1. Application Identification and Ownership
MacMirror for Android is an independent, open-source software project developed and maintained by Angel Velasquez ("Developer"). The companion desktop application is MacMirror for macOS.
2. Local-Only Architecture (No Cloud Servers)
MacMirror operates under an absolute Zero Cloud model. The application does not deploy, connect to, or interface with any remote servers, cloud databases, relay brokers, or hosted backend services.
All network communication occurs strictly over your private local area network (LAN / Wi-Fi) between your Android smartphone and your macOS computer. Notification data never leaves your personal local network under any circumstances.
3. Android Permissions and Data Handling
To deliver its core utility—mirroring notifications from Android to macOS—MacMirror requests specific Android system permissions. Below is the full disclosure of each permission, the exact technical purpose, and data boundaries:
android.permission.BIND_NOTIFICATION_LISTENER_SERVICE
Core Functional Permission
Purpose: Captures incoming notifications posted to the Android status bar (notification title, text body, emitting application package, and notification icon).
Data Handling: Notification data is held strictly in volatile device memory (RAM) for the duration required to encrypt it. It is immediately dispatched via local WebSocket to your paired Mac. The application never logs notifications to permanent disk storage, never saves message history, and never uploads notification content to any remote server.
FOREGROUND_SERVICE & FOREGROUND_SERVICE_CONNECTED_DEVICE
Companion Device Priority (Android 14+)
Purpose: Under Android 14+ (API 34+), foreground services require a designated functional type. MacMirror declares connectedDevice because it communicates directly with a physically paired desktop companion (your Mac). This grants process execution priority and prevents aggressive OEM task killers (such as Xiaomi MIUI/HyperOS, Samsung One UI, or OnePlus ColorOS) from prematurely severing the local socket.
Data Handling: Governs OS process lifecycle and connection resilience only. Collects zero personal metrics, usage statistics, or user data.
android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
Doze Mode Exemption (Local Real-Time Sync)
Purpose: Prompts the user to exempt MacMirror from Android's aggressive battery saving mechanisms (Doze Mode). When an Android device enters sleep mode with the screen off, Doze cuts active network sockets and restricts background task execution, which would delay or prevent notification mirroring.
Data Handling: This is an OS power management exemption. It does not record, harvest, or transmit any user information. It strictly ensures uninterrupted local Wi-Fi transmission while the device screen is turned off.
android.permission.POST_NOTIFICATIONS
Foreground Status Indicator
Purpose: Required on Android 13+ to post a persistent, low-priority (silent) status notification (IMPORTANCE_LOW) informing the user of the live connection state ("Connected to Mac" / "Standby"). Also used when triggering in-app local test notifications.
Data Handling: Generates transparent local visual cues on the device. Transmits zero notification logs off-device.
android.permission.QUERY_ALL_PACKAGES
In-App Apps Filter
Purpose: Reads the list of installed applications on your device solely to display them within the in-app "Apps Filter" settings screen.
Data Handling: This allows you to selectively include or exclude specific apps from having their notifications mirrored. The list of installed applications is processed exclusively on-device, is never transmitted over the network, and is not shared with any entity.
INTERNET, ACCESS_WIFI_STATE, CHANGE_WIFI_MULTICAST_STATE
Local Networking (LAN)
Purpose: Enables Network Service Discovery (mDNS / Bonjour under the _macmirror._tcp service) and local WebSocket communication with your Mac companion on port 50002.
Data Handling: Despite requiring Android's general INTERNET permission, MacMirror initiates zero outbound connections to the public internet. All network packets circulate exclusively inside your local LAN subnet.
4. Cryptographic Architecture & End-to-End Encryption
Even across your local Wi-Fi, MacMirror enforces authenticated End-to-End Encryption (E2EE) to safeguard notification payloads against local network eavesdropping or packet inspection:
- Pairing & Key Agreement: Ephemeral Elliptic Curve Diffie-Hellman (ECDH over NIST Curve P-256) combined with an out-of-band 6-digit cryptographic PIN displayed on the macOS menu bar during the handshake (
POST /pair/initiate and POST /pair/confirm). - Key Derivation: Session keys are derived using HKDF-SHA256 (RFC 5869) to guarantee forward secrecy.
- Payload Encryption: All notification packets transmitted across WebSockets are encrypted using AES-256-GCM with unique initialization vectors (IVs) and authentication tags, ensuring confidentiality and tampering detection.
- Key Storage: Derived session keys are stored locally on your device via Android Keystore and Jetpack DataStore /
EncryptedSharedPreferences, backed by hardware security modules (TEE/StrongBox) where supported.
5. Third-Party Tracking and Analytics
| Category | Status | Description |
| Personal Data Collection | NONE | No accounts, emails, names, phone numbers, or device IDs collected. |
| Analytics & Telemetry | NONE | No Google Analytics, Firebase, Mixpanel, or custom telemetry SDKs. |
| Advertising Frameworks | NONE | Completely ad-free. No advertising libraries or tracking cookies. |
| Remote Crash Logging | NONE | No external crash monitoring tools (e.g. Sentry, Crashlytics). |
| Data Sale or Sharing | ZERO | Data is never monetized, sold, rented, or transferred to third parties. |
6. Data Retention and Deletion
Because MacMirror collects zero data on remote servers, there is no remote user profile or database record to purge.
You retain absolute sovereignty over your local device configuration:
- Bidirectional Unpairing: Initiating an unpair action from either Android or macOS immediately invalidates the cryptographic handshake, purges the AES session key from
EncryptedSharedPreferences, and terminates the WebSocket channel. - Clearing App Data: Navigating to Android Settings > Apps > MacMirror > Storage > Clear Data permanently deletes all app preferences and cached metadata.
- Uninstalling: Removing the app from your device completely erases all local application files and cryptographic keys.
7. Children's Privacy and Open Source Verification
MacMirror does not knowingly collect, request, or process personal identifiable information from anyone, including children under the age of 13 (or under 16 in applicable jurisdictions).
Because the application is published under the MIT License, our privacy and security claims are directly verifiable. Developers, security researchers, and users can independently inspect the source code, verify dependencies, and build the APK directly from source:
8. Policy Inquiries and Contact
For privacy questions, security disclosures, or technical audits regarding MacMirror for Android, contact the developer directly: