Laminae

Privacy Policy — Aesthesia

Aesthesia is made by Laminae Limited (NZBN 9429053217417), New Zealand.

This is the privacy policy for the Android app Aesthesia, package nz.co.laminae.field, version 0.4.0 (build 12).

  • Effective date: the day this build is released to testers
  • Last updated: 1 October 2026
  • Policy version: 1.0
  • Where to read it: in the app, under Privacy in the menu. A copy is on our website at laminae.co.nz/privacy.

Aesthesia is a beta. This policy describes the build named above. When the app changes, this policy changes with it.


In short

Aesthesia draws a field of shapes on the screen and can play it as a sound. Your finger drives the field. The sound in the room can drive it too, if you choose the microphone in the field's settings.

Aesthesia keeps what it uses on your phone, and uses it only for what you ask the app to do. It has no internet permission, so it cannot send anything to us or to anyone else. There are no adverts, no analytics and no crash reporting. There is no account and no sign-in.

By default the app stores nothing about you. It stores something only when you do something that asks for it, and each is described below: an audio check you start, a timer you start, a recording you make.

One thing the app can write outside its own storage: if you switch on the plain copy when you record a take, it writes an ordinary .wav file into your phone's shared Music/Laminae folder. That file is a normal file on your phone. Other apps that can read audio or media can read it, and it stays on the phone after you uninstall Aesthesia.

What the app listens toThe microphone, only while you have the sound switched on.
What it works out from moment to momentA level, a peak, how much of what it hears is the app's own sound coming back, and how much sits on the notes the field is playing. These numbers move the field if you have chosen the microphone, and are then gone. They are not written down.
What it stores by defaultNothing.
What it stores when you askThe room's loudness during an audio check you start; the times of a timer run you start; a recorded take. All on the phone.
What the app sends over a networkNothing. It holds no network permission.
What can leave the app's controlThe plain .wav in Music/Laminae, because it sits in shared storage where the rest of your phone can reach it.

Sealed in this policy means encrypted so that only this phone can read it.


What the microphone is used for

This matters more than any other part of the policy, so it is set out in full.

While the sound is on, the app has the microphone open. From each short slice of audio it works out four numbers: how loud the slice is, how high its peak is, how much of it is the app's own output coming back through the speaker, and what share of it sits at the notes the field is playing. It does not keep the sound, and it does not keep those numbers.

Those numbers move the field only if you choose the microphone. In the field's settings, under Chaos from, the choice starts on The field's own generator. If you choose The microphone, a loud, sharp sound (a clap, a knock, a tap) puts a burst of energy into the field at a random place, in proportion to how hard it was, and the steady change in the room's level acts on the field as a kind of wind. The choice goes back to the field's own generator each time the app starts. While the sound is on and the microphone is not chosen, the microphone is open and nothing from it moves the field.

The audio check, on the Diagnostics screen, stores the room's loudness. It runs only when you start it. For the few seconds it runs it plays a test tone and some clicks, and it stores the room's loudness, one number between 0 and 1, sealed, at most once a second. No audio is stored. If no key is available, the check stores nothing rather than store it unsealed.

A recorded take is different. If you use the mixer to record, real audio is written to a file. See "Recording, and the plain copy" below.


Permissions, and what each one is for

These are the permissions the released build declares.

PermissionWhat it is forWhat is keptDoes it go over a network?
Microphone (RECORD_AUDIO)To let the room drive the field if you choose it, to run the audio check, and to record a take if you ask for one. You are asked for this the first time you switch the sound on, not when you open the app.Nothing, unless you run the audio check (the room's loudness, sealed, while it runs) or record a take.No. The app has no network permission.
Microphone while in the background (FOREGROUND_SERVICE_MICROPHONE)So the sound keeps going while you are in another app or the screen is off. This means the microphone can be open while Aesthesia is in the background. It applies only while the sound is on.Nothing of its own.No.
Background service (FOREGROUND_SERVICE, FOREGROUND_SERVICE_SPECIAL_USE)To keep the app's one background service running, so the field and its sound carry on when you leave the app, and so a timer you start keeps its times.Nothing of its own.No.
Notifications (POST_NOTIFICATIONS)To show the ongoing notification that tells you the service is running. You are asked the first time you open the app (Android 13 and later); if you decline, the service still runs but the notification does not appear. It reads Listening while the microphone is open and Collating when it is not. It is titled Aesthesia, and so is its entry in Android's notification settings.Nothing.No.
Fingerprint or screen lock (USE_BIOMETRIC)So Android can confirm it is you before a vault secret is shown. The app never sees your fingerprint, your face or your PIN. Android answers yes or no.Nothing.No.
Storage, Android 8 and 9 only (WRITE_EXTERNAL_STORAGE, capped at SDK 28)Only to write a plain .wav copy of a take into the shared Music folder on older phones, and only when you ask for one. Android 10 and later never see this request.The .wav file you asked for.No.

