Fast USB OTG & internal storage, direct NTFS/exFAT access
The short version: NTFS File Manager manages files on your device. The Developer runs no server, has no account system, and never receives your files, filenames, or file listings. But the App is not an entirely offline app, and this Policy will not pretend otherwise. It shows advertisements through Google AdMob, which collects device and advertising identifiers; it sells optional Premium subscriptions through Google Play; and it has optional features you can switch on that talk to cloud providers, network shares, and online media services. Sections 5 through 11 describe every one of those, in detail.
Who is responsible for your data. The data controller for the purposes of the EU and UK General Data Protection Regulation is the developer of NTFS File Manager, whose name, registered address and contact email address are published on the App's Google Play listing, under "App support" / "Developer contact". Where this Policy says "the Developer," it means that person or entity. Google acts as a separate and independent controller for the advertising described in Section 5.
Contents
This Privacy Policy explains how the NTFS File Manager Android application (the "App") handles information when you download, install, and use it. It is written to satisfy the disclosure requirements of the Google Play Developer Program Policies — including the User Data policy, the Permissions policy for sensitive permissions such as All Files Access, Camera and Query All Packages, the Ads policy, and the Subscriptions policy — and to give you an accurate and complete account of the App's data practices rather than a generic template.
This Policy covers the App itself, and the choices the Developer has made about what the App does. It does not govern, and the Developer does not control: (a) Google's advertising and Play platform services described in Sections 5, 6 and 12; (b) cloud storage providers you connect under Section 7, or network servers you connect under Section 8, which operate under their own policies; (c) the third-party media services described in Section 10; (d) third-party apps you choose to open a file with; or (e) any website or service not operated by the Developer. By installing or using the App, you acknowledge that you have read and understood this Policy.
Two different things are happening in this App, and conflating them is how privacy policies become misleading. This section separates them.
The Developer operates no server, no backend, no account system, and no analytics or crash-reporting SDK of its own. There is no mechanism by which your files, filenames, folder structure, file listings, bookmarks, search terms, or storage contents reach the Developer, because there is nowhere for them to go. That was true before this version and remains true.
The App is funded by advertising and optional Premium subscriptions. To show ads, the App embeds the Google Mobile Ads (AdMob) SDK, which — independently of the Developer — collects data from your device including your Android advertising identifier, IP address, device and OS characteristics, coarse location inferred from IP, and your interactions with ads. This is personal data under the GDPR and, for personalized advertising, is likely "sharing" under the California Privacy Rights Act. Section 5 sets this out in full, including how to turn personalized advertising off. If you subscribe to Premium, ads stop being requested or shown at all.
Cloud accounts (Section 7), network shares (Section 8), the device's own file servers (Section 9), and the online media features (Section 10) each send data outward when — and only when — you use them. In every case the traffic goes directly from your device to that destination. None of it passes through the Developer.
Subject to everything disclosed in Sections 5 through 12, the App does not:
This is the complete list of permissions the App declares. Each one is used for a specific, user-visible function, and the runtime-prompted ones are requested at the point they are needed rather than bundled at first launch.
File management is the App's entire purpose, so direct access to your device's shared storage (MANAGE_EXTERNAL_STORAGE on Android 11 and later, or READ_EXTERNAL_STORAGE/WRITE_EXTERNAL_STORAGE on Android 12 and earlier) is the one permission the App genuinely cannot function without. Prominent in-app disclosure: before the system's All Files Access settings screen is ever shown, the App first displays its own explanation screen stating why the permission is required and what will not work without it; you must take an explicit action on that screen before the system permission flow opens. The App uses this permission exclusively to let you browse, open, copy, move, rename, delete, compress and otherwise manage files you choose, on storage you choose. It is never used to scan, catalogue, index, upload or transmit your files or file listings to the Developer, to any advertiser, or to any third party.
READ_MEDIA_IMAGES, READ_MEDIA_VIDEO, READ_MEDIA_AUDIOThese granular media permissions supplement All Files Access on newer Android versions so the App can generate thumbnails and read metadata (such as image dimensions or audio/video duration) for the Photos, Videos and Music views, the gallery and players, and the file-properties panel. They are used solely to render those files' previews and details on your screen.
