Privacy Policy
Last updated: 2026-10-03
This policy explains what the Batbrief Android app
(name.gpm.batbrief) does with data. It covers the app only.
The app comes in two builds, and they differ in what they send. The Play build is the one installed from Google Play. The store-free build is the one installed from the F-Droid repository listed on the home page. Where a section applies to only one of them, its heading says so.
The short version: your bug report never leaves your device. Not the one you give the app to read, and not one the app captures itself. Nothing derived from a report is sent anywhere either.
What the app does send is separate from that, and most of it is optional:
- Both builds ask the author’s server for announcements (you can turn that off), and can send a report, an idea or a message to the author, and can prove an email address — all only when you use those screens.
- The Play build only also carries Google’s Firebase: crash reports and usage statistics, both on when you install the app, asked about once after the first run and switchable at any time in Settings; announcements by push; and Google Play billing.
- The store-free build only carries none of Google’s libraries, no billing and no Firebase.
Who is responsible
Gabriele Proietti Mattia is the data controller for the processing described here. Contact: apps@gpm.name.
What never leaves your device: the bug report
Batbrief analyses a bug report — the diagnostic file Android produces from
Developer options → Bug report, or through adb bugreport. The app can also capture one
itself, on demand or on a schedule (see below). Either way:
No part of a bug report is sent anywhere. No finding, no measurement, no package name, no file name. There is no code path in the app that sends one, and nothing from a report is in a crash report or in the usage statistics either.
A bug report is a very revealing file. Depending on your device and Android version it can contain the names of Wi-Fi networks you have joined, the accounts configured on the phone, the text of recent notifications, a complete list of your installed apps, device identifiers and system logs. This is why the app is built the way it is.
A report you give the app
The file reaches the app when you share it or pick it, through Android’s share sheet or file picker, which grant access to that one file and nothing else. Batbrief then:
- Streams the file and copies only the battery-history sections into the app’s private storage, which no other app can read.
- Analyses that extract on the device.
- Deletes it when you close the report.
The original file is yours and stays wherever you saved it; Batbrief neither moves nor deletes it.
A report the app captures itself
The app can ask Android for a bug report without you going through Developer options,
using Shizuku if you have installed it and started its service. Batbrief uses
Shizuku’s permission (moe.shizuku.manager.permission.API_V23) only to run Android’s own
bugreportz command on the phone; without Shizuku, the app does not capture anything
and you share a report to it instead. A capture can also run on a schedule you set, and
posts a notification with the result.
Reports the app captures are kept on the phone, under Captured reports, until you delete them or until automatic deletion removes the oldest. Automatic deletion is a setting; by default the app keeps the last 10 and removes older ones, and you can choose to keep 5, 10, 20, 50 or all of them. The setting is the same in both builds.
Captured reports, and the baseline (the app’s record of your phone’s good nights), are excluded from Android’s cloud backup and from device-to-device transfer. They are not copied to your Google account and do not move to a new phone.
What else stays on the device
- Its own settings: the theme, the language, the hours you consider night, the automatic-deletion setting, and the switches described below.
- The sign-in key, if you have signed in (see below). It lives in the app’s private storage and is sent only to the author’s server, to prove the address is yours. Sign out removes it.
- A record of your last Play purchase (Play build), so that you can prove support later; see “Purchases”.
- The battery history, if you turn it on (the History tab, or Settings → Battery history; Pro in the Play build). One reading of the battery every 15 minutes: the level, whether it is charging, the current, the charge counter, the voltage, the temperature, the cycle count where Android reports it, and whether the screen was on. It is kept in the app’s private storage for up to 400 days and is never sent anywhere. Stop recording keeps what was recorded; Delete history removes it.
Uninstalling the app removes all of it, as it does for any app’s private storage.
If Android’s app backup is enabled on your device, your settings may be included in your own device backup, under Google’s terms. Captured reports, the baseline and the battery history are not (above).
What leaves your device — both builds
Announcements from the author
The app checks about every six hours for announcements from the author. The request is a
plain GET to apps-management.gpm.name that carries the app’s id, your language, which build it is (Play or store-free) and the timestamp of
the last announcement it saw. It carries no identifier. Like any web request, it
necessarily reaches the server with your IP address.
You can turn this off in Settings (the Broadcast setting). The Play build additionally receives announcements by push, see below.
A report, an idea or a message to the author — optional
Batbrief has a screen to write in — something is wrong, or you have an idea — and a messages screen where you read the answers and reply in the same conversation. They are optional and nothing runs on its own: nothing is sent until you write something and press send.
What it carries:
- What you wrote: whether it is a bug or an idea, the title and the text, and any later message you add to the conversation.
- What makes it fixable: the app version, your Android version, the phone’s manufacturer and model, and your language tag. The app writes these into the message; none is read from an identifier.
- A screenshot, only if you pick one. Nothing is captured for you. The picture is shrunk and re-encoded on your phone, and what you see before sending is exactly what leaves it — so if part of the screen has nothing to do with the problem, remove it first.
- Your email address, only if you type one (in the Play build, the Google button can fill the field in for you). Without one a report is anonymous and cannot be answered; with one, it is how you get a reply.
This is a message you write, not a bug report. A bug report is never attached and cannot be.
It goes to apps-management.gpm.name, a service run by the author. It is not shared with
anyone, not used to build a profile and not published: reports are read, given a state
and answered by hand. No advertising id and no install id goes with it.
Signing in to prove an address — optional
Reading answers in the app, voting on ideas, being on the supporters list and receiving a licence granted by the author all need the service to be sure an address is yours. The app offers:
- An address and a code, in both builds: you type the address and the service emails a six-digit code (also a link) to it. Enter the code and the address is proved.
- Google sign-in, in the Play build only: the app asks Android for your Google account, and Google’s ID token is sent to the service, which checks it against Google’s own keys. The service then stores your email address, the Google account id and the name on the account. The store-free build has no Google sign-in and no Google libraries.
Once you are signed in, the app keeps a key — the one thing here that resembles a login:
- it hangs from the address you proved, never from your phone: nothing about the device goes into it, two phones that prove the same address get two separate keys, and removing the app throws the key away rather than recovering it;
- it works for Batbrief only, and opens nothing in any other app;
- the service stores a one-way hash of it, not the key itself;
- it stops working after a year without use, and Sign out withdraws it at the service and not only on your phone.
Sending a report needs none of this. You can write to the author having proved nothing, and that message carries no identifier of any kind.
When you are signed in, the app checks your licence on every launch: it uses the key to ask the service whether the author has granted you Pro. If you have not signed in, nothing is sent for that check.
Feature requests and votes
The messages screen lists what people have asked for in Batbrief, and lets you ask for something and vote. Reading the list needs no address. Asking and voting need a proved address, for one reason: one vote per person is a promise, and without something to hang it on the count would mean nothing.
What is published is the request itself, once the author has read it. Never your address, and never who voted for what.
Your name in the supporters list — optional, and off unless you ask
Batbrief can show who has supported it, in the app. Nobody is on it without asking, and asking is a screen you have to open. What is published is the name you typed and nothing else: never an address, never an amount, never a date. Turning it off removes the name at once.
How the service knows you supported the app depends on the build; see “Purchases” (Play build) and “Donations” (store-free build) below.
Deleting the account and its data
Everything in this section that the service holds about you can be deleted, in the app (messages screen → Delete my account and data) or from the delete-account page. See “Retention”.
What leaves your device — Play build only
Crash reports — on unless you turn them off
If Settings → Diagnostics → Send crash reports is on — and it is, unless you turn it off — a crash sends a report through Firebase Crashlytics: the stack trace, the device model, the Android version, the app version, and a Crashlytics-generated installation identifier. Nothing from a bug report is in it.
