Privacy Policy
Last updated: 19 May 2026
This Privacy Policy explains how AF APPS ("we", "us",
"our") handles information when you use the Omnifeed
mobile application ("the App"). It is written to satisfy the
transparency requirements of the EU/UK General Data Protection
Regulation ("GDPR"), the California Consumer Privacy Act as amended by
the California Privacy Rights Act ("CCPA/CPRA"), and the comprehensive
privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon
and Montana.
1. Who we are
AF APPS is an independent app developer. We are the data
controller (GDPR) and the business (CCPA/CPRA) for the
personal information described in this Policy.
Contact: mano-ocs@live.fr.
We do not currently maintain a separate Data Protection Officer or
EU/UK representative; you can reach the controller directly at the
address above.
2. The short version
- Omnifeed has no account system and no server that stores
your content. Your connected accounts, sign-in tokens, and
drafts live only on your device.
- We never see or store your social-network passwords.
- We collect anonymous diagnostics (crash reports, basic usage
analytics) to keep the App working, and we show ads in the free
version through Google AdMob.
- We do not sell or "share" your personal
information for cross-context behavioural advertising as those
terms are defined under CCPA/CPRA.
- EU/UK and California (and similar US state) residents have
enforceable rights described in Section
14. You can exercise them at any time by writing to us.
3. Categories of personal information we process
The table below summarises every category of personal information the
App handles, the source, the purpose, the legal basis under GDPR, and
who (if anyone) receives it. Detailed descriptions follow in
Sections 4 – 6.
| Category |
Source |
Purpose |
GDPR legal basis |
Recipients |
Retention |
| Account tokens, public handle, avatar URL of each connected social network |
From you (you sign in to the network) |
Operate the App's core feature: show your feeds and let you post |
Art. 6(1)(b) — contract (delivering the App you requested) |
Stored only on your device; transmitted directly to the social network you connected |
Until you disconnect or uninstall |
| Drafts and in-app settings (theme, last-viewed page per network) |
From you (you type / configure) |
Operate the App |
Art. 6(1)(b) — contract |
None — stored only on your device |
Until you clear or uninstall |
| Diagnostics: device model, OS version, language, app version, anonymous install ID |
Generated automatically by the App |
Stability, performance, aggregate usage understanding |
Art. 6(1)(f) — legitimate interest (improving the App) |
Google (Firebase Analytics / Crashlytics) |
Analytics ≤ 14 months; crash reports ≤ 90 days |
| Advertising identifier and ad-interaction signals |
Provided by your device and the AdMob SDK |
Serve and measure ads in the free version |
Art. 6(1)(a) — consent (personalised ads) / Art. 6(1)(f) — legitimate interest (non-personalised ads where consent is refused) |
Google AdMob |
See AdMob's own retention policy |
| Information you choose to send when contacting support (email address, message body) |
From you |
Respond to your request |
Art. 6(1)(b) / 6(1)(f) — pre-contract / legitimate interest in answering you |
Our email provider (Google Workspace) |
2 years from last message, then deleted |
CCPA/CPRA categories. The personal information above
falls within the following statutory CCPA categories: identifiers
(advertising ID, anonymous install ID, public handle); internet or
other electronic network activity information (in-app interactions,
crash trails); inferences drawn from the above (only by AdMob, for ad
relevance). We do not collect categories described as
sensitive personal information under §1798.140(ae) (such as government
IDs, precise geolocation, account log-in credentials, racial or ethnic
origin, religious beliefs, health information, sexual orientation, or
the content of mail/email/messages).
4. Information stored on your device
The following never leaves your device except to talk directly to the
social network it belongs to:
- Connected-account data. When you connect a social
network (e.g. Reddit, Bluesky, Mastodon), the App stores the access
token issued by that network, plus your public handle and avatar
URL, in encrypted device storage (Android Keystore).
- Sign-in credentials. For networks that use a
system browser or in-app web sign-in, you authenticate on the
network's own page — we never receive those credentials. For
Bluesky, the app password you enter is sent directly to Bluesky to
obtain a token and is not stored by the App.
