Privacy policy
NexusAGI for Android
Application com.vasaserafin.nexusagi, version 0.1.3.
Last updated .
This policy covers the NexusAGI Android app published by Vasa Serafin (the "developer", "I"). It is written to describe what the app actually does, not what a template says an app might do. Where a claim below is about something not yet built, it says so.
The short version
- The app talks to two servers, both run by me: your own NexusAGI and NexusHub. There is no third-party backend.
- It has no ads, no in-app analytics, no crash reporter and no notifications. No advertising or analytics SDK is compiled into it.
- It does nothing at all until you sign in to your own account.
- Camera and microphone are used only for owner verification, only when you start one, and what they capture is never written to your device's storage.
- Nothing collected is sold, and nothing is shared with a third party for advertising or any other purpose.
What the app collects, and why
| Data | Why | Where it goes | Optional |
|---|---|---|---|
| Install identifier — a random id generated on first launch | Identifies this installation to your account so devices can be listed and a coin ledger can belong to someone. It is not the Android advertising id, not the IMEI, and not a hardware serial. | Your NexusAGI, NexusHub | No |
| Account name and session token | Signing in. The token is held in Android EncryptedSharedPreferences; if that store is unavailable the app keeps it in memory only and never writes it in plaintext. |
Stays on the device, sent as an authentication header | No |
| Messages you send — chat, and lines you contribute to a mirrored terminal | They are the content of the feature. They go to your own NexusAGI so it can answer. | Your NexusAGI, NexusHub | No |
| Device model, Android version, app version | Shown to you in the sign-in device list so an unfamiliar sign-in is visible. | Your NexusAGI | No |
| IP address (approximate location only in the sense that any IP is) | Recorded server-side against a sign-in, for the same device list. The app never sends an address field; the server stamps the connection it actually received. | Your NexusAGI | No |
| A short voice sample | Operator verification only. See the section below. | Your NexusAGI, for one decision | Yes |
| A few camera frames (front camera) | Operator verification only. See the section below. | Your NexusAGI, for one decision | Yes |
| Subscription state from Google Play Billing | Deciding whether the optional subscription is active. The decision is made on your device by Google Play. | Google Play (as the seller); the resulting flag is reported to NexusHub | Yes |
Camera and microphone — the whole story
The app declares CAMERA and RECORD_AUDIO for one feature:
owner verification. This is how the person holding the phone proves to
their own NexusAGI that they are its owner, before it will show owner-only
content.
When, and only when, you start a verification:
- The server issues a challenge that includes a flash pattern — a sequence of brightness levels.
- The app records a short audio sample and takes a small number of still frames from the front camera while the screen plays that pattern back as light. (The screen is the light source; front cameras almost never have a flash unit.)
- Audio is captured into memory. Camera frames are captured in memory as JPEG stills. Neither is written to a file, to your gallery, to external storage, or to any cache on the device.
- They are sent, once, over HTTPS to your own NexusAGI — the server named in the app's settings — which returns a yes or a no with its reasons.
- The resulting claim is session-only: it expires, and it is not restored the next time the app launches. Verification is a live act, not a saved state.
There is no face template, no voiceprint, no biometric enrolment and no liveness model stored anywhere by this app. It does not build a profile of your face or voice, and it cannot recognise you in any other context.
You can decline both permissions. The app keeps working; only the owner-verified pages stay out of reach, and it says exactly that rather than failing silently.
Status in version 0.1.3: the server side of verification is not deployed yet. In this build the Verify page reports that your NexusAGI does not support verification, so in practice no audio or camera capture is uploaded. The permissions and this section describe what happens once it is enabled.
Where data goes
- Your NexusAGI — by default
nexusagi.thetooltuckshop.rs, changeable in the app's settings to your own host. - NexusHub —
api.thetooltuckshop.rs, for sign-in, the coin ledger and the chat hop. - Google Play Billing, if and only if you buy the optional subscription. Google is the seller and is the party that holds your payment details; I never see them.
Both servers are operated by me. There is no analytics provider, no advertising network, no crash reporting service and no data broker in the app. Nothing is sold.
In transit, everything is HTTPS. Release builds of the app refuse cleartext HTTP to anything other than the loopback address, so a non-TLS connection to a remote host cannot happen by accident.
Retention and deletion
- Audio and camera frames are held only for the verification decision and are not retained afterwards. Nothing is written to your device.
- Messages, sign-in rows and the coin ledger persist on the server so the features work — that is what a message history and a device list are.
- The sign-in ledger is bounded by design: it keeps a limited number of rows per account and device, and older rows fall out.
- Signing out clears the session on the device. To have your server-side account and its rows removed, email the address below and say so; I will delete them.
Children
The app is not directed at children, is not in a Play "designed for families" programme, and contains no content or feature aimed at them.
Permissions the app does not ask for
No location permission, no contacts, no SMS or call log, no external storage, no advertising id, no accessibility service, no background location, and no permission to run commands on any computer. The terminal mirror is read plus send-a-message; the app cannot execute anything on the machine it mirrors.
Changes
If this policy changes, the date at the top changes with it, and a material change will be described in the app's release notes. The version this policy describes is stated at the top so an old build is never covered by a policy written for a newer one.
About this website
Separate from the app: this website uses Google Analytics 4 with a consent banner and IP anonymisation, off until you choose Allow on that banner. There is no advertising anywhere on this website. The app itself contains no analytics and no advertising of any kind.
Contact
Vasa Serafin — vasa_serafin@hotmail.com. Privacy questions, data deletion requests and policy corrections all go to that address.