Privacy Policy for Flutor

Effective Date: 9 August 2026

Last Updated: 9 August 2026

Applies to: Flutor for Android (package com.ironfist.flutor), distributed through Google Play.


1. Summary

Flutor is a BitTorrent client and media player that runs entirely on your device. It has no user accounts, no login, and no Flutor-operated server. Your downloads, settings, and file names never reach us.

Three things do leave your device, and only these:

WhatWhere it goesCan you turn it off?
Your IP address and the content identifiers you downloadDirectly to BitTorrent peers, trackers and the DHT network — inherent to how BitTorrent worksYes — don't add torrents; or route traffic through a proxy in Settings
Anonymised crash, performance and usage diagnosticsGoogle Firebase (Crashlytics, Performance, Analytics)Not currently in-app; see §7
Advertising requestsGoogle AdMobPersonalisation is controlled by your consent choice; see §6

We do not sell or share personal information for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA, nor do we operate any advertising exchange of our own.


2. Who We Are (Data Controller)

Developer: IronFist

Contact e-mail: ironfist.apps@gmail.com

Postal address: Gujarat, India.

Website: https://udyan-dev.github.io

For privacy questions or to exercise any right in §11, contact the e-mail above. We aim to respond within 30 days.


3. Data We Collect

3.1 Data that never leaves your device

Flutor stores the following locally, in the app's private storage and in your chosen download folder. It is not transmitted to us or to any third party:

Uninstalling the app removes the app's private data. Files saved to a shared or user-chosen folder remain until you delete them.

3.2 Data shared with the BitTorrent network

This is inherent to the protocol and is not something Flutor adds:

Flutor does not operate any tracker, DHT bootstrap node, or peer server. We do not receive, log, or have any way to observe this traffic.

Controls available to you in Settings:

3.3 Diagnostics and analytics (Google Firebase)

Flutor uses Firebase Crashlytics, Firebase Performance Monitoring, Firebase Analytics, and Firebase App Check. Firebase is disabled entirely in debug builds and initialises only after the app's first screen is drawn.

Collected:

Redaction before transmission. All diagnostic text is passed through a sanitiser before it is sent. It removes magnet links, URLs and URIs, file-system paths, 32–40 character hex strings (info-hashes), and IP addresses, and truncates the remainder. Analytics parameter names are normalised and truncated. This is enforced in a single telemetry module and covered by automated tests.

We therefore do not receive: file names, folder paths, torrent names, magnet links, info-hashes, tracker URLs, feed URLs, or peer IP addresses.

3.4 Advertising data

See §6.

3.5 Data we do not collect

Flutor does not collect, and does not request permission to access: precise or coarse location, contacts, calendar, SMS or call logs, microphone, camera, photos or media libraries, health data, biometric data, or any account or profile information. There is no sign-up, and we do not ask for your name or e-mail to use the app.


4. Android Permissions

Flutor requests only the permissions below. Each is used solely for the stated purpose.

PermissionWhy it is neededData leaving the device
INTERNETBitTorrent peer, tracker and DHT traffic; ad requests; diagnosticsYes — see §3.2, §3.3, §6
ACCESS_NETWORK_STATEDetect connectivity type (Wi-Fi / mobile / metered / VPN) so transfers and ad requests can respect your network rulesNo
WAKE_LOCKKeep the CPU awake while a transfer is actively runningNo
FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNCRun the torrent engine as a visible foreground service so Android does not kill an in-progress transferNo, by itself
POST_NOTIFICATIONSShow transfer progress, completion and error notificationsNo — notifications are rendered locally by Android
READ_EXTERNAL_STORAGE (Android 12L / API 32 and below only)Read .torrent files and existing downloads you point the app atNo
WRITE_EXTERNAL_STORAGE (Android 10 / API 29 and below only)Write downloaded files to the folder you chooseNo

On Android 13 and above, Flutor uses the Storage Access Framework: you pick a download folder through the system picker and Flutor holds a persistable grant to that folder only. Flutor does not request MANAGE_EXTERNAL_STORAGE ("All files access") and has no broad filesystem access.

Flutor explicitly removes the READ_MEDIA_IMAGES, READ_MEDIA_VIDEO and READ_MEDIA_AUDIO permissions that some bundled libraries would otherwise declare, so the app cannot read your media library.


5. How and Why We Use Data

PurposeData usedLegal basis (GDPR Art. 6)
Provide the download, streaming and playback features you requestLocal data (§3.1), BitTorrent traffic (§3.2)Contract — Art. 6(1)(b)
Keep the app stable and diagnose crashesCrash and performance diagnostics (§3.3)Legitimate interests — Art. 6(1)(f)
Understand which features are used, in aggregateAnalytics events (§3.3)Legitimate interests — Art. 6(1)(f)
Protect against abuse and fraudulent API useApp Check attestation (§3.3)Legitimate interests — Art. 6(1)(f)
Serve non-personalised advertisingAd request data (§6)Legitimate interests — Art. 6(1)(f)
Serve personalised advertisingAdvertising ID and ad interaction data (§6)Consent — Art. 6(1)(a)

Where we rely on legitimate interests, we have assessed that our interest in operating and improving a free application does not override your rights, in part because the diagnostic data is redacted before it reaches us (§3.3). You may object to this processing at any time (§11).


