Privacy Policy — Android
SimplyBackup has no account and no server of its own. Your photos and videos travel directly from your phone to the destination you configured — your own drive, your own server, your own cloud account. Simply AppHub never receives, stores or can access your photos or your backups.
Last updated: 1 September 2026 · Simply AppHub LLC ·com.simplybackup.app
1. Your photos go where you send them — and only there
The app's job is to copy your photos and videos to a destination you choose: a USB drive or local folder, a NAS or home server over SMB, an SFTP (SSH) server, a WebDAV server, or your own Google Drive, Dropbox or OneDrive account. That copy is made directly, phone to destination. Nothing passes through Simply AppHub on the way, because there is nothing of ours for it to pass through.
| What | Where it goes | Does Simply AppHub receive it? |
|---|---|---|
| Photos and videos you back up | Directly to the destination you chose | Never |
| Backup history and catalog (what was copied, when) | App database on your phone | Never |
| Destination credentials — SMB/SFTP/WebDAV passwords, cloud sign-in tokens | Encrypted on your phone via the Android Keystore; sent only to the server or provider they belong to | Never |
| Server host keys you trusted (SFTP) | App storage on your phone | Never |
| Settings and plan status | App storage on your phone | Never |
Backup manifest (a small .simplybackup index written beside your files) | The destination you chose | Never |
Credentials deserve the extra sentence: the password for your NAS or the sign-in token for your cloud account is stored on the device in Android Keystore-encrypted storage, and the only thing it is ever transmitted to is the server or cloud provider it belongs to — the one you pointed the app at. It is never sent to us and never written to a log.
2. There is no account and no SimplyBackup server
The app has no sign-up, no sign-in and no backend holding your data. We could not read your photos, your backup history or your credentials if we wanted to — there is nowhere for them to arrive. When you sign in to Google Drive, Dropbox or OneDrive inside the app, you are signing in to your account with that provider, directly; we are not in the path and receive nothing from it.
3. What uses the network, named
Beyond the destinations you configure yourself, the app talks to a small, fixed set of outside services. Each is listed here with what it can actually see.
Your own destinations — the point of the app
When a backup runs, your phone connects to the server or cloud account you configured and uploads your files to it. That connection carries your credentials for that destination and the files being backed up — to that destination and nowhere else. What the receiving end does with data you store on it is governed by whoever runs it: you, for a NAS or a server; Google, Dropbox or Microsoft, under your own account terms, for a cloud destination.
Remote configuration — api.simplyapphub.com
On occasion the app fetches a small configuration file from api.simplyapphub.com
— feature flags and plan limits, so problems can be switched off without waiting for an app
update. The request contains no personal data and no identifier of you; like any HTTPS
request, it necessarily carries your IP address in transit. Nothing about your photos,
destinations or usage is sent with it.
Google AdMob — advertising, free tier only
The free tier shows ads supplied by Google AdMob. To do that, AdMob receives the ordinary signals every ad request carries: your device's advertising ID, IP address, device model and Android version, coarse location derived from that IP address, and how you interacted with the ad. It does not receive your photos, your file names, your destinations or your credentials — no such data is passed to the ad SDK at any point.
Where the law requires it, the app asks for your advertising consent before any ad loads, using Google's own consent form (the UMP framework), and you can change or withdraw that choice from the app's settings. You can also reset or delete your advertising ID in Android Settings → Privacy → Ads. Google's handling of this data is governed by How Google uses information from sites or apps that use our services.
Paid plans remove the ads. Ads — and the ad requests behind them — are a feature of the free tier only.
Firebase Crashlytics — crash reporting
If the app crashes, Crashlytics sends us the technical trace of the crash: what the code was doing, your device model and Android version, and a random installation identifier so repeated crashes can be recognised as the same problem. It carries no photos, no file names, no credentials and no name or email — the app has none of the latter to send.
Google Play Billing — purchases
Used only when you view or buy a paid plan, or restore an earlier purchase. Payment is handled entirely by Google Play; the app never sees a card number and Simply AppHub never receives one. The app learns only which plan you own, so it can unlock it.
4. Permissions, and why each is asked for
| Permission | Why |
|---|---|
| Photos and videos | To read what to back up. This is the core function of the app. |
| Access to a folder or drive you pick | To write backups to a USB drive or local folder. Android's folder picker grants the app that folder and nothing else. |
| Notifications | The progress notification that keeps a backup running reliably, and completion alerts. |
| Foreground service | Keeps a network backup running while the screen is off or you switch apps. |
| Internet, network state | To reach the destinations you configured and the services in section 3, and for nothing else. |
| Advertising ID | Used by AdMob on the free tier. See section 3. |
5. Keeping and deleting your data
- On the phone — the backup catalog, settings and stored credentials live on your device. Deleting the app deletes all of them.
- At the destination — the backups you made remain wherever you sent them: your drive, your server, your cloud account. They are yours, and deleting the app does not touch them.
- Cloud sign-ins — if you connected Google Drive, Dropbox or OneDrive, you can additionally revoke the app's access at any time from that provider's own security page.
There is no server-side copy to request, correct or have erased, because there is no server. Simply AppHub holds nothing about you to delete.
6. Children
SimplyBackup is not directed to children under 13, and we do not knowingly collect personal information from children. The app has no account system and requests no identifying information.
7. Your rights
Depending on where you live, you may have rights to access, correct, export or erase personal data held about you, and to object to processing. In this app those rights are largely satisfied by the design: your data is on your device and in storage you own, and you can read, move or delete it at any time. For the advertising ID, you can withdraw consent through the app's privacy options or reset the identifier in your Android settings.
8. Changes to this policy
If the app starts doing something this policy does not describe, this policy changes first. The date at the top reflects the most recent revision, and material changes are noted in the app's release notes on Google Play.
9. Contact
Questions about this policy, or about anything above: [email protected]