Legal

Privacy policy

Draft. This policy is accurate about what the software does, but it has not yet had a legal review. It will be reviewed before Pocket Studio charges money.

Pocket Studio — Privacy Policy (draft; lawyer review before charging money)

Canonical text for the Play-listing privacy-policy URL. This document has three renderings that must be edited together:

1. https://nativeworks.app/privacythe canonical URL to declare in Play Console and on the Google OAuth consent screen. Built from this file by site/build.mjs, so it updates automatically; no hand-editing. 2. GET /privacy on the API box (server/src/app.js) — a hand-maintained HTML copy that predates the site. Keep it in sync or delete it once nothing links to it. 3. This file.

Bump "Last updated" in all of them together.

Last updated: 2026-08-02.


Pocket Studio ("the app") is an Android IDE by NativeWorks, a sole proprietorship registered in Maharashtra, India under Udyam Registration UDYAM-MH-27-0272170. NativeWorks is the data controller for the personal data described below and can be reached at nativeworksapp@gmail.com.

This policy explains what data the app and its server (the "Pocket Studio server") handle.

Using the app without an account

Editing, project management, the terminal and the SDK manager work without signing in. Your code and projects stay on your device; we have no access to them.

What we collect when you sign in

Signing in with Google creates an account on the Pocket Studio server. We store:

  • Account: your Google account ID, email address, display name and profile-photo URL (as provided by Google sign-in), and the date the account was created.
  • Plan and usage: your subscription tier, monthly build counts, build-permit timestamps, weekly AI-usage token totals, and release-signing request timestamps.
  • Device association: a one-way salted hash derived from your device's Android ID, used solely to limit free-account abuse. We cannot recover the Android ID from it.
  • Purchases: your Google Play purchase token, product ID and subscription state. Payment itself is processed entirely by Google Play — we never see card or bank details.
  • Release signing key (paid feature): if you use server-side release signing, we generate and store a signing keystore for you, encrypted at rest (AES-256-GCM under a master key). APK/AAB files you upload for signing are processed in temporary storage and deleted immediately after the signed copy is returned; we do not keep your artifacts.

AI features

When you use the built-in AI assistant on a metered plan, the code and prompts you submit are forwarded to Anthropic (our AI provider) for processing and the response is streamed back. We store only token-usage totals, not your prompts or code. If you configure your own Anthropic API key, it is used to forward that request and is not stored on our server.

Device benchmarks (optional)

The app can run a standardised benchmark on your device and show you the results. Those results stay on your device unless you explicitly choose to publish them.

If you do choose to submit, we receive: your device manufacturer, model and chipset, total RAM, Android version and API level, CPU architecture, the app and benchmark versions, the measured timings and whether the run succeeded, and the thermal and battery readings that determine whether the run counted as valid.

A submission is not linked to you. It carries no account identifier, no device identifier and no location, and it does not require you to be signed in — we could not connect a result back to a person even if asked to. Your IP address is used briefly to limit abuse and is never stored alongside a result. Published results appear on nativeworks.app/pocket-studio/benchmarks only in aggregate, grouped by device model.

Integrity checks

The app uses Google Play Integrity to verify it is a genuine, unmodified installation. Integrity tokens are verified with Google and are not retained beyond processing.

Server logs

Like most services, the server keeps short-lived request logs (IP address, endpoint, status, timestamps) for security and abuse prevention.

Sharing

We share data only with the processors needed to run the service: Google (sign-in, Play billing, Play Integrity), Anthropic (AI request processing), and our hosting provider (Amazon Web Services / Lightsail). We do not sell personal data and we show no third-party advertising.

Retention and deletion

Account data is kept while your account exists. Delete your account at any time in the app (Settings → Account → Delete account) or via the instructions at https://nativeworks.app/delete-account; deletion removes all rows listed above, including your signing key (unrecoverable), within 30 days at the latest. An active Play subscription must be cancelled separately in Google Play.

Children

Pocket Studio is a developer tool and is not directed at children under 13.

Changes

We will update this page and the "last updated" date when the policy changes. Material changes will be announced in the app.

Contact

NativeWorks (Udyam Registration UDYAM-MH-27-0272170), nativeworksapp@gmail.com

Postal address: [POSTAL ADDRESS — Amit]. Deliberately still a placeholder: the address on the Udyam certificate has errors (the city field holds a state, and "Mumbai" is misspelled), and this must match the address verified on the Google Play developer account exactly. Fill it in once the Udyam record is corrected, not before.