Privacy Policy
Last Updated: October 9, 2026
Contents
- 1. Who We Are / Data Controller
- 2. Information We Collect
- 2.12 Configuration File
- 3. How We Use Information and Our Legal Basis
- 4. Third-Party Services
- 4.4a Google user data (Limited Use)
- 5. Data Storage and Security
- 6. Your Rights and Choices
- 7. Children's Privacy
- 8. Regional Privacy Rights
- 9. Changes to This Policy
- 10. Contact Us
Fravora ("we," "our," or "the App") is committed to protecting your privacy. This Privacy Policy explains what information is collected, how it is used, and what choices you have regarding your data. Fravora contains no advertising. The App does not use or collect the Android advertising ID.
1. Who We Are / Data Controller
Claudiu-Iulian Bumbel, trading as aniujual software, is the data controller for Fravora. You can contact us at aniujual.dev@yahoo.com or at Gardony Geza 6/8, 307160 Dumbravita, Romania.
2. Information We Collect
2.1 Photos and Personal Contact Details
Fravora does not require your name or contact details to use the App. Your photos, videos, and media files are not uploaded to Fravora's own servers.
2.2 App Usage Statistics (Firebase Analytics)
With your consent, Fravora uses Google Firebase Analytics to collect pseudonymous information about how the App is used. This may include:
- Device type, manufacturer, and operating system version
- App version
- Country and language settings
- App session duration and frequency
- Feature usage patterns
- A random app-instance identifier
This data is pseudonymous and linked to a random identifier, not your name or contact details. It is used to understand how the App is used and decide what to improve, not to identify you or build a profile about you. Google also processes technical data such as your IP address when it is transmitted.
2.3 Crash Reports (Firebase Crashlytics)
With your consent, Fravora uses Firebase Crashlytics to collect crash reports, which may include stack traces, device model, operating system version, app version, app state at the time of the crash, and a random installation identifier. Although the App filters technical error details, reports may in rare cases still contain them. Firebase collects fatal crash reports in their original form. Crash reports are collected only with your consent.
2.4 Website Analytics
When you visit fravora.app, we use Google Analytics, provided through a separate Firebase project for this website, to understand aggregate website use. Google Analytics may collect information such as pages viewed, approximate location derived from your IP address, device and browser type, referral source, and session duration. We use this information to maintain and improve the website. Website analytics is kept separate from the App's Firebase Analytics data. We ask for your choice before enabling website analytics; you can change it at any time using the Analytics Preferences link in the site footer.
2.5 Location Data
Weather is optional and off by default on new installations. Users who enabled it earlier keep that setting. When weather is on, Fravora uses your device location if location permission is granted; otherwise, it obtains an approximate location from your IP address through ipwho.is, which receives your IP address. Coordinates are sent to Open-Meteo and MET Norway (api.met.no) for forecasts, and city searches are sent to Open-Meteo's geocoding service. Fravora does not store your location. No weather request happens while the setting is off. See Section 4.8 for these services.
2.6 Voice Data
If you use the voice control feature (Pro tier), voice processing is handled in two stages:
- Wake phrase detection is processed entirely on your device using the OpenWakeWord library. No audio data is transmitted externally during wake phrase detection.
- Command recognition uses Google's Speech Recognition service to interpret your spoken commands after the wake phrase is detected. Audio captured during the command listening window is transmitted to Google's servers for processing. This audio is subject to Google's Privacy Policy.
Fravora does not store, log, or retain any audio recordings or transcripts of your voice commands. Voice control is an optional feature and can be disabled at any time from the App's settings.
2.7 Photo Metadata
If you enable the metadata overlay feature (Pro tier), Fravora reads EXIF data on your device, including location coordinates and date taken, to display information during the slideshow. Only when you enable the location or landmark overlay, coordinates rounded to 2 decimal places (about 1 km) are sent to OpenStreetMap Nominatim to find a place name. Results are cached on your device. Nothing else from your photos leaves the device. See Section 4.9 for this service.
2.8 Issue Reports
If you use the in-app issue reporting feature, you will be directed to send an email to our support address. Any information you include in that email — such as a description of the issue, your device details, or any attachments you choose to add — is shared with us voluntarily and is used solely to investigate and resolve the reported issue. We do not share this information with third parties.
