ESPU Launcher: Home Studio Privacy Policy

Last updated: September 29, 2026

ESPU Launcher: Home Studio operates on your Android device without an ESPU account. The app contains no advertising SDK, ESPU-operated analytics service, subscription system, or remote customer-data service. Google Play services can deliver the unbundled Google ML Kit Latin OCR model after installation. ML Kit may transmit the SDK diagnostics and usage measurements described below, but selected files, recognized text, and recognition results are not sent to Google.

This policy describes the ESPU 3.2, version code 32 unrestricted Production candidate. It documents the candidate source behavior only; it is not production approval, production release authorization, or a claim that Google Play Production review is complete. ESPU 3.0/code 30 remains the same-certificate upgrade baseline only.

Data used on the device

ESPU reads apps that expose launcher activities so it can work as a home-screen replacement. It stores launcher preferences—such as your optional Home greeting name, favorites, recents, hidden choices, focus choices, freeform positions, themes, and quick notes—in the app's private local storage.

If you explicitly grant Notification Access, ESPU can display active notification titles and message previews in the ESPU Island and in the relevant app's long-press preview. ESPU can offer a reply when the source app provides Android's standard quick-reply action. Publisher text/action labels and explicit replies cross a bounded, Unicode-normalized native boundary; at most 100 exact active items and 128 KiB are exposed at once, and raw Android notification keys/action slots remain native-only behind generation-bound opaque handles. ESPU processes this information on the device and does not upload it. Notification content is not persisted by default; only when you explicitly choose Save for follow-up does ESPU copy that visible notification's title and text into the app-private Intent Inbox. Hidden notification content is never saved. Repeating charging, USB, battery, System UI, and persistent service notices are filtered from ESPU surfaces and remain Android's responsibility. If you choose a per-app Island snooze, ESPU stores only that app's package name and the snooze expiry in private local storage, with a maximum of 256 active entries.

If you explicitly grant Contacts access, that permission supports contact-aware onboarding, reviewed ESPU Control call or text handoffs, and optional Contacts results in Universal Search. ESPU reads contact display names, phone numbers, phone labels, and lookup keys on your device and refuses ambiguous contact matches. On Android 12 or later, a bounded copy of an eligible contact's display name, number, label, and lookup key is stored in app-private AppSearch solely for on-device Universal Search. ESPU Phone may also store up to eight favorite contact lookup keys, but no favorite names or numbers, in app-private preferences. Turning Contacts consent off purges those favorite keys immediately. Revoking Android Contacts permission purges them when ESPU Phone detects the missing permission, including when the Phone activity resumes. ESPU does not upload contact data. If Contacts permission or ESPU consent is revoked, ESPU excludes contact results and purges contact documents after the change is detected during an eligible search query or index rebuild. Clearing ESPU storage or uninstalling ESPU deletes this contact data.

If you explicitly use ESPU Control to call one exact person or ordinary phone number, ESPU first shows the exact contact and normalized number in a visible per-call review. Choosing Cancel or dismissing that review opens nothing. Carrier/USSD strings, pause/wait dialing codes, search results, suggestions, recommendations, and ambiguous contacts can never start a call. When ESPU is the Android-selected Phone app, confirming an ordinary reviewed number can request direct-call permission just in time and hand the call to Android Telecom. Otherwise ESPU opens a reviewed ACTION_DIAL surface and you make the final call choice there. Android owns emergency routing in both paths.

ESPU 3.2 can qualify as Android's optional default Phone handler, but never changes that role by itself. Choosing ESPU Phone opens Android's role chooser. Only while Android reports that ESPU holds the role can Android bind ESPU's InCallService and show the verified ESPU Island call surface. Direct-call permission is requested only after a reviewed ordinary-number call, and Phone-state access only after you ask to choose a SIM/eSIM. ESPU requests no SMS or Call Log permission and does not read, display, modify, or delete Android call history. On Android 12 and later, the normal HIDE_OVERLAY_WINDOWS permission keeps non-system overlay windows off visible ESPU launcher, Phone, call, keyboard-settings, and protected-confirmation windows while those windows are active; ESPU does not request SYSTEM_ALERT_WINDOW or draw over other apps. An unfinished keypad entry is held only in current-process memory for Activity recreation, never in a preference, file, saved state, backup, log, or analytics, and disappears when cleared or the process ends. Denial leaves a safe dialer or unavailable path. Active-call and contact rows remain transient, are not uploaded, and ESPU does not record call audio. Android retains protected emergency routing and Telecom authority. ESPU does not register as Android's default Assistant handler.