CAMERA)Used by one feature only: the Document Scanner, which photographs a physical document and turns it into a PDF. The camera is opened only on the Document Scanner screen, only after you grant the permission at that screen, and never in the background. Captured images are processed entirely on your device and saved only where you choose to save them. No image, preview, or camera frame is transmitted to the Developer or to any third party. The App declares camera hardware as an optional feature, so devices without a camera can still install and use everything else. See Section 11.
Requested only when you physically connect a USB (OTG) drive, through Android's standard USB-host permission dialog, so the App can communicate with that specific drive directly to mount, read and write NTFS, exFAT or FAT volumes. It is scoped to the device you approve and is not requested speculatively.
POST_NOTIFICATIONS, Android 13+)Used to show and let you control long-running operations — file transfers, compression, drive formatting, media playback, and the built-in file servers — including while you are outside the App, and to let you pause, cancel or resume them. Requested the first time such an operation is about to run, not at install. It is not used for marketing or promotional messages.
FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNC, FOREGROUND_SERVICE_MEDIA_PLAYBACK)Lets an operation you started keep running when you navigate away from the App, rather than being silently killed by the operating system: DATA_SYNC for file transfers, compression, formatting and the built-in file servers; MEDIA_PLAYBACK for the audio and video players. Android requires a visible, ongoing notification for the entire time any of these is active, so none of them can run without your knowledge.
QUERY_ALL_PACKAGES)The App's Apps feature lets you view, launch, back up (extract as an APK) and manage the applications installed on your device — a file-management capability the Google Play Permissions policy specifically recognises as an approved use of this permission for file managers that work with the widest array of file types, including APKs. It lets the App read the on-device list of installed packages (package name, label, icon, version) to display them to you. That list is never transmitted anywhere, never logged by the Developer, and is never used for advertising, profiling or measurement.
INTERNET, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE)INTERNET is used by: advertising (Section 5); Google Play Billing (Section 6); cloud accounts you connect (Section 7); network locations you connect (Section 8); the built-in file servers (Section 9); the optional online media features (Section 10); and the Google Play platform features in Section 12. ACCESS_NETWORK_STATE is used to detect whether you are online before attempting a network operation, and to warn you before a large transfer on mobile data. ACCESS_WIFI_STATE is used by the built-in file servers to determine your device's local IP address and Wi‑Fi network name so the App can display the address other devices should connect to. It is not used to scan for, log, or report nearby networks, and the App holds no location permission, so it cannot use Wi‑Fi data to derive your location.
com.android.vending.BILLING)Required by Google Play Billing so the App can offer, and restore, the Premium subscription described in Section 6. Payment is handled entirely by Google Play; the App never sees or handles your payment details.
The free tier of the App is supported by advertising served through Google AdMob (the Google Mobile Ads SDK). This is the most privacy-significant thing the App does, so it is described here without euphemism.
The App shows banner ads within certain screens, occasional full-screen interstitial ads between actions subject to a frequency limit, and rewarded interstitial ads that you may optionally choose to watch in exchange for a temporary, single-use unlock of a Premium feature. A rewarded ad is never forced: it is offered as an alternative to subscribing, and declining it simply leaves that feature locked.
When an ad is requested, the Google Mobile Ads SDK collects and transmits to Google, independently of the Developer, data that typically includes: your Android advertising identifier (AAID) or, where you have opted out, a non-personalized substitute signal; your IP address, and coarse geographic location inferred from it; device model, manufacturer, operating-system version, language, screen characteristics and network type; the App's package name and version; and ad events such as which ads were requested, displayed, viewed, clicked or closed, and whether a rewarded ad was completed. Google uses this to select and deliver ads, to measure their performance, to limit how often you see the same ad, to detect invalid traffic and fraud, and — where you have consented, or where another lawful basis applies in your jurisdiction — to personalise advertising and to build advertising profiles across apps and sites.
The advertising SDK does not receive your files, filenames, folder structure, file listings, bookmarks, installed-app list, cloud or network credentials, scanned documents, or camera images. No content from your storage is used to target advertising.