2.9 Your Consent Choices
Before onboarding on first launch, the App shows a consent dialog with two separate optional toggles, both off by default: App usage statistics (Firebase Analytics) and Crash reports (Firebase Crashlytics). Accept All, Decline All, and Save Choices are presented with equal prominence. Nothing is collected for these purposes until you choose, or if you decline, and the App works the same either way. Nothing Firebase-related runs at App startup before you answer the consent dialog. The configuration file request described in Section 2.12 happens before you answer and regardless of your consent choice. You can change or withdraw your choice at any time in Settings > Support. Turning off usage statistics stops collection and resets analytics data on your device; turning off crash reports stops collection and deletes unsent reports. Data already sent is kept until the retention periods in Section 2.11 end. Withdrawal does not affect the lawfulness of processing that took place before you withdrew consent.
2.10 International Data Transfers
Google (including Firebase and its favicon service), GitHub Pages, ipwho.is, Open-Meteo (including its geocoding service), MET Norway, OpenStreetMap Nominatim, radio-browser.info, radio streaming providers, and Amazon Appstore are third parties we do not control. Some may process data outside the EEA or UK. Their privacy policies govern their processing, as described in Section 4. Where required, Firebase transfers rely on safeguards such as applicable data privacy frameworks and standard contractual clauses. You can withdraw your consent for analytics and crash reports at any time using Settings > Support; the configuration file request does not depend on that consent.
2.11 Retention
- Firebase Analytics event data is retained for 2 months; user-level data, including identifiers and user properties, is retained for up to 14 months.
- Firebase Crashlytics keeps crash stack traces, extracted minidump data, and associated identifiers (including Crashlytics Installation UUIDs and Firebase installation IDs) for 90 days before starting the process of removing it from live and backup systems.
- Support emails are deleted once a year, at the end of December.
- Your App analytics and crash-report consent choice is stored locally on your device until app data is cleared or the App is uninstalled.
2.12 Configuration File
At startup, even before you answer the consent dialog and regardless of your answer, the App downloads https://fravora.app/remote-config.json. This small static file contains safety and configuration switches, such as disabling a feature that is malfunctioning. The request carries your IP address and standard HTTP request details: it sends only an ETag header and the default Android HTTP user agent, with no identifier. The website and this file are hosted on GitHub Pages, which receives IP addresses and standard request data. See GitHub's Privacy Statement. Our legal basis is our legitimate interest in keeping the App working and safe, GDPR Article 6(1)(f). This request is separate from consent-based analytics and crash reports.
3. How We Use Information and Our Legal Basis
We use the information described above for the following purposes and legal bases:
- App usage statistics and crash reports: your consent, GDPR Article 6(1)(a)
- Configuration file request: our legitimate interest in keeping the App working and safe, GDPR Article 6(1)(f), as described in Section 2.12
- Providing features you choose, including photo display, weather, metadata overlay, voice control, and TV pairing: performance of the service, GDPR Article 6(1)(b)
- Answering support emails: our legitimate interests in responding to support requests, GDPR Article 6(1)(f)
- Website analytics: your consent
4. Third-Party Services
Fravora integrates with the following third-party services. Each service operates under its own privacy policy, which we encourage you to review.
4.1 Google Play Services
The Google Play build uses Google Play Billing for the Pro upgrade and Google Play Services for app licensing. Google processes the purchase. Purchase tokens are never sent to us. Privacy policy.
4.2 Google Firebase
The App uses Firebase Analytics and Firebase Crashlytics only with your consent, as described in Sections 2.2 and 2.3. Nothing Firebase-related runs at App startup before you answer the consent dialog. Firebase Authentication and Firestore are used for the TV pairing relay. The App also uses Firebase App Check: on the Google Play version, when you start TV pairing or cloud scanning, Google Play Integrity attests that the App is genuine and sends device attestation data to Google. Configuration updates use the separate static file described in Section 2.12. When you open a valid TV pairing link, the page automatically uses Firebase Authentication anonymous sign-in, before you press a button, solely to make TV pairing work. Firebase creates a random user ID for this anonymous account; it is not linked to your identity. The page uses Firebase Auth's default local persistence, and the sign-in state stays in the browser until browser data is cleared; the page does not sign out. See Section 5.5 for server-side account retention. Firestore is not used to store photos or long-term account credentials. A separate Firebase project provides Google Analytics for this website as described in Section 2.4; that website project is distinct from the App's Firebase services. Privacy policy.
