Privacy Policy & Data Safety Disclosures
Effective Date: September 2, 2026 • Version 1.0.3 • Applicable to Android Application & Web Connect Portal
Summary for Google Play Store Policy Reviewers & Users
- Zero Cloud File Storage: Local transfers stay on the local network. Internet transfers use direct connections or a temporary encrypted relay. Files are not kept as a cloud archive.
- Zero User Account Creation: No sign-up, email, phone number, login, or user profiling is required to use WiFiPlusPlus.
- Contacts Permission (`READ_CONTACTS`): Used solely when the user chooses to export and share contacts as a standard
.vcfvCard file. Zero contact books or addresses are uploaded to any server. - Camera Permission (`CAMERA`): Used exclusively to read on-screen pairing QR tokens and Wi-Fi hotspot parameters. Zero camera frames or photos are saved or transmitted.
- Location Permission (`ACCESS_FINE_LOCATION`): Used strictly on legacy Android versions to scan local Wi-Fi SSID airwaves for peer hotspot discovery. Zero geographic GPS coordinates are ever accessed, recorded, or shared.
- Storage & Media Access (`READ_MEDIA_*`, `READ_EXTERNAL_STORAGE`): Used to allow users to select, package, and transfer photos, videos, audio, and documents, and save received files safely into the public
/Download/WiFiPlusPlus/directory using Android's standard MediaStore API. - No User Data Sold: File contents and private sharing keys are not sold. File names, sizes and connection metadata are processed to operate internet sharing.
1. Zero-Telemetry & Direct Peer-to-Peer Architecture
At WiFiPlusPlus, we believe that your personal photos, 4K videos, documents, archives, music, contacts, and APK files belong strictly to you. Our system is designed with a direct peer-to-peer architecture: we do not operate any centralized file storage repositories, user tracking databases, or analytics monitoring beacons.
Local transfers use Wi-Fi Direct or local hotspot (SoftAP) networks. Internet transfers encrypt file contents on the sending device using a key derived from the six-digit room PIN and a room salt. Receivers need only the PIN to view and download files. When a direct connection is unavailable, the relay temporarily forwards encrypted chunks. The service knows the room PIN and salt, so this mode does not hide file contents from a service that derives the same key. Room metadata, including file names and sizes, device details, IP addresses and transfer status, is visible to the service. Anyone with the PIN can receive the shared files.
2. Android OS Permission Disclosures & Exact Justifications
To establish local device-to-device wireless connections, stream files, and scan pairing codes, Android OS requires explicit runtime permissions. Below is the complete disclosure for every permission requested:
A. Camera Permission (`CAMERA`) — QR Pairing Only
Purpose: Used solely when the user taps "Scan Sender QR Code" or "Scan Laptop QR" to read the connection URI.
Privacy Guarantee: Camera frames are processed strictly in-memory by the Google ML Kit / on-device barcode reader engine to parse local connection parameters. Zero photos or videos are captured, saved to disk, or transmitted to any server.
B. Nearby Devices (`NEARBY_WIFI_DEVICES`) — Android 13+
Purpose: Required by Android 13+ to discover nearby peer devices on the Radar screen and negotiate Wi-Fi Direct and Local-Only Hotspot socket connections without accessing GPS location coordinates.
C. Location (`ACCESS_FINE_LOCATION`, `ACCESS_COARSE_LOCATION`)
Purpose: Required by Android OS on Android 12 and below solely to scan Wi-Fi SSID broadcasts for nearby sender hotspots in the air. WiFiPlusPlus NEVER accesses, records, or shares your geographic GPS coordinates.
D. Contacts Access (`READ_CONTACTS`) — Local VCF Export Only
Purpose: Used exclusively when the user manually navigates to the "Contacts" tab to select specific contacts for direct device-to-device export as an industry-standard .vcf vCard file.
Privacy Guarantee: Contact records are compiled 100% on-device into a local vCard file strictly for user-directed transmission to the receiver device. WiFiPlusPlus NEVER uploads, syncs, stores, or transmits your contact book to any server or third-party company.
