This Privacy Policy explains what personal data TritonPanels (the “App”) collects, how it is used, who it is shared with, how long it is kept, and the rights you have over it. The App is published by TritonApps (“we”, “us”), an indie studio based in the Republic of Ireland. We are the data controller for the limited personal data processed through the App.
The short version: TritonPanels is local-first. There is no TritonPanels account and no sign-up. Your library, settings, bookmarks and reading progress live on your device. When you connect a cloud-storage provider, the App reads your comics directly from your account — we never receive, store, or see your files.
1. Who we are
The App is published by TritonApps, Republic of Ireland. For privacy matters please email privacy@tritonapps.com.
2. What we collect, when, and why
We try to collect as little as possible and only what we need to run the service. The categories below match our App Store privacy disclosure and the Google Play Data Safety form.
2.1 Data stored on your device
- Your library and reading data — the comics you import, covers and metadata, collections, reading lists, tags, favourites, bookmarks, notes, reading progress and stats. This is stored locally on your device and is not transmitted to us.
- App settings — reading modes, theme, cache limits and similar preferences. Stored on your device.
2.2 Cloud-storage access tokens and account email
- If you choose to connect Google Drive (Android only — see 3.1), Dropbox or OneDrive, the provider issues an OAuth access token that is stored only on your device, in the platform secure store (iOS Keychain / Android Keystore-backed storage). We use it only to read the comic files you point the App at. We never receive your files, and your token is never transmitted to TritonApps or to any third party. It is deleted from your device when you disconnect the provider.
- We also read the email address of the account you connected, and store it on your device next to the token. It exists purely so the App can show you which account it is reading from. It is never transmitted to us, never used to contact you, and is deleted when you disconnect. See section 3.1.
2.3 Subscription data
- Subscription status, plan, renewal date — received from RevenueCat (which receives it from Apple or Google) to manage your free trial and premium access. RevenueCat associates this with an anonymous, app-generated identifier, not your name or email.
- We do not receive your card details. Payment is handled by the Apple App Store or Google Play.
2.4 Diagnostics
- Crash reports and error traces via Sentry. Only an opaque, app-generated identifier is associated with traces — never your name or email.
- Crash reports never contain your cloud files or their names. Before any diagnostic event leaves your device, the App removes cloud-storage file names, file identifiers and provider API addresses from it. Your comic file contents are never included in a crash report under any circumstances.
- We do not use third-party analytics or advertising SDKs. We do not track you across apps or websites, and the App contains no ads.
3. Cloud-storage connections
Connecting a cloud provider is entirely optional — you can use TritonPanels with only on-device files. When you do connect one:
- You authenticate directly with Google, Dropbox or Microsoft through their own secure sign-in. We never see your provider password.
- Your files are downloaded from the provider straight to your device for reading. They are not routed through, copied to, or stored on any TritonApps server — we operate no server that touches them.
- Your use of each provider is also governed by that provider’s privacy policy (Google, Dropbox, Microsoft).
- You can disconnect at any time in Settings → Cloud storage, and revoke access entirely from the provider’s connected-apps settings. See Delete your data.
3.1 Google Drive
On iPhone and iPad, TritonPanels does not connect to your Google account at all. Google Drive comics are chosen through Apple’s Files app, which hands the App a copy of each file you pick. No Google sign-in takes place inside TritonPanels, no Google permission is requested, and no Google access token is stored. Google only permits an app to browse your Drive folders itself after a paid annual security review, so on iOS the Files app is the route we offer.
On Android, if you connect Google Drive, TritonPanels requests exactly three permissions — no others:
https://www.googleapis.com/auth/drive.file— access only to the individual files you pick in Google’s own file picker. This permission does not let the App see, list or search anything else in your Drive.openidandhttps://www.googleapis.com/auth/userinfo.email— your account’s email address, so the App can show you which Google account it is connected to.
In particular, we request no permission to browse your Drive, and no access to your Google profile, contacts, calendar, or any other Google service.
What Google user data we access. Three things: (1) your account’s email address, read once when you connect; (2) the name, identifier, type and size of each file you pick in Google’s file picker, which is what draws the list of chosen comics on screen; and (3) the contents of those files, downloaded when you import them. The picker itself runs on Google’s own pages; the App only receives the details of the files you selected. We do not scan, index, or read the rest of your Drive, and this permission does not allow us to.
How we use it. Solely to provide the feature you asked for: to download the comics you picked so you can read them — including offline. Downloaded comics are stored on your device and appear in your library.
How we use your email address. For one thing only: it is displayed back to you, on the Connect Storage and Settings screens, so you can see at a glance which account is connected — which matters if you have both a personal and a work Google account. It is stored on your device alongside the access token, in the platform secure store, and it is deleted when you disconnect. It is never transmitted to TritonApps, never used to contact you, never used to build a profile of you, and never shared with anyone.
Why this is the narrowest permission. drive.file grants access only to files you hand-pick, and is the least privileged Google Drive permission that can open a file at all. It is also why TritonPanels cannot show you your Drive folder tree the way it does for Dropbox and OneDrive: browsing your Drive would need a broader permission that Google gates behind an annual security review.
