SafeShow: Privacy & Viewer Limits

Android app: idiotlabs.safeshow · Last updated September 8, 2026

SafeShow by idiotlabs is a free, local photo viewer for showing selected photos to someone nearby. There is no account, payment, or advertising.

Selected photos stay on your device

SafeShow uses Android's system photo picker and does not request full gallery access. Selected images are copied to private temporary files on your device. SafeShow does not upload them, create cloud sessions, or generate shareable links. A cloud photo provider you select inside the system picker may download a photo according to that provider's policy.

Temporary storage and deletion

The viewer uses in-memory references and temporary photo copies. The timer begins when you start the viewer. Expiry, holding End viewer, Android Back, or clearing local data closes the viewer and clears the references and temporary copies. Your original photos are never deleted by SafeShow.

After a force stop or crash, temporary copies may remain until SafeShow next starts or Android clears its cache. Startup removes stale copies; cleanup failures are reported and you can retry from Settings. Photo content is never saved to app preferences. Normal file deletion is not secure erasure and cannot guarantee protection against device forensics.

Limits of the viewer

SafeShow does not prevent screenshots, screen recording, OS navigation, or opening your gallery. Anyone can hold End viewer; it is not owner authentication. Android screen pinning must be set up separately in Android Settings and applied to SafeShow by you. Availability and unpinning behavior depend on your device.

Optional Firebase Analytics

Analytics, including automatic collection, is off by default. If you opt in in Settings, Google Firebase Analytics receives basic app interactions, app/device information, an app-instance identifier, and may derive approximate location from the IP address. SafeShow's custom events are viewer_created, viewer_started, and viewer_ended, carrying only a selected-photo count, a timeout choice, or a fixed ending reason.

We do not send photo content, file paths, filenames, notes, contacts, or user-entered text. Advertising ID collection and advertising consent are disabled. Analytics data is processed by Google under its Privacy Policy; information about Firebase's processing is available in Firebase Privacy and Security.

You can turn analytics off at any time. This stops collection and resets analytics data held locally by the SDK. Clearing local data also resets your preferences and turns analytics off. These actions do not delete events already received by Google. We do not set a user account identifier in analytics.

Preferences and support

The app saves only your timer and analytics choices as preferences. Core viewing works without internet access or analytics consent. If you email support, idiotlabs and your email provider receive the information you choose to send. Avoid sending sensitive photos unless you intend to share them with support.

For questions or privacy requests, contact idiotlabs@gmail.com.