Your files. Your space.
Privacy policy.
Here’s what stays on your device, what happens when you connect a service, and what you can remove.
01 / The essentials
Pocket Editor is an Android code editor. You do not need a Pocket Editor account to use it. The app has no advertising, analytics, publisher-operated cloud synchronization, or automatic source uploads.
Editing, syntax highlighting, suggestions, language checks, formatting, and developer tools process your content on your device. Bundled language tools do not send your code to their authors, download missing dependencies or schemas, or execute your source as part of analysis.
When you choose to run a web preview, the app executes loaded HTML, JavaScript, or transpiled TypeScript locally. Outside network requests from that preview are blocked. Console and debugger contents remain in the app. Commands you deliberately run through SSH or Termux have the separate capabilities of that environment.
02 / Files and information on your device
Files you choose
Android’s document picker grants access to files or folders you select. Pocket Editor reads and writes those locations to provide editing. Opening a single document does not grant access to its parent folder. A cloud-backed document provider may synchronize your files under its own policy.
Settings and recovery
The app stores preferences, snippets, task definitions, recent locations, tab positions, and session information so you can return to your work. For folder workspaces and GitHub files, recovery drafts can contain full source text, including any secrets within it, and are stored in private app cache. Standalone-file and remote-file unsaved buffers use memory-only recovery.
Recovery is best-effort, not a backup. Android may clear cache, and an abrupt shutdown may lose recent edits. Source files and recovery drafts are not separately encrypted by Pocket Editor. They rely on the protections of Android and their storage location.
Credentials and permissions
Saved SSH credentials, retained GitHub tokens, and desktop pairing credentials are encrypted with Android Keystore protection. Connection details and SSH trust records are kept in app-private storage. App-data backup and extraction are disabled; this does not prevent backup or synchronization of folders you select.
The camera is used only when you choose to scan a desktop pairing QR code. Scanning happens locally without retaining barcode photos. You can paste the pairing string instead. Clipboard access happens when you select copy or paste.
03 / Connections you choose
Optional network features connect to the services or computers you select. Those destinations receive the connection information needed to serve your request, such as your IP address, authentication information, requested paths, or file content. Their own privacy policies and retention practices apply.
Your desktop
The companion API runs on your own computer. You select each shared folder and its permissions; nothing is shared by default. Pairing exchanges an installation identifier and device credential with that computer. Requests and file transfers use a pinned HTTPS connection. There is no publisher-operated discovery, file relay, or hosted storage service.
Uploads require an explicit action. Binary transfers may temporarily stage files in private app cache for verification. Normal completion or cancellation clears staging, but interrupted processes may leave cache remnants. If you use Tailscale to reach your computer, its separate terms and privacy policy apply.
SSH/SFTP and FTP/FTPS
Connecting sends authentication and the file or terminal requests you make to your selected server. Opening a remote file downloads a local editing buffer. Typing and language checking do not upload it. Saving is deliberate and defaults to a new copy, with overwriting as a separate choice.
SSH uses encrypted transport with host-key checks, and FTPS uses certificate-validated TLS. Plain FTP, when explicitly chosen, sends credentials and file content without encryption. Servers may retain access logs and uploaded content.
Saved SSH profiles contain connection details. Credentials are saved only when you enable their remember option. Selecting a profile or opening the app does not automatically reconnect.
GitHub and Git
Connecting GitHub sends your personal access token to GitHub over HTTPS to verify your account and access repositories. Account metadata is stored locally. “Stay connected on this device” is enabled by default in the connection form; you can turn it off to avoid retaining the encrypted token.
Browsing repositories, opening files, and reviewing published commits make the corresponding GitHub requests. An explicit file commit sends the content, commit message, selected branch, and prior file revision. Git operations can transfer source, repository history, author names, and email addresses. Published commits can remain in history after a working file is deleted.
GitHub browsing does not clone a repository. Editing does not automatically publish changes. GitHub’s handling of its service is described in the GitHub General Privacy Statement.
Termux and commands
Termux is a separately installed app. After you enable command access, Pocket Editor can run commands against supported saved workspace files using Termux’s permissions. The local terminal connects to a dedicated, authenticated SSH server on the phone’s loopback interface. OpenSSH and language runtimes require your setup; missing Git can be installed through Termux’s package manager after command permission is granted.
Commands can read, modify, delete, or transmit data available to that environment. Terminal setup uses temporary keys and control files; normal cleanup removes session keys, but interruptions can leave files behind. Shell history, installed packages, command output, and logs may remain in Termux or on your server. Transient Git authorization data passed to Termux can appear in its execution-error reports; review those before sharing them.
04 / Retention and deletion
- Your files and Git history
- Remain in their chosen locations until removed there. Uninstalling Pocket Editor does not remove user-selected projects, remote files, or published commits.
- Recovery drafts
- Successful saving, committing, or explicitly discarding removes the matching cached draft. Cache can also be cleared through Android settings or by uninstalling. Failed cleanup can leave remnants. Save your work before clearing data.
- Settings, snippets, tasks, and recent locations
- Remain until changed or deleted, or until app storage is cleared or the app is uninstalled.
- SSH and GitHub credentials
- Remove saved SSH profiles or disconnect GitHub to delete retained credentials locally. Revoke a GitHub token at GitHub to invalidate it there. Deleting an SSH profile does not stop an active connection or remove its host trust record.
- Desktop links
- Unlink revokes access on a reachable desktop and removes the local profile. Forget removes only the local profile; revoke access separately on an unreachable desktop. Neither action deletes shared files.
- Older private projects
- Export any projects stored privately by older versions before clearing app storage or uninstalling.
Clearing app storage removes Pocket Editor’s private settings, account information, trust records, and cache. It does not clear Termux storage, stop every detached command, remove server logs, or delete copies held by providers. Use the relevant provider or application to manage those.
05 / This website
This website’s code does not set cookies, use browser storage, load analytics, or include advertising trackers. Fonts, styling, and illustrations are served with the site. It has no signup form and does not collect email addresses.
A hosting provider may process IP addresses, requested URLs, timestamps, and browser information to deliver the site and keep it secure. The actual hosting provider, logging practices, retention period, and any international transfers must be disclosed here before launch.
Following an external link, including Google Play or GitHub, takes you to a service with its own privacy practices. Google Play and Android may also process information independently under Google’s policies.
06 / Questions, rights, and changes
Depending on where you live and the processing involved, you may have rights to access, correct, delete, restrict, or object to the processing of personal information, request portability, or complain to a data-protection authority. The publisher does not receive your local editor files through ordinary offline use and cannot retrieve or delete them remotely.
Requests about information held by a connected service should also be directed to that service. If the app’s data practices change, this policy and the related disclosures will be updated before those changes take effect.
07 / Publisher and contact
Publisher / legal entity: To be provided before publication.
Privacy contact: To be provided before publication.
Business address, where required: To be provided before publication.
This draft does not yet provide a working privacy contact. These details and the website-hosting disclosures must be completed before the policy is used for the public app listing.