Privacy Policy — HTTP Server Pro
In short: HTTP Server Pro runs a web server on your own phone. The developer runs no servers for this app and collects no data from it — no accounts, no analytics, no advertising, no crash reporting.
Data leaves your phone only when you use a feature that needs to: a public tunnel, Cloud Share, or the AI website builder. Each is described below.
1. Who we are
HTTP Server Pro is published on Google Play by an independent developer ("the developer", "we"). You can contact the developer at av.n@aol.com.
2. What the developer collects
Nothing, automatically. The app has no account system, contains no analytics, advertising or crash-reporting SDKs, and does not send your files, settings or usage to the developer. There is no developer-operated server for it to send anything to.
The developer receives information only if you choose to email it — for example when you report an AI reply and leave "Also email the report to the developer" ticked (see section 9). That email is used only to review what you reported.
3. What stays on your device
Everything you create in the app is kept in the app's private storage, which other apps cannot read:
- website files (the document root) and your nginx configuration, hosts and routes;
- TLS certificates and private keys you add;
- server access and error logs;
- your settings, including the app name and look you design, your language, and a Gemini API key if you enter one;
- Cloud Share files, if you keep them in app storage rather than a folder you picked;
- AI content reports you file (a local record of the report).
4. Android backup
If Android backup is turned on for your Google account, Android may include some of the app's data in that backup, which Google stores under your account. The app limits this to:
| Backup type | Included | Never included |
|---|---|---|
| Cloud backup | settings (profile.json), website files | TLS private keys, logs, runtime and temporary files |
| Direct phone-to-phone transfer | settings, website files, TLS certificates and keys | logs, runtime and temporary files |
Settings include your Gemini API key if you entered one. You can turn backup off in Android's settings.
5. Files and folders you choose
- Uploading files or folders: Android's file picker gives the app access only to what you select; the app copies it into the document root and keeps no further access.
- Device Sync and the Cloud Share folder: if you pick a folder for these features, Android grants the app ongoing access to that one folder, so it can keep working after a restart. The app reads and writes only inside it. You can revoke this at any time by choosing another folder, turning the feature off, or clearing the app's data.
The app does not request location, contacts, camera, microphone, phone, SMS or broad storage permissions.
6. Permissions
| Permission | Why |
|---|---|
| Internet, network state, Wi-Fi state | serve pages, open tunnels, show your LAN address |
| Foreground service (special use) | keep the web server running while the app is in the background, with a visible notification |
| Notifications | show that ongoing server notification and its Stop action |
| Wake lock | keep serving while the screen is off |
| Run at startup | only if you turn on start-on-boot |
7. Public tunnels
When you start a tunnel (you are asked to agree to a warning first):
- anything in your document root can be fetched by anyone who has the address;
- your traffic passes through the tunnel provider you chose — Cloudflare for Cloudflare tunnels, or Pinggy for Pinggy tunnels — and their handling of it is governed by their own terms and privacy policies;
- visitors use your device's bandwidth, battery and mobile data.
Quick-tunnel addresses change every time the tunnel restarts and come with no uptime promise.
8. Cloud Share and its Monitor
Cloud Share lets people you give the link to download files from your Send folder and upload files into your Received folder. It is off until you switch it on, and it works only while a tunnel is running.
What the Monitor records about visitors
So you can see who is using your share, the app records, on your device only, for each device that opens it:
- its IP address and the information its browser sends with every request: browser and operating system (read from the User-Agent), preferred languages and the referring page;
- information the share page reads in the visitor's browser without any permission prompt: screen and window size, pixel ratio, time zone, platform, number of CPU cores, approximate memory, touch support, connection type and speed, and light or dark mode;
- activity counts: pages opened, files downloaded and uploaded, and data transferred.
These records are held in memory on your phone, are never sent to the developer, and are erased when the app's process ends. A visitor sees their own record and overall totals on the share's Monitor tab, never another visitor's details. If you share the link with others, you are responsible for letting them know their visit is logged.
9. AI website builder (Gemini)
The builder is optional and uses your own Gemini API key; no key is included in the app. Only when you send a request does the app contact Google's Gemini API, sending:
- the text of your request;
- the names of up to 120 files already in your document root (not their contents), so the model can edit rather than duplicate them;
- your API key, which Google uses to identify your account.
The reply is written into your document root. Google's processing of this data is governed by the Gemini API Terms and Google's Privacy Policy. Your key is stored on your device only.
Reporting AI replies
Every AI reply has a Report option. Reporting hides the reply, stores a record of the report on your device, can optionally delete the files that reply wrote, and can optionally open your email app with the report (your request and the reply) addressed to the developer. Nothing is sent unless you send that email.
10. LAN upload and WebSocket
- LAN upload opens a temporary, token-protected upload page on your local network so another of your devices can send files to the app. The optional internet mode uses a temporary tunnel (see section 7).
- The WebSocket server relays messages between connected clients through your own server. Messages are not stored.
11. Server logs
nginx writes access and error logs to app-private storage. They contain visitors' IP addresses, requested paths, status codes and User-Agent strings. They are never uploaded and are excluded from cloud backup. You can clear them from the Console at any time.
12. Keeping and deleting data
All data is kept on your device until you delete it. You can delete website files, Cloud Share files, logs and settings inside the app. Clearing the app's data in Android settings, or uninstalling the app, deletes everything the app stored on the device. Copies in a folder you picked for Device Sync or Cloud Share are your own files and remain until you delete them. Data in an Android backup follows your Google account's backup settings.
13. Security
The app keeps its data in Android's app-private storage, serves public traffic over the tunnel provider's HTTPS, protects LAN uploads with a one-time token, and never sends TLS private keys to the cloud. No system is perfectly secure: do not place confidential files in your document root or Send folder while a tunnel is running.
14. Children
HTTP Server Pro is a developer tool intended for adults. It is not directed at children, and the developer does not knowingly collect personal information from anyone.
15. Your responsibility
You decide what your server publishes and who can reach it. You are responsible for the content you host or share, for complying with the laws that apply to you, and for the terms of any tunnel provider and of the Gemini API that you use.
16. Changes and contact
If this policy changes, the new version will be published at this address with a new effective date, and material changes will be shown in the app. Questions or requests: av.n@aol.com.