Skip to main content

Android Permissions

These are the permissions Colota uses and why. None are related to analytics, advertising, or data collection.

Permission Overview​

PermissionRequiredWhy
Fine LocationYesGPS-based location tracking
Coarse LocationYesNetwork-based location fallback
Background LocationYesTrack while app is in the background
Foreground ServiceYesRequired by Android for background services
Foreground Service (Data Sync)YesAuto-export background processing
InternetYesSend locations to your server
Network StateYesCheck connectivity before syncing
Wi-Fi StateYesDetect current SSID for sync condition filtering
Boot CompletedYesAuto-restart tracking after device reboot
NotificationsOptionalShow the tracking notification (Android 13+)
Local Network AccessAndroid 17+Access local network servers (self-hosted)
Battery Optimization ExemptionOptionalPrevent Android from killing the tracking service
Wake LockYesBriefly wake the CPU for the stationary heartbeat and background jobs

Permission Request Flow​

When you start tracking for the first time, Colota requests permissions in sequence:

  1. Fine Location - Required to access GPS hardware
  2. Background Location (Android 10+) - Appears as a separate dialog asking to "Allow all the time"
  3. Notification Permission (Android 13+) - Shows the tracking notification
  4. Battery Optimization Exemption - Optional dialog to prevent the system from restricting the app

Only the two location permissions are required. The app does not request anything until you tap "Start Tracking".

The Local Network Permission (Android 17+) is not part of this sequence. It is requested separately when you use Test connection with a local/private server endpoint.

Detailed Explanations​

Location Permissions​

android.permission.ACCESS_FINE_LOCATION
android.permission.ACCESS_COARSE_LOCATION
android.permission.ACCESS_BACKGROUND_LOCATION

Fine Location provides GPS-level accuracy (typically 3-10 meters). Coarse Location is declared as a fallback but fine location is always preferred. Background Location allows the foreground service to continue receiving GPS updates when the app is not in the foreground.

Foreground Service​

android.permission.FOREGROUND_SERVICE
android.permission.FOREGROUND_SERVICE_LOCATION
android.permission.FOREGROUND_SERVICE_DATA_SYNC

Android requires apps to declare a foreground service with a persistent notification to run in the background. The FOREGROUND_SERVICE_LOCATION type specifically indicates the service accesses location data. This is what keeps the tracking notification visible. The FOREGROUND_SERVICE_DATA_SYNC type is used by the auto-export WorkManager service for scheduled background exports and by the encrypted backup/restore service for the encryption phase.

Network​

android.permission.INTERNET
android.permission.ACCESS_NETWORK_STATE
android.permission.ACCESS_WIFI_STATE

Internet is needed to POST location data to your configured server endpoint. Network State lets the app check for connectivity before attempting to sync, avoiding unnecessary failures. Wi-Fi State is used to read the current Wi-Fi SSID when the sync condition is set to a specific network.

Boot Completed​

android.permission.RECEIVE_BOOT_COMPLETED

If tracking was active when the device was powered off, Colota automatically restarts the foreground service after boot. This is handled by LocationBootReceiver.

Notifications​

android.permission.POST_NOTIFICATIONS

On Android 13 and later, apps need this permission before they can show notifications. Colota asks for it but does not require it - tracking runs either way. Denying it hides the tracking notification, so you lose the live status and the tap-to-resume alert when Android kills tracking.

Local Network Access​

android.permission.ACCESS_LOCAL_NETWORK

Starting with Android 17, apps need this permission to connect to devices on the local network. Colota requests it when you use Test connection with a private/local endpoint - this includes IP addresses (e.g. 192.168.x.x, 10.x.x.x, 172.16-31.x.x, 100.64.x.x) and hostnames that resolve to private IPs via DNS (e.g. server.local). Loopback addresses (localhost / 127.0.0.1) do not require this permission. If your server is a public HTTPS endpoint, this permission is never requested.

Android 16

On some Android 16 devices, local network access may be enforced early via security patches. In this case, Android uses the Nearby Wi-Fi Devices (NEARBY_WIFI_DEVICES) permission instead. If your local server is unreachable on Android 16, go to Android Settings > Apps > Colota > Permissions and enable Nearby devices manually.

Battery Optimization​

android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS

This allows Colota to show the system dialog asking to exempt the app from battery optimization (Doze mode). When exempted, Android is less likely to kill the tracking service during idle periods. This is optional - tracking works without it, but may be less reliable on some devices.

Wake Lock​

android.permission.WAKE_LOCK

Lets Colota briefly hold the CPU awake when a heartbeat alarm fires during Doze. The stationary-profile heartbeat holds it while it acquires a location fix, and the geofence heartbeat while it writes and sends the zone-center point. It is also used internally by WorkManager for auto-export and battery-recovery jobs. Android grants this permission automatically and it gives no access to personal data.

Revoking Permissions​

You can revoke any permission at any time through Android Settings → Apps → Colota → Permissions. Revoking a location permission stops the tracking service, and Colota turns the tracking toggle off the next time you open the app. Other permissions can be toggled without affecting the core tracking functionality.