easy_pgp

Privacy Policy

Last updated 8 September 2026

Easy PGP is free software published by Níckolas Goline. This describes what the app does with your data. It is a factual account of how the app behaves, and can be checked against the source code.

Easy PGP collects nothing, sends nothing, and has no servers. The app does not request the INTERNET permission, so it cannot transmit your data anywhere even if it tried.

What the app stores, and where

All of this lives in the app's private storage, readable only by Easy PGP:

Your passphrase is never written to disk. It is held in memory for the duration you choose — until the screen turns off, one hour, or one day — then overwritten, and it is gone when the app process ends. It cannot be recovered: if you forget it, messages encrypted to that key cannot be decrypted by anyone, including us.

Notification access

If you enable it, Easy PGP uses Android's notification listener to spot encrypted messages in notifications from other apps, so it can offer to decrypt them. This is the app's most sensitive permission, so to be precise about it:

What the app does not do

Hardware keys

If you use a YubiKey, the app talks to it directly over USB or NFC. That communication stays between your phone and the key.

Permissions, and why each exists

PermissionWhy
POST_NOTIFICATIONSTo tell you an encrypted message was detected
RECEIVE_BOOT_COMPLETEDTo restart the detection service after a reboot
HIDE_OVERLAY_WINDOWSPrivacy mode: stop other apps drawing over the app
NFCTalking to a YubiKey over NFC
USE_BIOMETRICUnlocking your private keys with fingerprint or device PIN

Google Play

Distribution through Google Play means Google collects its own data about installs and, if you have opted in on your device, crash reports. That collection is Google's, governed by the Google Privacy Policy, and is outside this app's control. Easy PGP itself sends nothing to Google.

Children

Easy PGP is not directed at children and collects no data from anyone.

Changes

Changes to this policy are published here, and its history is public in the repository.

Contact

Questions about this policy, or about how the app handles data, can be raised as an issue. Please report security vulnerabilities privately instead — see CONTRIBUTING.

A note on trust

Easy PGP is alpha software and has not been security audited. This policy describes what the app is designed to do, and the source is public so the claims can be checked rather than taken on trust. It is not a warranty that the software is free of defects. Do not rely on it to protect information whose disclosure would put you at risk.