Android also gives the app one permission for its own internal use. It collects nothing.

No network permission ships in the released app. The build tool refuses to make a release whose final permission list includes internet access. (Development copies used at a desk carry it, as every project of this kind does; they are never published.)

Removed from this build, and therefore impossible here: location, activity recognition, calendar, app-usage statistics, network state, and every Health Connect reading. They belong to the full Laminae Console, which this app is made from, and this build removes them, along with the entries Health Connect uses to reach an app.

One thing you may still find. The app's code includes Google's Health Connect software library. Aesthesia asks for no health permission and reads no health data.


Where your data is stored, and how it is protected

Everything the app keeps is written into the app's own private folder on the phone, except a plain .wav copy if you ask for one. There is no server, no account and no sign-in.

The room's loudness from the audio check is classed as sensitive and sealed with AES‑256‑GCM, each record on its own with a fresh random value. The key is 32 random bytes made on the phone the first time the app runs. It is held in Android's encrypted storage, backed by the phone's own keystore. It never leaves the phone and is not known to Laminae Ltd.

Timers. If you turn a timer series on (on the What is collected screen) and start a run with the timer command, the app stores three numbers for that run: time elapsed, time remaining and progress. They are a clock you start, not anything about you, so they are kept unsealed. The switch goes back to off each time the app starts. The app's settings are also kept unsealed.


Recording, and the plain copy

When you record a take in the mixer, the app writes a sealed recording inside its own private folder. That file can only be read with the key on your phone. A take stops by itself after five minutes, and while one is recording the app shows a red dot and the time.

The mixer has a single plain copy switch, and it starts off.

  • With it off, the take exists only in sealed form, and no readable audio is written anywhere.
  • With it on, the app also writes an ordinary .wav file into your phone's shared Music/Laminae collection, so you can find it in a music or files app. That file is not encrypted. A working copy is made while the file is written and is deleted immediately afterwards.

What the plain copy means in practice. Once a .wav is in the shared Music collection it is an ordinary file on your phone:

  • any other app that has permission to read audio or media can read it;
  • any cloud-sync, file-manager or backup app you have installed can copy it off the phone;
  • it stays on the phone if you uninstall Aesthesia or clear its data.

Aesthesia having no internet permission does not limit what the rest of your phone does with that file. If you would rather nothing readable existed, leave the plain copy switch off.

Other people's voices. A recording made in a shared room may capture other people. Aesthesia does not know who is in the room and cannot ask them. If you record other people, it is for you to tell them and to handle the recording accordingly.


Controlling the app from a computer, in this test build

This test build lets a computer connected to the phone control the app. It is protected by a code made once when the app is installed.

You should know four things about it:

  1. The code is kept unencrypted in the app's own private folder, which other apps cannot open. It is also shown on the app's Commands screen, with a ready-made line for a computer to type.
  2. The code is written to the phone's system log when the app starts, and again every time a wrong code is offered. A computer connected to the phone with USB debugging turned on can read that log, so it can learn the code. The answers to commands, including any stored values read back, are written to the same log.
  3. Every command ships, including the ones that read, export and erase what the app has stored, and the ones that work on the vault.
  4. The same commands can be run on the app's own Commands screen.

So, in this test build, an app on your phone that holds the code, or a computer with USB debugging access to your phone, can read what Aesthesia has stored. That is a weakness of the test build, not an intended feature, and it is on the list of things to fix before wider testing.


The vault

The vault is a separate place for secrets you type in yourself: an id, a name, an optional account name and the secret. It is sealed under its own key, separate from the key that seals everything else.

  • A secret is shown only after Android has confirmed you are the owner, by fingerprint or screen lock.
  • The list of entries (their names, account names, and when each was changed and last used) is shown without that confirmation, and can be read over the computer connection described above.
  • You can start the unlock from the vault screen or from its tile in the notification shade.
  • The unlocked session ends after three minutes without use, when you leave the app, or when you close the vault screen.
  • The vault screen is marked secure, so it does not appear in screenshots or in the recent-apps preview.

