Privacy Policy
AFKPal — Remote Android Control
Last updated: August 8, 2026
Introduction
AFKPal ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our mobile applications and services.
Information We Collect
Account Information
- OAuth Authentication: When you sign in with Google or Apple, we collect your email address and provider ID for account creation and authentication.
- Device Registration: We collect device names and identifiers to provide account-bound cloud-phone discovery and remote control.
Technical Information
- Connection Data: IP addresses, port information, and network capabilities required for authenticated cloud streaming and control.
- Usage Analytics: Website and app usage events such as page views, sign-up flow progress, checkout starts, purchases, cloud-device actions, and support-ticket creation. We use this to understand conversion funnels and improve the service.
- Limited Abuse-Monitoring Metadata: Only after a cloud phone has used at least 85% of its assigned CPU quota for a sustained period, we may collect a bounded process snapshot containing PID, app/user identifier, a redacted command marker, executable path/stat metadata, and at most one executable SHA-256 hash. We do not continuously inspect processes, inspect network destinations, or maintain traffic histories for this monitoring.
- Refund and Revocation History: We retain provider-confirmed purchase refund/revocation identifiers and transaction lineages so webhook retries, partial refunds, and duplicate provider reports are not counted as separate purchases.
Information We Do NOT Collect
- Screen content or recordings of your device screens
- Personal files, photos, or documents from your devices
- Passwords or sensitive authentication data beyond OAuth tokens
- Precise location data
How We Use Your Information
- Service Provision: To provision, stream, and remotely control cloud phones associated with your account.
- Account Management: To authenticate users and manage device registrations.
- Technical Support: To troubleshoot connection issues and provide customer support.
- Service Improvement: To analyze usage patterns and improve our application (with anonymized data only).
- Service Protection: To monitor sustained processor saturation on cloud phones (including a bounded snapshot of the busiest process names, without command arguments, file contents, or network inspection), enforce prohibitions such as cryptocurrency mining through human review and appeals, temporarily limit processor use of reviewed cases, and identify repeated provider-confirmed refund activity without automated account bans or data deletion.
Data Storage and Security
Data Storage
- Account information is stored securely in encrypted databases.
- Connection data is temporarily stored only as needed for active sessions.
- No screen content or personal files are stored on our servers.
- Matched process evidence is retained for up to 180 days. We do not copy tenant files, capture traffic payloads, or retain a general connection history for abuse monitoring.
Security Measures
- End-to-end encryption for all device communications
- JWT-based authentication with secure token management
- Regular security audits and updates
- Industry-standard data protection practices
Data Sharing and Third Parties
We do not sell, trade, or rent your personal information to third parties. We may share information only in these limited circumstances:
- OAuth Providers: We verify authentication tokens with Google and Apple as part of the sign-in process.
- Google Analytics: We may send usage events to Google Analytics to measure website and product funnels. We do not send screen contents, personal files, passwords, or payment-card details to Google Analytics.
- Legal Requirements: When required by law, court order, or government regulation.
- Service Protection: To protect our rights, property, or safety, or that of our users.
Your Rights and Choices
Account Control
- Access: You can view your registered devices and account information within the app.
- Deletion: You can delete your account and all associated data at any time.
- Device Management: You can register, rename, or remove devices from your account.
Data Portability
You can request a copy of your account data by contacting us. Your data is provided in a standard format for easy portability.
Children's Privacy
AFKPal is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover that we have collected information from a child under 13, we will delete it immediately.
International Data Transfers
Our services may be hosted in various countries. By using AFKPal, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new policy on this page with an updated "Last updated" date
- Sending an in-app notification for significant changes
- Requiring re-acceptance of terms for major policy changes
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
- Email: privacy@afkpal.com
- GitHub: github.com/afksoft/afkpal
We will respond to privacy inquiries within 30 days.