If you choose a voicemail audio file through Android's document picker, ESPU can transcribe a supported mono 16-bit PCM WAV locally with the integrity-verified Vosk model. The selected audio, transcript, and extractive summary remain in process memory unless you explicitly save them as an ESPU Note. ESPU does not record cellular calls, read carrier voicemail automatically, retain the selected audio file, or upload its contents. Unsupported files and an unavailable verified model produce an unavailable state rather than a remote fallback.

ESPU does not request Phone-state or direct-call permission during first-run setup. Those permissions remain just-in-time inside the exact ESPU Phone action that needs them. ESPU requests no SMS or Call Log permission, provides no Android call-history browser or deletion tool, and leaves reviewed message drafts to Android's selected messaging app.

If you enable screen-lock access, Android grants ESPU only the device-admin force-lock policy. ESPU can invoke it only after you deliberately double-tap the Home Welcome heading, confirm an ESPU Control lock request, tap Lock now in Settings, confirm Test lock now in Focus Hub, or run an advanced gesture explicitly bound or rebound to Lock screen. ESPU does not lock on its own, erase the device, change or reset its screen-lock credential, restart or power off the device, or administer any other policy. This access is optional. To remove it, open ESPU Settings → Lock screen → Manage lock access, open ESPU screen lock in Android, and tap Deactivate; force-lock stops immediately and ESPU's launcher data remains in place.

Private Space uses Android's system authentication prompt. ESPU does not receive or store fingerprint, face, PIN, pattern, or password data. Hidden choices affect ESPU's interface; they do not uninstall or encrypt an app.

ESPU does not request hidden-profile access and does not expose or control Android's system Private Space. If Android nevertheless reports an app as belonging to a private profile, ESPU excludes it from ordinary All Applications. This is separate from ESPU's own hidden-app Private Space described above.

Battery/charging status, power-saver state, local time zone, and Android wallpaper colors may be read locally to adapt the interface. ESPU does not request location access.

An explicit foreground sound-profile request can read or change Android's ring, vibrate, or silent ringer mode through AudioManager. On devices that require Notification Policy access for that change, ESPU explains the need and opens Android's special-access settings; it does not grant itself access, edit Do Not Disturb rules, toggle unrelated radios/settings, or claim success until the resulting ringer mode is verified. Revoking that access leaves the feature unavailable.

Optional ESPU Calendar, scheduled routine, and Launcher Health reminders use Android JobScheduler and local notifications only after you enable them. RECEIVE_BOOT_COMPLETED lets ESPU restore those schedules after a restart or app update. Calendar reminders carry bounded event display/timing metadata, use private notification visibility, and do not request exact-alarm access. A scheduled routine can surface only a Review & Run cue; it cannot execute steps in the background.

Focus Hub offers optional Android Usage Access. Only after you explicitly grant this special access in Android Settings does ESPU read package name, foreground duration, and last-used time for a current-day, on-device screen-time summary. The raw usage data has no network path and is not persisted. ESPU stores only one non-identifying prior-grant bit in app-private preferences so it can distinguish access that was never granted from access that was later revoked; clearing ESPU storage or uninstalling ESPU deletes that bit.

Mindful Open is an optional digital-wellbeing pause shown before apps you designate for added friction. It uses a short countdown and a decorative breathing animation; it is not medical care, diagnosis, treatment, or measured breathing guidance. ESPU stores only aggregate counts of stay mindful and proceed anyway decisions in app-private local storage. It stores no app package, timestamp, launch history, or Usage Access record in this summary. The “estimated minutes not spent” value is calculated as five minutes for each avoided open and is not measured device use. Reset summary, Android Clear storage, or uninstall deletes the aggregate summary.