6. Advertising

6.1 What we use

Flutor displays advertising supplied by Google AdMob (publisher ID pub-5764447516567914) in four places: a small native ad inside the download lists, a banner on empty screens and the add-torrent preview, an occasional full-screen ad after adding torrents, and an optional full-screen ad before playback that you can always decline.

6.2 What advertising partners may collect

Google and its ad partners may collect and process:

This data is processed by Google as an independent controller or as a processor depending on your region and consent state. See Google's Privacy Policy and How Google uses information from sites or apps that use our services.

6.3 Consent and your choices

The Google Mobile Ads SDK is initialised only after the consent state has been resolved. Flutor's ad content rating is capped at Teen (T), and the app is not tagged as child-directed (see §9).

6.4 Ad frequency counters

To limit how often ads appear, Flutor stores a handful of integers on your device (number of torrents added since the last ad, number of playbacks since the last ad, a timestamp, and daily impression counts). These are stored locally only, are never transmitted, and are erased when you withdraw consent or clear app data.


7. Third Parties and Processors

ServiceRoleDataPolicy
Google AdMob / Google Mobile Ads SDKAdvertising delivery and measurement§6.2https://policies.google.com/privacy
Google User Messaging Platform (UMP)Consent collection and storageConsent statehttps://policies.google.com/privacy
Firebase CrashlyticsCrash diagnostics§3.3https://firebase.google.com/support/privacy
Firebase Performance MonitoringPerformance diagnostics§3.3https://firebase.google.com/support/privacy
Firebase AnalyticsAggregate usage analytics§3.3https://firebase.google.com/support/privacy
Firebase App Check / Play IntegrityAnti-abuse attestation§3.3https://firebase.google.com/support/privacy
Google Play Services / Google PlayApp distribution and platform servicesHandled by Googlehttps://policies.google.com/privacy

We have no other processors. We do not use any third-party SDK for attribution, mediation, tracking, or user profiling beyond those listed.

BitTorrent peers, trackers and DHT nodes (§3.2) are not our processors — they are independent parties on a public network, and we have no contractual relationship with them.


8. Data Retention

DataRetention
Torrent data, settings, downloads (on device)Until you delete them or uninstall the app
Ad frequency counters (on device)Until reset, consent withdrawal, or app data is cleared
Crash reportsRetained by Google per Firebase Crashlytics defaults (currently 90 days)
Analytics eventsRetained by Google per the configured Firebase Analytics retention window
Performance tracesRetained by Google per Firebase Performance defaults
Advertising dataRetained by Google per its own policies

We do not maintain any database of our own, so we hold no copy of your data beyond what Google retains on our behalf in the consoles listed above.


9. Children's Privacy

Flutor is not directed to children. It is rated for a general or teen audience and is not published in Google Play's Designed for Families programme. We do not knowingly collect personal information from children under 13 (or the applicable age of digital consent in your jurisdiction, up to 16 in parts of the EEA).

Flutor does not set the child-directed treatment flag on ad requests, because the app is not intended for children. If you believe a child has used the app and you wish to have any associated data removed, contact us at the address in §2 and we will act promptly.


10. International Transfers

Google processes data in the United States and other countries. Where personal data is transferred out of the EEA, UK or Switzerland, Google relies on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US / UK / Swiss-US Data Privacy Framework. Details are in Google's own policies linked in §7.


11. Your Rights

Depending on where you live, you may have the right to:

How to exercise them, in practice:

You want to…Do this
Withdraw or change ad consentSettings → Privacy → Ad Privacy Options
Reset your advertising identifierAndroid Settings → Privacy → Ads → Delete advertising ID
Delete everything Flutor holds locallyAndroid Settings → Apps → Flutor → Storage → Clear data, or uninstall
Request access to, or deletion of, diagnostic dataE-mail us at the address in §2, including your Firebase app-instance ID if you can provide it
Object to analytics or crash reportingE-mail us at the address in §2

Because the diagnostic data we receive is pseudonymous and redacted (§3.3), we may be unable to link it to you individually. In that case, under GDPR Art. 11 we may ask for additional information to locate it, or explain why we cannot.


12. Security

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.


13. Lawful Use and Content Responsibility

Flutor is a general-purpose BitTorrent client. It does not host, index, supply, or recommend any content, and it has no catalogue, search, or discovery of copyrighted works. The developer cannot see what you download and does not inspect, scan, or store your files.

You are solely responsible for the content you access, download, share or seed, and for complying with copyright, intellectual-property and all other laws applicable to you. Do not use Flutor to infringe the rights of others.


14. Changes to This Policy

We may update this policy as the app evolves or as legal requirements change. Material changes will be reflected in the Last Updated date at the top and, where the change is significant, surfaced in the app or in the Google Play release notes. Continued use after an update constitutes acceptance of the revised policy.


15. Contact

Developer: IronFist

E-mail: ironfist.apps@gmail.com

Address: Gujarat, India.

Website: https://udyan-dev.github.io

If you are in the EEA or UK and are dissatisfied with our response, you may complain to your national data protection authority.