# ENGLISH
# Privacy Policy — Fotoro
**Last updated: 27 August 2026**
Fotoro is a digital photo frame for Android, developed by BFX Developer Romania. This
policy explains exactly what the app does with your data. It is written to be read, not to
be ticked off a list.
## In short
Fotoro has no accounts, no servers and no ads. We collect nothing about you. Your photos,
your settings and your passwords stay on your device. There is no server of ours that
receives anything from the app — because we do not run one.
## What stays on the device
The app stores locally, in the device internal storage:
- frame settings (photo duration, transition, order, brightness, language, temperature
unit, time format);
- the list of folders and albums you selected;
- the username and password of your local network folder (NAS), if you configured one;
- the child-lock PIN, if you enabled it.
This data never leaves the device. It is erased completely when you uninstall the app or
clear its data from Android settings.
## Permissions and why each is needed
**Photos and video** (`READ_MEDIA_IMAGES`, `READ_MEDIA_VIDEO`, and on Android 12 or older
`READ_EXTERNAL_STORAGE`) — to display photos from the device gallery. Photos are only read
and displayed. They are not copied, modified, uploaded or analysed. The app contains no
face recognition code and does not identify people.
**Internet** (`INTERNET`) — for three optional things: weather, the local network folder and
the Google Drive folder. If you use none of them, the app makes no connections at all.
**Approximate location** (`ACCESS_COARSE_LOCATION`) — only if you enable the weather
display. The app uses the last known position the system already holds; it never turns on
GPS and never tracks movement. Coordinates are rounded to roughly 110 metres before being
sent, and are never stored. Without this permission the rest of the app works normally —
only the weather is missing.
**Calendar** (`READ_CALENDAR`) — only if you enable events on screen. Events are read to be
displayed and nothing more: they are not stored, copied or transmitted.
**Keeping the screen on** (`WAKE_LOCK`) — a photo frame that switches itself off is not a
photo frame.
## Third-party services
The app talks to three destinations, all started by you and all optional.
**Open-Meteo** (weather service). Receives the rounded coordinates and returns the
temperature. Nothing else is sent: no device identifier, no account, no photo. Open-Meteo
requires no account and no API key. Their terms: https://open-meteo.com/en/terms
**Google Drive** (optional). If you link your account, the app requests the `drive.file`
scope, the narrowest one Google offers: it sees **only the files it created itself**. It
creates a folder named "Fotoro" in your Drive and sees only that folder contents. The
rest of your Drive is invisible to it by construction — this is not our promise, it is a
limit enforced by Google.
The access token received from Google is kept in working memory only, while the app runs.
It is never written to disk and never included in a backup. You can unlink the account at
any time from within the app, or at https://myaccount.google.com/permissions
Fotoro use and transfer of information received from Google APIs adheres to the
[Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy),
including the Limited Use requirements.
**Your local network folder (NAS)** (optional). The app connects directly to your own
device, on your own network. The username and password are sent only to that device and are
kept on the tablet for automatic reconnection. They never reach us and never reach anyone
else.
## What the app does NOT do
- No analytics: no Firebase, no Crashlytics, nothing.
- No ads and no advertising SDKs.
- No account creation, no e-mail address requested.
- No selling or sharing of data, because no data is collected.
- No tracking of which photos you view, for how long, or when.
- No uploading of your photos anywhere.
## Children
The app is made for the whole family and collects no personal data from anyone, at any age.
The PIN lock exists precisely so that a child cannot change the frame settings by accident.
## Deleting your data
All data lives on the device. You can erase it in two ways:
- uninstall the app; or
- Android Settings → Apps → Fotoro → Storage → Clear data.
Google Drive access is revoked separately, from within the app ("Disconnect the account")
or at https://myaccount.google.com/permissions
## Changes
If we change anything material, we update the date above and describe the change here.
## Contact
BFX Developer Romania
----
# ROMANA
# Politica de confidentialitate — Fotoro
**Ultima actualizare: 27 august 2026**
Fotoro este o rama foto digitala pentru Android, dezvoltata de BFX Developer Romania.
Aceasta politica explica exact ce face aplicatia cu datele tale. Este scrisa ca sa fie
citita, nu ca sa fie bifata.
## Pe scurt
Fotoro nu are conturi, nu are servere si nu are reclame. Nu colectam nimic despre tine.
Pozele tale, setarile tale si parolele tale raman pe dispozitivul tau. Nu exista niciun
server al nostru care sa primeasca ceva de la aplicatie — pentru ca nu avem niciun server.
## Ce ramane pe dispozitiv
Aplicatia salveaza local, in memoria interna a dispozitivului:
- setarile ramei (durata unei poze, tranzitia, ordinea, luminozitatea, limba, unitatea de
temperatura, formatul orei);
- lista folderelor si a albumelor pe care le-ai ales;
- numele si parola folderului din reteaua locala (NAS), daca ai configurat unul;
- codul PIN al blocajului pentru copii, daca l-ai activat.
