Skip to content
WaftDrop

WaftDrop

Privacy Policy

Effective 5 August 2026 · Last updated 5 August 2026

WaftDrop does not collect your data. There is no WaftDrop account, no WaftDrop server, and no analytics or advertising of any kind. Files you share travel directly from your device to the receiving device over your local Wi-Fi or a direct Wi-Fi connection — they are never uploaded to us or to anyone else.

1.Who we are

WaftDrop is published by Polystellar Labs. If you have a question about this policy or about privacy in the app, write to support@polystellarlabs.com.

2.How WaftDrop works

WaftDrop shares files between nearby Android devices. One device (the sender) selects files and starts a “drop”, which makes those files available to nearby devices for a limited time. Other devices (receivers) see the drop, enter a 6-digit code, and download the files.

Depending on your situation, WaftDrop uses one of two methods, and both are entirely local:

  • Shared Wi-Fi. If both devices are on the same network, the sender announces the drop on that network and the receiver downloads over it.
  • Direct connection. If there is no shared network, the sender creates a temporary Wi-Fi Direct group and announces it over Bluetooth Low Energy. The receiver joins that temporary connection to download.

In neither case does file content pass through the internet or through any server we operate. We operate no servers for WaftDrop at all.

3.What we do not do

  • We do not collect, transmit, sell, or share your personal information.
  • There are no user accounts and no sign-in.
  • There is no analytics, telemetry, crash reporting, or usage tracking.
  • There is no advertising, and the app does not request or use an advertising ID.
  • We never see the files you send or receive, or their names, or who you send them to.
  • We do not collect, derive, or store your location. See section 6.

4.Information stored on your device

WaftDrop stores a small amount of information locally on your phone. This stays on your device and is never sent to us.

Your display name

When you first open WaftDrop you choose a short display name (or accept the suggested one). It is stored in the app’s private settings and is shown to nearby devices so people can tell which drop is yours. You can change it at any time in Settings. Choose a name you’re comfortable showing to people nearby — it does not need to be your real name.

Your history of received drops

When you download files, WaftDrop records a receipt in the History tab: the sender’s display name, the file names, sizes and types, whether each file succeeded or failed, the time, and a link to where the file was saved on your device.

These are receipts, not copies. WaftDrop does not keep a second copy of your files, and deleting a file from your phone simply makes its History row stop opening anything. You can delete individual entries in the app, and uninstalling WaftDrop removes the history entirely.

Files you select

When you choose files to share, WaftDrop reads them from your device in order to send them to receivers. It does not copy, index, or catalogue your library, and it does not retain anything about files after a drop ends.

Android backups

Android may include app data in your device backup. WaftDrop excludes the received drop history from backup and device transfer, because those records point at files on the original device and would be meaningless elsewhere. Your display name may be restored so you don’t have to set it up again. Backups are handled by Android and Google, not by us, under Google’s own privacy policy.

5.Information visible to other devices

This is the part worth understanding, because it is the only information WaftDrop deliberately makes visible to anyone.

While you are broadcasting a drop

Any nearby device running WaftDrop can see, without entering your code:

  • your display name;
  • the number of files and their total size;
  • whether the drop has an expiry time.

File names and file contents are not visible until someone enters your 6-digit code. Only the person you give the code to can download.

Network addresses during a transfer

While a drop is live, your device acts as a small local file server. It sees the local network address (IP address) of each device that connects, and uses it only to enforce the drop’s own rules — counting how many distinct devices have joined against your receiver limit, slowing down repeated wrong-code attempts, and tying an access token to the device it was issued to.

These addresses are held in memory for the life of the drop only. They are never written to storage, never sent anywhere, and are discarded when the drop stops.

6.Permissions, and why each one exists

Android asks for these permissions on WaftDrop’s behalf. Every one of them is used only for the purpose described here.

Photos and videos

To show your photos and videos so you can pick which ones to share, and to read the ones you pick in order to send them. Nothing is uploaded or scanned.

Files and storage

To save files you receive, and on older Android versions to read files you choose to send.

Wi-Fi and network

To find drops on your local network, to create the temporary direct connection, and to transfer files. No internet connection is used or required.

Bluetooth

To announce and discover nearby drops when there is no shared Wi-Fi network. Bluetooth is not used to transfer file content.

Nearby devices

To create and join the temporary direct Wi-Fi connection on newer Android versions.

Location

See the explanation immediately below — WaftDrop never uses this to determine where you are.

Notifications

To show an ongoing notification while a drop is live, so you can see it is running and stop it at any time.

About the location permission

WaftDrop never requests, collects, derives, stores, or shares your location. It does not use GPS and does not contain any code that determines where you are.

Android itself requires apps to hold a location permission before they are allowed to scan for Bluetooth devices (on Android 11 and earlier) or to use Wi-Fi Direct (on Android 12 and earlier), because those features can in principle be misused to infer position. WaftDrop requests the permission solely to satisfy that system requirement so nearby-device discovery works on those Android versions. Where Android allows it, the app explicitly declares that its Bluetooth and Wi-Fi scanning is neverForLocation. WaftDrop never asks for background location.

7.Security, stated plainly

Access to a drop is protected by:

  • a 6-digit code that you choose to share with the people you want;
  • short-lived access tokens issued only after the correct code is entered, and tied to the device that entered it;
  • a lockout after repeated wrong codes from the same device;
  • an expiry time and a receiver limit that you set, after which the drop stops.

You should also know this: transfers are not encrypted. WaftDrop sends files over a plain local connection rather than an encrypted one. The connection never leaves your local network, and access requires your code, but someone who is already on the same network and monitoring it could in principle observe traffic. We would rather say this clearly than imply protection that isn’t there.

Practical advice: prefer the direct connection mode, or a network you trust, when sharing something sensitive. Share your 6-digit code only with the people you intend to receive the files, and stop the drop when you’re finished.

8.Third parties

WaftDrop has no third-party analytics, advertising, or tracking libraries. Two third-party relationships are worth naming for completeness:

  • Google Play Services. The app includes Google’s location-settings component for one purpose only: to show Android’s standard “turn on Location” prompt when a required system setting is switched off. WaftDrop sends no information to Google through it.
  • Google Play. If you installed WaftDrop from the Play Store, Google handles the installation and any crash information Android reports at the system level, under Google’s privacy policy. We do not receive personal information from Google about you.

9.Data retention and deletion

Because we never receive your data, there is nothing on our side to retain or delete, and no deletion request to make. Everything WaftDrop stores is on your device and under your control:

  • Delete individual History entries from within the app.
  • Change your display name at any time in Settings.
  • Clear the app’s data, or uninstall WaftDrop, to remove everything it has stored.

Files you have already received are saved to your device’s normal photo, video and download locations. They belong to you and remain there after uninstalling; delete them as you would any other file.

10.Children

WaftDrop is not directed at children under 13, and we do not knowingly collect information from anyone — children included — because the app collects no personal information at all.

11.Changes to this policy

If WaftDrop’s behaviour changes in a way that affects this policy, we will update this page and change the “Last updated” date above. Significant changes will also be noted in the app’s release notes. Continuing to use WaftDrop after an update means you accept the revised policy.

12.Contact

Questions, corrections, or concerns about this policy are welcome at support@polystellarlabs.com.

WaftDrop · Polystellar Labs · Last updated 5 August 2026

← Back to WaftDrop