Who we are
Max Server is developed by Balliram (“we”, “us”). This policy explains what the app does with information on your device. If you have questions, contact us at amarj234@gmail.com.
The short version
Max Server turns your phone into a small file server that you start and stop yourself. While it is running, a web browser on a computer connected to the same network can browse, upload, download, rename, move and delete files on your phone after entering a one-time PIN shown in the app. Everything stays between your phone and that browser. The app does not send your files or their contents to us or to anyone else.
The app is free and shows ads provided by Google AdMob. To deliver them, the Google Mobile Ads SDK in the app connects to Google’s servers and processes some device information, as described under Advertising below.
Information we collect
We (the developer) collect none. We do not operate any servers for this app and the app contains no analytics or crash-reporting software. We have no way to see your files or how you use the app. The only third party that receives data from the app is Google, for advertising, as described next.
Advertising (Google AdMob)
The Android app shows a banner ad and, occasionally, a full-screen ad after you stop the server. These ads are provided by Google AdMob. The Google Mobile Ads SDK may collect and process:
- your device’s advertising ID (and app set ID),
- IP address, from which an approximate location may be inferred,
- device and app information such as model, OS version, language and app version,
- ad interactions (views and taps) and diagnostic information about ad performance.
Google uses this information to deliver, measure and personalise ads and to prevent fraud. It is handled under Google’s own policies: How Google uses information from apps that use its services and the Google Privacy Policy. Your files are never shared with Google or used for advertising.
Your choices: where the law requires it (for example in the EEA, the UK and Switzerland) the app asks for your consent before personalised ads are shown, and you can change your choice any time from the app’s menu → Ad privacy options. On Android you can also reset or delete your advertising ID, or opt out of ad personalisation, in Settings → Privacy → Ads. Ads and the consent message start only after you accept this policy and the Terms of Use.
The browser dashboard does not use any ad network. It may show small “More apps” cards that are plain links to Google Play listings; they load nothing from third-party servers and do not track you.
Information the app uses on your device
To work, the app uses the following information locally on your phone. None of it is sent to us.
- Your files. With your permission, the app reads and writes files in your phone’s shared storage (for example Photos, Downloads and Documents), only to carry out the actions you take from your browser.
- Network details. The app reads your phone’s local Wi-Fi IP address so it can show you the address to open in your browser. It does not read your Wi-Fi network name or your location.
- Connection activity. While the server runs, the app shows a list of recent requests and events on screen, including the local IP address of the computer that connected and any failed PIN attempts. This list holds up to 500 entries, is kept only in memory, and is cleared when the app is closed. It is never saved or sent anywhere.
Information stored on your device
- Thumbnail cache. To show photo and video previews quickly, the app saves small preview images in its private cache folder (up to 200 MB; the oldest previews are removed automatically). You can delete them any time in Android Settings → Apps → Max Server → Storage → Clear cache. Uninstalling the app removes them.
- Your agreement. The app remembers which version of this policy and the Terms of Use you accepted.
- No backups. The app opts out of Android cloud backup, so none of its data is copied off your device.
- In your browser. After you enter the PIN, your browser keeps a temporary session cookie so you don’t need to retype it. Sessions end when the server stops. The dashboard may also remember your preferred view (list or grid), sort order and thumbnail size in your browser’s local storage.
How the connection works and stays protected
- The server runs only while you have it switched on. A notification is shown the whole time, with a Stop button.
- A new random 6-digit PIN is created every time you start the server. Browsers must enter it before they can see any files. After 5 wrong attempts from the same computer, further attempts are blocked for 60 seconds.
- Only devices that can reach your phone over the network you are connected to (such as your home Wi-Fi or your phone’s hotspot) can connect.
- Files that could run code in a browser (such as HTML or SVG files) are opened in a restricted sandbox so they cannot act on your behalf.
Permissions
| Permission | Why the app needs it |
|---|---|
All files accessMANAGE_EXTERNAL_STORAGEAndroid 10 and older: READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE |
To list, preview, upload, download, rename, move and delete files in your phone’s shared storage when you ask it to from your browser. This is the app’s core function: a file server cannot work with access to only a few folders. The app explains this before opening the system setting, and never reads or sends files on its own. |
Internet and network stateINTERNET, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE |
To run the local web server, to detect your Wi-Fi connection and local IP address, and to load ads from Google AdMob. |
Advertising IDcom.google.android.gms.permission.AD_ID |
Added by the Google Mobile Ads SDK so ads can be delivered and measured. You can reset or delete the advertising ID in Android Settings. |
Ad services (Privacy Sandbox)ACCESS_ADSERVICES_AD_ID, ACCESS_ADSERVICES_ATTRIBUTION, ACCESS_ADSERVICES_TOPICS |
Added by the Google Mobile Ads SDK to use Android’s privacy-preserving advertising APIs where available. You can manage them in Settings → Privacy → Ads. |
Foreground service and notificationsFOREGROUND_SERVICE, FOREGROUND_SERVICE_SPECIAL_USE, POST_NOTIFICATIONS |
To keep the server running while the app is in the background, and to show the ongoing notification that tells you it is running. |
Wake lockWAKE_LOCK |
To stop the phone’s Wi-Fi and processor from sleeping during transfers while the server is on. |
You can revoke these permissions at any time in Android Settings. The app will ask again before it needs them.
Sharing of information
We do not sell or share any information ourselves, because we do not collect any. The Google Mobile Ads SDK sends the data listed under Advertising to Google. Your files leave your phone only when you, or someone using a browser that has your PIN, download them.
Your choices
- Stop the server at any time from the app or its notification.
- Remove storage access in Android Settings → Apps → Max Server → Permissions.
- Change your ad consent from the app’s menu (⋮) → Ad privacy options, where offered.
- Reset or delete your advertising ID, or opt out of ad personalisation, in Android Settings → Privacy → Ads (or Settings → Google → Ads).
- Clear the thumbnail cache, or uninstall the app to remove all of its data from your phone.
Depending on where you live (for example under the GDPR or the CCPA/CPRA), you may have rights to access, correct or delete personal information, or to object to its processing. As we hold none, requests about advertising data are handled by Google; you can also contact us and we will help.
Children’s privacy
Max Server is a general-purpose file tool and is not directed at children under 13. We do not knowingly collect information from children, and the app’s ads are not intended for them.
Changes to this policy
If we change how the app handles information, we will update this page and change the effective date above. The app will also show you the new version and ask you to agree before you continue using it.
Contact
Questions or requests about this policy: Balliram · amarj234@gmail.com.