Privacy Policy

Last updated: 2026-10-03

This policy explains what the Batbrief Android app (name.gpm.batbrief) does with data. It covers the app only.

The app comes in two builds, and they differ in what they send. The Play build is the one installed from Google Play. The store-free build is the one installed from the F-Droid repository listed on the home page. Where a section applies to only one of them, its heading says so.

The short version: your bug report never leaves your device. Not the one you give the app to read, and not one the app captures itself. Nothing derived from a report is sent anywhere either.

What the app does send is separate from that, and most of it is optional:

Who is responsible

Gabriele Proietti Mattia is the data controller for the processing described here. Contact: apps@gpm.name.

What never leaves your device: the bug report

Batbrief analyses a bug report — the diagnostic file Android produces from Developer options → Bug report, or through adb bugreport. The app can also capture one itself, on demand or on a schedule (see below). Either way:

No part of a bug report is sent anywhere. No finding, no measurement, no package name, no file name. There is no code path in the app that sends one, and nothing from a report is in a crash report or in the usage statistics either.

A bug report is a very revealing file. Depending on your device and Android version it can contain the names of Wi-Fi networks you have joined, the accounts configured on the phone, the text of recent notifications, a complete list of your installed apps, device identifiers and system logs. This is why the app is built the way it is.

A report you give the app

The file reaches the app when you share it or pick it, through Android’s share sheet or file picker, which grant access to that one file and nothing else. Batbrief then:

  1. Streams the file and copies only the battery-history sections into the app’s private storage, which no other app can read.
  2. Analyses that extract on the device.
  3. Deletes it when you close the report.

The original file is yours and stays wherever you saved it; Batbrief neither moves nor deletes it.

A report the app captures itself

The app can ask Android for a bug report without you going through Developer options, using Shizuku if you have installed it and started its service. Batbrief uses Shizuku’s permission (moe.shizuku.manager.permission.API_V23) only to run Android’s own bugreportz command on the phone; without Shizuku, the app does not capture anything and you share a report to it instead. A capture can also run on a schedule you set, and posts a notification with the result.

Reports the app captures are kept on the phone, under Captured reports, until you delete them or until automatic deletion removes the oldest. Automatic deletion is a setting; by default the app keeps the last 10 and removes older ones, and you can choose to keep 5, 10, 20, 50 or all of them. The setting is the same in both builds.

Captured reports, and the baseline (the app’s record of your phone’s good nights), are excluded from Android’s cloud backup and from device-to-device transfer. They are not copied to your Google account and do not move to a new phone.

What else stays on the device

Uninstalling the app removes all of it, as it does for any app’s private storage.

If Android’s app backup is enabled on your device, your settings may be included in your own device backup, under Google’s terms. Captured reports, the baseline and the battery history are not (above).

What leaves your device — both builds

Announcements from the author

The app checks about every six hours for announcements from the author. The request is a plain GET to apps-management.gpm.name that carries the app’s id, your language, which build it is (Play or store-free) and the timestamp of the last announcement it saw. It carries no identifier. Like any web request, it necessarily reaches the server with your IP address.

You can turn this off in Settings (the Broadcast setting). The Play build additionally receives announcements by push, see below.

A report, an idea or a message to the author — optional

Batbrief has a screen to write in — something is wrong, or you have an idea — and a messages screen where you read the answers and reply in the same conversation. They are optional and nothing runs on its own: nothing is sent until you write something and press send.

What it carries:

This is a message you write, not a bug report. A bug report is never attached and cannot be.

It goes to apps-management.gpm.name, a service run by the author. It is not shared with anyone, not used to build a profile and not published: reports are read, given a state and answered by hand. No advertising id and no install id goes with it.

Signing in to prove an address — optional

Reading answers in the app, voting on ideas, being on the supporters list and receiving a licence granted by the author all need the service to be sure an address is yours. The app offers:

Once you are signed in, the app keeps a key — the one thing here that resembles a login:

Sending a report needs none of this. You can write to the author having proved nothing, and that message carries no identifier of any kind.

When you are signed in, the app checks your licence on every launch: it uses the key to ask the service whether the author has granted you Pro. If you have not signed in, nothing is sent for that check.

Feature requests and votes

The messages screen lists what people have asked for in Batbrief, and lets you ask for something and vote. Reading the list needs no address. Asking and voting need a proved address, for one reason: one vote per person is a promise, and without something to hang it on the count would mean nothing.

What is published is the request itself, once the author has read it. Never your address, and never who voted for what.

Your name in the supporters list — optional, and off unless you ask

Batbrief can show who has supported it, in the app. Nobody is on it without asking, and asking is a screen you have to open. What is published is the name you typed and nothing else: never an address, never an amount, never a date. Turning it off removes the name at once.

How the service knows you supported the app depends on the build; see “Purchases” (Play build) and “Donations” (store-free build) below.

Deleting the account and its data

Everything in this section that the service holds about you can be deleted, in the app (messages screen → Delete my account and data) or from the delete-account page. See “Retention”.

