App name: ABSend (ABSend - Offline Media Sender)
Application ID: com.amarbaro.sender
Published at: https://amarbaro.com/privacy/absend
Last updated: 28 August 2026
ABSend makes smaller copies of your photos, and sends files straight from one device to another over a local network or a hotspot your phone creates. This policy explains what it does and does not collect.
Nothing is collected. Nothing is sent to us, or to anyone else.
There is no account, no login, no analytics, no advertising, and no server that holds your content. The app contains no code that contacts any address on the internet. Your photos, videos and files move only between your device and the device you are sending to.
Photos you convert are read from your device, re-encoded on your device, and written
back to your device in the folder Pictures/AVIF. Your originals are never modified or
deleted.
Files you send are served by a small web server that runs on your phone, over your local Wi-Fi or a hotspot your phone creates. The receiving device downloads them directly by opening a link or scanning a QR code. No part of that traffic passes through the internet, or through any server we operate — because there is no server we operate.
Files you receive from the other device are saved into Pictures/Received,
Movies/Received or Download/Received, according to their type.
Location data in photos is removed from converted copies by default. If you switch "Include location" on, GPS coordinates in the photo's metadata are preserved in the copy. The app never reads your device's current position.
This distinction matters, so it is stated plainly rather than implied.
On a network your phone did not create — someone else's Wi-Fi, a café, an office — the
transfer is encrypted with ChaCha20. The key never travels over the network: it lives in
the part of the link after the #, which browsers do not send to servers, and reaches the
other device only by QR code or by you passing the link along.
On a hotspot your phone creates, the transfer is not encrypted. The hotspot is yours, it exists for the length of the transfer, and its password is generated by Android for that session alone.
A transfer containing video is not encrypted, on any network. The receiver plays video in a browser, and a browser cannot decrypt a stream as it arrives. If you send a video over a network you do not control, treat it as sent in the clear.
Encryption on other people's networks is on when you install the app; it can be turned off in Settings. The other two cases above are not settings — they are how the app works.
The encryption protects the contents of a transfer from someone else watching the same network. It is not an identity check: it does not prove who is at the other end, and it does not detect tampering. Anyone who has the link and the key can download the files, so treat the QR code as the secret it is.
Earlier drafts of this policy described optional crash reporting through a third-party service. The app as published contains no crash reporting and no third-party reporting code of any kind. Nothing is transmitted when the app fails.
The app keeps a short log on your phone recording what it did — files converted, transfers started, errors encountered. It records file names, sizes and timings. It never contains the contents of your files.
It stays on the device. It is capped in size, it is excluded from Android's automatic backup, and it is never transmitted anywhere on its own.
If you use Report a problem, the app prepares that log as a text file and hands it to whichever app you choose to send it with. You can read it before you send it, and you choose the recipient. Nothing is sent automatically.
Automatic backup is switched off for this app. The activity log and your settings are not copied to Google Drive and are not carried across in a device-to-device transfer. The trade-off is that a new phone starts fresh — remembered networks do not follow you.
The app never asks for permission to read your photo library. Choosing photos goes through the Android photo picker, which hands the app only the files you select.
| Permission | Why |
|---|---|
| Internet | Local network sockets. Android uses this name for all socket access, including between two phones with no internet at all |
| Wi-Fi state, change Wi-Fi state | To create and manage a local hotspot when you choose that option |
| Nearby Wi-Fi devices | Required by Android to create a hotspot; declared "never for location" |
| Location (Android 12 and below only) | The older spelling of the hotspot permission above. Declared with a maximum version so newer Android never grants it, and never used to obtain a position |
| Local network access | Required from Android 16 to talk to another device on the same network |
| Notifications | To show the progress of a conversion or transfer |
| Foreground service (data sync, connected device) | To keep a transfer or conversion alive when the screen locks |
| Network state, wake lock, run at startup | Requested by Android's own background-work library, which the app uses to run conversions. They are not used to start the app on its own |
The app is not directed at children and collects nothing that would identify anyone.
If this policy changes, the date at the top changes and the new version appears at this address.
Questions about this policy: privacy@amarbaro.com