🔒 Privacy Policy

Flutter Jetty Runner

Last Updated: September 20, 2026

✓ Local-First · No Tracking · No Advertising
🛡️

The Web Server Runs on Your Phone, Not in Our Cloud

Flutter Jetty Runner turns your Android phone into a small Java web server. It embeds the Jetty server and runs demo web applications that you download from a public catalog. Everything the server does happens on your device and on the local network you connect it to. ScienceSoft e.U. operates no account system, no telemetry endpoint and no cloud service for this app, and the app contains no analytics, tracking, advertising or crash-reporting framework.

What This Means for You

📱

Server on Your Device

Web applications run inside the app on your phone and answer only browsers that reach it on your local network

📵

No Developer Collection

No account, no usage statistics, no crash reports and no remote database operated by ScienceSoft e.U.

⬇️

Downloads Only on Request

Demo applications are fetched from a public GitHub repository when you choose them and stay on the device afterwards

🚫

No Analytics or Ads

No Firebase, Crashlytics, Sentry, Google Analytics, AdMob, advertising ID collection or advertising SDK

Scope of This Policy

This policy describes the Flutter Jetty Runner Android app, the web applications it serves on your device and its optional browser-based web admin. It distinguishes between data processed locally by the app, data exchanged with the public download catalog, and data that Google processes independently when you use Google Play services such as in-app purchases.

The demo web applications are sample programs (a Hello World servlet and several Vaadin demos). They keep their data in memory inside the app and forget it when they are stopped. If you upload and run your own web application through the web admin, that application's data handling is your responsibility.

How the App Works

Flutter Jetty Runner embeds Jetty 12 with Servlet 6.1. You choose a demo, the app downloads it once, and a tap on Start makes it reachable from a browser on the phone itself and from other devices on the same Wi-Fi or LAN.

  • Web Server screen: pick a demo, choose plain HTTP (port 8080) or HTTPS with a self-signed certificate (port 8443), start and stop the server, and copy the addresses shown
  • Background service: while a web application or the web admin runs, an Android foreground service with a persistent notification keeps the server alive until you stop it
  • Web admin (optional): a password-protected HTTPS page on port 9443 that lets you download catalog demos, upload your own Android-converted WAR files, and start, stop or delete them from a browser on another device
  • No cloud dependency: after a demo is downloaded, serving it needs no internet connection and no developer-operated server

Data Processed by Flutter Jetty Runner

Depending on the features you use, the app processes the following categories on your device:

  • Downloaded and uploaded web applications: WAR files from the public catalog and, if you use the web admin, WAR files you upload yourself. They are stored in the app's private storage, excluded from Android backups, together with a small index of the uploads.
  • Server and network information: the selected demo, the chosen protocol and ports, and the Wi-Fi or Ethernet addresses of your phone, which the app displays so you can open the page on another device. Only Wi-Fi and Ethernet addresses are shown; cellular and VPN addresses are not listed.
  • Web admin credentials: the password you set is stored only as a salted PBKDF2-HMAC-SHA256 hash. Login sessions are random tokens held in the app's memory, and recent failed login attempts are counted briefly in memory to slow down password guessing.
  • TLS identity: one self-signed certificate per installation, generated on the device. The private key is created in and never leaves the Android Keystore.
  • App settings: the light/dark appearance preference, the port configuration and the web admin switch state, stored in the app's private preferences.
  • Console output: what the running web application writes to its standard output, shown in the app and in the web admin and held only in memory.
  • Support purchase state: whether the optional one-time support purchase has been made, as reported by Google Play. The app keeps no local purchase record of its own and never sees your payment details.

Network Connections

Flutter Jetty Runner sends no data to ScienceSoft e.U. The following network activity occurs only to provide the features you choose to use:

  • Demo catalog and downloads: when you open the Web Server screen or select a demo, the app fetches the catalog file and the chosen WAR file over HTTPS from the public repository github.com/pezi/flutter_jettyrunner, served by GitHub. GitHub receives ordinary web request data such as your IP address and processes it under the GitHub Privacy Statement. Every download is verified against a SHA-256 checksum from the catalog.
  • Embedded web server: while a demo runs, the app accepts HTTP or HTTPS connections on all network interfaces of the phone. Any browser that can reach the phone on that network can open the demo. The demos require no login except the Vaadin Bookstore demo, whose fixed demo accounts are documented in the app.
  • Web admin: when enabled, the app accepts HTTPS connections on port 9443. After password authentication, a client can download demos, upload WAR files and start, stop or delete web applications. Requests that change anything are protected against cross-site requests.
  • Google Play: opening the Support screen, buying or restoring the optional support purchase communicates with Google Play Billing. Google processes the store account, transaction, device and payment information under its own terms and privacy policy.
  • User-opened external links: links on the About, Introduction, Support and Other Products screens open in your browser or email app only when you select them. The destination then receives ordinary web request data under its own privacy policy.

Security notice: HTTP traffic on port 8080 is not encrypted, and an uploaded WAR file is code that runs inside the app. Use Flutter Jetty Runner only on networks you trust, choose a strong web admin password, and stop the server or the web admin when you do not need them. This app is an Android experiment, not a hardened production server.

