Read-only by design
Filearium Privacy Policy
Filearium reads only the folders you choose and does not upload them to a Filearium-operated cloud service.
Android folder access uses the system Storage Access Framework.
The reviewed build requests read access, not write access.
Filearium Link connects directly to folders approved on your computer.
Scope
What this policy covers
This policy covers the Filearium Android XR application and the optional Filearium Link companion for Windows. It describes the behavior verified in the reviewed application source and build configuration as of August 29, 2026.
The reviewed build does not create a Filearium account and does not include an application-level advertising, analytics, or crash-reporting integration. Google-provided runtime components may process their own operational data as described in the Google SDK section below.
On-device folders
Only folders you select
Filearium opens Android's system folder picker using the Storage Access Framework. You decide which folder to make available. Filearium requests and persists a read-onlygrant for that folder; it does not request a write grant or broad "all files" access.
Within a selected folder, Filearium reads directory and file metadata such as names, types, sizes, and modification times. It reads file byte ranges when needed to create previews or play supported media. The reviewed file-source interface does not provide operations to edit, rename, copy, move, or delete your files.
Network behavior
Filearium Link stays between your devices
Filearium Link is optional. When you use it, the Android app can discover a nearby Filearium Link companion or connect from a pairing code. The Android build declares internet, network-state, Wi-Fi, multicast, and local-network permissions for this nearby connection.
A folder on your computer is available only after it is approved in the Windows companion for a paired device. Directory metadata and requested file content then travel directly between the companion and Filearium over HTTPS. The connection uses a pinned certificate and a paired-device credential.
The reviewed implementation does not upload user files to a Filearium-operated cloud service. It contains no Filearium cloud endpoint or server-side account service. The companion serves approved folders from your computer to your paired Filearium device.
Stored data
What Filearium retains locally
On the Android device
- The content URI for each selected folder, stored in private app preferences, together with Android's persisted read grant.
- A randomly generated Filearium Link device ID and, after pairing, the computer's name, endpoints, certificate pin, and encrypted credential.
- Session directory metadata, preview bytes, and temporary app-private cache files used to render or play selected content.
On the Windows computer
- Local companion configuration, certificate material, paired-device identity and timestamps, credential hashes, approved folder paths, and opaque node mappings.
- This state is encrypted for the current Windows user. The approved files remain in their original folders; Filearium Link does not copy them into its state database.
Android backup is disabled for the reviewed app. Filearium does not operate a remote account database for this local state.
Google SDKs
QR scanning and ARCore
Google Code Scanner and ML Kit
Filearium uses Google Code Scanner, delivered through Google Play services, to read Filearium Link pairing QR codes. Filearium's manifest does not request camera permission for this feature. Google states that QR image processing occurs on the device, only the scan result is returned to Filearium, and Google does not store the QR image or result. Filearium receives the decoded pairing payload and keeps it in process until it is delivered to the pairing flow.
The scanner module may be downloaded or updated by Google Play services. Google's ML Kit notice also states that its APIs may contact Google for bug fixes, model or compatibility updates, and may send API performance and utilization metrics. See the ML Kit terms and privacy information and the Google Code Scanner documentation.
Google Play Services for AR (ARCore)
This application runs on Google Play Services for AR (ARCore), which is provided by Google and governed by the Google Privacy Policy.
The reviewed Filearium source uses ARCore and Android XR tracking or device-pose state to place and move the spatial workspace. It does not use ARCore Cloud Anchors or the ARCore Geospatial API. Google describes ARCore system-service processing, including camera, precise-location, and usage data where applicable, in How Google Play Services for AR handles your data. ARCore functionality is also subject to the Google Terms of Service.
Security and retention
App-private and bounded by purpose
Filearium Link credentials are encrypted with an Android Keystore key. The Android trust file is placed in no-backup storage. Windows companion state is protected with Windows Data Protection for the current user, and companion credentials are stored as hashes. Link traffic uses HTTPS, certificate pinning, authorization checks, path-containment checks, and request limits.
Selected-folder grants and pairing trust persist so Filearium can reconnect until access is revoked or the relevant local app data is removed. Preview content is held in a bounded, session-only memory cache. Temporary media files are created in Android's private cache and are deleted as previews are released; operating-system cache cleanup timing can vary.
No technical system can guarantee absolute security. Filearium limits the reviewed build to read operations and stores connection secrets using the platform protections described above.
Your choices
Grant, deny, or revoke access
- You can cancel the Android folder picker without granting access.
- You can revoke Filearium's Android access through system app settings or by uninstalling the app.
- You can deny local-network access; nearby automatic discovery will not run.
- In Filearium Link for Windows, Remove access revokes an approved folder and Revoke device removes the paired device and its folder authorizations.
- Removing app data or uninstalling Filearium removes its Android-local preferences and trust state.
Contact
Questions or policy changes
For privacy questions, contact hello@filearium.com.
If Filearium's data handling changes, this page will be updated with a new revision date.