- Drafts and app settings. Post drafts and your
preferences (theme, etc.) are saved locally.
Disconnecting an account in the App, or uninstalling the App, removes
this data from your device.
5. Information we collect automatically
To keep the App stable and understand which features are used, we
collect a limited amount of pseudonymous diagnostic
data through Google Firebase (Analytics and Crashlytics):
- Device & app data — device model, OS version,
language, app version, and an anonymous installation identifier
generated by Firebase.
- Crash reports — stack traces and a short trail of
in-app actions leading up to a crash. We do not include the text you
type or the content of your feeds.
- Usage analytics — which screens are opened and
which core actions occur (for example: an account was connected, a
post was published). These events are not tied to your real-world
identity.
6. Information from the networks you connect
When you connect a social network, that network returns your basic
public profile (such as your username and avatar) and the feed content
you ask the App to display. This is processed on your device to show
you your feeds. We request only the scopes necessary for the App to
function.
7. What we do NOT do
- We do not collect your social-network passwords.
- We do not read or upload your contacts, SMS, call logs, photos, or
precise location.
- We do not run a server that stores your posts, drafts, or feeds.
- We do not sell your personal information for money, and we do not
"share" it for cross-context behavioural advertising as those terms
are defined by CCPA/CPRA. We have not done so in the preceding
twelve months.
- We do not knowingly process the personal information of children
under 16 for sale or sharing (CPRA §1798.120(c)).
- We do not use your social-network content to train AI models.
- We do not make decisions about you that produce legal or similarly
significant effects using solely automated processing
(GDPR Art. 22).
8. Advertising
- The free version of the App displays ads through Google
AdMob. AdMob may use a device advertising identifier to
serve and measure ads.
- For users in the EEA, the UK, Switzerland, Brazil and US states
that require ad-personalisation consent (currently California), we
use Google's User Messaging Platform (UMP) to request consent
before any personalised ad is served. If you refuse, you still see
ads — they are non-personalised.
- You can re-open the consent form at any time via
Settings → Privacy → Manage privacy choices.
- You can reset or limit your advertising identifier at any time in
your device's settings (Android Settings → Privacy →
Ads).
- We honour Global Privacy Control (GPC) and other universal opt-out
signals to the extent forwarded to us by Google's SDKs.
9. Who we share information with
- Google Firebase — pseudonymous crash reporting
and analytics. (Acts as our processor under GDPR / service provider
under CCPA.)
- Google AdMob — to serve ads in the free version.
AdMob is a separate controller for its own ad-targeting purposes;
see Google's own privacy policy at
policies.google.com/privacy.
- The social networks you connect — the App
communicates directly with each network's API so you can read and
post.
- Legal authorities — only where required by law,
court order, or to protect our rights or safety.
We do not share your information with anyone else, and we do not
sell it.
10. Data security
- Account tokens are stored encrypted on your device using the
Android Keystore system via
flutter_secure_storage.
- All network communication uses HTTPS (TLS).
- Because tokens and content stay on your device, there is no
central database of user data for us to breach.
11. Data retention
- On-device data (tokens, drafts, settings) — kept until you
disconnect the account, clear it in the App, or uninstall the App.
- Pseudonymous analytics held by Firebase — up to 14 months, then
automatically deleted.
- Crash reports held by Firebase — up to 90 days, then automatically
deleted.
- Support correspondence — up to 2 years from last contact, then
deleted.
12. International transfers
Our diagnostic and advertising providers (Google) may process data in
the United States and other countries outside the EEA, UK and
Switzerland. Google relies on the EU Standard Contractual Clauses,
the UK International Data Transfer Addendum, and the EU-U.S. Data
Privacy Framework (where applicable) as the legal mechanism for those
transfers. You can request a copy of the relevant safeguards by
writing to us.
13. Children
Omnifeed is not directed at children under 13 (or, in the EEA/UK,
under the age set by your country, which can be up to 16). We do not
knowingly collect personal information from them. If you are a parent
or guardian and believe your child has provided us information,
contact us and we will delete it.
