-privilege integration guidance, verified workspace snapshots, and explicit confirmations for destructive operations. No system can guarantee absolute security. Protect your device, restrict GitHub tokens to required repositories and permissions, keep signing backups secure, and revoke credentials that may have been exposed.
11. Changes to this policy
This policy may be updated as Androsaurus evolves. Material changes will be published on this page and the effective date above will be updated.
12. Contact
For privacy questions, requests, or concerns, contact:
Developer: Pix-kit
Email: niko@pix-kit.com