DroidBake does not upload your source projects to Nyfir Studios merely because you build, repair or edit an app. Online account services use limited information such as your email address, security/session records and entitlement data. Optional external services are only used when you choose features that require them.
1. Who is responsible for your data
Nyfir Studios is responsible for personal data it determines the purposes and means of processing for in DroidBake account and service operations. For privacy questions or requests, contact support@nyfirstudios.com.
2. Local project data
DroidBake may process the following locally on your device:
- imported source archives, source files and generated or modified code;
- APK/AAB build outputs where supported;
- build logs, diagnostics, Repair Reports and Change Reports;
- project history, Project Memory, snapshots and restore data;
- local AI prompts, context and generated responses;
- application metadata and local signing information.
These files are not uploaded to Nyfir Studios simply because you create, build, repair or edit an application. Private signing keys are intended to remain protected locally and are not uploaded to DroidBake's account backend as part of normal operation.
3. Local AI and optional external AI
Where DroidBake provides local AI functionality, processing is intended to happen on the device. DroidBake may later offer optional AI Boost or other user-selected external AI integrations. If you explicitly enable an external provider, the minimum information necessary for the requested task may be sent to that provider. The provider's own privacy policy and terms then also apply.
4. Account and authentication data
When you use DroidBake account services, Nyfir Studios processes limited service data needed to authenticate you and operate the account. Current account infrastructure includes:
- your normalized email address and an internal account identifier;
- short-lived email verification challenges;
- hashed verification-code material rather than plaintext verification codes in the account database;
- session identifiers and hashed server-side session tokens;
- account creation/update timestamps and security/rate-limit records;
- plan/entitlement status where applicable.
Verification codes expire after a limited period. The DroidBake Android app stores its current session token encrypted using Android Keystore-backed AES-GCM storage rather than ordinary plaintext app preferences.
5. Email delivery and infrastructure providers
DroidBake currently uses service providers to operate account functionality. Cloudflare provides API, networking and database infrastructure. Resend is used to deliver verification emails. These providers may process information necessary to provide their services, such as your email address for message delivery and ordinary network information such as IP addresses and request metadata.
Nyfir Studios does not sell your personal data.
6. Purchases and entitlements
Where DroidBake offers purchases or subscriptions, a store such as Google Play may process payment. Nyfir Studios may receive the information necessary to verify purchases and maintain entitlements, but does not receive your complete payment-card details from Google Play.
7. Build tools and downloads
DroidBake may download approved build components, models or other verified resources from external hosting. Those providers may receive ordinary network information such as your IP address. Future downloadable engine/toolchain services will be documented when they are enabled.
8. Why we process account data
Account and service data is processed only for defined purposes such as providing requested account functionality, authenticating sessions, maintaining entitlements, delivering verification messages, preventing abuse, securing the service, complying with legal obligations and resolving disputes. Depending on the context, processing may be necessary to provide the service you requested, to meet legal obligations, or for legitimate interests such as service security and fraud prevention. Where processing relies on consent, you may withdraw that consent for future processing.
9. Retention
Local project data remains on your device until you remove it, use an applicable DroidBake deletion feature, clear app data or otherwise remove the files.
Server-side account and entitlement information is retained only for as long as reasonably necessary for its purpose. Security, fraud-prevention, transaction or accounting evidence may be retained where there is a legitimate or legal reason to do so. Retained information should be minimized and separated from an active account where appropriate.
10. Account deletion
You can request deletion from DroidBake's Account & Data area when that flow is available to your build, or from the external deletion page at nyfirstudios.com/droidbake-delete-account.html.
The current server-side deletion flow revokes active sessions and anonymizes the account email. Authentication challenge data associated with the deleted account is neutralized. Certain purchase/entitlement, deletion-request, security, fraud-prevention, accounting or transaction evidence may be retained where necessary and permitted.
Deleting your online DroidBake account does not automatically erase local projects, build history, signing files or other files stored on your Android device. Local device data remains under your control and must be removed separately if you want it deleted.
11. Your privacy rights
Depending on where you live, you may have rights concerning your personal data, including rights to information, access, correction, deletion, restriction, portability or objection. EU/EEA users may also have the right to lodge a complaint with their competent data-protection authority. Contact support@nyfirstudios.com to exercise an applicable right. We may need to verify your identity before acting on a request.
12. Security
DroidBake uses technical measures intended to protect sensitive information, including restricted application storage, cryptographic session storage, hashed backend authentication material and separation of private signing information from untrusted build execution. No software or storage system can guarantee absolute security.
13. Children
DroidBake is a software-development and application-creation tool and is not specifically directed toward children.
14. Changes to this policy
Nyfir Studios may update this policy as DroidBake evolves. Material changes will be reflected by updating the version/effective date and, where appropriate, communicated through DroidBake or the official website.
15. Contact
Nyfir Studios · DroidBake Support
support@nyfirstudios.com
https://nyfirstudios.com/droidbake.html