Overview and developer identity
This Privacy Policy applies to Secreto Hub 1.0, an Android TV and Google TV application developed and published by Mohamed LALAH under the SecretoTools name. Secreto Hub receives files from a browser on the same local network as the television. It does not require a Secreto Hub account or login.
The application source contains no advertising, analytics, telemetry, or crash-reporting service integration. SecretoTools does not operate a relay or cloud-storage service for Secreto Hub transfers and does not sell personal data.
Local network file transfers
When you start the receiver, Secreto Hub opens a local HTTP server on the television and displays its private local IP address and port as a URL and QR code. The sender opens that address in a browser on the same Wi-Fi or Ethernet network. The application does not send selected files to SecretoTools or route them through a SecretoTools-operated server.
Each receiving session generates a random 128-bit secret locally. The QR code carries the secret in its URL fragment; when the URL is entered manually, the user enters the matching pairing code shown on the television. Pairing derives separate authentication and encryption keys using HKDF with HMAC-SHA-256. Each upload request is authenticated with HMAC-SHA-256, a strictly increasing request counter, and a SHA-256 body digest.
File metadata—including filename, media type, size, and multi-file batch position—and file contents are encrypted in the sender browser with AES-256-GCM before transmission. Secreto Hub authenticates and decrypts each transfer locally on the television. Session secrets and derived keys are held in memory, are not written to persistent storage, and are destroyed when the receiver stops. A running session is also rejected after 12 hours.
Information processed by the application
To operate the local receiver, Secreto Hub processes the television's private local IPv4 address, receiver port, network type, device name, application version, receiver state, randomly generated session and client identifiers, pairing information, and the sender device's local IP address. The sender IP address is used temporarily in memory to limit repeated invalid pairing attempts.
For a transfer, the application processes the selected file contents and metadata needed to save and display the file: original and saved filename, media type, file size, batch position, time received, local storage reference, file category, and availability status. It also processes transfer progress, request counters, nonces, authentication data, and error states. These data are used to provide the requested local transfer and are not sent by the application to SecretoTools.
Storage, retention, and deletion
During a transfer, decrypted data is written to an application-private temporary file. Completed files are then published to Download/SecretoHub on the television. Incomplete, interrupted, idle, or failed transfers are not published as completed files; their temporary files are removed during failure cleanup or before the next transfer.
Completed files remain in Download/SecretoHub until the device owner deletes them with Android's storage or file-management tools. Secreto Hub stores a local History record in its private Room database for each completed file. A record contains the filename and transfer details described above, but not the file contents. If a completed file is deleted outside the application, History marks it unavailable; version 1.0 does not include an in-app control to delete individual History records.
History records remain until the user clears Secreto Hub's application data or uninstalls the application. Clearing app data or uninstalling removes the private History database but does not necessarily delete files already published in Download/SecretoHub. Android backup is disabled for Secreto Hub.
Android permissions
- Internet: allows the embedded receiver to accept HTTP connections from the local network. The application does not use this permission to upload files to SecretoTools.
- Access network state: identifies an active, non-VPN Wi-Fi or Ethernet network and a usable private IPv4 address.
- Local network access: requested at runtime on Android 17/API 37 and later so the receiver can accept local connections.
- Write external storage: requested only on Android 8 and 9/API 26–28 to publish completed files to Download/SecretoHub. On Android 10 and later, Secreto Hub uses Android MediaStore and does not request this legacy storage permission.
Denying a permission required for the device's Android version prevents the related receiving or saving operation. Permissions can be reviewed or changed in Android settings.
Accounts, third-party services, and data sharing
Secreto Hub requires no account or login. Its application dependencies provide local user-interface, database, QR-code, and Android platform functions; the application contains no advertising SDK, analytics SDK, telemetry service, crash-reporting service, or third-party cloud file-transfer service.
The application makes no external server request as part of the transfer workflow. Transfer data is disclosed only to the sender browser and television participating on the local network, as necessary to complete the user's requested transfer. SecretoTools does not receive that transfer data from the application and does not share it with advertisers or data brokers.
This product website
The public Secreto Hub website is static and contains no account form, advertising, analytics script, tracking pixel, or application cookie. Its hosting and network providers may process standard connection information, such as IP address and request headers, to deliver and secure the site under their own terms. Links to external websites and the sender's third-party browser are governed by their respective privacy practices.
Your choices
- Start the receiver only when you want to accept a transfer, and stop it when finished.
- Choose which files to send and cancel an active transfer from the sender page.
- Decline or revoke Android permissions, understanding that receiving or saving may then be unavailable.
- Delete completed files with Android storage tools.
- Clear Secreto Hub's application data or uninstall the application to remove its private History database and settings.
Security and limitations
Access to the receiver page alone does not authorize an upload. Secreto Hub uses session-specific pairing, authenticated requests, replay-resistant counters, encrypted metadata, and encrypted file chunks. Invalid pairing attempts are rate-limited, and inactive partial transfers expire after 45 seconds.
The initial browser page and encrypted application-protocol traffic are served by the television over local HTTP, not HTTPS. Application-layer encryption protects transfer metadata and file contents, but local-network security still depends on the sender, television, router, browser, and other devices on that network. No system can provide absolute security. Use Secreto Hub on a trusted local network, verify the address and pairing information shown on the television, and stop the receiver when it is not needed.
Children's privacy
Secreto Hub is a general-purpose file-transfer utility and is not directed to children. It requires no account and contains no advertising or analytics integration. A parent or guardian should supervise use and file selection where appropriate.
Effective date and changes
Effective date and last updated: August 10, 2026.
This policy may be updated as Secreto Hub, its distribution, or its features change. Material changes will be reflected on this page with a revised date.
Contact
For privacy, data-protection, or product-support questions, contact Mohamed LALAH / SecretoTools at support@secretotools.com.