Consent notice. Where required by the EU and UK GDPR and the ePrivacy Directive, the App presents a consent message, using a Google-certified Consent Management Platform, before personalized advertising is enabled. You may accept personalized ads, refuse them and receive non-personalized ads instead, or manage your choice in detail by purpose and vendor. Refusing does not disable any feature of the App. You can change or withdraw your choice at any time from Settings → Privacy → Ad privacy options in the App, and withdrawal is as easy as giving consent. Non-personalized ads still involve limited processing — including your IP address and frequency-capping and fraud-prevention signals — that is necessary to deliver and secure the ad.
Google's processing of the data above is governed by the Google Privacy Policy and, for advertising specifically, How Google uses information from sites or apps that use our services.
The App offers an optional Premium subscription, billed monthly or yearly, which removes advertising and unlocks certain features. Some users may also hold a legacy one-time "lifetime" unlock purchased in an earlier version, which continues to be honoured.
All purchases are processed by Google Play, which is the merchant of record. Your payment method, billing address and transaction details are handled entirely by Google under the Google Play and Google Payments terms. The Developer never sees, receives, or stores your payment card number, bank details, billing address, or any other payment credential.
What the App receives from Google Play is limited to the purchase state needed to unlock features: the product identifier purchased, a purchase token, the purchase time, and whether the subscription is active and acknowledged. The App verifies the cryptographic signature on that purchase record on your device, and caches the resulting yes-or-no entitlement locally so Premium keeps working while you are offline. Neither the purchase token nor the entitlement state is transmitted to the Developer, because there is no Developer server to transmit it to. The Developer does receive, from Google Play Console, the standard aggregated sales and financial reporting Google provides to every developer; it is used for accounting and is not used to build any profile of your use of the App.
Cancellation, renewal, price-change, withdrawal and refund terms are set out in Sections 5 to 7 of the Terms of Service.
The App's Cloud section lets you connect your own Dropbox or Microsoft OneDrive account so you can browse it and copy files to and from your device, the same way you already do with internal storage or a USB drive. This is entirely opt-in — nothing in this section happens unless you deliberately add a cloud account and complete that provider's own sign-in. Google Drive is not available in this version.
Connecting an account hands you off to that provider's own sign-in screen: Dropbox uses a browser tab with PKCE; Microsoft OneDrive uses Microsoft's own authentication library. You enter your credentials directly with the provider, never with the App. The App receives back only a limited-scope access token proving you approved the connection — never your password.
The access token, and where the provider issues one the refresh token, for each connected account is stored in EncryptedSharedPreferences, encrypted at rest under a key held in your device's Android Keystore. It stays on your device and is never sent to the Developer, because the Developer has no server to send it to. Disconnecting an account, or uninstalling the App, removes it.
When you copy or move a file between your device and a connected cloud account, that file's bytes travel directly between your device and the provider's own servers over an encrypted (TLS) connection. The Developer's infrastructure is not part of that path in any way, and the Developer cannot see, log, or retain the file, its name, or its contents. Once a file lands on the provider's side it is subject to that provider's own storage and privacy practices, not this Policy — see Dropbox and Microsoft.
You can disconnect any cloud account at any time from the App's Cloud section, which deletes its stored token from your device and stops the App accessing that account. The App attempts to revoke the token with the provider where that provider supports revocation. Disconnecting does not delete anything from the provider's side. As a belt-and-braces step you can also review and revoke the App's access directly in your account settings on the provider's own website.
The App's Network section lets you connect to file servers you already have access to, using the SMB, SFTP, FTP, FTPS and WebDAV protocols — for example a NAS on your home network, or a work file share.
To do this you enter that server's hostname or IP address, port, share or path, and the username and password or key material it requires. Those credentials are stored on your device only, in EncryptedSharedPreferences encrypted at rest under an Android Keystore key, so the App can reconnect without asking you every time. They are never transmitted to the Developer, and there is no Developer server that could receive them. Removing a saved connection deletes its stored credentials from your device; uninstalling the App removes all of them.
When you use such a connection your device communicates directly with the server you specified. The security of that traffic depends on the protocol you choose and on the server's configuration: SFTP, FTPS and WebDAV over HTTPS are encrypted in transit, whereas plain FTP and WebDAV over HTTP transmit credentials and file contents unencrypted, and SMB's protection depends on the dialect and settings your server negotiates. The App will use what the server offers; choosing an unencrypted protocol is your decision and its risks are yours. The Developer does not operate, control, or have any visibility into any server you connect to, and that server's operator determines what it logs about your connection.