ESPU Deck is an optional Android keyboard. Android requires you to enable it in system Input Method settings and choose it before it can type into another app. Ordinary key presses go directly to that app's active text field through Android's InputConnection; ESPU Deck does not send ordinary typing to React, ESPU Control, storage, analytics, or the network, and it does not passively read surrounding text. Its ESPU Control bar stays collapsed until you tap ESPU. Only after you tap Ask, Fix, Rewrite, or Shorten does ESPU Deck read text for that request: your exact selection wins, or, when nothing is selected, it reads a bounded portion of the current ordinary-text field around the cursor; Ask opens a blank prompt only when that field is blank. The chosen text is limited to 4,000 characters, held only in a same-process one-shot memory buffer for at most two minutes, never placed in an Intent, log, file, preference, or clipboard, and removed when consumed or expired. The launcher opens it as an editable review draft and never submits, inserts, sends, or runs it automatically. Editor-text writing tools are allowlisted only for documented ordinary text editors and are off for unknown/custom editor classes, no-personalized-learning fields, all number and phone fields, password variations, and fields whose Android/app metadata identifies payment, verification-code, private, or other sensitive use. On Android 11 and later, ESPU Deck can host a verification-code suggestion supplied by Android Autofill; receiving an Autofill suggestion disables the ESPU Control row for that editor. The keyboard does not read SMS or notifications and never retains the code. ESPU requests no SMS permission. Only appearance and key-haptic choices are saved as keyboard preferences.

ESPU Control processes typing and explicit voice requests locally through its compact Action Model and bounded deterministic command handlers. Each supported action still uses the same permission, role, confirmation, current-state, and result checks at its execution boundary. ESPU can open installed apps and supported Android destinations, start timers, open alarms and calendar views, prepare communication or calendar drafts for review, control an active media session, answer limited device-status questions, and change supported ESPU launcher settings. “Deep Thinking” is deterministic on-device planning and comparison logic; it is not a remote generative-AI service and does not claim live facts.

ESPU Control includes ESPU's own compact Action Model in the signed app. Its signed base is immutable at runtime. It recognizes supported requests and proposes typed actions, but it has no Android privileges. Reviewed code still enforces device capability, profile privacy, roles, permissions, confirmations, and result checks. It is an action model, not an open-ended language model, and it does not claim cached facts are current.

Optional automatic action learning is off until you enable it. When enabled, a bounded local action-matching adapter learns hashed feature weights only from verified low-risk outcomes; it does not change the signed Action Model base. You may separately teach a private phrase only by linking it to one supported low-risk open action; ambiguous, sensitive, external, contact, message, search, and navigation examples are rejected. ESPU does not keep raw commands, contact names, phone numbers, message text, or document contents as action-model training examples. You can disable, inspect, forget, reset, or erase that adapter. Android Clear storage or a full uninstall removes it. Apart from the explicit selected-file OCR described here, no remote vision, general background screen reader, cross-device, app-skill, enterprise, or OEM provider is active in ESPU. Any later provider would require separate signed delivery, review, compatibility, consent, and real device authority.

ESPU 3.2 also contains a local planning foundation. For supported planning wording, its deterministic path can create an expiring, preview-only plan card and Goal Space proposal for focus, travel, study, commute, accessibility, or general preparation. These responses contain bounded text, modules, and source labels; they do not contain executable code and do not change the launcher by themselves. ESPU does not offer a downloadable answer model, accept imported model files, or use a hidden remote generative-AI fallback. General document Q&A and general camera, screenshot, or screen understanding remain unavailable.

When a request needs open-ended or current knowledge, ESPU shows the exact request and shares nothing before you choose Continue. Continue asks Android to offer that text to your selected assistant through the public ACTION_ASSIST intent or, if no compatible assistant opens, through the disclosed public ACTION_WEB_SEARCH intent fallback. The receiving app or provider applies its own privacy and retention terms and may ask you to repeat the request. ESPU does not receive the other app's answer in the background and does not become Android's default Assistant. Cancel or an unavailable route sends nothing.

The 3.2 personal-context foundation can store a personal memory only after direct user entry or explicit confirmation. Each stored item is a bounded summary with a category, source label, approval time and required expiry. Likely raw secrets are rejected. The app-private local store holds at most 128 memories and allows no more than 366 days of retention. A session capsule similarly stores only bounded ESPU task-continuity metadata—a title, objective, optional next step, opaque local resource references and checklist state—after direct entry or confirmation. It does not copy another app's screen or internal state. At most 32 capsules are retained, each with at most 16 resource references and 24 checkpoints and a maximum 90-day retention period.

