← Back to HQ

Alien Apps

My own apps – minimal, fully offline, no Google.
No account, no server, no telemetry. Your data stays on your device. Open source on GitHub · distributed signed via the Nostr Zap Store

All six apps also come ready to use: preinstalled on the Alien Phone from the Digital Bunker tier, with Obtainium for updates.

App icon: Sachwert-Tresor

Sachwert-Tresor (Hard-Asset Vault)

Encrypted vault for Bitcoin, gold & silver

Your wealth is nobody's business. A local, encrypted vault for your Bitcoin, gold and silver holdings – fully offline. No cloud, no server, no price API reading along. Nothing leaves your device in plain text.

  • AES-256-GCM encryption, key derived from your passphrase with Argon2id (since v3.0) – makes brute-forcing costly
  • Optional two-factor authentication (TOTP)
  • Optional fingerprint unlock (app, since v3.0) – after every restart the passphrase first (optional since v3.2, box when enabling, off by default), and it switches itself off when a new finger is enrolled
  • Precious metals as count × unit size – bars and coins tracked cleanly
  • Manual price entry: no data leaking to external price services
  • Wealth over time: every price you enter is remembered with its date, the history tab shows value next to cost basis – still no price lookups
  • Cross-device sync via Syncthing – peer-to-peer, no middleman
  • Entries in EUR, USD or CHF, display in BTC or sats – no price lookups
  • Estate appendix: one sheet with your net holdings for the heir package, quantities only
  • Since v3.3: also for the Linux desktop – a Flatpak without network permission and without file access, with a GPG-signed checksum, backups interchangeable between phone and desktop
  • Since v3.5: confirmations as in-app dialogs instead of the Android system dialog (which did not inherit the screenshot protection), "Undo" after deleting an entry
  • Since v3.6: if the app locks while the file picker is open, the chosen file is not lost – the import continues after unlocking (.vault and CSV)

App only, deliberately no web version – full hardening in the Android app: no INTERNET permission (only system permission: fingerprint), FLAG_SECURE, no cloud backup and no transfer when switching phones – operating-system-level protection a website cannot offer. On the Linux desktop: a Flatpak without network and without file access, limits on the vault page.

Android / GrapheneOS · Linux (Flatpak) · open source (MIT) · no account, no server

Signature fingerprint of the Android APK (SHA-256), identical across all versions — the APK from the Zap Store carries it too: 66:0F:21:0C:7A:28:9F:38:8B:B4:81:2C:23:82:5A:77:F1:FC:84:E6:A7:EE:58:D6:42:81:B6:BF:5C:D8:79:88 apksigner: 660f210c7a289f388bb4812c23825a77f1fc84e6a7ee58d64281b6bf5cd87988 Linux desktop: GPG release key for the checksum (all desktop apps): 100F 9E25 BFAE A807 DBC3 57D7 50C0 D785 83BF CB81 · guide
App icon: Ausgaben-Tracker

Ausgaben-Tracker (Expense Tracker)

Minimal, fully offline expense tracker

A budget book without banking-app snooping. Keep an eye on your spending – no account, no server, no tracking. All data stays encrypted on your device.

  • Monthly and annual overview at a glance
  • Fixed-cost management for recurring expenses
  • Debts tab: note open payments with due date and tick them off
  • Breakdown by category, search and filter, your own categories (since v1.7)
  • Settings: selectable auto-lock, colour theme, built-in manual, German/English following the system language (since v1.7)
  • Pickers and the search clear button in the app's own style instead of grey system lists (since v1.8)
  • Confirmations as the app's own dialog instead of the Android system dialog (which was outside the screenshot protection), "Undo" after deleting an expense (since v1.9)
  • No third-party autofill: another password manager does not see the master password field and cannot offer to save it (since v1.10)
  • CSV export for your own analysis, encrypted .vault backup
  • AES-256-GCM encryption with master password, not a single Android permission

Android / GrapheneOS · open source

Signature fingerprint of the Android APK (SHA-256), identical across all versions — the APK from the Zap Store carries it too: DB:C5:08:71:53:B4:59:21:82:DD:13:1A:73:0C:11:A0:F7:12:4E:34:42:6C:54:2B:4B:A6:88:5A:B1:CC:01:0E apksigner: dbc5087153b4592182dd131a730c11a0f7124e34426c542b4ba6885ab1cc010e
Set up Obtainium (values to copy)

Signed releases are on our own download address api.alien-investor.org/downloads/ausgaben-tracker/; every release is also mirrored on GitHub. Without Obtainium: download the latest APK from the download page and install it.

