Privacy & purchases

Your files remain under your control

Fylo File Manager is a local-first Android utility published by Aeroloom. This notice explains what the app can access, what stays on your device, when information may reach another party, how consent works, how on-device AI is handled, and how Google Play purchases work.

No advertising SDK No Fylo account No Fylo cloud relay AI runs on your device

Effective and last updated: July 08, 2026.

The short version. Fylo does not operate an advertising profile, analytics pipeline, file-hosting service, or cloud account system. Browsing, previews, file operations, the Vault, search, tools, and every AI feature run on your Android device.

A file or related information leaves the device only when you direct Fylo to share it, connect to a service or computer you choose, use an Android or companion-app handoff, make a Google Play purchase, or rely on Android backup and device-transfer features. Each case is explained below.

1. Scope, publisher & definitions

Who this notice covers

This notice applies to the Fylo File Manager Android application and the Privacy & Purchases page bundled with it. “Fylo,” “the app,” “we,” and “us” refer to the app as published by Aeroloom. Any third-party service, operating-system component, website, server, device, or companion app follows its own terms and privacy notice.

No mandatory account

Fylo does not require a Fylo or Aeroloom account and does not maintain a remote profile that combines your file activity across devices. Google Play, Google Drive, a network server, or another app may require its own account when you choose that service.

What “local-first” means

Local-first means Fylo performs its work on the device and does not send file listings, file contents, search history, thumbnails, Vault contents, AI results, or tool output to a Fylo-operated server. It does not mean that Android backup, a service you connect, a recipient you select, or Google Play can never receive information.

Public or embedded copies

The copy embedded in the app contains no advertising script, analytics script, or cookie code. If the same policy is also hosted on a public website, that hosting provider may receive ordinary request data such as an IP address, browser type, and access time under its own policy.

2. Information Fylo processes on your device

Processing is not the same as collection by Aeroloom. Fylo must read some local information to display and manage it, but the app does not automatically transmit that information to us.

CategoryWhy it is usedNormal location
File contentPreview, edit, copy, move, rename, archive, extract, convert, play, share, scan, or otherwise complete the action you selected.The file’s existing location, a destination you choose, temporary working memory, or app-private storage for specific features.
File metadataShow names, paths, sizes, dates, MIME types, categories, media details, checksums, archive entries, and sort or search results.Read from Android storage and held in bounded local caches where needed.
PreferencesRemember theme, layout, navigation, viewer, performance, Home, and feature choices.App preferences on the device; eligible preferences may participate in Android backup.
Favorites, pins & recentsReturn to locations or files you chose and show recent activity.Local app storage. Removing an entry from these lists does not delete the underlying file.
Transfer stateShow progress, completion, failure, and notifications for operations you started.Memory and local operation state; Manage on PC session lists clear when that server stops.
Version snapshotsKeep a reversible copy before the built-in text editor overwrites a local file.App-private storage. History is bounded and older snapshots are pruned automatically.
Saved connectionsReconnect to SMB, FTP, WebDAV, Nextcloud, or compatible NAS locations you configured.App no-backup storage; passwords are encrypted with a device-bound Android Keystore key.
Purchase entitlementDetermine whether Google Play reports Fylo Pro as active, pending, canceled, refunded, or unavailable.Queried through Google Play Billing and cached locally; Fylo operates no payment database.
AI models & indexesSupport optional on-device AI features after you install them and grant the related consent.App-private or no-backup storage, never uploaded to Fylo.

3. What Fylo does not build or sell

No advertising profile

Fylo includes no advertising SDK and does not sell, rent, or trade file activity or personal information for targeted advertising. Your files are never used to choose ads.

No in-app analytics pipeline

Fylo does not embed a behavioral analytics tracker that uploads screen views, taps, file names, or usage events to Aeroloom. Android and Google Play may provide platform-level diagnostics according to your device and Play settings; that platform processing is separate from an in-app analytics SDK.

No remote file or AI index

Fylo does not create an Aeroloom-hosted copy of your storage tree, search index, Vault catalog, thumbnails, clipboard, file contents, AI prompts, embeddings, or generated output.

4. Android permissions & access

Photos, video, audio & selected media

Media permissions let Fylo list and manage supported photos, videos, and audio. On newer Android versions you can grant access to selected visual media only. On older versions Android uses a broader storage-read permission. Fylo works within the scope Android grants and cannot bypass a denied permission.