Storage, Retention, and Deletion

  • Web applications: downloaded demos stay on the device until you delete them in the web admin, until they disappear from the catalog, or until you uninstall the app. Uploaded WAR files stay until you delete them in the web admin or uninstall the app. Neither is included in Android backups.
  • Demo application data: the demos keep their contacts, books or button presses in memory only. Stopping the demo or the app discards them.
  • Preferences and password hash: stored in the app's private preferences until you change them, clear the app's data or uninstall the app, subject to Android's backup and restore behaviour.
  • Web admin sessions: the web admin sets one strictly scoped, HTTP-only, secure session cookie named __Host-jetty-admin. The matching token lives only in the app's memory, expires after 30 minutes without use, and is invalidated by logout, a password change or stopping the web admin. After five failed logins, logins are refused for 30 seconds, doubling up to 15 minutes.
  • Certificate and key: the self-signed certificate and its Keystore-backed private key are removed when you clear the app's data or uninstall the app.
  • Console output and network addresses: held in memory and discarded when the server stops or the app process ends.
  • Store records: Google may retain transaction records according to its own legal obligations and privacy policy. Removing local app data does not delete records maintained by Google Play.

Permissions

The app declares only the Android permissions needed for its features:

  • INTERNET: to download the catalog and demos and to accept browser connections to the embedded server
  • ACCESS_NETWORK_STATE: to list your Wi-Fi and Ethernet addresses and refresh them when the network changes
  • FOREGROUND_SERVICE and FOREGROUND_SERVICE_SPECIAL_USE: to keep the user-started web server running while you use other apps
  • POST_NOTIFICATIONS: to show the running-server notification with its Stop action
  • com.android.vending.BILLING: to offer and restore the optional one-time support purchase through Google Play
  • No location, camera, microphone, contacts, storage, Bluetooth or nearby-device permission is declared

In-App Purchase

Flutter Jetty Runner is free and fully functional without payment. The Support screen offers one optional one-time contribution through Google Play Billing; it unlocks nothing and is purely a way to support development. Google handles the payment transaction. The app only learns from Google Play whether the purchase exists in order to show a thank-you message and to offer a restore. For details about store processing, review the Google Privacy Policy.

Third-Party Services and SDKs

The app uses Google Play Billing for the optional purchase and downloads its demos from GitHub. It also uses open-source components that run within the app: the Eclipse Jetty server, Flutter packages for preferences, package and device information, checksums, opening links and rendering the Introduction page, and the Inter font. These components do not create a developer-operated cloud service.

Flutter Jetty Runner does not include Firebase, Sentry, Crashlytics, Google Analytics, Facebook SDK, AdMob, Branch, AppsFlyer, advertising ID collection, remote configuration, push notifications or any other tracking or advertising framework.

Data Controller

The provider responsible for Flutter Jetty Runner and for any personal data sent directly to us, such as a support email, is:

  • Company: ScienceSoft e.U.
  • Address: Oberzellergasse 12/13, 1030 Vienna, Austria
  • Commercial Register: FN 644834k
  • VAT ID: ATU60406778
  • Email: peter.sauer@flutterdev.app

ScienceSoft e.U. does not receive the web applications you run, their data, your web admin password or the traffic between your browsers and the phone. If you run your own web application through Flutter Jetty Runner for an organization, you or your organization are the controller for the data that application processes.

Legal Bases

To the extent ScienceSoft e.U. processes personal data in connection with Flutter Jetty Runner, we rely on Article 6(1)(b) GDPR where processing is necessary to respond to a request or provide a service you asked for, and Article 6(1)(f) GDPR for our legitimate interests in providing support, operating and securing this policy website, and protecting our legal rights. We do not use app data for advertising or profiling.

Data processed solely on your device or exchanged with browsers on your own network is not sent to us. GitHub and Google determine their own legal bases for the request and store data they process under their respective privacy policies.

This Policy Page and External Links

This page is part of the FlutterDev website. It uses first-party scripts for functions such as theme switching and does not use analytics, advertising trackers or third-party cookies. The hosting web server may process standard technical log data, such as IP address, browser type, requested page and access time, to deliver and secure the website.

Links to GitHub, Google, app stores or other external sites are governed by the privacy policies of those destinations. We do not control their data practices.

Children's Privacy

Flutter Jetty Runner is a developer utility and is not directed to children. We do not knowingly collect personal data from children through an account or developer server because the app has neither. This applies to children under 13 (COPPA, United States) and under 14 (Austrian data protection law under the GDPR).

Your Choices and Rights

  • Choose whether to download a demo, start the server, use HTTP or HTTPS, enable the web admin or make a support purchase
  • Delete downloaded demos and uploaded WAR files in the web admin, change the password and ports in Settings, stop the server or the web admin, clear the app's data or uninstall the app
  • Contact us to request access, correction, deletion, restriction, objection or portability for personal data that you have directly provided to ScienceSoft e.U., subject to applicable law and any required retention
  • Exercise store-related rights directly with Google for data controlled by Google Play

California notice: ScienceSoft e.U. does not sell or share Flutter Jetty Runner app data for cross-context behavioral advertising and does not use it for targeted advertising. You may contact us using the address below with any applicable privacy request.

Changes to This Privacy Policy

We may update this Privacy Policy when Flutter Jetty Runner's features, data practices or legal obligations change. The date at the top of this page identifies the latest version. Material changes apply prospectively from the updated date unless applicable law requires otherwise.

Contact Us

If you have questions about this Privacy Policy or want to exercise an applicable privacy right, please contact us:

Supervisory Authority

You have the right to lodge a complaint with a competent data protection authority. The Austrian supervisory authority is:

  • Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
  • Address: Barichgasse 40-42, 1030 Vienna, Austria
  • Email: dsb@dsb.gv.at
  • Website: www.dsb.gv.at
✅

Our Commitment

At ScienceSoft e.U., we build Flutter Jetty Runner so that the web server, its applications and their data stay on hardware and networks you control. The app has no tracking or advertising frameworks, needs no account or cloud, and gives you direct controls to stop the server and delete what it stores.