This policy covers the Android version of Fandi distributed on Google Play. The iOS version is a separate build with a separate policy — see the Fandi Privacy Policy for iOS.
Summary
Fandi has no account and no server of ours. Your biases, schedule, spending, photocards, and diary all live in a database on your phone. The app makes no network request of its own — the only thing that leaves your device is the pseudonymous usage analytics described below, which never contains what you wrote or the pictures you added.
What Is Stored on Your Device
Fandi keeps everything in a private database and a private folder inside the app's own storage:
- Biases — the name, colour, emoji, group, birthday, debut date, and “fan since” date you record, and a photo if you add one
- Schedule — event titles, types, dates, recurrence, notes, and reminder settings
- Ledger — the amounts, categories, currencies, dates, and notes of the spending you log, plus your monthly budget
- Binder — the photocard images you add and their frame, foil, album, version, and memo
- Diary — entry titles, free-text bodies, dates, photos, and ticket stubs
- App settings, your Pro entitlement, and onboarding state
Photos you add are copied into Fandi's own private folder, where no other app can read them. Nothing is uploaded. Clearing the app's data or uninstalling the app deletes all of it, and there is no server-side copy for us to hold, hand over, or lose.
Photos and the Camera
When you add a photo, Android's system photo picker opens in a separate process and hands the app only the picture you chose. If you take a new photo instead, Android's own camera app opens and returns the single shot. Because Android handles both, Fandi declares no photo, media, storage, or camera permission and never asks you for one — it cannot browse your gallery or open the camera on its own.
The photocard cut-out runs Google ML Kit entirely on your device with a model bundled inside the app. The image is not uploaded for processing and no network request is made.
Sharing
When you share a card, a schedule, or a wrapped summary, Fandi renders an image into its cache and hands it to the Android share sheet. You choose where it goes.
A shared schedule can also travel as a fandi:// link. The schedule you chose to share is carried inside the link itself and passed between devices by whatever messenger you used — it does not pass through a Pentarab server, and we never see it. Only share such a link with people you intend to share that schedule with.
Analytics
To understand how the app is used and to improve it, Fandi sends usage events to an analytics service that Pentarab runs itself. It is not Google Analytics, and the data is not passed on to any third party. The events record which screens you open and which features you use — adding a bias, logging an expense, adding a photocard, sharing a card — along with the steps of the purchase flow. This is the complete list of what that service receives:
- The app identifier, the platform, and the app version and build number.
- An install identifier — a random value the app generates on first launch. It is not derived from your device, your Google account, or any advertising identifier, and reinstalling the app produces a new one.
- A session identifier, so one run of the app can be told apart from the next.
- Screen names, and how long each screen was open. The duration is measured from a matching open and close, not guessed from the gap between events.
- The UTC time of each event, plus your time-zone offset so local time can be reconstructed.
- Device information: the operating system and its version, the screen size, and the locale. The device model is not sent.
- A country. This is worked out by the receiving server from the connection itself — the app never sends it, and it is country-level only.
The service does not store your IP address. It is read at the edge only to derive the country and is then discarded. It collects no advertising identifier, no precise location, and no personal identifier such as a name, email address, or phone number. Nothing you create or enter in Fandi is part of an analytics event.
Bias names, event titles, amounts, notes, diary text, and photos are never included in an analytics event. Event values are screen names and feature names only, and Fandi has no account, so nothing in the analytics stream identifies you.
Fandi does not collect the Android Advertising ID. Both advertising-ID permissions (com.google.android.gms.permission.AD_ID and android.permission.ACCESS_ADSERVICES_AD_ID) are explicitly removed from the app's manifest and are absent from the build published on Google Play. There are no ads, no crash reporting, and no performance monitoring.
Purchases
Fandi Pro is an auto-renewing subscription billed through Google Play Billing. Pentarab does not receive or store your payment card details, your Google account details, or your billing address. There is no receipt-verification server — your entitlement is confirmed by Google Play and cached on your device so the app still works offline.
Permissions
Fandi declares two permissions, both for event reminders:
- Notifications — so the app can remind you about a comeback, a concert, a fan meeting, or a pre-order deadline. Android asks you for this the first time you switch a reminder on, not at launch, and you can decline or revoke it at any time.
- Run at startup — so reminders you scheduled survive a reboot. An ordinary permission; no prompt.
There is no camera, microphone, photo, media, storage, location, contacts, or calendar permission. Reminders are scheduled on your device; there is no push server.
Your Data Control
- Everything stays on your device — nothing is on a server for us to hold or hand over
- You can delete individual biases, events, expenses, photocards, and diary entries inside the app
- Uninstalling the app, or clearing its data from Android Settings → Apps → Fandi → Storage, removes everything permanently
- If you want the analytics associated with your install removed, email us and we will act on it
Children's Privacy
Fandi is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided information through the app, please contact us so we can address it.
Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated revision date.
Contact Us
Questions about this policy? Email us:
Email: info@pentarab.com