The App can turn your device into a file server on your local network, so a computer on the same Wi‑Fi can browse and transfer files from it. Three modes are available: a browser-based file manager over HTTP, a WebDAV network drive, and an FTP server. Each runs only while you explicitly start it, shows a permanent notification the whole time it is running, and stops when you stop it, when the system removes the App, or when you leave the network.
Understand what this does. While a server is running, the storage area you selected is reachable over your local network by anything that can reach your device's IP address and supply the access PIN. Access is protected by a PIN you set, with failed-attempt rate limiting and lockout, and a time-based code where enabled. That is meaningful protection against casual access on a home network — it is not a substitute for network security. Do not run a server on a public, guest, café, airport or hotel Wi‑Fi network, or on any network whose other users you do not trust. The browser-based mode uses plain HTTP and the FTP mode uses plain FTP; neither encrypts traffic on your local network. You are the operator of any server you start, and Section 17 of the Terms of Service allocates that responsibility.
Nothing about a running server is reported to the Developer. Connection and transfer state is held on your device and shown in the App; it is not uploaded anywhere. The App does not open ports on your router, does not use UPnP, and does not make your device reachable from the public internet — reachability is limited to your local network unless you have separately configured your own network to expose it.
Beyond managing local files, the App includes optional media features that fetch content from public third-party services. Each of these only makes a network request when you open that feature and browse or play something in it. If you never open them, the App never contacts these services.
When you do use them, your device connects directly to the service in question, which necessarily receives your IP address, approximate location inferred from it, the request you made (for example a search term or a channel or track identifier), and standard connection metadata. The Developer receives none of this and operates none of these services. The services used are:
api.pexels.com) — the free stock-video catalogue in the Video Library. Governed by the Pexels Privacy Policy.api.radio-browser.info and its mirrors) — a community-maintained directory of internet radio stations. Playing a station connects your device directly to that station's own stream URL, operated by that broadcaster.archive.org) — public-domain and freely-licensed audio collections, governed by the Internet Archive's terms and privacy policy.iptv-org.github.io, raw.githubusercontent.com) — a community-maintained, publicly published index of free-to-air live TV channel URLs. The App downloads that index; playing a channel connects your device directly to that channel's own stream, operated by a third party with whom the Developer has no relationship. See Section 18 of the Terms of Service for the important limits on this feature.cdn.pixabay.com) and Unsplash (images.unsplash.com) — royalty-free audio and cover artwork used by the built-in free-music catalogue.fonts.googleapis.com) — web font delivery for certain in-app web content.The Developer does not host, control, moderate, or endorse any content available through these services, receives no data about what you browse or play in them, and cannot guarantee their availability. Requests carry no identifier of you beyond what any HTTP client necessarily sends; the App does not attach an account, advertising identifier, or persistent user ID of its own to them.
The Document Scanner lets you photograph a document with your device camera, crop and correct it, optionally extract its text, and save it as a PDF or image.
Image processing — edge detection, perspective correction, filtering and PDF generation — happens entirely on your device. Text recognition uses Google ML Kit text recognition, which runs its recognition model on-device; the image and the recognised text are not uploaded to Google for recognition. Where ML Kit is delivered through Google Play services, Google Play services may download or update the recognition model itself over the network, which is a Google platform operation and does not involve your images.
Scanned pages and extracted text are written only where you tell the App to write them, plus a working copy in the App's own private storage while a scan is in progress. Nothing from the camera, and no scanned page or recognised text, is sent to the Developer or used for advertising.
The App integrates several Google Play platform features. Each is Google's own infrastructure operating under Google's Privacy Policy; the Developer does not receive, store or process the underlying data and cannot configure them beyond what Google Play provides:
To provide its features, the App stores data locally — within its own private app storage, or within folders you control. None of it is transmitted to the Developer, and all of it is removed when you clear the App's data or uninstall it, except where noted:
.NtfsHelperTrash folder on your own device storage, or Android's own system recycle bin for media the system has indexed. Items are automatically and permanently purged after the retention period you choose in Trash settings — 7, 30, 60 or 90 days, defaulting to 30 — or sooner if you empty Trash yourself. USB (OTG) and network deletions are immediate and permanent and never pass through Trash.The on-device data in Section 13 is used exclusively to provide the feature it belongs to. The Developer does not profile, analyse, or monetise it, and never receives it.