Usage statistics — on unless you turn them off
If Settings → Diagnostics → Send usage statistics is on — and it is, unless you turn it off — Firebase Analytics records:
- the events it collects on its own, such as first open, session start and screen views;
- around Pro, that the support sheet was opened and from which control, that it was closed, and, if you go on, which plan you picked (monthly or yearly) and whether it came with a free trial, whether the purchase was cancelled, failed or is pending, and whether a trial or a subscription started. Pressing Restore and pressing Manage on the subscription are recorded too. These are the names of controls and plans, never an address or anything you typed;
- with those events, the identifiers Analytics collects by default: the Android Advertising ID, the Firebase app-instance id, the device model and Android version, and a coarse location that Google derives from your IP address.
Nothing from a bug report is ever in it: no reading, no package name, no file name.
Both are asked about once, and both can be turned off
Both switches are on when you install the app. After the first run the app asks you once, with the two switches on the screen and what each one sends, and you can switch either off there. Both stay under Settings → Diagnostics for ever afterwards. Turning one off takes effect immediately and holds across restarts.
Both SDKs are switched off in the app’s manifest, so nothing is collected while Android is still starting the app, before a setting has been read; the app then switches them on to match your settings, and your settings start out on. Collection starts with the first launch, and stops the moment you turn it off.
The app carries no advertising and no ad personalisation. The advertising ID is collected only as one of Analytics’ default identifiers, for statistics.
Deleting this data per person is not possible for the author. Firebase keys it to the app-instance id and the advertising ID, which the app cannot list and cannot give to the author, so a request cannot be matched to a device. The practical remedy is to turn the two switches off, and, for the Advertising ID, to reset or delete it in Android’s own settings.
Firebase is operated by Google. See the Firebase privacy documentation and the Google Privacy Policy.
Announcements by push
For the same announcements as above, the Play build also subscribes to Firebase Cloud
Messaging topics (broadcast-all and broadcast-batbrief). The registration token
that lets Google deliver a push stays with Google and Firebase and is never sent to the
author’s service. The Broadcast setting that turns the announcements off applies to
this too.
Purchases
Pro is one subscription, monthly or yearly, with a free trial. It is bought through Google Play Billing: the author never sees your payment details, and Google’s handling of the purchase is covered by Google’s own privacy policy.
The app keeps the token of your latest purchase on the phone, so that you can prove you have supported it even after a subscription lapses. If you sign in and open the supporters screen, the app sends that token, with the sign-in key, to the service, which records the purchase against your address. Google has already told the service about that purchase, without saying who made it. The record is what makes your name available for the supporters list; it is shown there only if you choose to turn that on.
What leaves your device — store-free build only
The store-free build has no Firebase, no Google libraries and no billing. It has no crash reporting, no usage statistics and no push. Its screen for supporting the app has:
- Donations through external links (Ko-fi, and a card, Google Pay and PayPal page), which open in your browser and are handled by those services, under their own policies. The app does not see your payment.
- A reminder notification once a week asking whether you would like to donate, on its own notification channel that you can silence in two taps in Android’s settings. Silencing it takes nothing away, and it stops when a donation is confirmed.
- The supporters list, if you have proved an address (above): the service can match a donation that was made with that address to you. The address is never shown.
What the app never does
- No advertising, no ad personalisation, and no sale or sharing of data with advertisers or data brokers.
- No tracking across other apps or websites.
- No password anywhere. An email address only if you type one in, or sign in with Google in the Play build — to be answered about a report, to read those answers, to vote, or to have a purchase or donation recognised — and never for anything else. No contact list.
- No reading of your files, photos, contacts, messages or call history. A screenshot for a message and a bug report to analyse each come through Android’s picker or share sheet, which hands the app the one file you chose and nothing else.
- No sending of a bug report, or any part of one, anywhere.
