qIV Remote — Privacy Policy
What the app stores, and where
Everything the app keeps stays in its private storage on your device. None of it is transmitted anywhere except to the servers you configure.
- Server profiles — the name, address and port you typed for each computer running QuickImageViewer.
- Passwords — only when you switch on "Save password" for a profile. When that switch is off, the password is held in memory for the session and written to storage as an empty value. You can erase every stored password at any time from Settings, without uninstalling the app or losing the servers themselves — see Your rights below.
- Certificate fingerprints — the identity of each server you have accepted, so the app can detect if it later changes. A fingerprint identifies a server; it does not authenticate to one and it is not a secret.
- Preferences — your app settings: theme, screen-on and vibration behaviour, preview size and quality, the streaming options, which remote screen opens by default, and the device name the app announces to a server.
Uninstalling the app removes all of it. If you have Android's own backup enabled, these files may be included in your personal device backup, which is handled by Google under your own account and its settings, not by this app.
What leaves your device
The app asks for no permission that can read your files, your location, your contacts or your identity. What it does declare, and why:
INTERNET— opening a TCP connection to an address you entered, and nothing else.ACCESS_NETWORK_STATE— checking whether you are on Wi-Fi, so streaming can stay off mobile data.com.android.vending.BILLING— required by Google Play to offer the one-time unlock. Used only if you buy it.
A signature-level permission from an AndroidX library is also merged in at build time. It is internal to the app process and grants access to nothing on your device. Beyond the connection you ask for and a purchase you choose to make, the app performs no network activity of any kind.
Over that connection, and only to that server, the app sends:
- the commands you press — next image, zoom, slideshow, and so on;
- the password for that server, if the server requires one;
- the device name, so the receiving computer can show which phone is connected. If you have not set one in Settings, the app falls back to the name your phone already carries on the network (Android's own device name), then to the model. That default may contain your own name if you gave your phone one — it is shown to you in Settings and you can replace it with anything you like at any time;
- an image you explicitly pick, when you use the Stream screen to push a photo to the desktop. Nothing is sent until you choose a file, and only that file is sent.
In the other direction, the desktop sends back the picture it is currently displaying, when you ask for it. That image is held for display, and written to your phone's storage only if you press Save.
Demo mode
The app includes a demo mode for evaluating it without a computer running QuickImageViewer. Demo mode opens no network connection at all — no address is resolved and no data is transmitted. Everything shown is generated inside the app.
Security of the connection
Connections to anything other than the loopback address are encrypted with TLS, and the server's certificate is pinned: the app refuses to connect to a certificate it has not been shown and told to trust, and warns you if a previously accepted one changes. The password is never sent in the clear.
The connection is between your phone and your computer. It does not pass through any server operated by the developer, because there is no such server.
Analytics, advertising and tracking
There are none. The app contains no analytics SDK, no advertising SDK, no crash reporting service and no tracking identifiers. It does not use the Android Advertising ID and does not declare the permission that would allow it to.
Purchases
If a paid feature is offered inside the app, the purchase is processed entirely by Google Play Billing. Payment details are handled by Google and are never seen by, sent to, or stored by this app or its developer. The app receives only the fact that an entitlement is or is not owned.
Children
qIV Remote is a utility for controlling desktop software and is not directed to children. It collects no personal information from anyone, including children.
Your rights
Because no personal data is collected or transmitted to the developer, there is nothing held about you to access, correct, export or delete.
What is stored on your own device is yours to remove, and you do not have to uninstall the app to do it:
- Forget saved passwords — in Settings, under Servers. Removes every password stored on this device in one action. Your servers, their addresses and their accepted certificates are kept, so you are simply asked for the password again the next time you connect.
- Restore defaults — in Settings. Returns every setting to how the app shipped and forgets every saved password as well.
- Deleting a server removes that profile entirely, including its password and its certificate fingerprint.
- Clearing the app's storage, or uninstalling, removes all of it.
Changes to this policy
If the app's behaviour changes in a way that affects this policy — for example if a feature is added that transmits something new — this page is updated and the date at the top changes with it.
Contact
Questions about this policy: icyhoty2k@gmail.com