When eligible local context is requested, ESPU can synthesize at most eight approved, unexpired memory or capsule fragments and 2,400 characters into a non-persisted envelope that expires after 60 seconds. The synthesizer does not store the retrieval query or conversation transcript and returns no context while ESPU Control is paused. Memory and capsule records use app-private local AsyncStorage; they are not represented as encrypted at rest and are not automatically included in the passphrase-encrypted Personal Archive. They are not used to train the Action Model or private neural predictor.

To support immediate follow-up questions and missing-detail prompts, ESPU stores a short local conversation window in app-private AsyncStorage: at most 40 user/assistant turns, 2,000 characters per turn, plus at most eight bounded clarification fields. This record is not encrypted at rest or included in Personal Archive. It expires 15 minutes after the last update; expired, future-dated, or malformed state is physically deleted the next time it is read. Erase ESPU Control data, Android Clear storage, or uninstall also removes it.

ESPU keeps up to 100 local execution receipts so it can show whether a reviewed action completed, failed, was cancelled, or was handed to Android. A receipt contains bounded request/action identifiers, source, risk and confirmation mode, status, verification authority, and start/finish times. It does not persist the raw command or result message. Receipts remain in app-private AsyncStorage until you erase ESPU Control data, clear app storage, or uninstall ESPU.

Clipboard Vault never monitors Android's clipboard. It stores text only after an explicit visible import, rejects likely authentication secrets, financial numbers, and government identifiers, and holds at most 20 entries of 4,000 characters each. You choose a 15-minute, 1-hour, or 24-hour expiry. Expired or malformed entries are physically removed when read, and you can erase all entries immediately. Vault text uses app-private AsyncStorage but is not encrypted at rest or included in Personal Archive. Opening External Brain does not read the system clipboard. Only after you choose Check clipboard does ESPU perform one foreground read of at most 4,000 literal text characters; Android-marked sensitive clips and other sensitive-looking text are rejected, the accepted preview remains in process memory, and nothing is saved until you separately choose Note or Event.

Optional local family profiles retain at most eight user-authored profile labels and, per profile, eight trusted-contact labels, relationship labels, and Android Contacts lookup queries. ESPU resolves current phone numbers from Android Contacts only when you request a reviewed call or message handoff; resolved numbers are not saved in the family-profile store. Profiles remain until you remove them, clear ESPU storage, or uninstall ESPU.

Optional product experiments and feedback diagnostics both start off. If enabled, ESPU stores at most 20 random experiment/variant assignments and 80 aggregate metric records; it stores no raw experiment-event stream and uses no device or account identifier. A separately user-authored feedback draft can contain a 1–5 rating and up to 2,000 characters. Sharing creates only a five-minute in-memory preview and opens Android's share sheet after confirmation; ESPU never sends it automatically. Turning experiments off clears assignments and aggregates. Reset, Android Clear storage, or uninstall removes the remaining experiment and feedback record.

After qualifying verified use, ESPU may ask Google Play to display Play's unmodified in-app review card. You choose whether to enter a rating and optional free-text review. Google Play—not ESPU—receives that content over an encrypted connection and uses it for a public Play review, or shares it privately with the developer while the app is in Closed testing. ESPU cannot read the submitted content or whether a review was submitted. You can delete the review in Google Play or your Google Account.

Google Play services can begin delivering the unbundled Latin OCR model after ESPU is installed; that model delivery is separate from permission to read a file. Before opening the selected-file OCR picker, ESPU offers Agree and choose file or Not now and discloses the Google ML Kit SDK data below. If you agree and explicitly select a JPEG, PNG, WebP, or PDF, recognition runs on-device after the model is delivered. If delivery is incomplete, ESPU shows a deterministic Retry OCR action and does not treat an empty result as success. Images are bounded and PDFs are limited to the first three pages. ESPU persists only the selected content URI and basic searchable attachment metadata; recognized text and receipt hints remain in process memory unless you explicitly save them as a Note. Forget releases the persisted Android read grant. ESPU does not request broad photo/file access, capture screenshots, operate an Accessibility service, scrape another app, or upload the selected content. Google states that ML Kit processes feature inputs and outputs on-device. Its SDK may transmit encrypted diagnostics and usage measurements such as app/device information, a non-user-identifying per-installation identifier, performance, API configuration, input/output sizes, feature version, event type, and error codes; Google states those measurements are not shared with third parties.

