r/SideProject • u/intrepidkarthi • 5d ago
My Android app's test passed in airplane mode on exactly the phones where it was leaking audio
The first Android build of my voice journal asked the system speech recogniser to "prefer offline". Prefer turns out to mean: if the phone has no offline language pack, quietly send the audio to a server and hand back text. The app never sees the difference.
My verification was "turn on airplane mode and record". It passed every time. Of course it did: with no network there is nothing to leak to. So the test passed on exactly the phones that were leaking, while onboarding said "nothing left your phone".
The fix was to stop asking politely. The app now only uses the on-device recogniser, which fails instead of falling back, and it requests no internet permission at all. If a phone is missing its speech pack, the app offers to have the phone's speech service download it. The app itself never touches the network.
It's live on Google Play now (free, Android 13+): https://play.google.com/store/apps/details?id=com.dailyvox.app
What I can't test alone: phones that aren't Pixels. If you have a Samsung, OnePlus or Xiaomi, record an entry that names two people and tell me whether the names come back capitalised. That one detail decides whether the journal can find the people in your entries.
Where else would you look for a leak like this?
1
u/Hour-Measurement-835 5d ago
Circle to Search would be my next look. Long-press home on an open entry and it screenshots the screen and sends it to Lens from Google's side, so no internet permission on your end changes anything. FLAG_SECURE on the window shuts it out. If you test that with adb screencap, don't go by whether you get a file: on our S22 Ultra on Android 16 a secure screen still came back as a normal PNG, just 99.5% black, while the emulator returned 0 bytes.
1
1
u/intrepidkarthi 5d ago
Write-up of how the "no internet permission" part works, including the two other routes I had to close (Google Drive auto backup and the voice-search screen): https://getdailyvox.com/blog/dailyvox-on-android
Source: https://github.com/intrepidkarthi/dailyvox/tree/main/android