What the Play Console and F-Droid are told, and why each answer is true of the build. The listing text itself is in fastlane/metadata/android/en-US: F-Droid reads it from there, and fastlane supply uploads the same text to Play.
generic (F-Droid) carries no Google library apart from the open-source LiteRT runtime its alt-text drafts use, which reports to no one. gplay (Google Play) adds Google's ML Kit to reach Gemini Nano (10-intelligence.md), each off until the reader turns it on. ML Kit would send Google diagnostics about its own use; the Play build removes the backend that sends them, so the app transmits none, and the answers below hold for both builds. Gemini Nano runs in Android's AICore service, which is part of Android, not of the app, and is not the app's to declare.
| Question | Answer | Why |
|---|---|---|
| Does the app collect or share any of the required user data types? | Yes | Posts, messages and pictures the reader writes go to the server they signed in to. |
| Is all collected data encrypted in transit? | Yes | Release builds refuse http://; every server is reached over TLS. |
| Can users request that their data be deleted? | Yes | Settings, Delete account, which deletes the account on Nextcloud Social and opens the server’s own page on Mastodon. |
| Data collected: Personal info, name, email, user IDs | Yes: user IDs (the account handle) | Shown to and kept by the reader’s own server; required to sign in. |
| Data collected: Messages, other in-app messages | Yes | Direct messages go to the reader’s server. |
| Data collected: Photos and videos | Yes | Attachments go to the reader’s server. |
| Data collected: App activity, other user-generated content | Yes | Posts, replies, favourites and boosts go to the reader’s server. |
| Data shared with third parties | No | The developer receives nothing. The reader’s server is the service they chose and sign in to, not a third party of the developer’s; a translation goes to the server, which hands it to the translation service it uses. |
| Is it processed ephemerally? | No | The server keeps what the reader posts. |
| Is collection required or optional? | Required | A fediverse client cannot post without sending the post. |
| Purposes | App functionality, account management | Nothing else: no analytics, advertising or personalisation by the developer, and none by the libraries in either build (10-intelligence.md, Telemetry). |
| Location, contacts, calendar, health, financial info, device or other IDs, app info and performance (crash logs, diagnostics) | Not collected | No such permission, no crash reporting or analytics library. Settings, About, Share diagnostics builds a report of the build, the device, the servers’ software and the recent log on the device, and shows it; it leaves only when the person taps Share and picks an app in the system share sheet. Play counts as collected only what the app transmits off the device, which it does not, and exempts from sharing a transfer the user starts and expects. |
- Category: Social or communication.
- The app lets users interact and exchange content (posts, messages, pictures, video): yes.
- It shares the user’s location with others: no; the app has no location permission. A post may carry a place the writer chose, as text.
- Digital purchases: no. Gambling: no.
- The content comes from other users across the fediverse, unfiltered by the developer: answer the user-generated content questions accordingly, which places the app at the rating for unrestricted web content.
Each requirement, and where the app meets it:
| Requirement | Where |
|---|---|
| Terms that forbid objectionable content and abuse, accepted before any content shows | The terms on first launch (with Decline, which leaves the app), again in Settings, About |
| Reporting content and users | A post’s menu, Report; a profile’s menu, Report; the report goes to the server’s moderators with the posts chosen |
| Blocking users | A profile’s menu, Block; Settings, Muted and blocked lists them and takes a block back |
| Blocking whole servers | A profile’s menu, block the server; Settings, Muted and blocked, Servers |
| Filtering objectionable content | Filters (account sheet and Settings): keywords, where, warn or hide, expiry; media marked sensitive shown as the account chose |
| Moderation of the service | The reader’s server moderates; About this server shows its rules and moderated servers |
| Contact | Settings, About, Report a problem (the issue tracker). The developer e-mail is the Play Console account’s. |
| Permission | Why |
|---|---|
INTERNET, ACCESS_NETWORK_STATE |
Reaching the server; checking whether a network is up and whether it is mobile data |
POST_NOTIFICATIONS |
Notifications, asked once an account exists |
FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNC |
Sending the outbox and uploads while the app is closed |
FOREGROUND_SERVICE_MEDIA_PLAYBACK |
Audio and video that keep playing in the background |
USE_BIOMETRIC |
The app lock |
WRITE_EXTERNAL_STORAGE (Android 9 and older only) |
Saving a picture to the shared Pictures folder |
READ_EXTERNAL_STORAGE (Android 12L and older only) |
Nothing reads shared storage. The build adds it beside the permission above, so the app declares it to cap it |
WAKE_LOCK |
Keeping playback (Media3) and background work (WorkManager) running with the screen off; both libraries declare it |
RECEIVE_BOOT_COMPLETED |
WorkManager scheduling its work again after a restart: background refresh and the outbox |
genericis the F-Droid build: no Google library, no proprietary dependency.- Reproducible builds are what F-Droid checks, building from the tag and comparing with the signed APK; whether this build is byte for byte reproducible is checked when the first release is cut (two clean builds of the tag, compared).
- Metadata:
fastlane/metadata/android/en-US(title, short and full description, a changelog perversionCode). Screenshots and the icon go underimages/when the release is cut.