Privacy policy
Last updated 2026-09-15
Pocket Studio ("the app") is an Android IDE by NativeWorks, a sole proprietorship registered in Maharashtra, India under Udyam Registration UDYAM-MH-27-0272170. NativeWorks is the data controller for the personal data described below and can be reached at nativeworksapp@gmail.com.
This policy explains what data the app, the course website and their server (the "Pocket Studio server") handle. It covers the Pocket Studio Android app, the website at nativeworks.app, and Pocket Studio Academy.
Using the app without an account
Editing, project management, the terminal and the SDK manager work without signing in. Your code and projects stay on your device; we have no access to them.
What we collect when you sign in
Signing in with Google creates an account on the Pocket Studio server. We store:
- Account: your Google account ID, email address, display name and profile-photo URL (as provided by Google sign-in), and the date the account was created.
- Plan and usage: your subscription tier, monthly build counts, build-permit timestamps, and release-signing request timestamps. We store nothing about your AI usage — it never reaches us.
- Device association: a one-way salted hash derived from your device's Android ID, used solely to limit free-account abuse. We cannot recover the Android ID from it.
- Purchases: your Google Play purchase token, product ID and subscription state. Payment itself is processed entirely by Google Play — we never see card or bank details.
- Release signing key (paid feature): if you use server-side release signing, we generate and store a signing keystore for you, encrypted at rest (AES-256-GCM under a master key). APK/AAB files you upload for signing are processed in temporary storage and deleted immediately after the signed copy is returned; we do not keep your artifacts.
AI features
The AI assistant uses your own API key, on every plan. Your prompts, and the project files, build output and attachments the assistant works with, go directly from your device to the AI provider you configured — OpenRouter by default, or another provider you choose, such as Google's Gemini API. They do not pass through our servers, so we never see them, never store them and never meter them. Your key is kept on your device and is not sent to us.
On the Ultra plan, when an app you built with Pocket Studio crashes, its crash report is kept on your device and reaches your AI provider only when the assistant reads it for you.
We are not a party to those requests. The AI provider's own privacy terms govern what it does with them, so read the terms of whichever provider's key you use.
Device benchmarks (optional)
The app can run a standardised benchmark on your device and show you the results. Those results stay on your device unless you explicitly choose to publish them.
If you do choose to submit, we receive: your device manufacturer, model and chipset, total RAM, Android version and API level, CPU architecture, the app and benchmark versions, the measured timings and whether the run succeeded, and the thermal and battery readings that determine whether the run counted as valid.
A submission is not linked to you. It carries no account identifier, no device identifier and no location, and it does not require you to be signed in — we could not connect a result back to a person even if asked to. Your IP address is used briefly to limit abuse and is never stored alongside a result. Published results appear on nativeworks.app/pocket-studio/benchmarks only in aggregate, grouped by device model.
Course progress (optional)
Pocket Studio Academy — the free course at https://nativeworks.app/academy/, also reachable from Learn in the app — works without an account. Your progress is kept in your browser's local storage and is not sent to us.
If you choose to turn on sync, we store, against your Google account ID: which lessons you have completed and when, your quiz results, XP, day streak, achievements, glossary-term counts and which lesson you last opened. Nothing else about your reading is recorded — no page views, no timings, no analytics.
Signing in to the course does not create a Pocket Studio account, and the session it gives you cannot be used for anything else on our servers — it can read and write your own course progress and nothing more.
You can delete the stored copy at any time from the account menu in the course (Delete synced progress), which removes it from our server immediately and leaves the copy in your browser alone. Deleting your Pocket Studio account removes it too.
Cookies and tracking
We use no cookies for analytics or advertising, and there is no third-party analytics, tracking or advertising code on the website, in the course or in the app.
Signing in stores a session token in your browser's local storage so you stay signed in; the course also keeps your progress there. Both are cleared when you sign out or clear site data. If you sign in on the website, Google's sign-in script is loaded from Google at that moment — it is not loaded until you press the button, and never for readers who do not sign in. When you are signed in, your Google profile photo is fetched from Google's servers to display it.
Integrity checks
The app uses Google Play Integrity to verify it is a genuine, unmodified installation. Integrity tokens are verified with Google and are not retained beyond processing.
Server logs
The web server keeps no access log. The application writes operational logs — request method, path, response status, timing and the originating IP address — which are used only to keep the service running and to investigate abuse. They are never combined with your account to build a profile, never used for analytics, and never shared.
Where your data is held
The Pocket Studio server runs on Amazon Web Services infrastructure in the Mumbai, India region, and database backups are stored there too. Google processes sign-in, Play billing and Play Integrity on its own infrastructure under its own privacy policy, which may involve transfers outside India.
Security
Traffic between your device and our server is encrypted with HTTPS, and the app additionally pins the certificate authority for its API connection. Sign-in sessions are short-lived tokens that expire after 14 days. Release signing keystores are encrypted at rest with AES-256-GCM under a separate master key. Access to the server is restricted to key-based administrative login.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a security problem, please write to nativeworksapp@gmail.com.
Sharing
We share data only with the processors needed to run the service: Google (sign-in, Play billing, Play Integrity) and our hosting provider (Amazon Web Services / Lightsail). AI requests are not on that list because they never reach us — they go straight from your device to your own AI provider. We do not sell personal data and we show no third-party advertising.
We may disclose data if we are legally required to, and will tell you unless we are prohibited from doing so.
Retention and deletion
Account data is kept while your account exists. Delete your account at any time in the app (Settings → Account → Delete account) or via the instructions at https://nativeworks.app/delete-account; deletion removes all rows listed above, including your course progress and your signing key (unrecoverable), within 30 days at the latest. An active Play subscription must be cancelled separately in Google Play.
One exception exists for abuse prevention. On the free plan, the number of builds already used in the current month is retained for up to 7 days after deletion, stored only against your device's anonymous identifier (the same one-way value described above). It holds no account identifier, name or email and cannot be linked back to you or to a deleted account. Its only purpose is to stop the monthly free-build limit being reset by repeatedly deleting and recreating an account. It is discarded after 7 days, or when the month ends, whichever comes first.
Database backups are kept for 14 days and then destroyed, which is why deletion is complete within 30 days rather than instantly. Course progress can also be deleted on its own, without deleting your account, from the account menu in the course.
Your rights
You can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything inaccurate — most of it comes from your Google account, so correcting it there and signing in again updates it here;
- delete your data, which you can also do yourself at any time as described above;
- restrict or object to our processing of it.
Write to nativeworksapp@gmail.com and we will respond within 30 days. We will ask you to sign in, or to write from the email address on the account, so that we do not hand your data to someone else.
Grievance redressal
If you have a complaint about how we have handled your personal data, write to nativeworksapp@gmail.com with "Grievance" in the subject line. We will acknowledge it within 48 hours and aim to resolve it within 30 days, telling you what we found and what we did about it.
If you are not satisfied with the outcome, you are entitled to complain to the data protection authority in your country.
Children
Pocket Studio is a developer tool and is not directed at children under 13.
Changes
We will update this page and the "last updated" date when the policy changes. Material changes will be announced in the app.
Contact
NativeWorks (Udyam Registration UDYAM-MH-27-0272170), nativeworksapp@gmail.com
Postal address: available on request at nativeworksapp@gmail.com.