Privacy in the Opensolr app

The Opensolr Android app shows the indexes of your Opensolr account and warns you before they reach a limit. This page says what it sends, what it keeps and what it shares. No ads, no analytics, no tracking, no crash reporting.

Signing in

You sign in on opensolr.com, in your phone’s browser. The app never sees your password or your two-factor code. It receives an API key issued to this phone only, which you can revoke at any time from Account › Devices.

What the app sends to opensolr.com

Account email and API key

With every request, to prove the request is yours.

Device id

A random id the app creates on first use. It is not the Android id and not the advertising id.

Phone model

The maker and model of the phone, to name it in Account › Devices.

App version

So opensolr.com knows which release the phone runs.

Push token

The address Google’s push service gives the phone, so opensolr.com can send it alerts.

Your choices

The usage thresholds you set per index, the notification categories you switch on or off, and which alerts you have read.

The app sends nothing else: no location, no contacts, no photos, no files, no list of other apps.

What opensolr.com keeps

The phone’s record

Device id, phone model, app version, push token, and the dates the phone first and last signed in.

Thresholds and notification choices

Kept with your account, so every phone you sign in on gets the same alerts.

Alerts

Each alert sent to the app: its title, its text, the index it is about, when it was sent and whether you read it.

Server logs

Kept for a short period as part of normal operation, then overwritten. They hold the IP address and the request line.

What passes through Google

Alerts reach the phone through Firebase Cloud Messaging, Google’s push service. Google receives the push token and the content of each notification: for a usage alert, the index name, disk or bandwidth, and the percentage; for an announcement, its title and text. Google handles it under the Google Privacy Policy. Nothing else is shared with Google or with anyone else, and nothing is sold.

What stays on the phone

The API key, encrypted with a key held in Android’s secure key store; the list of alerts; your settings. They are excluded from phone backups, and uninstalling the app deletes them.

Deleting your data

  1. In the app, open Account and choose Sign out. The API key, the alerts and the settings are removed from the phone.
  2. On opensolr.com, open Account › Devices and sign the phone out. Its record, its API key and its push token are deleted from our servers.
  3. To delete the thresholds, the alerts or the whole account, follow Delete your data, keep your account or Delete your account and your data.

How Opensolr handles data in general is described in our Privacy Policy. For any question about your data, write to support@opensolr.com.