Aceste date nu parasesc dispozitivul. Se sterg complet cand dezinstalezi aplicatia sau
cand alegi „Sterge datele" din setarile Android.
## Permisiunile cerute si motivul fiecareia
**Fotografii si video** (`READ_MEDIA_IMAGES`, `READ_MEDIA_VIDEO`, iar pe Android 12 sau mai
vechi `READ_EXTERNAL_STORAGE`) — ca sa poata afisa pozele din galeria dispozitivului.
Pozele sunt doar citite si afisate. Nu sunt copiate, modificate, trimise nicaieri sau
analizate. Aplicatia nu are cod de recunoastere faciala si nu identifica persoane.
**Internet** (`INTERNET`) — pentru trei lucruri, toate optionale: vremea, folderul din
reteaua locala si folderul din Google Drive. Daca nu folosesti niciunul, aplicatia nu face
nicio conexiune.
**Locatie aproximativa** (`ACCESS_COARSE_LOCATION`) — numai daca pornesti afisarea vremii.
Aplicatia foloseste ultima pozitie cunoscuta pe care sistemul o are deja; nu porneste
niciodata GPS-ul si nu urmareste deplasari. Coordonatele sunt rotunjite la aproximativ
110 metri inainte de a fi trimise si nu sunt salvate niciodata. Fara aceasta permisiune,
restul aplicatiei functioneaza normal — doar vremea nu apare.
**Calendar** (`READ_CALENDAR`) — numai daca pornesti afisarea evenimentelor pe ecran.
Evenimentele sunt citite pentru a fi afisate si atat: nu sunt salvate, copiate sau trimise.
**Mentinerea ecranului aprins** (`WAKE_LOCK`) — o rama foto care se stinge nu este o rama
foto.
## Servicii din afara aplicatiei
Aplicatia vorbeste cu trei destinatii, toate pornite doar de tine si toate optionale.
**Open-Meteo** (serviciul de vreme). Primeste coordonatele rotunjite si intoarce
temperatura. Nu se trimite nimic altceva: nici identificatorul dispozitivului, nici vreun
cont, nici vreo poza. Open-Meteo nu cere cont si nu cere cheie de acces.
Termenii lor: https://open-meteo.com/en/terms
**Google Drive** (optional). Daca iti legi contul, aplicatia cere permisiunea `drive.file`,
cea mai restransa pe care o ofera Google: vede **numai fisierele pe care le-a creat ea**.
Isi face un folder numit „Fotoro" in Drive-ul tau si vede doar continutul acelui folder.
Restul fisierelor tale din Drive ii sunt invizibile, prin constructie — nu este o promisiune
a noastra, ci o limitare impusa de Google.
Cheia de acces primita de la Google este tinuta doar in memoria de lucru, cat timp
aplicatia ruleaza. Nu se scrie pe disc si nu se include in backup. Poti dezlega contul
oricand din aplicatie, sau de la https://myaccount.google.com/permissions
Folosirea si transferul de catre Fotoro al informatiilor primite de la Google API
respecta [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy),
inclusiv cerintele de Utilizare Limitata (Limited Use).
**Folderul tau din reteaua locala (NAS)** (optional). Aplicatia se conecteaza direct la
dispozitivul tau, in reteaua ta. Numele si parola sunt trimise doar catre acel dispozitiv
si sunt pastrate pe tableta pentru reconectare automata. Nu ajung la noi si nu ajung la
nimeni altcineva.
## Ce NU face aplicatia
- Nu are analytics: nici Firebase, nici Crashlytics, nici altceva.
- Nu are reclame si nu are SDK-uri de publicitate.
- Nu creeaza cont si nu cere adresa de e-mail.
- Nu vinde si nu partajeaza date, pentru ca nu colecteaza date.
- Nu urmareste ce poze te uiti, cat timp sau cand.
- Nu incarca pozele nicaieri.
## Copiii
Aplicatia este facuta pentru intreaga familie si nu colecteaza date personale de la nimeni,
indiferent de varsta. Blocajul cu PIN exista tocmai ca un copil sa nu poata modifica
setarile ramei din greseala.
## Stergerea datelor
Toate datele stau pe dispozitiv. Le poti sterge in doua feluri:
- dezinstalezi aplicatia; sau
- Setari Android → Aplicatii → Fotoro → Spatiu de stocare → Sterge datele.
Accesul la Google Drive se retrage separat, din aplicatie (butonul „Deconecteaza contul")
sau de la https://myaccount.google.com/permissions
## Modificari
Daca schimbam ceva important, actualizam data de sus si descriem modificarea aici.
## Contact
BFX Developer Romania
unagentai@gmail.com
---