What we do with it — and what we never do. Google user data obtained through Drive is never transmitted to a TritonApps server, never sold or transferred to any third party, never used for advertising, profiling, credit or lending decisions, and never used to develop, improve or train any AI or machine-learning model — ours or anyone else’s. TritonPanels contains no AI/ML component of any kind. No human at TritonApps reads your Drive data; we have no technical means to do so.
Downloads only. TritonPanels only ever downloads the files you pick. It never creates, uploads, renames, moves, shares or deletes anything in your Google Drive. Removing a comic from your TritonPanels library deletes only the local copy on your device; the file in your Drive is untouched.
Retention and deletion. The access token is held in your device’s secure store and is deleted the moment you disconnect Google Drive in Settings → Cloud storage. The list of files you picked is held in memory only while you are choosing and importing, and is never written to disk. Comics you import are stored on your device until you delete them, clear the App’s data, or uninstall the App. You can additionally revoke TritonPanels’ access to your account at any time at myaccount.google.com/connections. See Delete your data for step-by-step instructions.
Limited Use. TritonPanels’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Sub-processors
We use the following sub-processors. Each is bound by a Data Processing Agreement (or equivalent) and processes data only to deliver the service.
- RevenueCat (subscription state, keyed to an anonymous identifier).
- Sentry (diagnostics — no PII linked to identity).
- Expo / EAS (build distribution and over-the-air updates).
- Apple and Google (app distribution and payment processing, under their own privacy policies).
Separately, the cloud-storage provider you choose to connect (Google, Dropbox or Microsoft) processes your files on your behalf as your own data controller — not as our sub-processor.
5. How we protect your data
Because TritonPanels is local-first, the strongest protection is structural: there is no TritonApps server holding your library, your files, or your credentials, so there is no central store of them to breach. Beyond that:
- Credentials. Cloud-storage OAuth tokens are held only in the platform secure store — the iOS Keychain and Android Keystore-backed storage — which is encrypted at rest by the operating system and readable only by TritonPanels. We never see, transmit or store your provider password, and the App holds no password of its own.
- Data in transit. All communication with Google, Dropbox and Microsoft uses HTTPS/TLS. Sign-in uses the OAuth 2.0 authorization-code flow with PKCE, so no long-lived secret is embedded in the App, and the App never handles your provider password.
- Data at rest. Your library, comics, covers and reading data are stored inside the App’s private, sandboxed storage area, which the operating system protects from other apps and encrypts on a locked device.
- Least privilege. We request the narrowest permission each feature needs, and no permission whose result the App does not actually use. Access to Google Drive is read-only (see section 3.1).
- Diagnostics. Crash reports are stripped of cloud file names, file identifiers and provider API addresses before they leave your device, and never contain file contents.
- Maintenance. Dependencies are kept current and the App is covered by an automated test suite that runs on every change, including tests asserting that the protections above hold.
No system is perfectly secure, but we do not hold the kind of centralised data that makes a breach damaging. If we ever become aware of a breach affecting your personal data, we will notify you and the Irish Data Protection Commission as required by GDPR Article 33.
6. How long we keep it
Data stored on your device is kept until you delete it, clear the App’s data, or uninstall the App — you are in control (see Delete your data). Subscription state held by RevenueCat persists for as long as needed to honour your entitlement and meet accounting obligations. Diagnostic events (Sentry) are retained for 90 days then deleted. Apple and Google retain payment records under their own policies; we do not control those records.
7. Your rights
If the GDPR or UK GDPR applies to you, you have the right to:
- access the personal data we hold about you,
- have inaccurate data rectified,
- have your data erased (“right to be forgotten”),
- restrict or object to certain processing,
- receive your data in a portable format, and
- lodge a complaint with your supervisory authority — for users in Ireland, the Data Protection Commission.
Because most of your data never leaves your device, you can exercise many of these rights directly in the App. Other jurisdictions may give you similar rights (CCPA, LGPD, and others). We honour requests on the same basis regardless of where you are.
8. How to exercise your rights
The fastest path is in-app: clear your data and disconnect any cloud provider (see Delete your data). For requests about data a sub-processor holds (for example, your RevenueCat subscription record), email privacy@tritonapps.com. We respond within 30 days, in line with GDPR Article 12. We may need to verify details before processing a request.
9. Children’s data
TritonPanels is not directed to children under 13 (or 16 in jurisdictions where GDPR Article 8 sets that as the threshold). We do not knowingly collect personal data from children below the applicable age. Comics you add are your own content; please ensure material is age-appropriate for whoever uses the device. If you believe a child has provided us personal data, contact privacy@tritonapps.com and we will delete it.
10. International transfers
Some of our sub-processors (RevenueCat, Sentry) may process data outside the European Economic Area. Where they do, transfers rely on the European Commission’s Standard Contractual Clauses or an equivalent transfer mechanism. Your data continues to be protected to the standard required by the GDPR.
11. Changes to this policy
If we change this policy in a way that affects your rights, we will update the effective date above and notify you in-app before the change takes effect. Older versions are kept on file and are available on request.
12. Contact
Questions, complaints, or requests under this policy:
- Email: privacy@tritonapps.com
- Postal address: available on request via the email above.
For cookies on this website, see the shared TritonApps Cookie Policy. Within the App itself we do not use cookies.