1. Overview
Bridge: Closed Test ("Bridge") is an Android service for coordinating closed testing between developers and testers. The developer is elm_cr4. Questions and data requests may be sent to support.elmcr4@gmail.com.
Bridge uses information only as needed to authenticate accounts, operate testing and Campaign features, maintain Coins and reliability state, deliver requested functions, protect the service, and meet legal obligations. Bridge does not sell personal information to advertisers.
Firebase Analytics is not enabled. Firebase Crashlytics is not enabled.
2. Information used for sign-in
Bridge uses Google Sign-In and Firebase Authentication. Google and Firebase Authentication process the information needed to authenticate your Google account, establish a Firebase identity, help secure sign-in, and manage the authenticated session.
Bridge uses the authenticated Firebase identity internally to associate service data with the correct account. Bridge does not publish your Google email address. Instead, you choose a public Bridge alias. Your Google display name or email address is not silently adopted as that public alias.
3. Bridge account and service data
Depending on how you use Bridge, the service may store:
- your chosen public Bridge alias and an internal Firebase account identifier;
- Coin balance, Coin ledger entries, reservations, and other account state;
- reliability state and events used to support genuine participation;
- DeveloperApp ownership and marketplace state;
- Test sessions, completion state, Campaign participation, and warnings; and
- notification permission and preference state.
Some marketplace information—such as public aliases, app listings, and app icons—is visible to other Bridge users because those features are designed for community coordination. Internal account identifiers, Coin ledgers, private notification infrastructure, and other private account records are not intended as public profile content.
4. Developer apps and uploaded icons
When you add an Android app, Bridge may store information you provide, including the app name, developer name, Google Play Store URL, testing instructions, derived package identity, listing or Campaign state, and an app icon when you choose to upload one.
Icons selected through Android Photo Picker are adapted inside the app to create a normalized Bridge copy suitable for marketplace display. Bridge uploads that normalized copy; the original image in your gallery is not modified.
Firebase Cloud Storage is used for uploaded app icons. App icons are public marketplace assets because other Bridge users need to see the apps they may test. Only an authenticated owner may upload or replace an app's icon through Bridge. You must have the right to use any image you submit.
5. Private feedback
Testers may optionally submit private feedback about a tested DeveloperApp. That feedback is made available to the owner of the tested app. The tester's Google identity and email address are not exposed to the app owner through private feedback.
Free-form private feedback text is not included in push-notification payloads. Notifications may say that feedback is available, after which the authenticated app owner can open Bridge to view it. Private feedback is not used for Firebase Analytics; Firebase Analytics is not enabled.
6. App reports
When you report a marketplace app, Bridge processes the selected report category, any optional description you provide (up to 500 characters), internal account and listing references, and the report time and status. We use this information to review service safety and listing quality, prevent duplicate reports, and support moderation.
Reports are stored in server-only systems and are not shown to the reported app owner. Submitting a report does not automatically remove a listing or change Coins or reliability.
Report descriptions are not included in push notifications, Firebase Analytics, or application logs. Firebase Analytics is not enabled.
7. Coins
Coins are an in-app participation currency used only within Bridge. They have no cash value, cannot be withdrawn, and cannot be exchanged for money. Eligible testing activity and successfully verified rewarded ads may grant Coins under the current in-app policy.
Coin grants, spends, reservations, releases, and related mutations are server-authoritative. Bridge keeps Coin account and ledger state to apply limits, resolve balances, prevent duplicate grants, and investigate fraud, abuse, or technical errors.
8. Optional rewarded advertising
Bridge uses Google AdMob for optional rewarded ads. You decide whether to request a rewarded ad; refusing advertising consent does not remove access to Bridge's core testing functionality.
Google AdMob may process device and app information, IP address, diagnostics, advertising identifiers, and ad interaction information according to your consent choices, device settings, region, and Google's privacy policies. Bridge uses Google's User Messaging Platform (UMP) consent flow where required so that relevant privacy choices can be presented or revisited.
A viewed ad does not by itself guarantee a reward. Coins are granted only after Bridge receives and validates server-side verification under the current reward allowance and anti-abuse rules. Bridge does not sell personal information to advertisers.