E. Storage & Media Access (`READ_MEDIA_*`, `READ_EXTERNAL_STORAGE`)
Purpose: As a comprehensive file transfer utility, WiFiPlusPlus utilizes Android's standard Scoped Storage and MediaStore APIs across Android versions to allow users to select, package, and transfer photos, videos, audio, archives, APKs, and documents—and write received files safely into the device's standard /Download/WiFiPlusPlus directory without requiring elevated all-files system access.
F. Install Unknown Apps (`REQUEST_INSTALL_PACKAGES`)
Purpose: Enables users to install Android Application Packages (APKs) that they have explicitly received from another trusted device via direct Wi-Fi transfer, strictly subject to explicit user confirmation at the Android OS system prompt.
G. Foreground Service & Notifications (`FOREGROUND_SERVICE`, `POST_NOTIFICATIONS`)
Purpose: Ensures high-speed file transfers complete uninterrupted when the screen turns off or the app is minimized, while displaying real-time transfer speed (MB/s) and completion percentage in the system status bar.
3. Web Connect & Desktop Pairing Security Policy
When using the Web Connect feature (wifiplusplus.com/web) to connect a laptop or desktop computer:
- Ephemeral 6-Digit Pairing Tokens: Pairing codes and QR payloads expire automatically after 10 minutes (TTL).
- Direct Local Wi-Fi Tunnel: The cloud relay server only facilitates the initial handshake signal; 100% of all file downloads and uploads stream directly over the local private Wi-Fi network at local gigabit speeds without touching any cloud storage.
- Isolated Session Tokens: Every connection requires mutual token authorization, preventing unauthorized access from unknown devices on the network.
4. P2P Live Share & Zero Server Storage Guarantee
When users initiate P2P Live Share (over the internet or LAN):
- Zero Permanent Disk Storage: Transferred files are NEVER written to hard drives or permanent cloud storage on our servers.
- In-Memory Streaming Relay: If devices cannot reach each other directly over LAN, the relay acts as a transient memory buffer (PassThrough stream). The moment the receiver consumes the byte chunk, it is immediately garbage-collected from server RAM.
- No File Indexing or Tracking: We do not index filenames, track file hashes, or maintain a search directory. Room PINs expire within minutes of host disconnection.
5. User Account & Data Deletion (Google Play Compliance)
WiFiPlusPlus operates with zero user account creation, zero login credentials, and zero cloud identity repositories. Because we do not create accounts or store user profiles on our servers, there is zero user account data stored on our servers to delete.
All transfer sessions and temporary pairing codes are ephemeral and destroyed immediately upon session completion. Users can erase all local app preferences and cached files at any time simply by clearing app data or uninstalling the app from their Android device.
6. Intermediary Status & Legal Safe Harbor (Section 79 IT Act & DMCA)
Under Section 79 of the Indian Information Technology Act, 2000 and 17 U.S.C. § 512(a) of the Digital Millennium Copyright Act (DMCA), WiFiPlusPlus operates as a neutral intermediary and mere conduit.
We do not initiate, modify, or select the content of any transmission. Senders and receivers bear full legal responsibility for ensuring they hold all necessary rights and licenses for the files they transfer. Please review our complete Terms of Service & Acceptable Use Policy for detailed prohibited content rules.
7. Advertising & Google Mobile Ads (AdMob) Compliance
WiFiPlusPlus integrates Google Mobile Ads (AdMob) SDK to serve banner and non-personalized advertisements to support ongoing development and keep the service free. Google AdMob may collect and process pseudonymous identifiers (such as Google Advertising ID / GAID) in accordance with the Google Play Developer Distribution Agreement.
Users can reset or opt out of personalized ads at any time via Android System Settings (Settings > Google > Ads > Reset or Delete advertising ID). No file contents, contacts, file names, or transfer logs are ever shared with advertising networks.
8. Children's Privacy (COPPA & GDPR Compliance)
WiFiPlusPlus does not knowingly collect or solicit personal information from children under the age of 13. Because our service requires zero account creation, logins, or cloud databases, no personal child data is ever collected or stored.
9. Official Support Desk & Grievance Inquiries
For questions regarding this policy, Google Play compliance, legal notices, or developer support:
WiFiPlusPlus Compliance & Grievance Desk
BytePlusPlus Technologies
Email: support@wifiplusplus.com
Support Hours: 10:00 AM – 5:00 PM IST (Mon – Sat)
Official Portal: https://wifiplusplus.com