← NPM Pocket

Privacy Policy

Effective date: September 7, 2026

NPM Pocket is an Android client published by Medicw Limited. Privacy questions can be sent to tech@up.ac.cn.

What NPM Pocket does

NPM Pocket connects directly from your Android device to the Nginx Proxy Manager or NPMplus server address that you configure. NPM Pocket does not use a Medicw Limited relay, control cloud, analytics service, advertising SDK, or telemetry backend.

Data handled by the app

To provide its core functionality, NPM Pocket handles information that you enter or receive from your configured server, including the server URL and instance name, account email and password, Nginx Proxy Manager access-token or NPMplus session-cookie material, two-factor authentication codes during login, and proxy-host configuration and certificate metadata returned by your server.

Passwords and saved session material are encrypted on the device with an Android Keystore-backed key. Two-factor authentication codes are used for the authentication request and are not intentionally retained after the login flow.

Collection and sharing by Medicw Limited

Medicw Limited does not collect, receive, sell, rent, or share your NPM Pocket credentials, proxy-host configuration, server responses, device identifiers, usage analytics, advertising identifiers, or crash telemetry through NPM Pocket.

Network requests initiated by NPM Pocket are sent to the Nginx Proxy Manager or NPMplus endpoint that you configure. The operator of that endpoint controls its own server-side logs, retention, access controls, and privacy practices.

Network security

HTTPS is the default connection method. Plain HTTP is available only after an explicit opt-in intended for trusted local networks. NPMplus connections require HTTPS. NPM Pocket does not install a trust-all certificate manager or disable hostname verification.

Retention and deletion

Saved instance configuration remains on your device until you remove the instance, clear NPM Pocket app data, or uninstall the app. Removing an instance deletes its locally saved profile and encrypted credential/session values from NPM Pocket storage.

NPM Pocket does not create a Medicw Limited user account, so there is no separate cloud account or developer-held account data to delete.

Android backup

Android cloud backup is disabled for NPM Pocket app data. Instances should be reconnected on a new device rather than restoring encrypted credential material without its original Android Keystore key.

Children

NPM Pocket is a technical infrastructure administration tool and is not designed for or directed to children.

Changes

This policy may be updated when NPM Pocket's data handling changes. The effective date at the top of this page will be updated when material changes are made.

Contact

Medicw Limited
Email: tech@up.ac.cn