Privacy Policy

Last Updated: September 2026

This Privacy Policy explains how Caffeinated Math, a subsidiary of HJJB, LLC (“we,” “us,” or “our”), handles information when you use webRoid (“the App”).

1. Our Privacy Commitment

R runs on your device. Your code, your data, your variables and your plots stay there. We operate no server for the App, you do not have an account with us, and the App sends us nothing on its own.

Three things reach the network because you asked them to: browsing or installing R packages, exporting a script as a GitHub gist, and sending us feedback. R code that you write can also reach the internet by itself. Section 3 covers all four.

2. What We Do Not Collect

We do not collect:

  • Your R code or scripts
  • Your data files or computation results
  • Your plots or visualizations
  • Your variable names or values
  • The contents of your files
  • Your device identifiers, advertising ID, or location
  • Usage analytics of any kind

The App contains no analytics, telemetry, or crash-reporting library, and it does not report crashes to us automatically. If the App crashes, we hear about it only if you tell us. It does keep a short log of why its recent sessions ended, on your device, which reaches us only if you attach it to feedback (see Send Feedback, below). The App requests two Android permissions: internet access, and vibration for haptic feedback.

3. What Leaves Your Device, and When

Installing R packages

When you install a package, your device downloads it from repo.r-wasm.org, the webR package repository. Opening Packages > Browse, and picking a package there, downloads the repository’s public list of packages from the same place. Those connections are between your device and the repository. We do not run it, intermediate it, or see it.

GitHub Gist export

The editor can publish the file you are editing as a GitHub gist. This happens only when you open Export to Gist and tap Create Gist, and only for that one file.

When you do:

  • The contents of that file are sent over HTTPS to api.github.com. They are not sent to us, and we never see them.
  • Your personal access token, which GitHub requires, is sent to GitHub as an authorization header, and nowhere else.
  • If you tick Save token securely, the token is stored encrypted on your device under a key held in the device’s hardware keystore. It is excluded from Android’s cloud backup and from device-to-device transfer, so it does not leave the phone. You can delete it at any time from Settings > GitHub.
  • If you leave that box unticked, the token is used for that one request and then discarded, and any token saved earlier is deleted.

Gists you create are governed by GitHub’s Privacy Statement, not by this one. The export sheet creates a secret gist unless you turn on Public Gist. A secret gist is not listed or searchable, but anyone who has the link can read it.

Send Feedback

Settings > Send Feedback composes a report and hands it to an app you choose. Nothing is transmitted until you send it yourself.

The report contains your description of the problem, the app version, your Android version, your device manufacturer and model, and the R version. Three switches attach the session’s startup log and error log, and the session end log. All three are off until you turn them on, because the error log quotes R’s messages, which can include your code and data, the startup log names your storage folder and installed packages, and the session end log records when the App was in use. You can read each log in full with View before deciding whether to include it.

The session end log is kept on your device only, and is never part of a backup. It holds the last 50 times a session ended: how Android recorded the App’s process ending (the reason, whether the App was on screen or in the background, and how much memory it was using), and each time the view R runs in crashed or was stopped, with what R was doing then.

You then pick where it goes: Send via Email opens your mail app addressed to support@caffeinatedmath.com, Copy to Clipboard puts the text on the clipboard, and Share… hands it to the Android share sheet. If the R runtime fails to start, or its session stops, the screen shown in its place has a Report Issue button that composes a shorter version of the same thing, with the app version, Android version and device model, and no logs.

Email you send us is ordinary email. We keep it as long as we need it to answer you.

R code you run

R code can reach the network by itself, and when it does it goes wherever you point it. download.file(), url(), readLines(url(...)) and read.csv() on a URL all work, and the request goes directly from your device to whatever host that URL names. Some packages do this on your behalf: a leaflet map, for example, fetches its map tiles from OpenStreetMap as you pan and zoom. Interactive plots are shown in a view that cannot read your storage folder or files shared to the App, and a link inside one does not open, except an email or phone link you tap, which goes to your mail or phone app.

The App does not restrict which hosts your code may contact, does not proxy those requests, and does not log them. What you send and what the far end does with it are between you and that host. See Network Access from R for the practical limits.