4.3 Cloud Storage Providers (optional, user-initiated)
Current cloud sources are Google Photos, Microsoft OneDrive, Dropbox, Google Drive, and Immich. If you choose to connect a cloud source, Fravora uses provider-appropriate authorization (Google or Microsoft OAuth, Dropbox OAuth, or server URL + API key for Immich). The App's media browsing and display are based on the items, folders, or albums you select, but the technical scope of a provider's authorization may be broader, as described for Google Drive below.
- Your photos are downloaded to your device solely for display in the slideshow
- Photos are cached locally on your device at screen resolution to improve performance
- Cloud authorization credentials are stored securely on your device. Provider-specific authorization values may be relayed temporarily through Firebase Firestore during TV pairing, as described in Section 5.5
- Selected cloud media is accessed and cached only for slideshow display; we do not index or analyze it
- You can disconnect a cloud account in the App or revoke access through the provider
Google Drive
If you connect Google Drive, Fravora uses the Google Drive API with the drive.readonly OAuth scope so you can browse Drive folders using Fravora's folder picker and select folders or media for the slideshow. This is a broad, read-only Google permission: Google's authorization is not technically restricted to only the folders you select in Fravora, even though the App's browsing and intended use are based on your selections. Fravora does not create, edit, delete, or upload Drive files, and does not use Drive data for analytics or any other purpose beyond the features you choose. Selected media is retrieved for display and cached on your device. While you browse, Fravora reads the names, types and sizes of the folders and files in the folders you open. It reads the contents of media files only from the folders you select. Files are downloaded when the slideshow needs them and are kept in a size-limited cache on your device. You choose the size limit in the App's settings, and the oldest items are removed when it is reached. You can disconnect the account in the App or revoke access through Google.
Google Photos and Google Drive use short-lived Google access tokens; Fravora does not request or store Google refresh tokens. During TV pairing, a short-lived Google access token is temporarily relayed through Firebase Firestore as described in Section 5.5.
4.4 Google Photos API (additional disclosure)
When you connect Google Photos, Fravora uses the Google Photos Picker. You choose photos and videos in Google's own picker, and Fravora receives access only to the items you select, not to the rest of your library. Selected items are downloaded to your device for display. Specifically:
- We access only the media items you select
- Selected items are downloaded, resized to fit your device's display resolution, and stored in a dedicated cache on your device, together with basic details such as date, location and orientation read from the photo. They stay there until you remove the item or the source, or until the app clears the oldest items automatically when your device is critically low on storage. You choose how much free space the app must always leave on your device.
- We do not modify, delete, or upload any content to your Google Photos library
- We do not share your Google Photos data with any third party
- We do not use your Google Photos data for analytics or any purpose other than displaying your photos
- Temporary Google Photos image-download URLs may be cached in memory for a connection and media item. They are not persisted to disk, and a URL may be reused from that in-memory cache while available
4.4a Google user data (Limited Use)
Fravora's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Fravora requests two Google scopes, each only when you connect the matching source:
photospicker.mediaitems.readonly(Google Photos): lets you pick photos and videos in Google's own Photos Picker. Fravora receives only the items you pick.drive.readonly(Google Drive): lets you browse your Drive folders in Fravora's folder picker and choose folders for the slideshow.
Fravora uses this data only to display your selected media in your slideshow on your device. We do not use it for advertising, analytics or profiling. We do not sell it, transfer it to third parties, or use it to train AI models. No person at Fravora reads your Google data. Fravora has no access to it, because it goes directly from Google to your device.
4.5 Radio Streams
When you play a radio station, the App connects directly to that station's streaming server. The streaming server may log your IP address as part of normal server operation. Fravora has no control over and no access to those server logs.
4.6 Voice Recognition
Wake phrase detection is handled locally on your device by OpenWakeWord — no audio is transmitted externally during this stage. Follow-up command recognition is handled by Google Speech Recognition, which transmits audio to Google's servers for processing as described in Section 4.7. Fravora does not store or retain any audio data at any stage.