On a phone with Obtainium installed it takes one tap; all settings are prefilled and Obtainium asks before adding:
Open in Obtainium

Or by hand, in Obtainium “Add app”:

  1. “App source URL” https://api.alien-investor.org/downloads/ausgaben-tracker/
  2. Under “Additional options for HTML”: “Version string extraction RegEx” ausgaben-tracker-([0-9]+(\.[0-9]+)+)\.apk$
  3. “Match group to use for version string extraction RegEx” $1
  4. “Expected signing certificate hashes” DB:C5:08:71:53:B4:59:21:82:DD:13:1A:73:0C:11:A0:F7:12:4E:34:42:6C:54:2B:4B:A6:88:5A:B1:CC:01:0E
  5. Tap the “+” to add. Obtainium downloads the APK once to recognise the app. If Ausgaben-Tracker is already installed, it stays as it is.

Why the RegEx? On a download page Obtainium reads the version number from the file name only with it. Without it, Obtainium only has a substitute identifier and cannot compare against the installed version. The certificate hash is a hard lock: Obtainium will not install an APK signed with a different key.

Still on the Codeberg address? No new releases appear there. Once: create an encrypted .vault backup in the “Export” tab first, remove the “Ausgaben-Tracker” entry and in the dialog keep only “Remove from Obtainium” switched on (“Uninstall from device” off, it deletes the app and its data), then add it again as above. Obtainium detects the installed app; signing key and package ID stay the same.

App icon: Alien Fitness

Alien Fitness

Minimal, fully offline workout tracker

A training log that belongs to you. A personal workout tracker – training plans, live logging and progress, without a fitness platform recording your health data.

  • Create your own training plans or use the built-in ones: strength (Push / Pull / Legs) and HIT (Tabata, Power)
  • Free workouts: start empty, add exercises on the fly, save when done
  • Live logging with rest and HIT interval timer, "last time" comparison and corrections
  • Resume interrupted workouts, per-session training notes
  • Progress charts per exercise (max weight / reps over time)
  • Exercise library with images, muscle groups and equipment
  • JSON backup to save and migrate (merge or replace)

Android / GrapheneOS · open source · no account, no server, no internet permission

Signature fingerprint of the Android APK (SHA-256), identical across all versions — the APK from the Zap Store carries it too: 85:9E:88:B7:43:5F:84:1D:8B:C1:CF:F1:FE:A9:12:56:A6:33:DE:A5:59:D9:5A:91:02:4B:22:53:A2:AD:13:26 apksigner: 859e88b7435f841d8bc1cff1fea91256a633dea559d95a91024b2253a2ad1326
Set up Obtainium (values to copy)

Signed releases are on our own download address api.alien-investor.org/downloads/alien-fitness/; every release is also mirrored on GitHub. Without Obtainium: download the latest APK from the download page and install it.

On a phone with Obtainium installed it takes one tap; all settings are prefilled and Obtainium asks before adding:
Open in Obtainium

Or by hand, in Obtainium “Add app”:

  1. “App source URL” https://api.alien-investor.org/downloads/alien-fitness/
  2. Under “Additional options for HTML”: “Version string extraction RegEx” alien-fitness-([0-9]+(\.[0-9]+)+)\.apk$
  3. “Match group to use for version string extraction RegEx” $1
  4. “Expected signing certificate hashes” 85:9E:88:B7:43:5F:84:1D:8B:C1:CF:F1:FE:A9:12:56:A6:33:DE:A5:59:D9:5A:91:02:4B:22:53:A2:AD:13:26
  5. Tap the “+” to add. Obtainium downloads the APK once to recognise the app. If Alien Fitness is already installed, it stays as it is.

