Legal

Privacy policy

Written to describe what the software actually does. Where a section says data never leaves your browser, you can verify it in your own network tab.

This policy explains what Faisal Nadeem ("we", "us") collects when you use ziptoapk.net, the ZIPtoAPK builder and the companion Android app, and what we do with it. If anything here is unclear, ask us at support@ziptoapk.net.

The short version

  • The free tools upload nothing. Files you drop on them are processed in your browser and never reach us.
  • To build an app you need an account, and the content you submit is transmitted to our build service and stored with your project.
  • We never see your card details. Subscriptions are billed by Google Play.
  • You can delete your account and its data from inside the builder.
  • We do not sell personal data, and we do not buy it.

What we collect

Account information

When you sign in with Google we receive your email address, display name and profile picture URL from Google. We also record that the account signed in here rather than in the Android app, with the date, so we know which surface a user came from, and an approximate country derived from your browser's time zone setting. That country is worked out on your device — we do not use an IP geolocation service, and your IP address is not sent to a third party for this. Alongside it we keep a count of the apps you have built and the website addresses or file names of the projects in your account, so we can see how the service is used; files you upload for a build are not part of that record. Sign-in on this website is Google only; the Android app additionally offers email and password, where the password is handled by Firebase Authentication and is never visible to us. Each account has an internal identifier used to associate your projects and subscription with you.

Content you submit for a build

When you build an app we receive the settings you chose (app name, package name, colours, permissions and so on), the icon and images you supplied, and — if you are bundling rather than loading a live URL — the HTML, CSS, JavaScript and assets in your ZIP. This content is transmitted to our build service, used to compile your app, and retained with the project so you can rebuild or download it again.

If you generate or upload a signing keystore, it is transmitted so the build can sign your app. Treat your keystore password as you would any other password: we cannot recover it for you.

Files used with the tools

Nothing. Every tool under /tools/ runs entirely in your browser — icons are drawn on a canvas, previews are rendered locally, and the checkers never make a network request with your data. This is why the tools keep working with your connection switched off.

Technical information

Our servers record ordinary request information — IP address, timestamp, requested URL, user agent — for security, abuse prevention and diagnosing failures. Your browser also stores a sign-in token so you stay signed in, and a small amount of local data for conveniences like remembering a filter list. Those live in your browser, not on our servers.

What we do with it

PurposeData used
Building your appSettings, images, web content, keystore
Keeping your projects between sessionsAccount identifier, project data
Applying build limits fairlyAccount identifier, build history
Unlocking Pro featuresAccount identifier, subscription status from Google Play
Answering your support emailsWhatever you tell us, plus your account email
Preventing abuse and investigating incidentsRequest logs

We do not use your web content for anything other than building your app. We do not train models on it, publish it, or share it with anyone except the processors listed below.

Who else is involved

Running this service means using other companies' infrastructure. Each of these receives only what it needs:

  • Google (Firebase) — authentication and the database holding your account, projects and subscription state.
  • Cloudflare — the service that receives your requests and routes them.
  • GitHub — the build pipeline. Content you submit for a build is stored in a private repository while the build runs and while the result remains available to you.
  • Google Play — subscription billing for the Android app. Google handles the payment and tells us only whether your subscription is active.

These providers operate internationally, so data may be processed outside your country.

Cookies and analytics

We use Google Analytics (through Firebase) to count visits and see which pages and tools get used. It sets cookies in your browser and records the pages you view, an approximate location derived from a truncated IP address, and your device and browser type. It does not receive your name, your email address, or any file you use with a tool. If you are in the UK or the EEA we ask before any of that runs, and you can change your answer at any time with the Cookie settings link at the bottom of every page. We show no advertising and use no advertising cookies. Sign-in uses browser storage that is strictly necessary to keep you logged in.

This site carries no advertising, so no advertising network sets cookies or reads identifiers here.

How long we keep things

  • Account data — until you delete your account.
  • Projects and build content — until you delete the project or the account.
  • Request logs — a short period for security and diagnostics, then discarded.
  • Support emails — as long as needed to resolve the issue and for our records.

Your choices

You can delete a project at any time in the builder, which removes its stored build. You can delete your entire account from the builder's settings, which removes your account record and associated projects. Deletion is permanent, and apps you have already downloaded or published remain yours — deleting your account here does not remove an app from Google Play.

You may also ask us for a copy of the personal data we hold about you, or ask us to correct it, by emailing support@ziptoapk.net from your account address.

Children

This service is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has created an account, contact us and we will remove it.

Security

Connections use HTTPS, authentication is handled by Firebase, and build content is held in private storage. No service can promise perfect security, and we will not pretend otherwise — but we do not store payment details at all, which removes the most sensitive category entirely.

Changes

When this policy changes materially we will update the date at the top and, for significant changes, tell account holders by email. Continuing to use the service after a change means accepting the updated policy.

Contact

Faisal Nadeem, Sialkot, Pakistan — support@ziptoapk.net.