Suggested Apps & Coach learning is a separate opt-in control and on-device adapter; it does not modify the signed Action Model or its action-matching adapter. Each bounded, profile-aware app or allow-listed action target uses its own 20 → 8 → 4 → 1 multilayer perceptron with two hidden layers. Its score is advisory and can only rerank suggestions already admitted by ESPU's existing contextual or Coach rules. Everyday Apps remains the default Home dock, and manual ordering or an explicit customer choice always wins.

The private neural store can contain bounded profile-aware app/action identifiers, counters and coarse context metadata, per-target weights and biases, and at most 48 anonymous training timestamps used only to enforce the strict trailing-24-hour quota. The quota timestamps have no target or content association and are not a raw app-activity timeline. The store does not retain raw commands, note/document/message/contact content, or a copy of the installed-app catalog. Training occurs only when Private learning is enabled and ESPU receives a verified low-risk outcome or explicit suggestion feedback. ESPU skips optional training under app-lifecycle, battery/power, thermal, or memory pressure and accepts no more than 48 updates in a trailing 24-hour window. There is no timer, background training service, network upload, or cloud-model synchronization. You can delete one exact app/action target and its counters/model or globally reset private neural prediction. Turning learning off stops new training and hides learned suggestions.

ESPU 3.2 is Suggestions-only for private-neural output. Neural output cannot open an app, change a setting, execute a routine, create a grant or permission, or call an executor. Scheduler cues remain not-run Review & Run presentations. Suggested Apps remains unavailable until ESPU records at least 3 successful launcher opens across at least 2 local days, and appears only after you explicitly select Suggested. ESPU never opens the suggested app by itself, and Coach setting changes require your approval. You can inspect or reset learned and taught matching signals. While Private Space is locked, ESPU Control filters hidden apps from notification results.

ESPU Notes stores up to 120 plain notes or checklists, including the compatible Quick Note, in versioned app-private local storage. Records can contain titles, bodies, checklist items, pin choices, revisions, and created/updated times. ESPU has no email-account connector or automatic mailbox sync. If saved Notes data cannot be read safely, ESPU does not overwrite it; it preserves one app-private recovery copy capped at 2,500,000 characters. You can export that copy, start clean while retaining it, or permanently delete it through a separate confirmation. You can also review, edit, delete, or undo deletion of readable notes. ESPU does not continuously read another app or mailbox.

Android Share or Process Text are transient capture entry points. Selecting ESPU passes only the text you selected into a bounded one-shot process buffer and opens it for review in External Brain; selecting ESPU alone does not create an Intent Inbox record, Note, task, or event. Data is persisted only after you explicitly choose an action such as saving a Note, adding a backlog task, or scheduling an ESPU Calendar block. Manual Intent Inbox drafts and notification content explicitly saved with Save for follow-up remain separate bounded local records that you can review or delete. If Intent Inbox data becomes unreadable, ESPU preserves one app-private recovery copy capped at 750,000 characters; you can export it, start clean while retaining it, or permanently delete it through a separate confirmation. Calendar, call, message, and other Android-owned handoffs still require their own review and are not treated as complete merely because a draft surface opened.

External Brain stores at most 180 outstanding backlog tasks in app-private local storage. A task can contain its title, backlog/scheduled state, optional ESPU Calendar event identifier and scheduled time, and created/updated times. Scheduled work is owned by the matching ESPU Calendar event; scratchpad and meeting notes are owned by ESPU Notes. Completing or clearing a backlog does not silently delete linked Calendar events or Notes. If the backlog cannot be read safely, ESPU preserves the unreadable raw record in a separate app-private recovery entry and blocks overwrite until you explicitly start an empty backlog. You can inspect or export that saved recovery copy and can delete it through a separate confirmation; confirmed Delete copy, Android Clear storage, or uninstall removes it.

