Muralis

Privacy policy

This is the same text the app itself shows on its About screen, published here so it is readable without a device in front of you.

Muralis is a kiosk launcher that displays a web dashboard you choose, on a device you own. This policy says what the app does with data, in plain words, and is written against the EU General Data Protection Regulation, the GDPR.

What the app sends to the developer

Nothing. Muralis has no analytics, no crash reporting, no advertising identifiers and no server of its own. The developer receives no data from your device, at any time, for any reason.

What the app sends elsewhere, and where

Nothing, until you configure a destination yourself. Two optional features publish data, and both stay off until you set them up: MQTT stays off until you enter a broker address, and the local web administration stays off until you set a password. A third optional feature fetches data rather than publishing it: the screensaver can show pictures from the internet, and it does so only if you pick that source.

MQTT.

If you enter a broker address, Muralis publishes a status snapshot to that broker, about once a minute and sooner when something changes. It contains device status and diagnostics: battery, memory, storage, network state, the device's own address on your network, processor load and temperatures, screen state, the panel's settings including the device identifier it generates for itself, the app version, the health of the dashboard: which page is loaded, whether it loaded, how often the view crashed or was rebuilt, and, if you use the Pictures screensaver, the name of the playlist in use and of the picture on screen.

Three things in it deserve to be called out, because you might not expect them. The snapshot includes the address of the dashboard being shown, so if that address is itself something you would not want on your broker, do not enable MQTT. It includes the network address of any device that was locked out of the web administration for repeated wrong passwords, published so that you can act on a guessing attempt. And it is retained: your broker keeps the most recent copy and hands it to anything that subscribes later, even after the panel is switched off or removed, until you clear it on the broker.

The complete, current content of the snapshot is not a secret and cannot go stale in this document: it is visible to you at any time on your own broker, and in the web administration.

Local web administration.

If you set an administration password, the panel serves the same status information, plus its settings, over your local network to anyone who supplies that password. This surface also shows things that are deliberately never sent to the broker: the corner-tap combinations that unlock the kiosk, and the panel's connection settings. If you use the Pictures screensaver, it also lists the picture folders on the panel, shows small previews and the pictures themselves, and lets whoever has the password upload pictures to the panel and delete the ones that were uploaded. Whoever has the password can also upload a certificate and its private key for the panel to serve instead of its own, and delete them again. The password is what protects the way out of the kiosk; treat it accordingly.

Pictures from the internet.

The screensaver can show Bing's image of the day or Wikimedia Commons' picture of the day, and it does so only if you pick one of them. It then fetches a handful of pictures from that service over an encrypted connection, when the screensaver starts and about once an hour, and keeps them for a day. Like any web request, the service sees your network's public address and what was asked for; Muralis sends nothing about you or the device. Bing publishes no interface for this: Muralis reads the same address the Bing homepage uses, which Microsoft can change or close at any time, and the pictures are copyrighted works shown with Bing's own credit line. Wikimedia Commons pictures carry free licences that require the author and the licence to be named, and the credit line does that.

What it is all for. The snapshot exists so that your own dashboard can show the panel's state and control it, and the web administration exists so that you can change the panel's settings without walking to the wall. Nothing in either is used for analytics, advertising, profiling or any purpose beyond making the app work.

MQTT is not encrypted: the snapshot and your broker credentials travel in clear text over your network, so use it on a network you trust. The web administration is served over HTTPS with a certificate the panel makes for itself, so your browser warns about it once, or with a certificate of your own that you upload; the panel's settings screen shows the fingerprint of the certificate in use for you to compare, and a request over plain HTTP is answered with a redirect to the encrypted address. A certificate and its key can only be uploaded over HTTPS. If the panel cannot make a certificate it serves plain HTTP and its settings screen says so.

The Wi-Fi network name is never read or transmitted. Reading it would require the location permission, which the app holds only for the Bluetooth beacons sensor, because Android counts a Bluetooth scan as a use of location: on an ordinary install Android asks you when you tap Allow on that sensor, and a panel set up as device owner grants it to itself at start, with the other sensors' permissions, so their switches work with nobody at the panel. The app reads neither the network name nor a position with it.

Who is responsible for that data

You are. The broker and the network are yours: the developer is not a recipient of anything the app publishes and cannot read, correct or delete any of it. The developer processes personal data in exactly one case: if you write to the contact address below, he receives your address and what you wrote, uses them to answer you, and nothing else. For that mail the developer is what the GDPR calls the controller, and the legal basis is that you asked (Article 6(1)(b) and (f) of the GDPR).

