Effective date: October 10, 2026
FTP Server is an Android application developed by PolyApp Studios that lets users run an FTP or FTPS server on their own device, accessible over a local network or a VPN that permits incoming connections.
FTP Server does not create accounts, use authentication services, upload your files to our servers, or provide a cloud file service.
We do not collect through product analytics:
Your files
File names
Folder contents
Folder paths or exact root folder paths
FTP username or password
FTP server address or server URL
Phone IP address
FTP client IP addresses
FTP client usernames
FTP commands
Contact information
Precise location data
Account identifiers
Raw JavaScript warning or error messages
The app may store settings locally on your device, such as:
Port number
Username
Password
Anonymous access setting
FTPS setting
Root folder path
Read-only setting
Language and theme preference
Analytics and crash-reporting preference
Recent FTP client IP addresses and last connection times
User-chosen device names and trusted/blocked IP rules
This information stays on your device and is used only to run and configure the local FTP server and app preferences. Device history and rules are stored privately on the phone and are not sent to analytics or crash-reporting services. You can remove a saved device and its rule from the Devices page. IP addresses can change or be reused, so a trusted label does not authenticate a physical device.
You can remove advertising with a one-time purchase processed by Google Play. Google manages payment and ownership through your Google Play account. FTP Server does not receive payment card or bank details and does not create a purchase account or database on our servers.
The app checks ownership with Google Play and stores a signed purchase record privately on your device for offline access. Restore purchases using the same Google Play account. Receipts, order IDs, and purchase tokens are not sent to our analytics or crash-reporting services. Refunded or revoked purchases may lose access when Google Play reports the updated status.
FTP Server may request broad file access so you can choose folders and serve files from your device through the local FTP server. Files are accessed only according to the folder and server settings you choose.
When the FTP server is running, devices on the same network may access the selected root folder if they have the configured server address and login credentials, or if anonymous access is enabled.
FTP Server uses PostHog as a product analytics service provider to understand pseudonymous app usage. Random installation identifiers link events from the same installation, without identifying you by name, email or account. Person profiles and session replay are disabled.
Analytics and crash reporting are enabled by default. You can turn Analytics and Crash reports off separately under Settings > Privacy choices. PostHog initializes only after the saved Analytics preference is read. Turning Analytics off stops new collection/delivery and removes locally queued analytics and the stored random identity. It does not delete events already received by PostHog; in-flight requests cannot be recalled. Re-enabling uses a fresh random identity.
The app may send pseudonymous product events such as:
App opens and screen visits
Address-copy success/failure with local-network or VPN category only, without the copied address or clipboard contents
Address QR-code views with local-network or VPN category only, without the address or QR contents
Storage-permission check outcomes and Android settings-launch outcomes with entry screen only, without folder paths
Folder-loading failure categories, without folder names or paths
Connection-disconnect action outcomes, without client or connection identifiers
Device-management action categories and success/failure, without device names, addresses, saved rules or connection history
Safe setting categories, such as enabled or disabled values, default or custom port category, and internal-root or custom-folder category
FTP server start and stop success or failure categories, including the startup phase and error type category
Client connection/disconnection and successful authentication events, without client identity, username or address
Upload/download start, completion or failure with coarse size/duration buckets, failure categories, file-stream phase and numeric FTP failure reply codes, without reply text, names, paths or exact per-file sizes
Server-session duration, whether a client connected or authenticated, and bucketed connection/transfer counts and total transferred data
Remove Ads offer views and user-checkout start, verified completion or controlled failure, with entry screen only
Explicit purchase-restore requests and restored/not-found/pending/failure outcomes, without receipts, purchase tokens or order IDs
Banner loading, controlled error-code categories and impressions, with screen only
Ad-consent and advertising initialization operation success/failure with fixed phase/error-code categories, without consent strings, selected choices or original Google response text
App/build version, operating-system version, platform, selected language/theme, screen-awake setting, ad-removal ownership boolean and random installation/session/event identifiers
The app does not send files, file names, folder paths, FTP credentials, IP addresses, server URLs, FTP client usernames/commands, hardware or advertising IDs, purchase receipts/order IDs/tokens, or raw exception messages/stacks to PostHog. Automatic UI/touch capture, PostHog error tracking and replay are disabled. Events may be stored privately on your device for delivery after connectivity returns. Our PostHog project uses European Union hosting and its current plan retains analytics for one year. Receiving infrastructure processes the source network address to deliver requests; the client disables GeoIP enrichment and our project is configured to discard client IP data. This is pseudonymous analytics, not guaranteed network anonymity. Learn more at https://posthog.com/privacy.