All files access is optional

All files access enables full file-manager behavior across shared storage where Android permits it. It is requested through Android system settings, is not required for every feature, and can be revoked there at any time. Revoking it may hide locations or block operations, but it never instructs Fylo to delete your files.

Notifications & foreground work

Notification and foreground-service access keep copy, move, extraction, transfer, and Manage on PC operations you started visible and reliable while the app is in the background. Denying them can limit background continuity. Fylo does not use notifications for advertising.

Biometric or device credential

Android’s biometric prompt can gate Vault and locked-file access. Android performs the match and Fylo receives only the allow-or-deny result. Fingerprint, face, and device-credential data are never received, stored, or uploaded by Fylo.

Internet & network state

Network access supports servers you configure, Google Play flows, Google Drive actions you start, local-network features, links you open, and optional AI model downloads you request. Network-state access lets Fylo explain connectivity and decide whether a local session can start.

Nearby Wi-Fi devices

Nearby transfer uses Wi-Fi Direct discovery and sockets after you start it. On older Android versions the platform may require location permission to discover nearby Wi-Fi peers even though Fylo does not use location for advertising or tracking. Newer versions use the nearby-devices permission with a never-for-location declaration.

Installed-app inventory

APK Extractor and the optional Manage on PC app catalog read installed package names, labels, versions, and APK locations for those tools only. This visibility is never used to build an advertising profile, and app management hands control to Android’s own settings or installer.

Package installation

When you choose to install an APK or XAPK, Fylo prepares the selected package and hands it to Android’s installer, which shows its own confirmation and applies its own security checks. Fylo cannot install a package silently.

Microphone for optional voice search

Microphone access is requested only when you start optional offline voice search, and only while that feature is installed and enabled. Audio is processed on the device for that query and is not uploaded or retained by Fylo as a recording.

Wallpaper, scanning & background-process requests

Set wallpaper is used only after the explicit image-viewer action. Document scanning uses the supported Android or Google scanner, which controls camera access and returns only the document you confirm. The RAM utility asks Android to trim background or cached processes, and Android decides what is allowed. None of these give Fylo access to another app’s private data.

6. On-device AI, consent & derived data

Every AI feature in Fylo runs on your device. AI features are part of Fylo Pro, are off until you turn the specific feature on, and stop working as soon as your Pro entitlement is no longer active. Nothing you feed to an AI feature is sent to Aeroloom, and no AI data is stored on a Fylo server.

AI is a Fylo Pro feature and is entitlement-checked continuously

AI plugins, semantic file search, natural-language search, offline voice search, local PDF chat, AI-assisted enhancement, and model-based cutout require an active Pro entitlement. Fylo re-checks entitlement with Google Play, so if a subscription is canceled, expires, is refunded, or is on hold, those features stop being usable immediately and their entry points disappear. Restoring or renewing Pro re-enables exactly the features you had chosen.

Nothing runs until you give the right consent

Having Pro does not switch AI on by itself. Each AI capability has its own explicit control, and separate decisions are required for downloading a model and for allowing your files to be indexed. Until the relevant control is on, Fylo does not scan your files, build an index, transcribe audio, or generate output.

  • Installing a model does not authorize file indexing.
  • Enabling one AI handler does not enable any other AI feature.
  • Turning a handler off stops future processing right away.
  • Turning something off never deletes your files.

Processing is local, and there is no online AI service

When you enable an AI feature, Fylo processes the inputs on the device: file names, limited folder context, bounded text extracted from supported documents, image pixels you selected, or microphone audio for a voice query. Inference runs locally using the installed model. Fylo does not call a remote AI API, does not use a cloud inference provider, and does not upload your inputs, embeddings, prompts, generated text, masks, or results.

No AI data is stored by Fylo, and none is used for training

Aeroloom keeps no copy of your AI inputs or outputs and does not use your files, prompts, or results to train, fine-tune, or evaluate any model. There is no Fylo-side prompt history, no server-side embedding store, and no AI account.

