Privacy Policy
Last updated: 2026-09-04
This policy explains what the Statlet Android app
(name.gpm.statlet) does with data. It covers the app only.
The short version: Statlet has no user accounts and no password to remember. Nothing reaches a server run by me unless you chose it — a report you send from inside the app, and, if you want to read the answers in the app rather than in your mailbox, proof that the address you used is yours.
Two things do go to Google rather than to me, and they are on when you install the app: crash reports and usage statistics, both under Settings → Diagnostics, both off the moment you turn them off. This page used to say nothing was collected in the background, which was not true of those two, and saying so plainly is better than correcting it quietly. The detail is below, and the store-free build contains neither.
Who is responsible
Gabriele Proietti Mattia is the data controller for the processing described here. Contact: apps@gpm.name.
What leaves your device
Location, when a weather icon is on
If you enable a weather icon and grant location access, the app reads your approximate location and sends the coordinates to the weather service to ask what the weather is there. The coordinates are rounded to four decimal places, are used for that single request, and are not stored by the app.
You can avoid this entirely: deny the location permission and pick a city by name instead. The app then sends the coordinates of that city, not yours. With no weather icon enabled, no location is read at all.
The weather service is one of:
- Open-Meteo (the default) — privacy policy
- OpenWeatherMap (only if you select it and enter your own API key) — privacy policy
The app has no control over what those services log about the request; both receive your IP address, as any web request does.
City search, when you use it, sends the text you typed to Open-Meteo’s geocoder — always Open-Meteo, whichever weather source you selected.
A report you send from the app
Statlet has a “send feedback” sheet. Nothing is sent until you write something and press send, and nothing about it runs on its own — there is no background upload and no queue that empties later.
What the report carries:
- What you wrote: whether it is a bug or an idea, the title and the description.
- What makes it fixable: the app version and which build it is, your Android version, the phone’s manufacturer and model, and your language tag. Typed into the message by the app — none of it is read from an identifier.
- The app’s own log, only if you attach it. It is redacted first: keys, URLs and the name of the place your weather comes from are replaced before it leaves, and a redacted log is visibly redacted so you can see what went.
- A screenshot, only if you pick one. There is a button to attach an image from your gallery; nothing is captured for you and nothing is read without you choosing the file. The picture is shrunk and re-encoded on your phone before it is sent, and what you see in the sheet is exactly what leaves it — so if part of the screen has nothing to do with the bug, remove it or crop it first. You can take the attachment back out before sending.
- Your e-mail address, only if you type one. Without it a report is anonymous and cannot be answered; with it, it is how I write back.
- A random identifier generated for that single report, so a duplicate submission is not counted twice. It is not a device id, it is not stored on your phone, and a second report gets a different one.
Where it goes: apps-management.gpm.name, a service I run. It is not shared with anyone, it is
not used to build a profile, and it is not published — reports are read, given a state, and
answered by hand.
No advertising id and no install id, ever, in a report or anywhere else.
Reading the answers in the app — optional, and only if you ask
A report is answered by e-mail, to the address you typed into it. That is the whole of what is needed, and if you never open the screen below, nothing here applies to you.
Statlet also has a messages screen, where you can read what you sent and what came back without going to find the mail, and write another message into the same conversation. Since your reports are yours and nobody else’s, the screen has to be sure it is you — so it asks for the address and sends a six-digit code to it, the same way the supporters screen does.
What the app then keeps, and it is worth being exact about it because it is the one thing on this page that resembles a login:
- A key, issued by the service once the code has been checked, and stored in Statlet’s private storage on your phone. It saves you a code every time you open the screen.
- It hangs from the address you proved, never from your phone. Nothing about the device goes into it; two phones that prove the same address get two separate keys; removing the app throws the key away rather than recovering it. It is not a device id and cannot be used as one.
- It works for Statlet only. It opens nothing in any other app of mine.
- The service stores a one-way hash of it, not the key itself.
- It stops working after a year without use, and Sign out withdraws it immediately — at the service, not just on your phone.
Sending a report still needs none of this. You can report a bug having proved nothing, and that report carries no identifier of any kind, exactly as described above. The key is for reading back.
Feature requests and votes — optional
The messages screen also shows what people have asked for in Statlet, and lets you ask for something and vote for other people’s requests. Reading that list costs nothing and needs no address. Asking and voting do, for one reason: one vote per person is a promise, and without something to hang it on the count would mean nothing.
What is published is the request itself — the words you wrote, once I have read it and published it. Never your address, and never who voted for what. Nothing you write appears to anybody until I have read it, and a request that is declined is simply not shown.
Your name in the supporters list — optional, and off unless you ask
Statlet has a list of the people who pay for its upkeep, in Info → the supporters card, and on this site. Nobody is on it without asking, and asking is a screen you have to go and open.
How it works depends on how you supported the app, because the two are genuinely different:
- If you donated (Ko-fi, Stripe), you type the address you donated with and a six-digit code is sent to it. The address is what lets the service recognise a donation as yours — it is stored so a reply is possible, and it is never shown to anybody. A donation that arrives some other way, or from a different address, is matched by hand after you write.
- If you subscribed on Google Play, nothing is asked and nothing is typed. Play never tells an app who bought — the app sends the purchase’s own token, which the service had already been told about by Google, and that is the whole proof. No address is involved.
What is published is the name you typed and nothing else: never an address, never an amount, never a date. The choice is per app, both halves of it are yours to change whenever you like, and turning it off removes the name at once. Ask and the whole record goes.
Crash reports — on unless you turn them off
If Settings → Diagnostics → Send crash reports is on — and it is, unless you turn it off — a crash sends a report through Firebase Crashlytics: the stack trace, the device model, the Android version, the app version, and a Crashlytics-generated installation identifier. It does not include your location, your readings, or your OpenWeatherMap key.
Usage statistics — on unless you turn them off
If Settings → Diagnostics → Send usage statistics is on — and it is, unless you turn it off — Firebase Analytics records which features are used — for example that an icon was enabled — together with the identifiers Analytics collects by default, which include the Android Advertising ID, an app instance identifier, device model, OS version and coarse region. It never records what your icons measure: no temperature, no network rate, no location.
Both switches are found under Settings → Diagnostics, and both are on when you install the app. This page said the opposite until 4 September 2026 — that “nothing is collected before you have had the chance to decide” — and that was wrong in the half that matters. What is true is the mechanism: both SDKs are switched off in the app’s manifest, so nothing is collected while Android is still starting the app up, before a single setting has been read. What happens next is that the app switches them on to match your settings, and your settings start out saying yes.
So the honest sentence is: collection starts with the first launch, and stops the moment you turn it off. Turning either switch off takes effect immediately and holds across restarts. Nothing was ever collected that this page did not describe; what it got wrong was who had decided.
The store-free build has neither SDK in it at all, and no switch to turn on: there is nothing there to turn on.
Firebase is operated by Google. See the Firebase privacy documentation and the Google Privacy Policy.
What stays on your device
- Every setting: which icons are enabled, their order, units, intervals, theme, language.
- Your OpenWeatherMap API key, if you entered one. It is stored in the app’s private storage and is sent only to OpenWeatherMap, as part of your own weather requests.
- The sign-in key, if you have used the messages screen. Same private storage, sent only
back to
apps-management.gpm.nameto prove the address is yours. Sign out removes it. - The in-app diagnostic log, which is held in memory and lost when the app stops.
None of this is transmitted anywhere. If Android’s app backup is enabled on your device, your settings may be included in your own device backup, under Google’s terms.
What the app never does
- No advertising, and no sale or sharing of data with advertisers or data brokers.
- No tracking across other apps or websites.
- No account and no sign-up, and no password anywhere. An e-mail address only if you type one in yourself — to be answered about a report, to read those answers in the app, to vote for a request, or to prove a donation was yours — and never for anything else. No contact list, ever.
- No reading of your files, photos, contacts, messages or call history. Attaching a screenshot to a report uses Android’s photo picker, which hands the app the one image you chose and nothing else — the app never asks for access to your gallery.
- No collection of the values shown in your icons.
Permissions, and why
| Permission | Why |
|---|---|
| Notifications | The icons are notifications; without this the app cannot work at all. |
| Foreground service | Keeps the sampling alive so the icons stay current. |
| Internet | Weather requests, and the optional diagnostics above. |
| Approximate location | Optional. Only to ask the weather service about where you are. |
| Start at boot | Optional. Restores your icons after a restart. |
Legal basis (GDPR)
For readers in the EU/EEA and the UK:
- Weather requests — necessary to provide the feature you asked for (Art. 6(1)(b)); processing only happens when you enable a weather icon.
- Crash reports and usage statistics — your consent (Art. 6(1)(a)), given by turning the switch on and withdrawable at any time by turning it off. Withdrawal stops future collection; it does not retroactively delete reports already sent.
- A report, and the address you attach to it — your consent, given by pressing send.
- Proving your address to read the answers, and to vote for a request — your consent, given by asking for the code. Withdrawn by signing out, which withdraws the key. The vote itself is kept while the request is open, because a count that emptied when somebody signed out would not be a count.
Retention
The app itself retains nothing beyond your device. Firebase retains crash and analytics data according to Google’s retention settings for the project; analytics data is kept for a bounded period and then deleted or aggregated.
A supporters listing is kept while you want it there. Turn it off and the name stops being published; ask and it is deleted along with the address it hangs from.
A sign-in key stops working a year after you last use it, and is withdrawn the moment you press Sign out. Deleting the app removes the copy on your phone; the record at the service lapses on its own.
A feature request you asked for is kept while it is open, and as the record of a decision once it is not. The address it hangs from is never shown with it. Ask and it goes.
Reports are kept while they are useful — an open one until it is answered and the version it describes is out, a closed one as the record of a decision. A screenshot is part of the report it came with and goes when the report goes. Ask and yours is deleted, including the address you sent it from.
Your rights
Under the GDPR you may request access to, correction of, or deletion of your personal data, object to processing, and lodge a complaint with a supervisory authority.
For a report you sent with your address, those rights are straightforward: write from that address and I can find it, show you what it holds, and delete it.
For everything else there is usually no way to link a request to a specific person, because the app holds no account: the practical remedy for the optional diagnostics is to turn them off, and for the rest to uninstall the app, which removes all local data.
Write to apps@gpm.name for any request.
Children
Statlet is not directed at children under 13 and knowingly collects no data from them.
Changes
Material changes will be published on this page with a new date at the top, and significant ones will be noted in the app’s changelog.
Last updated: 2026-09-04