4.7 Google Speech Recognition
When voice control is enabled and a wake phrase is detected, the follow-up command audio is transmitted to Google's Speech Recognition service for processing. Fravora does not retain this audio data. For information on how Google handles speech data, please refer to Google's Privacy Policy.
4.8 Weather and IP-Based Location
Weather is optional and off by default on new installations; existing users who enabled it keep their setting. When it is on, Fravora uses device location if permission is granted, otherwise an approximate IP-based location from ipwho.is, which receives your IP address. Coordinates are sent to Open-Meteo and MET Norway (api.met.no) for forecasts; city searches go to Open-Meteo's geocoding service. Fravora does not store location, and no weather request happens while the setting is off. For Fravora, the legal basis is providing the feature you choose (GDPR Article 6(1)(b)); each provider may process connection and request data under its own privacy terms. Privacy policies: ipwho.is, Open-Meteo forecasts and geocoding, and MET Norway.
4.9 Photo Reverse Geocoding
EXIF is read on your device. Only when you enable the location or landmark overlay, photo coordinates rounded to 2 decimal places (about 1 km) are sent to OpenStreetMap Nominatim (nominatim.openstreetmap.org) to find a place name. Results are cached on your device. This request is not made when those settings are off; nothing else from your photos leaves the device. For Fravora, the legal basis is providing the metadata display feature you choose (GDPR Article 6(1)(b)); OpenStreetMap's services may process the request and connection data under their privacy policy.
4.10 Radio Directory and Station Icons
When you browse or search the radio station directory, Fravora contacts radio-browser.info. The service receives your IP address as part of the connection and the search terms you submit. When a station icon is requested from Google's favicon service at www.google.com/s2/favicons, Google receives your IP address and the station domain used to retrieve the icon. Streams are contacted directly as described in Section 4.5. These requests occur when you use the directory or its station icons. For Fravora, the legal basis is providing the radio features you choose (GDPR Article 6(1)(b)). We could not verify a published privacy policy for radio-browser.info; see its official website for service information. Google's favicon service is covered by Google's Privacy Policy.
4.11 Amazon Appstore
The Amazon Appstore build uses Amazon's in-app purchase service for the Pro upgrade and entitlement validation. Amazon processes the purchase and the purchase-entitlement information needed to complete or verify it. Purchase tokens are never sent to us. Fravora does not use this SDK for advertising or background analytics. For Fravora, the legal basis is providing the purchase you request (GDPR Article 6(1)(b)); Amazon's processing is governed by its Privacy Notice. The Google Play build uses Google Play Billing as described in Section 4.1.
4.12 GitHub Pages
The website and the App's static configuration file are hosted on GitHub Pages, which receives IP addresses and standard request data. The App downloads the file at startup before you answer the consent dialog and regardless of your choice, as described in Section 2.12. GitHub's Privacy Statement.
5. Data Storage and Security
5.1 Local Storage
All app configuration, including your selected photo sources, album settings, scheduling preferences, overlay settings, and all other app preferences, is stored locally on your device in private app storage accessible only to Fravora.
5.2 Credential Security
Credentials for network shares (SMB) and cloud authorization credentials are stored securely on your device using Android's EncryptedSharedPreferences. Authorization is provider-specific: Google Photos and Google Drive use short-lived Google access tokens, and Fravora does not request or store Google refresh tokens. During TV account pairing, some provider-specific authorization values are temporarily relayed through Firebase Firestore; see Section 5.5. Fravora does not operate its own server that receives or stores your photos.
5.3 Photo Cache
Photos from all sources (local, network, and cloud) are cached locally on your device, sized to fit your device's display resolution, to improve slideshow performance. The size of the general image cache, which also holds media from Google Drive, is set in the App's settings (128 MB to 2048 MB). When the limit is reached, the oldest cached items are removed automatically. Photos picked from Google Photos are kept in a separate cache limited by a minimum free-space setting that you choose. If your device runs low on storage, the App pauses downloads and may remove the oldest cached items automatically. Cached photos are stored in private app storage and are not accessible to other apps.
5.4 Photo Metadata
EXIF metadata is read on your device for the metadata overlay. Only when you enable the location or landmark overlay, coordinates rounded to 2 decimal places (about 1 km) are sent to OpenStreetMap Nominatim to find a place name, as described in Section 4.9. Results are cached on your device. Nothing else from your photos leaves the device.
