Your data stays
on your device.
Fuusio has no account and no analytics. Everything you create in Fuusio is stored only in the app's private storage on your device. We have no way to read it, and no Fuusio service holds a copy.
Four things leave your device, and only when you ask for them: the AI assistant, barcode lookup, a report you choose to send us, and the name you choose to publish on the Wall of Supporters. One thing leaves it without being asked: if the app crashes, a crash report is sent so the crash can be fixed. It contains no content of yours. All five are described below.
1. Who this is about
Fuusio is an Android app published by Marko Salmela, an individual developer based in Finland. Contact: fuusio.app@gmail.com.
This policy explains what happens to information when you use Fuusio. It applies to the app itself; the pages on fuusio.org are static and set no cookies.
2. What we collect
None of your content. Fuusio has no account system. We do not receive, store or have any means of obtaining your notes, records, folders, applets, files, settings, location or usage patterns.
Three things can reach us, and each is described in its own section below:
- a report you write and submit about something the assistant produced (section 6);
- the name, and optional message, you enter when you choose to appear on the Wall of Supporters (section 7);
- a crash report, sent automatically if the app crashes (section 8). It describes the crash and the device, not you.
The app contains no analytics SDK, no advertising SDK and no usage tracking. It does not record which features you use, how often you open it, or what you do in it.
3. Where your data is
| Data | Where it is kept | Leaves the device? |
|---|---|---|
| Notes, records, folders, item types | A private SQLite database in the app's storage | No |
| Applets, tools and their files | A sandboxed directory in the app's storage | No |
| Your AI provider API key | Encrypted with a key held in your device's hardware keystore | Only to that provider |
| App settings and preferences | Private app storage | No |
| Your location | Read on demand, used on the device, not stored | Never |
| Assistant conversations | On the device | To your AI provider |
| Reports you submit | Queued on the device until sent | To the developer |
| Scanned barcodes | Not stored unless you save the product | To Open Food Facts |
| Supporter name and message | Only on the Wall of Supporters, not on the device | Published, if you submit it |
| Crash reports | Not kept on the device | To Firebase Crashlytics, on a crash |
Because your data lives only on your device, uninstalling Fuusio, clearing its storage, or losing or resetting your device will delete it. Fuusio's export feature is the only way to make a copy. Keeping backups is up to you.
4. The AI assistant
It does nothing until you set it up
Fuusio ships with no AI credentials. The assistant will not run until you choose a provider in Settings and enter your own API key for it. If you never do that, no data of any kind is sent to any AI provider.
What is sent, once you have
During a conversation that you start, Fuusio sends your chosen provider:
- the text of your conversation with the assistant;
- anything you share into the assistant;
- the contents of any records or files the assistant reads in order to answer you.
The providers currently offered are Anthropic/Claude, Google Gemini AI, OpenAI and DeepSeek. The assistant has no ability to read your location, clipboard, contacts, calendar, photos or messages — those are not among the things it can reach, so they cannot be sent.
You are the provider's customer, not ours
Because you supply your own API key, you use that provider under your own agreement with them. Their terms and privacy policy govern what they do with what they receive — including whether they retain it and whether they use it to improve their models. We are not a party to that relationship. We have no access to your key or to anything you send, and we cannot inspect, retrieve, correct or delete it. Please read your provider's policy before sending anything confidential.
Removing the key in Settings stops all of it immediately.
5. Barcode lookup
When you scan a product barcode, Fuusio sends the barcode number and nothing else to Open Food Facts, a public food database, to look the product up. No device identifier, no location and no information about you accompanies it. The app identifies itself with its version number and a link to its public repository, as that project's usage guidelines ask.
6. Reporting AI-generated content
Every reply the assistant gives, and every applet, carries a Report action. Google Play requires it of apps that generate content with AI, and it is the one way something you have in Fuusio can reach us.
When you submit a report, it sends: the content you reported, the reason you chose, your note if you wrote one, and the app version. That is the whole list — no account, no location, no device identifier, and nothing else from the app. The report form says the same thing before you send it.
Reports are read by the developer and used to decide what the assistant should be allowed to produce. They are kept for as long as they are useful for that. Because a report is not tied to any account or identifier, we have no way to link one back to you or to find your other reports — which also means we cannot delete a specific report on request. If you would rather not send something, do not submit the form; nothing is sent until you do.
Reporting also acts on your device straight away: a reported reply is hidden, and a reported applet is flagged. That happens whether or not the report reaches us.
7. The Wall of Supporters
Fuusio is free. If you want to support its development, you can make a one-time donation through Google Play and, if you like, have a name of your choosing and an optional short message shown on the Wall of Supporters inside the app, where every Fuusio user can see them.
