Skip to the content.

Privacy Policy for Cakebyte

Effective date: 2026-08-29 Last updated: 2026-09-16 App: cakebyte

Cakebyte is a firewall app for Android. It lets you allow or block network access for individual apps, block IP addresses and ranges, and look at what your apps have been connecting to. This policy describes what it does with the information it handles.

In short: Cakebyte has no servers and no accounts. Nothing it records about you is sent anywhere. The only network request the app itself makes is to Google Play, and only when you buy or restore the Pro upgrade.

1. Who we are

Cakebyte is developed by Twius. You can reach us at twius.09@gmail.com.

There is no backend server or cloud service behind Cakebyte. We hold no copy of your data because we never receive one. If you buy the Pro upgrade, Google Play handles the payment and we never see your card details.

2. What the app stores on your device

Cakebyte keeps its data in a private SQLite database inside the app’s own sandboxed storage. That covers:

None of it is transmitted to us or to anyone else. We create no backups and run no sync. Android’s own cloud backup is switched off for the app as well, so none of it is copied into your Google account either.

3. What leaves your device

Nothing, apart from the purchase described in section 8.

Cakebyte contains no analytics SDK and no advertising. Nothing reports crashes back to us either. It does not profile you, and there is no data for us to sell even if we wanted to. At runtime the app contacts no server of ours, because there isn’t one. Google’s Play Billing library is the exception: it brings Google Play services components with it, and those send Google diagnostics about the billing flow.

It does bundle a static copy of the StevenBlack/hosts blocklist (MIT License) so it can recognise known tracking domains. That file ships inside the app and is read from local storage. Nothing is fetched at runtime, and no lookup you make is sent anywhere.

VPN usage. Cakebyte uses Android’s VpnService API to open a local tunnel so it can inspect packets on the device. It is not a VPN service in the usual sense: your traffic is never relayed through a server we or anyone else operates.

4. Permissions

Permission Why it is needed
QUERY_ALL_PACKAGES To display the full list of installed apps so you can set firewall rules for each one
BIND_VPN_SERVICE To intercept network traffic locally on-device for firewall enforcement
INTERNET To forward the traffic your apps send, once the firewall has allowed it. Cakebyte itself sends no data anywhere
FOREGROUND_SERVICE To keep the firewall running while the app is in the background
FOREGROUND_SERVICE_CONNECTED_DEVICE The foreground-service type that Android 14 and later requires for a VPN service
RECEIVE_BOOT_COMPLETED To restart the firewall automatically after the device reboots, if enabled
POST_NOTIFICATIONS To show firewall status and blocked connection alerts
ACCESS_NETWORK_STATE To detect when you switch between WiFi and mobile data
CHANGE_NETWORK_STATE To bring the local VPN tunnel up and down as your device moves between networks
WAKE_LOCK To keep packet forwarding responsive while the screen is off so background streaming does not stall, when “Keep awake for streaming” is enabled
USE_BIOMETRIC To unlock the app with your fingerprint, face, or device PIN/pattern/password when the optional App Lock is enabled. Android does the authentication itself; Cakebyte never receives or stores your biometric data
com.android.vending.BILLING To process the optional one-time in-app purchase that unlocks Pro features, through Google Play

5. Logging and deletion

Connection logging is on by default. Turn off Activity logging in settings and the app stops recording connections altogether.

You can wipe the connection logs and the alert history from inside the app whenever you want. Logs belonging to a particular app are also dropped automatically if you uninstall or disable that app.

One thing that wipe does not cover: the per-app counts your connection logs are rolled up into. There are two of these. An hourly one, kept for 60 days, and a daily one, which is not pruned at all. Each row holds an app’s package name, which hour or day it covers, and how many connections that app made and how many were blocked. There are no domains and no addresses in either, and nothing about what any single connection was for. They stay on your device like everything else, and uninstalling Cakebyte clears them along with the rest.

Turning Activity logging off stops the roll-ups too, not only the connection logs. While it is off nothing is recorded and nothing is aggregated.

6. Your rights

Data protection law gives you rights over personal data an organisation holds about you: access, correction, erasure, portability. We hold none. Cakebyte has no server and no account system, so there is no copy on our side to hand over, correct or delete. Everything those rights would cover sits on your device, under your control. You can clear the logs and alerts from inside the app, turn logging off so nothing is recorded in the first place, and clear the app’s data or uninstall it to remove the lot.

Google processes your Pro purchase, and its own billing diagnostics, as a separate controller, under Google’s privacy policy. Rights over those are exercised with Google. Cakebyte never sees your payment details.

7. App Lock and device security

Everything lives in the app’s private storage, which Android keeps sandboxed from other apps. Beyond that the usual advice applies: a screen lock and current OS updates protect device-stored data better than anything an app can do for you.

App Lock is an optional extra. Switch it on and Cakebyte asks for authentication when you open it, and again if it has sat in the background for more than about 30 seconds, so someone holding your unlocked phone cannot change your firewall rules or read your connection logs. It ships off by default.

Android handles the authentication itself, through its biometric and device-credential APIs. Cakebyte stores no credentials and never sees your fingerprint or face data. While App Lock is on, the app also hides its contents from the recents screen.

8. Purchases

The firewall itself is free and stays free. Pro adds the detailed connection log, per-app statistics, alerts and the IP blocklist, and you get a 14-day trial before deciding. Unlocking it is a single one-time purchase. There is no subscription and there are no ads.

Google Play Billing processes the payment, the same system behind every paid app on the Play Store. Google runs the transaction and keeps a record of what you own so it can be restored on any device where you are signed in. We never receive or store your payment details, and Google’s own privacy policy governs how it handles them. Your trial status is tracked locally and never uploaded.

The app talks to Google Play for one reason: to complete or restore a purchase. Your firewall rules and connection logs are never part of that conversation.

Once you have bought Pro, it stays bought. We will not switch it off remotely, and we will not ask you to pay again for something you already own. The app itself will carry on changing, and the Terms of Use explain how.

9. Children

Cakebyte is not aimed at children under 13, or under whatever minimum age applies where you live. We do not knowingly collect information from children. Since we collect nothing from anyone, there is nothing on our side to process.

10. Changes to this policy

We may revise this policy occasionally. When something material changes, the “Last updated” date above changes with it, and where it matters we will say so in the app or on the store listing.

Your use of the app is also covered by the Terms of Use.

12. Contact

Questions about any of this: twius.09@gmail.com