Where the GDPR or UK GDPR applies, the legal bases are:
The Developer does not carry out automated decision-making producing legal or similarly significant effects concerning you.
The Developer does not sell your personal information for money, and does not share personal information with third parties for their own independent marketing.
The flows of data off your device are, in full: (a) the advertising described in Section 5, where Google acts as an independent controller and, for personalized advertising, receives data that is likely to constitute "sharing" for cross-context behavioural advertising under the CPRA (see Section 19); (b) the Google Play platform and billing services in Sections 6 and 12; (c) cloud accounts you connect (Section 7); (d) network servers you connect (Section 8); (e) devices you allow to connect to a server you started (Section 9); and (f) the online media services you choose to use (Section 10). In (c) through (f) you select the destination and the Developer is not a party to the transfer.
The Developer may disclose information if legally required to do so — for example in response to valid legal process. In practice the Developer holds no personal data about you to disclose: not your files, not your file activity, not whether you connected a cloud account or which one, and not what you played or browsed.
If the App or the Developer's business is ever transferred to another party, any obligations under this Policy would pass to that party, and you would be notified through an updated Policy at this URL before any change in how data is handled took effect.
Your files and app data are protected by Android's standard application sandboxing and filesystem permission model, which isolates the App's private storage from other apps. Cloud tokens and network credentials are additionally encrypted at rest under keys held in the Android Keystore. Network communication with Google, cloud providers and the online media services uses encrypted HTTPS/TLS connections.
Two limits deserve emphasis rather than burial. Safe Folder restricts access via your device credential but does not encrypt files — if you need encryption at rest for particularly sensitive material, use a dedicated encryption tool as well. And the built-in Web and FTP servers (Section 9), and plain FTP or HTTP network connections (Section 8), transmit data unencrypted over the network you are on.
No method of storage or transmission is completely secure and the Developer cannot guarantee absolute security. The App's core security posture remains that the Developer holds nothing: there is no server to breach, no database of users, and no copy of your files anywhere the Developer can reach.
The Developer operates no server and therefore retains no personal data of yours off your device. On-device data is retained for as long as it is useful to you and is within your control:
Data held by Google in connection with advertising, Play Billing and Play platform services is retained under Google's own retention schedules, which you can review in the Google Privacy Policy and manage through your Google Account. Files you have copied to a cloud account, a network server, or another device are retained wherever they now live, under that location's own rules — the App has no further involvement once a transfer completes.
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests, together with the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Because the Developer holds no personal data about you, a request made to the Developer will in most cases be answered by confirming that no data is held. Where your request concerns advertising data, the effective route is: withdraw or change your consent in Settings → Privacy → Ad privacy options; reset or delete your advertising identifier in Android Settings; or exercise your rights directly with Google, which is the controller for that data, through your Google Account and the contact routes in the Google Privacy Policy. The Developer will help you direct a request correctly if you ask.
You may contact the Developer at the address in Section 25 to exercise any right, and you will receive a response within one month. You also have the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office.
If you are a resident of California, or of another US state with a comprehensive privacy law (including Colorado, Connecticut, Virginia, Utah, Texas and others as they take effect), you have rights to know, access, correct and delete personal information, to opt out of its sale or sharing and of targeted advertising, and not to be discriminated against for exercising them.
Do Not Sell or Share My Personal Information / Opt out of targeted advertising. The Developer does not sell personal information for money. However, personalized advertising through AdMob (Section 5) involves disclosing identifiers and device data to Google for cross-context behavioural advertising, which the CPRA treats as "sharing" and which other state laws treat as targeted advertising. To opt out: open Settings → Privacy → Ad privacy options in the App and decline personalized ads; and/or delete your advertising ID in Android Settings → Privacy → Ads; and/or subscribe to Premium, which stops advertising entirely. Any one of these is effective on its own, and none of them restricts your use of the App.