9. Functional notifications
Bridge may use Firebase Cloud Messaging (FCM) for functional notifications, including Campaign reminders, Campaign lifecycle updates, listing updates, and notice that private feedback is available.
Notification permission is optional. You can change Android notification permission and available Bridge notification preferences. FCM registration tokens are private infrastructure data used to address notifications to an app installation; they are not public profile identifiers. Free-form private feedback is not included in notification payloads.
10. Google Play Billing
Bridge offers optional permanent slot upgrades as one-time products through Google Play Billing. Google handles the payment transaction under Google Play's terms and policies. Bridge receives and verifies limited purchase and entitlement information needed to grant, restore, or protect the upgrade.
Bridge does not receive or store your payment-card details. Coins are not sold through these purchases.
11. Device account limits, App Set ID, and App Check
To help protect the testing economy from multi-account abuse, Bridge allows up to 2 Bridge accounts to be associated with the same Android device identity. This is a device-level control. It does not establish that the accounts belong to the same real-world person.
For security, abuse prevention, and enforcement of this account limit, Bridge retrieves the Android App Set ID and its scope from Google Play services. The raw App Set ID is sent only when needed over an authenticated, App Check-protected connection. Bridge does not store the raw App Set ID. The server derives an opaque, deterministic device key and stores only that key with the internal Bridge account associations needed to enforce the limit. These records are not available to normal client reads.
Bridge does not use the Advertising ID, hardware serial, IMEI, MAC address, phone number, Google email address, Google display name, SIM data, or an invasive composite device fingerprint for this account-limit feature. The App Set ID and derived device key are not included in Analytics; Firebase Analytics is not enabled.
Bridge uses Firebase App Check with Google Play Integrity to help protect backend services from abuse, automated misuse, and unauthorized clients. These services may process technical app, device, and integrity information needed to assess whether requests come from a genuine app installation. These protections reduce risk but cannot guarantee that every malicious action will be prevented.
12. Service providers and data processing
Bridge relies on service providers to operate the app:
- Google Firebase for authentication, database, server functions, icon storage, messaging, and backend protection;
- Google Play for app distribution, account-mediated sign-in components, App Set ID, Play Integrity, and optional purchases; and
- Google AdMob and UMP for optional rewarded advertising and applicable consent choices.
Data may be processed by these providers under their own terms and policies where necessary to provide the service, prevent abuse, comply with law, or maintain their platforms. Processing is not guaranteed to occur only in Sweden or the EEA. You can review Firebase privacy and security information and the Google Privacy Policy.
This public legal site is static: it contains no analytics or third-party tracking scripts and creates no cookies itself. It is hosted by GitHub Pages, which may process ordinary web-request and security data under GitHub's policies.
13. Data retention and deletion
Bridge keeps account and service data for as long as needed to provide the service, maintain security and abuse records, meet legal obligations, enforce the Terms, or resolve disputes.
You may request account or data deletion by contacting support.elmcr4@gmail.com. Where necessary, limited records may be retained for fraud prevention, security, accounting, dispute resolution, or legal obligations. Some server-authoritative transaction or audit records may therefore not be deleted immediately.
Service providers may retain data under their own legal requirements and retention policies. Removing Bridge from a device does not by itself delete data held in a Bridge account or by Google services.
14. Security
Bridge uses reasonable safeguards appropriate to the service, including Firebase Authentication, App Check, server-authoritative business operations, and access controls for private account and owner data. No internet service can promise absolute security. If you believe your account or data may be at risk, contact support promptly.
15. Children's privacy
Bridge is intended for Android developers and testers. It is not designed for children. If you believe a child has provided personal information through Bridge, contact support so the situation can be reviewed.
16. Your privacy rights
Depending on where you live and the circumstances, you may have rights to request access to, correction of, deletion of, restriction of, or objection to processing of your personal data. You may also have a right to complain to the relevant data-protection authority.
To exercise an applicable right, email support.elmcr4@gmail.com. Bridge may need to verify that the request relates to your account before acting on it.
17. Changes to this Privacy Policy
This policy may be updated when Bridge features, legal requirements, or service providers change. The current version and last-updated date will be published on this page. Material changes may also be communicated in the app or through another appropriate channel.
18. Contact
Developer: elm_cr4
Email: support.elmcr4@gmail.com
Website: https://elm4-cmd.github.io/