Spitfire mobile app privacy policy
Effective: 2 October 2026
This policy covers the Spitfire Android app (tr.spitfire.app). The app is a client that connects to the Spitfire controller your organization runs on its own server. It contains no advertising, analytics or crash-reporting library and does not track you.
What stays on your phone
- The names and addresses of the servers you add, your language and theme choice.
- Session tokens (not your password) and the notification key, kept in Android's encrypted storage (Keystore). Your password is sent to the controller only to sign in and is not stored on the phone.
- Signing out deletes the session tokens and the notification key from the phone, removing a server deletes its details too; uninstalling the app deletes all of it.
What goes to your organization's controller
Your sign-in details, what you do (starting or stopping tests, sharing reports) and, if you turn notifications on, the phone's notification registration (device name, Firebase device token, notification public key, the events you chose). The controller is your organization's server; your organization is responsible for this data and Spitfire cannot access it. If you connect to the controller over http the traffic is not encrypted; the app warns about this when you add the server.
Notifications
If you turn notifications on, the phone gets a device token from Google's Firebase Cloud Messaging. The controller (or your organization's gate) encrypts every notification with a key only your phone can open (X25519 + AES-256-GCM) and sends it to Spitfire's notification server (relay.spitfire.tr), which hands it to Google for delivery. The notification server and Google cannot read the content. It holds the test name, the result and the status; no measurements, target addresses or test data.
The notification server does not store the device token; it only passes it on. The only thing it stores is a record of each Spitfire installation that sends notifications (installation id, public key, name and version, the IP it registered from, a send count); its request logs hold the installation id, the path, the status and the duration, but no IP address and no content. How Google handles Firebase: firebase.google.com/support/privacy. Turning notifications off in the app, or signing out, removes the phone's registration from the controller and its key from the phone; turning them off in Android settings only stops them from being shown.
Permissions
- Internet: to reach the controller and the notification service.
- Show notifications: asked only if you turn notifications on.
Sharing, children, changes
Spitfire does not sell or share any data from the app with third parties; apart from the notification delivery described above, no data reaches Spitfire from the app. The app is for business use and not directed at children. If this policy changes, the new version is published on this page with its effective date.
Contact
For questions and personal data requests: the contact address at the bottom of the page. For your data on the controller, contact your organization's Spitfire administrator.