5.5 No Fravora-Operated Photo Servers
Fravora does not operate its own server that receives or stores your photos. When you open a valid TV pairing link, Firebase Authentication automatically signs in anonymously before you press a button, solely to make TV pairing work. Firebase creates a random user ID that is not linked to your identity. The page uses Firebase Auth's default local persistence, so the sign-in state remains in the browser until browser data is cleared; the page does not sign out. The anonymous Auth account is reused indefinitely and is not actively deleted by us; a replacement account may be created only after a recoverable authentication failure. The standalone page does not show the website analytics-consent choice; anonymous sign-in is limited to the pairing flow and does not enable website analytics. During pairing, Firestore has a limited, temporary role as a relay: for Google Photos or Google Drive, a short-lived Google access token is relayed through a temporary pairing document; for Dropbox, only an authorization code is relayed, not a Dropbox access or refresh token. The PKCE code verifier remains on your device. Pairing documents are deleted by the TV as soon as the token or code arrives, or if pairing is cancelled or times out. Security rules accept a token only within 15 minutes of the document's creation, and a Google access token expires in about an hour. Access to a pairing document requires its random 12-character code. If the TV app is closed or uninstalled while pairing is pending, the document may remain in Firestore. The app removes leftover documents the next time it starts, and we delete any remaining ones at least once a year. A leftover document can contain only an access token that has already expired. It never contains a refresh token, your email, or any of your files. Firestore is not used to store photos or long-term account credentials. See Section 4 for the third-party services used by Fravora.
6. Your Rights and Choices
6.1 Analytics and Crash-Report Consent
You can change or withdraw your consent for App usage statistics and crash reports at any time in Settings > Support. Turning off usage statistics stops collection and resets analytics data on your device. Turning off crash reports stops collection and deletes unsent reports. Data already sent is kept until the retention periods in Section 2.11 end. The configuration file request in Section 2.12 happens regardless of these choices. Withdrawal does not affect the lawfulness of processing based on your consent before it was withdrawn.
6.2 Cloud Provider Access
You can disconnect any connected cloud account at any time from within the App or revoke access through the provider. When you remove a Google source in the App and no other source uses the same Google account, Fravora revokes its access with Google, deletes the stored credentials from your device, and deletes the cached media for that source. You can also revoke access at any time in your Google Account under Security > Third-party apps and services.
6.3 Location
You can revoke location permission at any time through your device's app permission settings. If weather remains on without location permission, the App uses approximate IP-based location through ipwho.is. Turn off weather in the App's settings to stop weather requests.
6.4 Voice Control
You can disable voice control at any time from within the App's settings. When disabled, neither OpenWakeWord nor Google Speech Recognition will be active and no audio will be processed.
6.5 Photo Metadata Display
You can disable the metadata overlay at any time from within the App's settings. When disabled, no EXIF data is read or displayed.
7. Children's Privacy
Fravora is not directed at children under the age of 16. The age at which a child can consent to online services independently varies from 13 to 16 across EU countries. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided personal data through the App, please contact us and we will take steps to delete such data.
8. Regional Privacy Rights
8.1 EEA and UK Users (GDPR and UK GDPR)
If you are in the European Economic Area or the UK, you may have the right to access, rectify, or erase your personal data; restrict or object to its processing; request data portability; withdraw consent at any time; and lodge a complaint with your local data protection authority (in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP) at dataprotection.ro; in the UK, the Information Commissioner's Office, or ICO). You can send a request to aniujual.dev@yahoo.com. We may need your App instance identifier to locate relevant Firebase data because it is not indexed using your name or contact details. Google can also handle requests for data it holds. We respond to requests within one month. See our Data Deletion page for further information.
8.2 California Users (CCPA)
If you are a California resident, you have the right to know what personal information is collected about you and to request deletion of that information. Fravora does not sell or share personal information for cross-context behavioral advertising. For data collected by third-party services, please refer to their respective privacy policies.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the App's features or applicable legal requirements. When we make changes, we will update the "Last Updated" date at the top of this document. We encourage you to review this policy periodically. Material changes affecting analytics or crash reporting will be shown in the App, and we will ask for your consent again.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us at: