Why does the app have no internet permission?

Published By Stillgarth3 min read

Stillgarth has no internet permission so that it can’t send anything anywhere. On Android, an app has to declare the internet permission before it can open any network connection. Stillgarth doesn’t, so it can’t reach any server, ours or anyone else’s. Your files, Guard’s photos and everything else the app keeps stay on your phone unless you share them yourself.

What does that rule out?

Because the app can’t go online, there is:

  • no account to sign up for;
  • no ads;
  • no analytics, crash reporting or tracking of any kind;
  • no copy of your data with us. The developer never receives any of it.

That’s also why, on Google Play’s data safety form, the answer is that the app collects and shares no data. In Google’s terms, data is “collected” when an app sends it off the phone, and Stillgarth has no way to do that.

How can you be sure it stays that way?

The rule is enforced when the app is built, not just promised. The build is set up to fail if the internet permission ever appears in the app’s final manifest, including one a code library would add on its own. So a version of Stillgarth with network access can’t be built by accident.

How does the backup work without internet?

The encrypted backup goes through Android’s own “save to” screen. You pick a place, for example a folder in your Google Drive, and Stillgarth writes the backup file there. The app you picked does the uploading, under its own privacy policy. Stillgarth never sees your Google account, and the file holds only encrypted data that opens with your password (12 or more characters) or a recovery code.

Sharing and exporting work the same way. When you share a file from the vault, you choose the app it goes to, and that app sends it.

What do you give up?

Being offline has real costs, and it’s fair to say them plainly:

  • No password reset. There’s no server holding a reset link, and the password isn’t stored anywhere. See what happens if you forget your password.
  • No remote features. Stillgarth can’t locate, lock or wipe a lost phone, and it can’t send you Guard’s photos. Intruder photos stay on the phone, in the vault.
  • No automatic sync between phones. To move your vault, you back it up and restore it on the new phone.
  • No web version. Your vault opens only in the app, on the phone.

Why does that matter for a vault?

Every connection an app can make is a path your data could take, whether by design, by a bug, or through a library that sends data somewhere you never agreed to. An app that holds your most private files and photographs your lock screen is exactly the kind of app that should have no such path. Taking the permission away settles the question: there’s nothing to trust about where your data is sent, because it can’t be sent.

What does Phone Guard do with its photos, then?

Guard’s photos are taken and stored on the phone. Once you have a vault, each one is encrypted for the vault the moment it’s taken and can only be seen inside the unlocked vault. Nothing is emailed or uploaded. See how Phone Guard catches a wrong unlock.

Which permissions does the app use?

The permissions Stillgarth does use are listed in the privacy policy, each with its reason:

  • the camera, for Guard’s photos and for Take photo in the vault;
  • a foreground service, so Guard can watch with a visible notification;
  • unlock detection (device admin, watch login only);
  • notifications;
  • starting after a restart, to remind you to re-arm Guard;
  • biometrics, for fingerprint unlock;
  • Usage access, only if you turn on the intruder-activity log.

It doesn’t access your contacts, location, messages, call log, microphone or photo gallery.