Permissions
What the installed app declares, after merging the app’s own manifest with its libraries.
| Permission | Why |
|---|---|
INTERNET |
Announcements, messages to the author, sign-in, the supporters list, licence check, and (Play build) Google’s services. Never a bug report. |
POST_NOTIFICATIONS |
The progress and result of a capture, announcements, and (store-free build) the weekly donation reminder. Asked for when a capture starts or a schedule is turned on; refusing it costs the notifications and nothing else. |
FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNC |
A capture runs as a foreground service so it can finish with the app closed. |
RECEIVE_BOOT_COMPLETED, WAKE_LOCK, ACCESS_NETWORK_STATE |
Added by the WorkManager library: scheduled work is restored after a restart, and kept awake while it runs. |
moe.shizuku.manager.permission.API_V23 |
Shizuku’s own permission, used only to run bugreportz on the phone. It does nothing unless you have installed Shizuku and started it. |
com.android.vending.BILLING |
Play build. Buying and restoring Pro. |
com.google.android.c2dm.permission.RECEIVE |
Play build. Receiving announcements by push. |
com.google.android.gms.permission.AD_ID, ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION |
Play build. Added by Firebase Analytics, for the Advertising ID it collects. The app shows no advertisements. |
USE_BIOMETRIC, USE_FINGERPRINT, BIND_GET_INSTALL_REFERRER_SERVICE |
Play build. Added by Google libraries. The app has no biometric feature and does not use the install referrer itself. |
The store-free build declares only the permissions up to and including Shizuku’s.
Legal basis (GDPR)
For readers in the EU/EEA and the UK:
- Crash reports and usage statistics (Play build) — your consent (Art. 6(1)(a)), given by leaving the switch on after being asked, and withdrawable at any time by turning it off. Withdrawal stops future collection; it does not retroactively delete data already sent.
- A report or message, and the address you attach to it — your consent, given by pressing send.
- Proving an address, and the sign-in key — your consent, given by asking for the code or pressing the Google button. Withdrawn by signing out, or by deleting the account.
- Announcements — the author’s legitimate interest in telling users about a release or a problem (Art. 6(1)(f)); you can object by turning them off in Settings.
- Purchases — performance of the contract with you (Art. 6(1)(b)); Google is the seller and handles the payment.
Retention
On the phone: captured reports until you delete them or automatic deletion does; the battery history for up to 400 days, or until you delete it; the extract of a report you gave the app is deleted when you close it.
At the service (apps-management.gpm.name):
- An address, and what hangs from it (a sign-in, votes, a name on the supporters list, the link to a purchase) is kept while you use it. An address that has been silent for five months — nothing sent, requested or signed in with — is sent an email saying it will be deleted, and is deleted a month later, six months after it went quiet, unless you have come back in the meantime. Nothing is deleted that was never warned.
- Never deleted this way: an address with a donation recorded against it, one that is on a supporters listing, one with an active licence or subscription. These are records of something that was paid for or given.
- A sign-in key stops working a year after you last use it, and is withdrawn the moment you press Sign out.
- Reports and feature requests are kept while they are useful — an open one until it is answered, a closed one as the record of a decision. A screenshot is part of the report it came with and goes when it goes. When an address is deleted, its reports and requests stay with the address removed from them.
At Google (Play build): Firebase keeps crash and analytics data according to Google’s retention settings for the project; the author cannot delete it per person (above).
Your rights
Under the GDPR you may request access to, correction of, or deletion of your personal data, object to processing, and lodge a complaint with a supervisory authority.
For what the service holds, that is straightforward: in the app, messages screen → Delete my account and data, or write to apps@gpm.name from the address you signed in with, or use the delete-account page. Deletion takes the address, the sign-in, your votes, your supporter name and listing, and the link to a purchase. It does not cancel a Google Play subscription, which you cancel in Google Play, and Google keeps its own payment records.
For Firebase data (Play build) there is usually no way to link a request to a specific person, since it is keyed to identifiers the app cannot list: the remedy is to turn the two switches off in Settings. For everything on the phone, uninstall the app.
Children
Batbrief is not directed at children under 13 and knowingly collects no data from them.
Changes
Material changes will be published on this page with a new date at the top, and significant ones will be noted in the app’s changelog.
Last updated: 2026-10-03