The categories of personal information involved are identifiers (advertising ID, IP address), internet or network activity (ad interactions), and coarse geolocation inferred from IP — all as described in Section 5, and all collected by Google rather than received by the Developer. No sensitive personal information is collected, and the Developer does not knowingly sell or share the personal information of consumers under 16.
The Developer transfers no personal data internationally, holding none. Google — for advertising, billing and Play services — and any cloud, network or media service you connect to may process data on infrastructure located outside your country, including in the United States. Those transfers are made under that company's own safeguards, which for Google include the EU Standard Contractual Clauses and its certification under the EU–US, UK and Swiss–US Data Privacy Frameworks. Details are in each company's own privacy policy, linked from the relevant section above.
The App is a general-purpose file-management utility intended for a general audience aged 13 and over, or the equivalent minimum age in your jurisdiction, which is 16 in some EEA member states. It is not directed to children, is not part of Google Play's Designed for Families programme, and is not designed or marketed with child appeal.
Because the App serves advertising, this matters: the Developer does not knowingly collect personal information from, or permit personalized advertising to be served to, children below the applicable age, and the App does not request the data categories that would require child-directed treatment. If you are a parent or guardian and believe a child below the applicable age has used the App, contact the Developer at Section 25 and the Developer will take reasonable steps to address it — though, as set out in Section 3, the Developer holds no account or profile data that could identify the child. Advertising data collected by Google can be removed by deleting the device's advertising identifier in Android Settings.
The App's Help & Feedback page and in-app Settings link out to GitHub Issues (github.com) so you can report bugs or request features publicly. Anything you submit there is governed by GitHub's Privacy Statement, not this Policy, and a public issue is, by its nature, public. The same Help page may also collect messages through a Google Form hosted by Google; answers to that form are stored with Google under Google's Privacy Policy, and the Developer reads them there. Do not submit passwords, file contents, or other sensitive material through either channel. Similarly, when you use "Open with" to hand a file to another app, that app's own privacy practices govern from that point on, and the Developer has no visibility into or control over what it does.
The App's NTFS and exFAT filesystem support is built on the open-source libntfs-3g and ntfsprogs libraries, and the App uses a number of other open-source components listed in Section 26 of the Terms of Service. Using them does not change any data practice described above — see the Terms for licensing details and the corresponding-source offer required by their licences.
If this Policy changes, the updated version will be posted at this same URL with a revised effective date. For material changes that meaningfully affect your rights, the Developer will provide additional notice — such as an in-app notice or a note in the release notes — before the change takes effect, and where a change requires your consent, that consent will be sought rather than assumed.
What changed on September 14, 2026. Cloud connections currently offered are Dropbox and Microsoft OneDrive. Google Drive is not available. The Help & Feedback page may collect messages through a Google Form hosted by Google.
What changed on September 11, 2026. This is a substantial revision, made because the App itself changed substantially. The previous version of this Policy stated that the App contained no advertising and no analytics, requested no camera permission, and operated entirely offline apart from cloud storage. That is no longer accurate, and this version replaces it. Newly disclosed here: advertising through Google AdMob and the associated consent mechanism (Section 5); Premium subscriptions through Google Play Billing (Section 6); the Camera permission and Document Scanner (Sections 4 and 11); network file-share connections (Section 8); the built-in Web, WebDAV and FTP servers (Section 9); and the optional online media features (Section 10). Also corrected: the list of supported cloud providers, which is Google Drive, Dropbox and OneDrive — an earlier version incorrectly listed Box and pCloud, which the App does not support — and the Trash retention period, which is user-selectable between 7 and 90 days and defaults to 30, rather than a fixed 7 days.
Questions, concerns or requests regarding this Privacy Policy, including any request to exercise a right under Section 18 or Section 19, can be sent to:
The Developer's name, registered address and contact email address are published on the App's Google Play listing, under "App support" / "Developer contact". Email sent to that address reaches the Developer directly and is the correct route for any privacy request, including one made under Section 18 or Section 19; you will receive a response within one month.
You may also raise non-confidential matters publicly via GitHub Issues. Please do not post personal information in a public issue.