What is stored locally, and how to remove it

Local AI still uses local storage. Model weights, resumable partial downloads, embedding indexes, and cached recognition results may sit in Fylo’s private storage on your device. These stay on the device, are excluded from cloud backup and device transfer, and can be removed independently: deleting derived index data leaves your files and model in place, and deleting a model leaves your files in place. Clearing the app’s storage or uninstalling Fylo removes app-private AI data as well.

Model downloads happen only when you ask

AI models are not bundled in the app and are never downloaded silently. When you request installation, Fylo fetches the model files identified in the app from their public host. That host can see ordinary network metadata such as your IP address, the time of the request, and which file was requested. Fylo verifies the downloaded data against a pinned checksum before the feature becomes usable and stores it in app-private storage that is excluded from backup.

Device requirements and graceful fallback

Some models need a 64-bit ARM device with enough memory and free storage. If your device cannot run a model safely, or the model is not installed and verified, Fylo reports the feature as unavailable and uses its ordinary non-AI behavior instead. It does not fabricate a result or quietly substitute a different model.

Output limitations

AI output can be incomplete, inaccurate, or misleading. Enhancement cannot recover detail that is not in the source, segmentation can cut the wrong area, recognition can misread text, and generated answers can be wrong. Check results against the original file. AI output is not professional, legal, medical, financial, or safety advice.

7. Sharing, remote storage & device connections

Android Share and Open with

When you share a file or open it in another app, Fylo hands the selected recipient a content reference and the temporary access that handoff needs. The recipient may then copy, keep, upload, analyze, or redistribute the file under its own behavior and policy. Fylo cannot recall a copy the recipient already made.

Manage on PC is a direct local connection

Manage on PC starts a small web server on the phone after you press Start. A browser on the same network connects straight to the phone, and your files are not routed through an Aeroloom server. The connection is plain local HTTP rather than an encrypted tunnel, so use it on a network you trust and stop it when you are finished.

Session access key

The address Fylo shows contains a random key for that session only. Anyone who can reach your phone and has the full address can use whatever categories and actions you enabled, so avoid posting or forwarding the link. Stopping the server invalidates that key, and starting again creates a new one.

You choose what a session exposes

Separate switches control images, videos, audio, documents, other files, uploads, file management, the app list, and app management. App management can only open Android’s own management screen; it cannot uninstall anything silently. Session transfer names, direction, byte counts, and status are kept only for the running session and cleared when it stops.

SMB, FTP, WebDAV, Nextcloud & NAS

Fylo sends connection details, sign-in credentials, paths, listings, and requested file bytes directly to the server you configured. Saved passwords are encrypted with a device-bound key and stored outside cloud backup. Transport protection depends on the protocol and server: plain FTP and plain local HTTP are not encrypted, while HTTPS and secure server modes protect data in transit.

Google Drive

When you pick a Drive folder through Android’s system picker, Google and the account you select handle the authorization and file requests under Google’s terms. Fylo asks only for access to what you choose. Direct Drive connection inside Fylo is being improved and is temporarily unavailable; choosing a Drive folder through Android works in the meantime.

Nearby transfer

Nearby transfer finds and connects to another device over Wi-Fi Direct after you start it. The devices taking part can see connection details and the transferred content. Confirm the intended device before sending or accepting files.

Companion apps

An explicit handoff, such as playing a video in another installed player, passes only the file reference and the temporary access needed to open it. The other app then follows its own terms. Fylo does not grant a companion app access to your whole library.

8. Retention, backup & deletion

You control how long your files stay

Your files live in your storage for as long as you keep them. Fylo has no retention schedule for your content because it holds no server-side copy. Items you delete may pass through Recycle Bin so you can restore them; emptying it removes them from Fylo’s recovery path.

Backup and device transfer

Android may include eligible app data, such as ordinary preferences, in its own backup or device-transfer flow under your Google account settings. Sensitive items are deliberately excluded from that flow, including saved connection credentials, downloaded AI models, and derived AI indexes. You can turn Android backup off in system settings.

Vault

Moving an item to the Vault relocates it into Fylo’s private app storage so other apps and the media gallery no longer see it, and access is gated behind your device credential. This is app-sandbox isolation, not separate at-rest encryption of the file contents. Move Vault items back out before clearing app data or uninstalling, because removing the app removes its private storage.