What the app stores on the device

Your settings, a device identifier Muralis generates itself, and the corner-tap combinations you record. Your broker credentials, the administration password, the Pro purchase record, the private key of the panel's own HTTPS certificate and, if you upload one, your certificate and its private key are stored encrypted through the Android keystore; the uploaded certificate's names, end date and fingerprint, which the certificate itself makes public, are stored with your settings. The dashboard view stores whatever cookies and sessions your dashboard sets, in the same way a browser would. To notice a dashboard that has frozen, the app compares two size measurements of the page against their previous values, on the device; they are never stored beyond that comparison and never transmitted.

If you use the Pictures screensaver, the app also stores the playlists you make, the names you give pictures for their credit line, the pictures you upload, small previews of the pictures you browsed, and the last few pictures fetched from an online source. Your own pictures are read where they are and never copied, changed or deleted; the one thing Muralis deletes is an uploaded copy, when you ask it to.

Muralis reads the photos on the device only if you turn on the Pictures screensaver with the panel's own pictures as the source, and only after you grant the permission Android asks for at that moment; it reads them to list the folders, draw the previews and show the pictures you picked, and for nothing else. It does not read your contacts, messages or call history, and requests no permission that would allow it to.

Sensors

Every sensor that reads the room (the camera, the microphone, Bluetooth beacons, NFC, light, proximity, movement and the other hardware sensors) is off until you switch it on on the app's Sensors page; the panel's own readings (battery, power, network, memory, processor, display and screensaver) are on, as they always were. When a sensor is on, its reading is part of the status message and is shown in the web admin, and the app's own automations can react to it on the device. The camera, when on, streams live pictures to the web admin behind its password and, only if you switch that on too, sends a picture to your broker when it sees movement or when you ask for one; that picture is retained on the broker until the switch or the camera goes off, or you clear it there; nothing is recorded. The microphone, when on, reports how loud the room is as a number from 0 to 100; no sound is recorded or sent. Bluetooth, when on, listens for beacons near the panel and never sends one; each beacon in reach goes into the status message with its identifier, the name you gave it, its signal strength and estimated distance. The scan needs the location permission on every Android version, because Android counts a Bluetooth scan as a use of location; the app reads no position with it. NFC, when on, reads a tag held to the panel: its identifier and any text or web address written on it, both part of the status message, and the identifier is also sent to your broker on its own topic as a tag read. The names you give beacons are stored on the device like your other settings, as are the identifiers of the last twenty tags read and when each was read, so the automations can offer them. The app's own log, which the web admin shows and lets you copy or download for a support mail, carries what the app does: tag identifiers, the names of your automations, the addresses of sounds it was asked to play without their secrets, page errors and the network addresses locked out of the web admin.

Deletion

Uninstalling the app, or clearing its data, removes everything it has stored, including the encrypted credentials, the uploads, the previews and the cached pictures. The copies outside its reach are the retained status snapshot on your broker and, if you had pictures to the broker on, the camera's last picture, both of which you clear there.

If you buy Muralis Pro

The purchase is handled by Google Play. Google is the seller, takes the payment and issues the receipt. The developer never sees your name, your address or your payment details, and receives no report of who bought anything.

To know whether the remote-control features are unlocked, Muralis asks the Google Play app on the same device what the signed-in account has bought, and stores Google's signed answer, encrypted like the other credentials, so the panel stays unlocked with no network and no account. Whether Google Play then talks to Google's own servers is Google's business, covered by Google's privacy policy rather than this one. On a device without Google Play there is no one to ask, and the app asks no further.

Children

Muralis is not directed at children. It has no accounts, no profiles, no messages and nothing anyone can post, and it asks for nothing about the person using it. What it can send is the state of the device, described above, and it goes to your broker and your network, never to the developer.

Your rights

The GDPR gives you rights over personal data someone holds about you: access, correction, deletion, restriction, portability and objection. They run against whoever holds the data. For everything this app handles, that is you, on your own device and your own services, and the DELETION section above is how you exercise them there. The developer holds nothing beyond any mail you send him, which he answers and will delete on request. You also have the right to complain to a data protection authority; for the developer that is the Austrian one, dsb.gv.at.

Contact

Juri Calleri, Vienna, Austria. spazio17@protonmail.com.

A postal address is published on the imprint at muralis.spazio17.org, as Austrian law requires of it. It is kept in that one place rather than repeated here, so that changing it does not need a new release of the app.

This policy was last updated on 5 October 2026.

This website

The policy above is about the app. The website you are reading it on works like this: it is served by GitHub Pages, so opening a page sends GitHub the technical data any web server receives, including your IP address, which GitHub logs for security. GitHub Inc. is a US company certified under the EU-US Data Privacy Framework, and the legal basis for this processing is the developer's legitimate interest in publishing a website, Article 6(1)(f) of the GDPR. The details are in GitHub's own privacy statement.

The site itself sets no cookies, runs no analytics, and loads nothing from third parties: every font, stylesheet and script comes from this domain. If you pick a colour theme, that choice is stored in your browser and nowhere else, and only because you picked one.