Summary: nothing leaves your phone, and the operating system enforces it.
Flip Rescue does not declare the INTERNET permission. On Android, an app
without that permission cannot open network connections at all. This is not a
policy promise that could quietly change in an update to the same version -
it is a technical property of the installed APK that you can verify yourself
(App info → Permissions, or by inspecting the manifest).
| Permission | Used for | When |
|---|---|---|
| Display over other apps | Drawing the rescue interface on the cover screen | Whenever rescue standby runs |
| Accessibility service | Performing Back / Home / Recents / notification shade / lock screen when you tap those buttons | Only on your tap |
| Notification access | Showing your notifications inside the rescue notification center | While the screen is open |
| Post notifications | The persistent "rescue standby" notification | While standby runs |
| Read contacts | The Export contacts tool | Only during an export you start |
| Modify system settings | The brightness slider | Only when you move it |
Its configuration (accessibility_service_config.xml) sets
canRetrieveWindowContent="false" and requests no gesture capability. The
system therefore never delivers your screen content or input to this app.
Settings (pinned favorites, bubble position, layout inset, onboarding state) are stored locally in the app's private DataStore. Contact exports are written to your public Downloads folder at your explicit request and are managed by you.
None. There is no analytics SDK, no crash reporter, no advertising identifier use, and no server component.