ESPU Calendar stores up to 300 events you create in versioned app-private storage on this device. Records can include title, times, all-day state, location, details, basic recurrence, reminder timing, and an optional local Notes identifier. Pasted meeting text or a VEVENT is previewed before you save it. If the private Calendar store becomes unreadable, ESPU preserves one app-private recovery copy capped at 1,500,000 characters; you can export it, start clean while retaining it, or permanently delete it through a separate confirmation. When you explicitly open External Brain's Schedule view or schedule a backlog task, that visible foreground Calendar interface reads the same private events it creates so it can show the day and avoid overlapping blocks; this is not an AI context export. ESPU Control can search or use private ESPU Calendar records as answer context only after you enable the separate Use private events with ESPU Control choice; it is off by default and does not grant Android Calendar permission. Reminder scheduling copies only bounded display/timing metadata into app-private native preferences, requires notification permission on Android 13+, and uses inexact delivery. Export is a separate action that opens an Android Calendar draft for your review; ESPU does not request Calendar write permission or silently copy the event to an account.

The optional Android Calendar Agenda is off by default and asks for Android's read-only Calendar permission only after you explicitly choose Calendar access in first-run Optional features or Enable agenda in Today and accept the preceding ESPU disclosure. Skipping either choice leaves access off. Each read covers at most the next 36 hours and 24 items across Android's unified provider, including events synchronized by accounts or written through that provider. Results are reused in process memory for at most 60 seconds and are cleared when you turn the feature off or the app process ends. ESPU does not persist provider agenda records, query attendees, account addresses, organizers, or event notes, or access arbitrary app-private sandboxes.

Selected Document Search accepts at most 12 UTF-8 text, Markdown, CSV, JSON, or XML files of up to 256 KiB each, chosen explicitly through Android's document picker. ESPU stores each selected content URI, display name, MIME type, size, added time, and last-indexed time in app-private storage and retains Android's read grant so the original can be searched or opened later. Extracted text is held only in process memory, is never uploaded, and is not a general document-answer model. Forget or Forget all removes the record, clears its memory index, and releases Android access; Android Clear storage or uninstall removes all records and grants.

Personal Archive can create a passphrase-encrypted copy of ESPU Notes, today's priorities, validated routines, AI privacy choices, and Island preferences in a folder you choose through Android's Storage Access Framework. AES-256-GCM encryption happens before Android writes the file to the selected provider. ESPU does not save or recover your passphrase, has no provider account integration, and performs no automatic or background archive sync. Preview, per-section conflict choices, export, import, encrypted-copy deletion, folder-access release, and erasing the covered on-phone data are explicit foreground actions. The selected provider can observe file metadata and may transport the encrypted file under its own terms.

ESPU is an Android Home app with an optional default-Phone handler, not an operating system. Android owns Telecom, emergency routing, protected system UI, car-display and Android Auto surfaces, role and permission prompts, package installation, and package removal. ESPU does not have unrestricted access to your phone. Android permissions, installed-app support, confirmation screens, and protected-system limits determine which actions can run. ESPU does not bypass Android security, silently send messages, call from an unreviewed target, save calendar entries without review, install apps, change protected settings, or read another app's private data.

ESPU Control does not access, read, or store passwords, PINs, banking details, or payment credentials. Never enter them in an ESPU Control command.

Voice is tap-to-talk. Before first use, you can choose Agree and continue for ESPU's one-session microphone path or Not now. ESPU does not keep a background wake listener or microphone foreground service. With microphone permission, built-in Vosk recognition processes the one request on-device without saving, uploading, or learning from audio. If on-device recognition is unavailable, voice input is unavailable and you can type instead; ESPU never switches to Android speech or another online recognition provider. ESPU may read an on-device answer aloud after a voice request, including an approved personal-context answer, only through a TTS voice that Android identifies as not requiring a network connection. If no such voice can be selected and verified, the answer stays visible and speech reports unavailable; ESPU never falls back to a network-required TTS voice. ESPU has no voice-upload server.

Integrated ESPU live weather is permanently retired. ESPU does not ask for a city or postal code, retrieve a temperature or forecast, contact a weather provider, or retain a later activation path. Home ambience is selected manually or follows the device clock, and a legacy @espu_weather_sync_v1 profile is ignored and erased when the production runtime reads weather state. You can separately add a compatible Android weather widget; its provider app supplies and processes that widget under its own privacy terms.

If you choose My Photo, Android's system picker grants ESPU access only to the image you selected. ESPU decodes it locally, applies its orientation, strips other source metadata through re-encoding, and keeps an optimized JPEG copy in app-private storage so Home and Lock wallpaper do not depend on the source provider. ESPU retains at most four optimized My Photo copies while photos are replaced, plus the active content reference and locally sampled average color. Remove My Photo deletes every app-owned optimized copy and its saved references; Android Clear storage or uninstall does the same. ESPU never deletes the source image, requests no broad gallery or file access, and does not upload the photo. Android Auto and other car-display backgrounds remain independently controlled by Android and the vehicle.

