Filova › Privacy
Filova privacy policy
Last updated: September 24, 2026
Filova is an FTP, FTPS and SFTP client for Android, published by WaTiFy. This page explains what data the app handles and what it does with it.
In short
- Filova collects no personal data. The developer receives nothing from your phone.
- No account, no advertising, no analytics, no crash reports sent.
- The app only connects to the servers you configure yourself.
Data stored on your phone
To work, Filova stores only on your device:
- your server profiles (name, address, port, user name, start folder, options);
- the passwords, SSH private keys and passphrases you choose to save, encrypted with AES-GCM using a key held by the device's Android Keystore;
- the fingerprints of servers you approved, your favorite folders, your syncs, the transfer history and your settings.
This data is never sent to the developer. The database holding your credentials is excluded from Android backup and from device-to-device transfer. Only your settings (theme, transfer options, app lock) may be included in your Google account's Android backup, if you enabled it. Uninstalling Filova deletes all of this data.
The connection log, available in the settings, stays in memory and is cleared when the app closes. Passwords never appear in it.
Network connections
Filova only connects to the servers you configured, to browse, upload or download your files. These exchanges go directly between your phone and your server, with no intermediary. SFTP and FTPS encrypt the connection; plain FTP does not, including the password: prefer SFTP or FTPS whenever your server supports them.
Access to your files
Filova does not request access to all files on the phone. It only reads and writes the files and folders you pick yourself in Android's file picker. You can remove a folder at any time.
Your servers may appear in the Files app and in Android's "Open" and "Save" dialogs. Another app only gets access when you pick a file there yourself.
Profile export
If you export your profiles, Filova creates an encrypted file (AES-256-GCM, key derived from the passphrase you choose) at the location you pick. This file only leaves your device if you move it yourself.
Permissions
- Internet and network state: connect to your servers, wait for a network or for Wi-Fi if you require it.
- Local network: reach a server on your home network (NAS, computer).
- Notifications: show transfer progress and report a failed sync.
- Foreground service, user-initiated transfer jobs: keep your transfers running while the app is in the background.
- Boot completed, wake lock: run your scheduled syncs, including after a restart.
- Biometrics: lock the app if you enable that option. Recognition is done by Android; Filova receives no biometric data.
Children
Filova is not directed at children and does not knowingly collect any data about them.
Changes
If this policy changes, the new version will be published at this address with its update date.
Contact
For any question: dev@watify.fr