One qualification, stated plainly: while the vault is unlocked, a request from a connected computer to show a secret is answered without asking again. The check is on the unlocked session, not on each request. This is on the list of things to fix before wider testing.


Backups

Android's automatic backup is turned off for this app, and the app excludes every part of its storage from cloud backup and from moving to a new phone. So nothing in Aesthesia's private folder is copied to your Google account, and nothing is carried across when you set up a new phone.

If you use a backup or file-sync app of your own that copies your Music folder, a plain .wav from Music/Laminae will be caught by it. That copy is outside the app's control and is governed by whatever service you used.


Testing, and what reaches us

During the beta, the only information that reaches Laminae Limited is what you choose to send us, such as feedback by email. We use it only to find patterns that help us make the app better for you. We remove anything that identifies you before we analyse it, and we delete it once the analysis is done. There is never a shared central store of your data.


What this app never does

  • It never sends your data over a network. It holds no network permission, and no networking, sharing or upload code is written into it.
  • It shows no advertising and contains no advertising library.
  • It collects no analytics and reports no crashes to us.
  • It has no accounts, no sign-in and no password.
  • It does not read your location, your calendar, your health data or which other apps you use.
  • It does not sell your information. It shares nothing with us or anyone else; the only other way in is the computer connection described above.

If you take part in the beta through Google Play, Google handles the tester list and anything you choose to send through Play. That is Google's process, not the app's.


How long things are kept, and how to delete them

What the app keeps stays on your phone until you remove it. The app does not expire it for you.

What you doWhat it removesWhat it leaves
On the Commands screen, run store.forget (it asks you to confirm; there is no undo)Everything the app has stored: the loudness from audio checks and any timer runs.Takes, the vault, the settings.
In the vault, press Forget on an entryThat entry.Everything else.
Uninstall AesthesiaThe app's private folder: everything stored, the settings, the sealed takes, the connection code, and the keys.Any plain .wav you exported to Music/Laminae.
Settings → Apps → Aesthesia → Storage → Clear dataEverything in the app's private storage.Any plain .wav in Music/Laminae.
Delete the files in Music/Laminae with your phone's Files or Music appThose .wav files.Nothing else.

There is no single button that removes everything. The simplest way is to delete any exported .wav files and then uninstall the app.

You do not need to ask us to delete anything, because we hold nothing of yours. If you want that confirmed in writing, write to developer-feedback@laminae.co.nz.


Children

Aesthesia is not directed at children. On Google Play it is declared for an audience of 18 and over.

The app has no accounts, no adverts, no purchases, no messaging and no way to contact anyone through it, so there is nothing in it for a child to be exposed to by another person.


Before the microphone is used

Before Android asks for the microphone, Aesthesia shows a short screen, The sound in the room, saying what it listens for and what it keeps. Continue goes on to Android's own dialogue; Not now, the back button or a tap outside the screen leaves the sound off and asks nothing. If you decline Android's dialogue, the sound does not start and the rest of the app works as before.


Your rights, and New Zealand law

Laminae Limited is a New Zealand company and is the agency responsible for this app under the Privacy Act 2020.

Because Aesthesia holds nothing of yours on any system of ours, there is normally nothing for us to give you access to or to correct. Everything the app holds is on your own phone, where you can read it and delete it yourself, as described above.

If you believe we hold personal information about you, you may ask for access to it and for correction of it. Write to developer-feedback@laminae.co.nz. We will answer within the time the Privacy Act allows.

If you are not satisfied with our answer, you may complain to the Office of the Privacy Commissioner (privacy.org.nz).

If something goes wrong. If we become aware of a privacy breach affecting personal information we hold, and that breach is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and the people affected, as the Privacy Act 2020 requires. Because the app sends us nothing, the realistic scope of such a breach is what you have sent us directly, such as an email.


Changes to this policy

If this policy changes, the updated version will be in the app's Privacy screen, and on our website at laminae.co.nz/privacy, with a new effective date and a new version number at the top. Material changes will also be described in the release notes of the version they apply to.


Contact

Laminae Limited (NZBN 9429053217417), New Zealand Privacy contact: developer-feedback@laminae.co.nz Website: laminae.co.nz

Write to that address for any question about this policy or about what the app holds.