Mobile apps

Symbifox Account

com.bluefoxconsultant.compte

Last updated: 5 September 2026

Controller: Blue Fox Inc., bonjour@symbifox.com

Symbifox Account is the access broker for the Symbifox apps on your own device. It grants access to your own Odoo instance. The app has no account, no server and no service of its own.

English version of PRIVACY.md, published on 18 September 2026 and carrying the date of the French policy it translates (5 September 2026). Both say the same thing; where they differ, the French one governs, because it is the one Blue Fox Inc. writes first.

In one sentence

The app collects nothing, transmits nothing to Blue Fox or to any third party, and talks only to the Odoo instance you point it at yourself.

What the app reaches

  • Your Odoo instance, the one whose address you enter when adding the account. It asks it for one device record per calling app, and nothing else.
  • Android's account manager, so the account appears under Settings, Accounts, and so sibling apps can ask it for access.

🔴 What it does not reach

It reads none of your data. No email, no calendar, no tasks, no contacts, no messages. It grants access, it does not use it. That is the whole point of the app: each sibling app receives its own device record, revocable on its own, rather than a shared token.

Nor does it serve the token vault: Symbifox Tokens keeps its own pairing, because a vault must not depend on another app to open.

No camera, no microphone, no location, no SMS, no shared storage. The declared permissions can be checked: internet and account management.

What the app keeps, and where

Everything stays on your device, in Android's account store:

What is keptHow
The instance address and the account identity (person@host)Android's account store
The accesses granted to sibling appssealed by the Android Keystore

⚠️ The app refuses to store an access in the clear if the hardware declines: it fails plainly rather than writing a readable token.

Android grants an account's data only to apps signed with the same key as its authenticator. An app that is not part of the Symbifox fleet does not see this account, whatever it asks for.

What the app transmits, and to whom

Only to the Odoo instance you designated, and only to request or revoke a device record. The app contacts no other server: no analytics, no telemetry, no crash reporting, no advertising, no remotely loaded code. Blue Fox Inc. receives no data about your use of it.

No password passes through the app: sign-in happens on your instance's own web page, where your session is already open.

Retention and deletion

  • Removing the account under Settings, Accounts, erases everything the app was keeping on the device.
  • The "Revoke" button in the list of accesses revokes a granted access, on the server as well as on the device.
  • From your instance, the "My devices" page (/my/appareils) lists the paired devices and lets you remove one, or all of them.

Removing the account also revokes the accesses on the server, whether it is removed from the app or from Android's settings: the revocation lives in the authenticator, not in the screen.

⚠️ The local removal goes first, and it always goes through. The server call that follows is best effort: with no network, or past the timeout, the access has indeed left the device but may stay open on the instance. The "My devices" page is the fallback that settles it in that case.

Your rights

Since no personal data is collected by Blue Fox Inc., there is nothing on our side to consult, correct or delete. Your data stays under your control, on your device and on your Odoo instance. For any question: bonjour@symbifox.com.

Changes

Any change to this policy will be published at this address, with its date.

All three policies