Google Play

The App is distributed through Google Play, and standard Google Play services apply to installation and updates. See Google’s Privacy Policy.

A note on the on-device server

R runs inside a WebView, which cannot load its runtime from a file on disk, so the App serves those files to itself from a small web server it starts on 127.0.0.1. That address is your device talking to itself: the server is bound to the loopback interface, so nothing on your network, or anywhere else, can reach it. It carries the webR runtime and your package cache, and nothing leaves the device through it. Other apps on the same device can reach that address too, so your package cache and interactive plots are served only to requests carrying a random key the App makes for each R session; without it, another app cannot tell which packages you have installed.

4. Where Your Data Is Stored

Your work is stored in two places: your storage location, and the App’s private storage.

Your storage location. During setup you either pick a folder with Android’s storage picker or tap Use App Storage, and that is where your projects, scripts, data files and the package cache live. Settings > Storage Location shows which you are using.

  • A folder you picked is your folder, not ours, and the App reaches it through the permission you granted. Because it is outside the App’s own storage, uninstalling the App does not delete it. To remove that work, delete the folder yourself with Android’s file manager.
  • App storage is a folder inside the App’s own storage, and uninstalling the App deletes it with everything in it. No other app can read it by itself: it is listed as webRoid in Android’s Files app and in other apps’ file pickers, and another app gets a file from it only when you pick that file there, or open or share it from the App. That is also how to copy your files out before you uninstall. Choosing a folder later in Settings > Storage Location does not move them.

The App’s private storage. Command history, execution history, settings, custom themes, editor recovery files, saved plot images and the session end log live in the App’s private data directory, where no other app can read them. Uninstalling the App deletes all of it.

Backups. If you have Android’s backup turned on, your Google account backup and a device-to-device transfer to a new phone carry part of the App’s private data: your settings, custom themes, keyboard shortcuts and R toolbar buttons, snippets, the list of projects, recent files, command and execution history, and the editor tabs you had open, including any unsaved text in them. The Google account backup is made only on a device with a screen lock, where Android encrypts it end to end; on a device without one, nothing of the App’s goes to your Google account, and only a device-to-device transfer carries it. Neither ever carries your saved GitHub token, saved plot images, crash-recovery data or the session end log. App storage, with your project files and package cache, goes to a new phone in a device-to-device transfer but is left out of the Google account backup. A folder you picked is not part of the App’s backup at all; back it up as you would any other files. Whether backup is on at all is a device setting you control, in Android’s Settings under System > Backup.

5. Tracking

The App does not track you across apps or websites, contains no advertising, and contains no third-party tracking SDK.

This documentation website is separate from the App and does use Google Analytics (measurement ID G-MJTJ19TQ6S) to count page visits, which sets cookies in your browser. Blocking that in your browser, or through its “do not track” setting, has no effect on the App.

6. Data Retention

We retain nothing from the App, because we receive nothing from it. The only thing we hold is correspondence you start: feedback and support email, and whatever logs you chose to attach to it. Write to us at the address below if you would like us to delete an exchange.

Data on your device stays there until you delete it, as described in section 4.

7. Children’s Privacy

The App is intended for a general audience and is not directed at children under 13. We do not knowingly collect personal information from anyone, children included.

8. Your Rights

Depending on where you live, you may have rights over your personal data, including access, correction, deletion, portability, and the right not to have it sold or shared. This covers residents of the European Economic Area and the United Kingdom under the GDPR, and residents of California under the CCPA and CPRA.

Those rights are simple to satisfy here: we hold no personal data from the App, and we do not sell or share personal information, so there is nothing for us to hand over, correct, or delete. Data created by the App lives on your device, where you can inspect and delete it directly. If you have written to us and want that correspondence deleted, ask at the address below and we will do it.

9. Changes to This Policy

We may update this Privacy Policy. Changes are reflected in the “Last Updated” date above. Continued use of the App after a change constitutes acceptance.

10. Contact Us

Caffeinated Math A subsidiary of HJJB, LLC

Email: Contact Support Website: webroid.caffeinatedmath.com