14. Your privacy rights
14.1 Rights available to everyone
Because your personal content stays on your device, you are in direct
control of it. You can at any time:
- Delete your data — disconnect accounts in
Settings → Privacy, or uninstall the App. You can also
submit a request at our
data-deletion page or by email.
- Manage ad-personalisation via
Settings → Privacy → Manage privacy choices
(re-opens the AdMob/UMP consent form) and via your device's ad
settings.
- Contact us with any privacy question.
14.2 Residents of the EEA, the United Kingdom and Switzerland (GDPR / UK GDPR / FADP)
You have the following rights with respect to personal information we
process about you:
- Access — obtain a copy of the personal data we
hold about you (Art. 15).
- Rectification — have inaccurate data corrected
(Art. 16).
- Erasure — request deletion (Art. 17), subject to
narrow exceptions.
- Restriction of processing (Art. 18).
- Data portability — receive your data in a
structured, machine-readable format (Art. 20).
- Object — to processing based on legitimate
interests, including for direct marketing (Art. 21).
- Withdraw consent — at any time, where processing
is based on consent (Art. 7(3)); withdrawal does not affect
processing already carried out.
- Lodge a complaint with your national supervisory
authority. A list is available at
edpb.europa.eu/about-edpb/about-edpb/members_en.
- Not be subject to solely automated decision-making
with legal or similarly significant effects (Art. 22). We do not
carry out such processing.
The legal bases on which we rely are described in the table in
Section 3. To exercise any right, write to
mano-ocs@live.fr. We aim to
respond within one month (extendable to three months for complex
requests).
14.3 California residents (CCPA / CPRA)
California residents have the rights below. We did not sell or share
personal information for cross-context behavioural advertising in the
preceding 12 months and we do not knowingly do so for consumers under
16.
- Right to know — the categories and specific
pieces of personal information we have collected, the sources, the
purposes, and the categories of third parties to whom we disclosed
it. See Section 3 for a standing answer.
- Right to delete — request deletion of personal
information we have collected from you.
- Right to correct inaccurate personal
information.
- Right to opt out of sale or sharing — exercisable
via Settings → Privacy → Manage privacy choices
and by recognising the Global Privacy Control signal forwarded by
your browser or device. We do not sell or share personal
information, but this control remains available to you.
- Right to limit use of sensitive personal information
— we do not collect sensitive personal information for any
secondary purpose, so no separate limit is necessary.
- Right to non-discrimination — we will not deny,
charge different prices, or provide a different level of service
because you exercised your rights.
- Authorised agent — you may designate an agent to
make requests on your behalf. We will require written proof of the
agent's authority and may verify your identity directly.
- Shine the Light (Cal. Civ. Code §1798.83) — we
do not share personal information with third parties for their own
direct-marketing purposes.
To exercise any of these rights, write to
mano-ocs@live.fr. We will
verify your request by matching information you provide against the
personal information we hold; if we cannot verify you we will tell
you why. We aim to respond within 45 days, extendable once by a
further 45 days.
14.4 Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana
You have rights substantially similar to those in Section 14.3:
access, deletion, correction (where applicable), portability, and
opt-out of targeted advertising, sale of personal data, and certain
profiling. We honour these rights on the same terms, and where your
state's law (Colorado, Connecticut, Texas, Oregon, Montana)
recognises a universal opt-out signal such as Global Privacy
Control, we treat it as a valid opt-out for the user. If we decline
a request, you may appeal by replying to our response email; we will
reply within the period required by your state's law.
14.5 How to exercise your rights
For any jurisdiction, write to
mano-ocs@live.fr describing
what you want and which jurisdiction's law you are invoking. We will
not discriminate against you for making a request.
15. Changes to this Policy
We will update the "Last updated" date above when this Policy
changes, and for significant changes we will notify you in the App.
Continued use of the App after a change means you accept the updated
Policy.
16. Contact
Questions about this Policy or your data:
mano-ocs@live.fr.