ESPU listens for Android package-added and package-removed events so newly installed launcher apps can appear without a manual reload and confirmed removals can disappear. Choosing Uninstall opens Android's required confirmation screen; ESPU refreshes its local launcher data only after Android confirms the package is gone.

Android widgets remain provided by their source apps. ESPU shows one compatible widget choice per visible installed app and stores Android-assigned widget identifiers locally so it can host up to four independent Home widget cards. Removing a widget releases its identifier but does not uninstall its provider app.

Sharing and backup

ESPU does not automatically share personal data. If you choose Export Backup, ESPU creates a readable JSON file of launcher preferences and hands it to Android's system share interface. You choose the destination. Backup files can contain app package names and hidden/focus choices. The handoff requires one app-private plaintext cache copy; ESPU deletes any prior handoff copy before export and deletes the current copy after 15 minutes while the process remains alive, or on the next app start, Android Clear storage, or uninstall. A destination you choose remains under that provider's retention controls.

Personal Archive is separate from that readable backup. It manages only the encrypted ESPU-Personal-Archive.espu file in a folder you explicitly select. ESPU writes no plaintext archive payload through this path.

Retention and deletion

Launcher data remains on the device until you change it, restore a backup, clear ESPU storage, or uninstall ESPU. Notes, Calendar events, External Brain backlog tasks, Intent Inbox drafts, and their bounded recovery copies remain until the applicable in-app remove/reset/erase action, Android Clear storage, or uninstall; starting clean after recovery retains the copy until you separately export or delete it. Mindful aggregate counters, family profiles, feedback drafts, and execution receipts follow their applicable in-app controls. Approved personal memories expire no later than 366 days after creation; session capsules expire no later than 90 days after creation; conversation state expires after 15 minutes; Clipboard Vault items expire after the selected 15-minute, 1-hour, or 24-hour period. Expired or malformed bounded records are removed when their store is read. An encrypted Personal Archive remains in your selected folder until you delete that named copy there or through ESPU; forgetting the folder releases ESPU's access but does not delete the file. ESPU never retains the archive passphrase. ESPU Control settings let you inspect or forget Action Model action-learning signals and reset that adapter. Private neural controls separately delete one exact app/action target or globally reset neural prediction. A focused erase removes all ESPU Control-owned adapter and suggestion state, conversation state, execution receipts, personal memories, and session capsules without removing your launcher layout or apps. Notification content is not copied by default; a draft copy exists only after Save for follow-up. Revoking Notification Access stops ESPU from reading active notifications but does not silently delete drafts you previously chose to save. ESPU does not create a user account.

Network access

Direct device commands, deterministic planning previews, personal-context retrieval, the built-in ESPU Action Model, offline Vosk recognition, and opt-in bounded learning have no ESPU Control server or remote generative-model integration. ESPU does not send requests or results, speech audio, personal memories, session capsules, learned app-use profiles, Action Model learning weights, installed apps, contacts, notifications, Home layout, launcher data, or command history to an AI provider in the background. A request leaves ESPU only after you review and continue the disclosed Android assistant or web-search handoff described above; the receiving app applies its own terms. Google Play services may use the network to deliver the unbundled OCR model. The OCR SDK diagnostics described above can include app/device information and a non-user-identifying per-installation identifier, but not the selected image, recognized text, or recognition output.

The signed base install includes ESPU's wallpaper collection, all 10 theme assets, and offline Vosk voice assets. These features do not use Google Play Asset Delivery, require a separate asset download, or add an asset-delivery data-processing path. The built-in ESPU Action Model likewise does not require a separately downloaded model archive.

When you manually export or apply a reviewed Personal Archive sync, Android may give the encrypted archive file to the local or cloud-backed document provider you selected. ESPU receives no provider account token and gives that provider no plaintext archive data. ESPU does not schedule later transfers; the provider independently handles any transport.

Contact

Developer: Spes Acharya. Visit the official product site at espulauncher.com. For support, privacy questions, or data requests, email engineerspes7@gmail.com.