F-Droid and what it means to own your data

Owning your data is not a setting you switch on. It starts with where the app came from, what it stores, and whether it needs an account at all.

6 min read

“You own your data” is printed on a lot of privacy pages. Read the next paragraph and it usually turns out the data lives on a server somewhere, tied to an account, and you own it the way you own a parking space you rent.

Real ownership is simpler and much more boring. The data sits on your device. No account. Nothing to sync. If the company disappears tomorrow, your years of habits, notes or game progress are still there, because they were never anywhere else.

Getting that right takes more than good intentions in the app. It also depends on how the app reached your phone.

The store is part of the product

Most people think of an app store as a shelf. You pick something up, you walk out. But the shelf watches you.

An app store knows which apps you searched for, which ones you installed, when you opened them, which device you used, and which account you were signed into while doing it. That profile exists whether the app you installed collects anything or not. You can write the cleanest app in the world, with no analytics, no ads and no network calls, and the install itself still produces a record on somebody else’s server.

So an app that promises local-only data, delivered through a channel that logs the transaction, is telling half the truth. The half it tells is real. The other half is outside its control.

That gap is the reason alternative stores exist.

What F-Droid actually is

F-Droid is not a company store with a different logo. It is a client app plus a list of repositories. The client is the part you install. A repository is just a place that publishes apps, and you choose which ones to trust.

Two things follow from that design, and both matter.

You decide who you trust, one source at a time. Adding a repository is a deliberate act. Nothing arrives from a source you did not add. Compare that to a single store where trust is all or nothing and granted once, years ago, when you first set up the phone.

No account is involved. You do not sign in to browse or install. There is no profile accumulating your installs, because there is nobody to hold one. Updates work the normal way, with a notification when a new version is published.

The tradeoff is honest and worth stating. You are not removing trust from the system, you are moving it. Instead of trusting one large company, you trust whoever publishes the repository you added. That is better only if you actually think about who you are adding. A repository from a stranger deserves the same suspicion as an APK from a forum post.

What the client does give you is consistency. It checks that updates come from the same publisher as the version you already have, so an app cannot quietly change hands behind your back.

Owning data is a design decision, not a feature

The store solves distribution. It does not make an app respect you. That part has to be built in, and it usually comes down to three questions.

Does the app need an account? Most apps that ask for one do not need one. A habit tracker, a calculator, a puzzle game, a typing trainer: none of these require knowing who you are. An account exists to link your activity across devices and sessions, which is useful for sync and also useful for profiling. When we skip the account, sync goes away. That is a real loss, and for this class of app it is a fair price.

Where does the data live? On the device, in a local database, readable by the app and nothing else. Not mirrored to a backend “for your convenience.” Our habit tracker keeps its entries in a local store and checks your unlock status offline, which is why it works the same on a plane as it does at home.

What is in the build? This is the part users cannot see and mostly have to take on faith, which is why it should be stated plainly. Our shipped apps carry no analytics library, no advertising SDK and no crash reporter that phones home. The dependency list of a small game like ours is the game engine, a sound library, local preferences and a link opener. Nothing in there is watching you play.

None of this is clever engineering. It is mostly restraint: not adding the thing that everyone else adds by default.

Why we published our own repository

We now run our own F-Droid repository at fdroid.oxisoft.io. You add the address once in the F-Droid client and our apps show up with normal update notifications.

The apps there are the same builds we publish everywhere else, so nothing is locked to one channel. Install from our repository today, move to the other store next year, keep your data either way. Switching stores should never cost you your history.

For now it is a small shelf. One game is published, and more will follow as each one is ready. We would rather list a short honest catalogue than pad it.

The reason to bother is the same reason we do not add trackers. If we tell people their data stays on their device, they should also have a way to install the app without announcing it to a third party. Otherwise the promise has a hole in it that we were pretending not to see.

The part nobody can automate

You still have to read. Whether an app is on a big store, a small one or ours, the questions do not change: does it ask for an account it does not need, what does it want permission to touch, and what happens to your data when you stop using it.

A privacy-friendly store makes those questions easier to answer. It does not answer them for you.

If you are running a phone without Google services, you already know most of this, probably from a week of things quietly breaking. For everyone else, the useful idea is smaller than a full migration. You do not have to leave anything. You can add one more source, install one app from it, and see how it feels to install something without being counted.

Our apps are built to survive that test: no account, no tracking, and your data staying exactly where you put it.

Share