Short version: Photo Slider Digital Frame has no backend server. Everything the app
shows — your photos, your settings, your linked accounts — stays on your device or goes
directly between your device and the service you personally chose to connect (Google,
Dropbox, Microsoft, or your own local network). We (Aurora Devs) never see, receive, or
store your media, credentials, or location.
Who we are
Photo Slider Digital Frame is developed by Aurora Devs. If you have questions about this
policy or the app's data practices, contact us at
auroradevs@gmail.com.
What the app does
Photo Slider Digital Frame turns a phone or tablet into a photo slideshow / digital picture frame. It
displays photos and videos pulled from sources you choose to connect, optionally with a
date/time and weather overlay, and can wake automatically on motion or on a daily schedule.
Data the app accesses, and why
Your photos and videos
The app reads photos/videos only from sources you explicitly enable in "Your Sources":
On this device — your device's photo gallery (specific albums you pick) or specific folders you pick, read via Android's standard media APIs.
Cloud accounts you link — Google Photos, Google Drive, Dropbox, and/or OneDrive, only after you sign in to that provider directly and only for the specific items/folders you select.
Your local network — an SMB share (e.g. a NAS) you configure with its own host/credentials.
In every case, media is fetched directly from that source to your device to be displayed —
it is never uploaded to, processed by, or stored on any server we operate, because no such
server exists.
Location
If you turn on the optional Weather overlay, the app reads your device's coarse/fine
location and sends only the latitude/longitude to
Open-Meteo, a
third-party weather service, to fetch the current forecast. No account, device identifier,
or other personal information is sent with that request, and it is not stored by us. If the
Weather overlay is off, location is never accessed.
Camera
If you turn on the optional Motion-based wake feature, the app uses the front camera to
detect presence/motion, using on-device face detection (Google ML Kit) that runs entirely
locally. Camera frames are analyzed in memory and immediately discarded — none are saved,
displayed, transmitted, or uploaded anywhere. If this feature is off, the camera is never
used.
Account credentials and linked-account tokens
Signing in to a cloud source is handled by that provider's own official sign-in flow:
Google (Photos/Drive) — Google Sign-In, tokens managed by Google's SDK.
Microsoft OneDrive — Microsoft's own MSAL SDK, tokens managed by Microsoft.
Dropbox — Dropbox's official SDK (PKCE sign-in); the resulting credential is encrypted at rest on your device using Android Keystore-backed AES-256-GCM encryption.
SMB (local network) — host/username/password you enter are encrypted at rest on your device the same way, and are only ever sent to the SMB server address you configured.
None of these credentials are ever transmitted to us. Unlinking a source in the app, or
revoking access from that provider's own account-permissions page, stops all future access.
Purchases
The optional one-time "Pro" upgrade is processed entirely by Google Play Billing. We never
receive or store your payment card details — only a purchase confirmation from Google Play,
which the app uses locally to unlock Pro features.
How we protect your data
Some of the data described above — OAuth account access, your photos/videos, and your
network credentials — is sensitive. Here's specifically how it's protected:
Encryption in transit. All communication between the app and any
source you connect — Google, Dropbox, Microsoft OneDrive, and the Open-Meteo weather
service — uses HTTPS/TLS. Media, account, and location data are never sent over an
unencrypted connection.
OAuth sign-in and tokens. Signing in to Google Drive, Google Photos
(via the Google Photos Picker), Dropbox, and OneDrive is handled entirely by that
provider's own official SDK (Google Sign-In, Dropbox SDK, Microsoft MSAL) — the app
never sees or stores your password. Google and Microsoft manage their own session/token
storage inside their SDKs. Dropbox's OAuth credential is the one provider token our app
does hold locally, and — like SMB network credentials — it is encrypted at rest using
AES-256-GCM with a key generated and held inside Android's hardware-backed Keystore, so
it can't be extracted even from an unencrypted device backup.
No off-device copy of your sensitive data. Because the app has no
backend server, the Google Drive files, Google Photos Picker selections, Dropbox files,
and OneDrive files you grant access to are streamed directly from that provider to your
device for display. We do not copy, log, or relay the *content* of that data anywhere
else. Locally we only cache lightweight metadata (item ID/filename, not file content) so
the slideshow can paint instantly the next time the app opens.
Minimum necessary Google data access. For Google Drive and Google
Photos, the app only reads the specific folders/items you explicitly select in "Your
Sources" — it never writes, modifies, deletes, or shares anything in your Google
account, and never touches Drive or Photos content you haven't picked.
You control revocation. You can disconnect any source from inside the
app, or revoke the app's access directly from that provider's account settings (e.g.
Google Account → Security → Third-party access), at any time. Revoking access
immediately stops all future access by the app.
Google API compliance. Photo Slider Digital Frame's use and transfer of
information received from Google APIs to any other app adheres to the
Google API Services User Data Policy,
including the Limited Use requirements.
What we don't do
No analytics, crash reporting, or advertising SDKs are included in the app.
No account or sign-up with us is required or offered.
We do not sell, rent, or share your data with third parties, because we never receive it in the first place.
We do not run any server that stores your photos, credentials, location, or usage activity.
Where data actually lives
App settings and a local cache of "what media exists in each source" (filenames/IDs, not
the media itself in most cases) are stored in the app's private storage on your device, using
standard Android local storage (Room database, DataStore preferences). This data is removed
when you uninstall the app. Android's standard app backup may include non-sensitive settings
in your own personal Google account backup — this is Android platform behavior, not something
we access.
Permissions this app requests
Permission
Why it's needed
Internet
Fetch photos/videos and weather from the sources you configure.
Camera
On-device motion/presence detection for the optional wake feature. Nothing is stored or sent anywhere.
Location (coarse/fine)
Fetch local weather for the optional weather overlay.
Photos/videos on device
Show media from the gallery albums or folders you pick.
Notifications / full-screen intent
Reliably show the slideshow at scheduled times, including over the lock screen.
Schedule exact alarm / receive boot completed
Power the optional Daily Schedule automation, including after a device restart.
Wake lock
Keep the screen on while the slideshow is playing.
Display over other apps
Show the slideshow as a screensaver/kiosk-style overlay.
Children's privacy
Photo Slider Digital Frame is not directed at children under 13, and we do not knowingly collect personal
information from children.
Changes to this policy
If this policy changes, we'll update the "Last updated" date above. Continued use of the app
after a change constitutes acceptance of the updated policy.
Contact
Questions, requests, or concerns about this policy or the app's data practices:
auroradevs@gmail.com.