Last updated: 5 September 2026
This policy explains what data the npm Registry app processes, why, and who receives it. The app has no user accounts and never asks for your name, email address or any other personal detail.
Controller
Daniel Sogl, Helmut-Kohl-Str. 1, 76661 Philippsburg, Germany. Email: me@danielsogl.de.
Full contact details are in the legal notice.
Data that stays on your device
The packages you bookmark and the counters that decide when the app may ask you for a review are stored only on your device, in the app's own storage. They are never transmitted to us or to anyone else, and they are removed when you uninstall the app.
Requests to the npm registry and other services
To show you anything at all, the app queries public APIs. Every request necessarily reveals your IP address and the content of the request to the operator of that service:
- registry.npmjs.org and api.npmjs.org (npm, Inc.) — your search term, the names of the packages you open, and download statistics.
- api.npms.io — the name of the package you open, to retrieve its quality, popularity and maintenance scores.
- icanhazdadjoke.com — a request for the random joke shown on the empty search screen. Nothing about you is sent with it.
Legal basis: performance of the service you asked for (Art. 6(1)(b) GDPR) and our legitimate interest in operating the app (Art. 6(1)(f) GDPR).
npm's own privacy policy: https://www.npmjs.com/policies/privacy
Firebase (Analytics, Crashlytics, Performance Monitoring)
The app uses Firebase, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to understand how the app is used and to find crashes.
- Analytics: which screens you open, that a search was run — only the number of characters in your query is recorded, never the query itself — and that a package detail page was opened.
- Crashlytics: crash reports, stack traces and error logs.
- Performance Monitoring: app start times and the duration of network requests.
- Alongside these, Firebase records a randomly generated app instance ID and technical device data such as operating system version, device model and language.
The app uses no advertising identifier. On Android the advertising-ID permission is actively removed from the app; on iOS there is no advertising SDK and no tracking permission is requested. Nothing is collected until you agree: all three Firebase services are switched off natively at every launch, and the app asks on first start. Legal basis: your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can withdraw it at any time under About › Share usage data, with effect for the future (Art. 7(3) GDPR).
Firebase's privacy information: https://firebase.google.com/support/privacy
Transfer outside the EU
Google processes data both inside the EU and in the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework, and Google's standard contractual clauses apply in addition.
Retention
Analytics events, crash reports and performance data are kept for the retention periods configured for the Firebase project and are then deleted or aggregated. Data held only on your device disappears when you uninstall the app.
Your rights
You have the right to information, rectification, erasure, restriction of processing and data portability, and the right to withdraw your consent at any time under About › Share usage data (Art. 15–21, Art. 7(3) GDPR). Write to me@danielsogl.de.
Because the app collects nothing that identifies you, we usually cannot link a request to a particular record — please describe what you need so we can help. You may also lodge a complaint with a supervisory authority (Art. 77 GDPR).
Encryption
Every request the app makes uses TLS (HTTPS), so the content in transit cannot be read by third parties.
Changes to this policy
We update this policy whenever the app's data processing changes. The date at the top shows the current version.