Earshot Privacy does not collect anything about you.
There is no account, no sign-up, and no server. Everything the app records stays in its own private storage on your phone. We cannot see it, we do not receive it, and there is nothing for us to sell, share, or lose in a breach — because we never have it.
You can verify most of this yourself without trusting us. Open Settings → Apps → Earshot Privacy → Permissions: there is no microphone permission, because the app never asks for one and never will. You will see a camera permission, and it is used for one thing — the lens scan, which only runs when you tap to start it. You can turn it off and everything else still works. The app is also excluded from Google's cloud backup, so its history is not copied off the device.
Earshot Privacy keeps a record of when your microphone and camera were used. Each entry contains:
| Stored | Example |
|---|---|
| When it started and ended | 3:04 a.m., lasted 6 seconds |
| Which sensor | Microphone or camera |
| The kind of audio source Android reported | MIC, VOICE_CALL |
| Whether the screen was on, and whether the phone was locked | screen off, locked |
| Whether it carried on after you put the phone down | yes / no |
| Whether it was your own face unlock | yes / no |
| The time zone your phone was in at the time | America/Vancouver |
This never leaves your device.
When you accept the page that sets out what the app cannot do, your phone records the date and time, which version of that page it was, which build of the app you were using, and a SHA-256 fingerprint of the exact words.
It stores the fingerprint rather than the words so the record can say what was agreed without saying anything about you. There is no name in it, no identifier, and no address — it would be equally true of anybody who accepted the same page on the same day.
It exists because the app has no server, so there is nowhere else a record of your agreement could live, and because the alternative to a record is an argument. You can read it yourself under Alerts → Your record of acceptance, and send yourself a copy. We never receive it.
Nothing here happens unless you tap Save this room. Scans you do not save are still shown on screen and then forgotten, exactly as before.
When you do save a place, Earshot stores three things:
192.168.1.1 and 192.168.1.0/24.No device names. No IP addresses. No MAC addresses. No manufacturer names. Not the wifi network's name. And no location — Earshot holds no location permission and does not ask for one. It recognises a place by the devices in it, not by where your phone is. The app never learns that you were in a particular city, building or street; it knows only that this looks like the room you once called "Airbnb — Lisbon".
They are scrambled together with a random value created on your phone the first time you save a room. That value never leaves the device. So the same device produces a different fingerprint on every copy of Earshot in the world, and a stored row cannot be looked up against any list — not by us, not by anyone who obtained the file, and not by another copy of this app.
Everything else in this policy concerns your handset: when its microphone was used, when its camera was used. A saved room is a record of other people's devices — your host's television, your neighbour's printer.
We thought carefully about whether to build it at all, and the shape above is the result: the least information that still answers the question "has anything appeared here since I last looked?" We do not think a product arguing for restraint should keep a readable list of the people around you.
Delete any saved place, or all of them, at any time and at no cost. Deleting removes its fingerprints with it. Places you have not returned to for twelve months are deleted automatically, without you asking.
As with everything else in Earshot, none of this is sent anywhere. There is no server.
Nothing to us, and nothing to anyone else.
The app declares internet and Wi-Fi permissions for one purpose: the Wi-Fi camera sweep, which you start by pressing a button. That sweep talks only to devices on the local network you are already connected to — the router and the things plugged into it — to ask what they are. It contacts no server of ours, because we do not run one.
Because the app can technically reach the network, we cannot claim it is incapable of phoning home. We can tell you plainly that it does not, and that there is no analytics library, no crash reporting service, no advertising SDK, and no remote configuration anywhere in it. The app's entire dependency list is Google's own AndroidX and Jetpack Compose libraries and the Room database.
| Permission | Why |
|---|---|
| Foreground service (special use) | To keep watching while your phone is idle. This is why the app shows a permanent notification — Android requires it, and an app that watches quietly from behind a hidden notification is exactly what this app exists to catch. |
| Post notifications | To alert you when something starts recording while you are not using the phone. |
| Run at startup | To resume watching after a reboot, so your history has no gaps. |
| Nearby devices (Bluetooth scan) | For the Bluetooth sweep. Marked neverForLocation, which tells Android we are not permitted to use it to work out where you are — and we do not. The app listens for broadcasts; it never connects to any device. |
| Internet, network state, Wi-Fi state, multicast | For the local Wi-Fi sweep described above. |
| Camera | For the lens scan, and nothing else. It opens when you tap to start a scan and closes when you leave that screen. It is never opened in the background, never when your phone starts up, and never by the service that watches your sensors. Nothing it sees is kept: the picture is examined as it arrives and then discarded, no photo or video is ever saved to your phone, and your room report describes what was found in words rather than pictures. |
Not requested, ever: microphone, precise location, approximate location, contacts, storage, phone, SMS.
And no longer requested: the list of your installed apps. Until 11 August 2026
Earshot held Android’s QUERY_ALL_PACKAGES permission, which let it read every app on your
phone in order to show you which ones could use your microphone, camera or location. That is gone.
The Apps tab now points you at your phone’s own permission manager instead, which has the same
information and does not require an app to enumerate everything you have installed.
It was dropped on purpose rather than because anybody made us: a privacy app holding the right to read your entire app list is a trade we would rather not make, and it is one fewer thing you have to take our word about. You can confirm it in Android’s settings — Earshot’s permission list is short and getting shorter.
An earlier version of this policy said Earshot Privacy never asks for camera access. That changed on 6 August 2026, before the app was released, and we would rather tell you about it than quietly reword the page.
The lens scan looks for the reflection a hidden lens gives back when light hits it, and for the infrared light night-vision cameras give off in the dark. Neither can be done without letting the app see what the camera sees. We could not build the feature and keep the old sentence, so we chose to build it and describe the limits precisely rather than leave them vague.
We think you should know what that costs you. Before, you could open your phone's permission list and prove we had no camera access — you did not have to trust us. Now you have our word, plus one thing you can still check for yourself: when Earshot Privacy uses the camera, it records that in your own history, next to every other app. If it ever used your camera when you had not asked it to, the app would tell on itself.
On the History screen, choose Delete all history. It is immediate and permanent.
Uninstalling the app also destroys all of it. Because the app is excluded from cloud backup, there is no copy anywhere else to clean up. We cannot delete your data for you, because we never receive it.
Earshot Privacy is not directed at children and does not knowingly collect anything from anyone, of any age.
If this policy changes in a way that affects what the app does with your information, the updated version will be published here with a new date, and the change will be described in the app's release notes rather than made quietly.