The payment itself is handled entirely by Google Play under Google's privacy policy. We never see your payment details, your Google account or your Play identity.
If you choose to appear on the wall, Fuusio sends the name you typed (up to 50 characters), your message if you wrote one (up to 200 characters), and the tier you donated at. That is the whole record. It is stored in Cloud Firestore, a database service operated by Google as part of Firebase, and displayed publicly in the app. Nothing links it to your device or to you unless you put your real name in it — you can enter any name you like, or donate without appearing on the wall at all.
To confirm that a request comes from a genuine copy of Fuusio, the app attaches a Play Integrity attestation obtained from Google Play services when it reads or writes the wall. That is a check on the app and the device, not on you, and it is described in Google's documentation.
Entries stay on the wall indefinitely. If you would like yours changed or removed, email fuusio.app@gmail.com with the name and the approximate date, and we will take it down. Because entries are not tied to any account, we rely on that description to find the right one.
8. Crash reports
If Fuusio crashes, it sends a report to Firebase Crashlytics, a crash reporting service operated by Google, so that the crash can be understood and fixed. The same channel also receives a small number of non-fatal error reports: places where the app recovered from a failure but recorded it as worth investigating.
A report contains: the technical description of the crash (the stack trace), the app version, the device model and Android version, the device's orientation, free memory and storage at the time, a timestamp, and the app's own recent internal log lines written when something went wrong. Crashlytics identifies the installation with a random identifier it generates itself; it is not your Google account, advertising ID or any hardware identifier, and it is reset when you reinstall the app.
Crash reports do not include your notes, records, applets, conversations, API keys or location. Fuusio does not attach your name, an email address or any account identifier to them, and there is none it could attach. Reports are retained by Crashlytics for 90 days. Google's handling of this data is described in Firebase's privacy documentation.
Crash reporting is enabled in release builds of Fuusio — the version distributed through Google Play — and cannot be switched off inside this version of the app. If that is not acceptable to you, please do not install the app.
9. Applets
Applets run inside a restricted view with network access blocked. An applet cannot make a request to the internet, so it cannot transmit anything anywhere.
An applet may ask, once and by name, for access to one type of your records or for your location. You answer that question yourself, and both capabilities are additionally governed by master switches in Settings that are off by default. Anything an applet is given stays on the device.
Applets share one storage area with each other, so an applet can read what another applet has saved. Please treat applets you did not write with the same care you would any other software: do not put anything private into one you do not trust.
10. Permissions
- Location — optional. Used to show your position on the Today card and to supply it to an applet you have granted it to. Never transmitted.
- Internet — used only for the purposes in sections 4 to 8: the AI provider you configure, Open Food Facts, reports you send, the Wall of Supporters, and crash reports.
- Vibration — used for haptic feedback.
- Camera — not requested. Barcode scanning is performed by Google Play services in its own process; only the decoded number is returned to Fuusio.
11. Children
Fuusio is not directed at children and we do not knowingly collect personal information from anyone under 16. The only place a person can send us something identifying is the Wall of Supporters, which requires a purchase through Google Play; if you believe a child has posted there, email us and we will remove the entry. If you set up an AI provider, please note that most providers set their own minimum age in their terms.
12. Your rights
Under the GDPR you have rights of access, rectification, erasure, restriction, portability and objection. In Fuusio's case those rights are mostly exercised directly on your device, because that is where the data is:
- Access and portability — everything is visible in the app, and the export feature produces a copy you can take elsewhere.
- Erasure — delete items in the app, clear the app's storage, or uninstall. We hold nothing to erase.
- Data sent to an AI provider — we cannot retrieve or delete this, because we never had it. Contact the provider directly; their policy will say how.
- Your Wall of Supporters entry — email us and we will remove or change it (section 7).
- Crash reports — these carry no identifier we could match to you, so we cannot locate or delete a specific person's reports. They expire after 90 days.
You can also complain to your national supervisory authority. In Finland that is the Office of the Data Protection Ombudsman (tietosuoja.fi).
13. Security
Fuusio keeps your data in app-private storage, which Android isolates from other applications, and encrypts your API keys with a key held in your device's hardware-backed keystore. All traffic — to AI providers, Open Food Facts, the report endpoint and Firebase — uses HTTPS, and the Wall of Supporters accepts writes only from copies of the app that pass Google's Play Integrity check.
No security measure is absolute. Data on a device that is lost, stolen, shared, unlocked or rooted, or that is affected by other software on it, is outside what any app can protect. Please use a screen lock.
14. Changes
If this policy changes in a way that affects what leaves your device, we will say so in the app's release notes and update the date at the top of this page. Continuing to use Fuusio after a change means you accept the updated policy.
15. Contact
Questions about this policy, or about anything above: fuusio.app@gmail.com.