The app also uses Sentry for JavaScript errors and native Android crash diagnostics, including selected handled failures with fixed error messages such as purchase-verification failures and unexpected FTP startup, shutdown or upload/download failures. Ad-consent failures use fixed operation/phase/error-code categories, including structured Google SDK codes and fixed native exception categories, without original Google response text, consent strings or your selected ad choices. Handled FTP diagnostics contain fixed operation, failure and phase categories, fixed exception identities, Android socket error categories, port classes (without the actual port), and bounded code stack frames for nested causes. The original storage or FTP error text is not attached. Crash reports controls Sentry separately from Analytics. Sentry receives app/build versions, operating system and device model information, original exception messages, code stack frames, foreground/background breadcrumbs and fixed screen/operation categories. Exception messages may include details supplied by the code that raised the error. Attached application settings, console logs, and network request breadcrumbs are removed or disabled. Screenshots, view hierarchies, session replay, and performance tracing are disabled. Native crash reports can contain low-level crash information needed to diagnose failures. We do not attach your documents or FTP data to these reports.
Sentry reports can be cached on the device for delivery after a crash or loss of connectivity. Turning Crash reports off stops new reporting and removes the local Sentry cache; it does not delete reports already received by Sentry. As with any internet service, the receiving infrastructure processes a network IP address to deliver requests. The SDK does not intentionally add your IP address or a user identifier to diagnostic events. Our Sentry organization stores data in the European Union. Under our current Developer plan, individual error and crash events are retained for 30 days. Aggregated issue information can remain after individual events expire. Learn more at https://sentry.io/privacy/.
Unexpected banner failures can also create Sentry diagnostics with fixed operation, phase, SDK error-domain, error-code and failure-reason categories, including fixed categories for an underlying SDK cause when available. Original Google responses and messages, request identifiers, ad content and consent choices are not attached.
Failed checkout and explicit purchase restores can include fixed operation-phase, failure-reason and Google Play SDK response-code categories in PostHog. Failed device updates can include fixed validation, initialization, saving and list-refresh categories. Selected unexpected failures in these operations can also create Sentry diagnostics using those fixed categories. We do not attach raw Google Play messages, purchase contents, device names, addresses, access rules or stored device records. Expected input-validation, network-availability, timeout and cancellation outcomes do not create these additional Sentry reports. Analytics and Crash reports remain independently controlled.
FTP Server displays ads using Google AdMob. Google's Mobile Ads SDK may collect and share IP addresses (which can be used to estimate approximate location), app interactions, diagnostics, advertising ID, App Set ID and other device or account-related identifiers where applicable. Google uses this data for advertising, analytics, and fraud prevention and security, according to Google's policies and applicable consent choices. FTP Server does not request precise device location for advertising.
The app uses Google's User Messaging Platform where required to request consent before ads are loaded. Where Google requires privacy options for your region, you can reopen those ad privacy choices from Settings > Privacy choices.
The Analytics and Crash reports switches control PostHog and Sentry independently. Advertising has separate Google privacy choices. Purchasing Remove Ads disables advertising in the app. Google's retention and deletion practices are governed by its policies; clearing FTP Server's local data does not delete data already received by Google. Android provides controls to reset or delete your advertising ID where supported.
Learn more about how Google uses data:
https://policies.google.com/technologies/partner-sites
Google Privacy Policy: https://policies.google.com/privacy
App-private settings, saved device history and rules, and the signed purchase record stay on your device until changed or removed, or until the app's storage is cleared or the app is uninstalled. Queued analytics and crash reports can remain locally until delivered; their respective opt-out switches remove the local queues as described above.
You can remove individual saved devices and their rules on the Devices page. Reset settings restores FTP server settings; it does not erase device history, privacy choices, or Google Play purchase ownership. To remove all app-private data, use Android Settings > Apps > FTP Server > Storage > Clear storage (wording may vary by device), or uninstall the app. Files in shared storage, such as your selected FTP folder, remain unless you delete them separately. Files stored inside an app-private directory can be removed with that app's data.
Clearing storage or uninstalling does not cancel the Remove Ads purchase or remove Google's purchase records. Ownership can be restored through Google Play using the same account. It also does not delete telemetry already received by PostHog, Sentry or Google. Our current PostHog analytics retention is one year and Sentry individual-event retention is 30 days, as described above. FTP Server has no user accounts or account-deletion flow. Contact us below with questions about data retention or deletion; pseudonymous events may not be identifiable from your name or email alone.
FTP Server is not directed to children.
Analytics, crash-reporting and Google advertising requests use encrypted HTTPS/TLS connections.
Use FTP Server only on trusted networks. FTP is not encrypted. If encryption is needed, enable FTPS and use a client that supports it.
For privacy questions, contact:
Developer: PolyApp Studios
Website: https://polyappstudios.com/