Deleting Fylo’s own data

You can clear caches and derived data from inside the app, delete AI indexes or models separately, remove saved connections, clear version history by deleting the tracked files, or use Android’s Clear storage to reset the app. Uninstalling Fylo removes its app-private data from the device. Files you stored elsewhere on your own storage remain untouched by an uninstall.

9. Security practices & limits

What Fylo does

Credentials for saved connections are encrypted with a non-exportable device key. Downloaded model data is checksum-verified before use. Local previews of web documents run with scripting and network access switched off. Long operations are bounded, and archive extraction applies path and size safety checks before writing files.

What no app can promise

No software can guarantee absolute security. A compromised device, a modified build, a malicious network, a weak server configuration, or an untrusted recipient can expose data regardless of Fylo’s protections. Keep Android updated, install Fylo from an official channel, and be careful with links and sessions you share.

10. Fylo Pro purchases & subscriptions

Choose in Fylo, confirm in Google Play

Fylo Pro unlocks the app’s premium features, including its on-device AI features. Pro is offered as an auto-renewing subscription and, where available, as a one-time purchase.

Pricing is shown by Google Play, not by this page. Prices, taxes, available plans, promotional offers, and any free-trial or introductory terms differ by country and currency and can change over time. The current price and full terms for your account are always displayed in the app and on the Google Play checkout screen before you confirm anything.

Checkout stays with Google Play

Google Play processes the payment. Fylo never receives or stores your card number or other full payment credentials. Play shows the localized price, billing period, renewal behavior, and cancellation terms before purchase.

Renewal, cancellation & loss of access

A subscription renews automatically until you cancel it in Google Play. Canceling stops the next renewal and access normally continues to the end of the period you already paid for. When the entitlement ends, expires, is paused, or goes on hold, Fylo blocks Pro features, including AI features, on the next entitlement check. A one-time purchase does not renew.

Restore, pending payments & refunds

Fylo restores a recognized purchase from the Google account signed in on the device, so reinstalling or changing devices does not require buying again. A pending payment unlocks Pro only after Google Play reports it as purchased. Refunds, chargebacks, and plan changes are handled by Google Play and can end access.

What Fylo learns from a purchase

Fylo reads the entitlement state needed to unlock features and a purchase token used to verify and acknowledge the transaction. It does not receive your payment method, billing address, or Google account password, and it does not use purchase data for advertising.

11. Third parties

Contacted only for something you start

External parties are involved only when you use the related feature: Google Play for purchases, updates, and review prompts; Google services for Drive access or on-device scanning components; a server you configure; a public model host when you request a model download; and any app you hand a file to. Each applies its own privacy terms.

On-device libraries

Some features use on-device processing libraries for tasks such as text recognition in images, media playback, document parsing, and archive handling. These run locally as part of the app. Fylo does not add an advertising, attribution, or behavioral-analytics SDK.

No data brokers

Fylo does not share your files, file names, or usage with data brokers, advertising networks, or profiling services, and does not sell personal information.

12. Children’s privacy

General-purpose utility

Fylo is a general-purpose file manager and is not directed at children. It does not knowingly collect personal information from anyone, including children, and it has no account system, social feed, or messaging service. Because the app can browse whatever is on the device, a supervising adult should decide whether it is appropriate for a young user’s device.

13. Your choices and rights

Practical controls

Because your content stays on your device, you exercise most control directly:

  • Grant, narrow, or revoke each Android permission in system settings.
  • Turn any optional feature, including every AI feature, on or off in the app.
  • Delete AI indexes and downloaded models separately from your files.
  • Remove saved connections and stop local sessions at any time.
  • Move Vault items back to normal storage whenever you want.
  • Clear the app’s storage or uninstall Fylo to remove its app-private data.
  • Manage or cancel a subscription in Google Play.

Access, correction and erasure requests

Depending on where you live, you may have rights to access, correct, delete, or port personal data, or to object to certain processing. Since Aeroloom holds no server-side copy of your files or AI data, there is normally nothing on our side to export or erase, and the fastest route is the on-device controls above. Purchase records are held by Google Play under Google’s policy.

14. Changes to this notice

How updates are communicated

If this notice changes, the updated version ships inside the app and any published copy shows a new date at the top. Material changes to how information is handled will be described in the notice itself. Continuing to use Fylo after an update means the current notice applies.