What leaves your device — Play build only

Crash reports — on unless you turn them off

If Settings → Diagnostics → Send crash reports is on — and it is, unless you turn it off — a crash sends a report through Firebase Crashlytics: the stack trace, the device model, the Android version, the app version, and a Crashlytics-generated installation identifier. Nothing from a bug report is in it.

Usage statistics — on unless you turn them off

If Settings → Diagnostics → Send usage statistics is on — and it is, unless you turn it off — Firebase Analytics records:

Nothing from a bug report is ever in it: no reading, no package name, no file name.

Both are asked about once, and both can be turned off

Both switches are on when you install the app. After the first run the app asks you once, with the two switches on the screen and what each one sends, and you can switch either off there. Both stay under Settings → Diagnostics for ever afterwards. Turning one off takes effect immediately and holds across restarts.

Both SDKs are switched off in the app’s manifest, so nothing is collected while Android is still starting the app, before a setting has been read; the app then switches them on to match your settings, and your settings start out on. Collection starts with the first launch, and stops the moment you turn it off.

The app carries no advertising and no ad personalisation. The advertising ID is collected only as one of Analytics’ default identifiers, for statistics.

Deleting this data per person is not possible for the author. Firebase keys it to the app-instance id and the advertising ID, which the app cannot list and cannot give to the author, so a request cannot be matched to a device. The practical remedy is to turn the two switches off, and, for the Advertising ID, to reset or delete it in Android’s own settings.

Firebase is operated by Google. See the Firebase privacy documentation and the Google Privacy Policy.

Announcements by push

For the same announcements as above, the Play build also subscribes to Firebase Cloud Messaging topics (broadcast-all and broadcast-batbrief). The registration token that lets Google deliver a push stays with Google and Firebase and is never sent to the author’s service. The Broadcast setting that turns the announcements off applies to this too.

Purchases

Pro is one subscription, monthly or yearly, with a free trial. It is bought through Google Play Billing: the author never sees your payment details, and Google’s handling of the purchase is covered by Google’s own privacy policy.

The app keeps the token of your latest purchase on the phone, so that you can prove you have supported it even after a subscription lapses. If you sign in and open the supporters screen, the app sends that token, with the sign-in key, to the service, which records the purchase against your address. Google has already told the service about that purchase, without saying who made it. The record is what makes your name available for the supporters list; it is shown there only if you choose to turn that on.

What leaves your device — store-free build only

The store-free build has no Firebase, no Google libraries and no billing. It has no crash reporting, no usage statistics and no push. Its screen for supporting the app has:

What the app never does

Permissions

What the installed app declares, after merging the app’s own manifest with its libraries.

Permission Why
INTERNET Announcements, messages to the author, sign-in, the supporters list, licence check, and (Play build) Google’s services. Never a bug report.
POST_NOTIFICATIONS The progress and result of a capture, announcements, and (store-free build) the weekly donation reminder. Asked for when a capture starts or a schedule is turned on; refusing it costs the notifications and nothing else.
FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNC A capture runs as a foreground service so it can finish with the app closed.
RECEIVE_BOOT_COMPLETED, WAKE_LOCK, ACCESS_NETWORK_STATE Added by the WorkManager library: scheduled work is restored after a restart, and kept awake while it runs.
moe.shizuku.manager.permission.API_V23 Shizuku’s own permission, used only to run bugreportz on the phone. It does nothing unless you have installed Shizuku and started it.
com.android.vending.BILLING Play build. Buying and restoring Pro.
com.google.android.c2dm.permission.RECEIVE Play build. Receiving announcements by push.
com.google.android.gms.permission.AD_ID, ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION Play build. Added by Firebase Analytics, for the Advertising ID it collects. The app shows no advertisements.
USE_BIOMETRIC, USE_FINGERPRINT, BIND_GET_INSTALL_REFERRER_SERVICE Play build. Added by Google libraries. The app has no biometric feature and does not use the install referrer itself.

The store-free build declares only the permissions up to and including Shizuku’s.

For readers in the EU/EEA and the UK:

Retention

On the phone: captured reports until you delete them or automatic deletion does; the battery history for up to 400 days, or until you delete it; the extract of a report you gave the app is deleted when you close it.

At the service (apps-management.gpm.name):

At Google (Play build): Firebase keeps crash and analytics data according to Google’s retention settings for the project; the author cannot delete it per person (above).

Your rights

Under the GDPR you may request access to, correction of, or deletion of your personal data, object to processing, and lodge a complaint with a supervisory authority.

For what the service holds, that is straightforward: in the app, messages screen → Delete my account and data, or write to apps@gpm.name from the address you signed in with, or use the delete-account page. Deletion takes the address, the sign-in, your votes, your supporter name and listing, and the link to a purchase. It does not cancel a Google Play subscription, which you cancel in Google Play, and Google keeps its own payment records.

For Firebase data (Play build) there is usually no way to link a request to a specific person, since it is keyed to identifiers the app cannot list: the remedy is to turn the two switches off in Settings. For everything on the phone, uninstall the app.

Children

Batbrief is not directed at children under 13 and knowingly collects no data from them.

Changes

Material changes will be published on this page with a new date at the top, and significant ones will be noted in the app’s changelog.

Last updated: 2026-10-03