Privacy Policy
Effective date: September 7, 2026
NPM Pocket is an Android client published by Medicw Limited. Privacy questions can be sent to tech@up.ac.cn.
What NPM Pocket does
NPM Pocket connects directly from your Android device to the Nginx Proxy Manager or NPMplus server address that you configure. NPM Pocket does not use a Medicw Limited relay, control cloud, analytics service, advertising SDK, or telemetry backend.
Data handled by the app
To provide its core functionality, NPM Pocket handles information that you enter or receive from your configured server, including the server URL and instance name, account email and password, Nginx Proxy Manager access-token or NPMplus session-cookie material, two-factor authentication codes during login, and proxy-host configuration and certificate metadata returned by your server.
Passwords and saved session material are encrypted on the device with an Android Keystore-backed key. Two-factor authentication codes are used for the authentication request and are not intentionally retained after the login flow.
Collection and sharing by Medicw Limited
Medicw Limited does not collect, receive, sell, rent, or share your NPM Pocket credentials, proxy-host configuration, server responses, device identifiers, usage analytics, advertising identifiers, or crash telemetry through NPM Pocket.
Network requests initiated by NPM Pocket are sent to the Nginx Proxy Manager or NPMplus endpoint that you configure. The operator of that endpoint controls its own server-side logs, retention, access controls, and privacy practices.
Network security
HTTPS is the default connection method. Plain HTTP is available only after an explicit opt-in intended for trusted local networks. NPMplus connections require HTTPS. NPM Pocket does not install a trust-all certificate manager or disable hostname verification.
Retention and deletion
Saved instance configuration remains on your device until you remove the instance, clear NPM Pocket app data, or uninstall the app. Removing an instance deletes its locally saved profile and encrypted credential/session values from NPM Pocket storage.
NPM Pocket does not create a Medicw Limited user account, so there is no separate cloud account or developer-held account data to delete.
Android backup
Android cloud backup is disabled for NPM Pocket app data. Instances should be reconnected on a new device rather than restoring encrypted credential material without its original Android Keystore key.
Children
NPM Pocket is a technical infrastructure administration tool and is not designed for or directed to children.
Changes
This policy may be updated when NPM Pocket's data handling changes. The effective date at the top of this page will be updated when material changes are made.
Contact
Medicw Limited
Email: tech@up.ac.cn