Why the RegEx? On a download page Obtainium reads the version number from the file name only with it. Without it, Obtainium only has a substitute identifier and cannot compare against the installed version. The certificate hash is a hard lock: Obtainium will not install an APK signed with a different key.

Still on the Codeberg address? No new releases appear there. Once: export a JSON backup in the history first, remove the “Alien Fitness” entry and in the dialog keep only “Remove from Obtainium” switched on (“Uninstall from device” off, it deletes the app and your training history), then add it again as above. Obtainium detects the installed app; signing key and package ID stay the same.

App icon: Alien Pass

Alien Pass

Offline password manager without internet permission

The master key stays with you. A local, encrypted password manager – fully offline. No account, no sync server, no telemetry. The app does not even have an internet permission.

  • Logins, encrypted notes, cards and bank accounts (IBAN, BIC, PIN), sorted into categories
  • Argon2id + AES-256-GCM, file header authenticated
  • Password generator with characters or EFF dice words, TOTP codes per entry
  • Clipboard auto-clear, flagged sensitive, auto-lock also in the background
  • Encrypted backup and merge between devices (Syncthing)
  • Migration from Proton Pass straight from the PGP-encrypted export; CSV from Google Password Manager/Chrome, Apple Passwords, Firefox, KeePassXC, Bitwarden, LastPass, 1Password and NordPass (since v1.10 detected by format, folders and tags become categories)
  • Since v1.2: optional fingerprint unlock via the Android keystore — passphrase required after every restart (optional since v1.8), "Lock now" as the deliberate bolt
  • Since v1.3: account entry type; no more age warning for passwords (forced rotation is an anti-pattern)
  • Since v1.4: up to eight freely named, always-secret extra fields per entry (app PIN, phone password …), e-mail field next to the username, generator right inside the entry form
  • Since v1.5: trash – deleted entries stay restorable for 30 days (up to 200 entries, only on the device where they were deleted), pickers in the app's own style
  • Since v1.6: a more honest strength meter – spots predictable patterns such as years, keyboard runs and common words (also P4ssw0rd), flags them in the list and asks before accepting a weak vault passphrase
  • Since v1.6.1: a warning when a fingerprint was newly enrolled in Android – even across a restart – and the failed-attempt brake keeps counting across app restarts
  • Since v1.7: also for the Linux desktop – a Flatpak without network permission and without file access, with a GPG-signed checksum, backups interchangeable between phone and desktop
  • Since v1.8: Android – "fingerprint also after a restart" box (off by default); desktop – quick unlock with a PIN after a lock (in memory only, at most 24 hours, honestly assessed); a third internal audit of the desktop branch
  • Since v1.9: confirmations as in-app dialogs instead of the Android system dialog (which did not inherit the screenshot protection), "Undo" after deleting, multi-select – several entries at once to the trash, into a category or as favourites

App only, deliberately no web version: on Android no internet permission (only the fingerprint sensor), FLAG_SECURE, no cloud backup – hardening at the operating-system level; on the Linux desktop a Flatpak without network. Details on the Alien Pass page.

Android / GrapheneOS · Linux (Flatpak) · open source (MIT) · no account, no server

Signature fingerprint of the Android APK (SHA-256), identical across all versions — the APK from the Zap Store carries it too: 73:C7:17:D8:05:6C:6A:02:B0:8B:AB:BA:24:18:17:F3:93:E4:6D:EA:03:19:D4:FA:26:B8:C3:D8:E1:F9:3C:95 apksigner: 73c717d8056c6a02b08babba241817f393e46dea0319d4fa26b8c3d8e1f93c95 Linux desktop: GPG release key for the checksum (all desktop apps): 100F 9E25 BFAE A807 DBC3 57D7 50C0 D785 83BF CB81 · guide
App icon: Alien Notes

Alien Notes

Encrypted offline notes and checklists without internet permission

Your notes never leave the device in plaintext. A local, encrypted notes and checklist app – fully offline. No account, no server, no telemetry. Sister app of Alien Pass with the same architecture and the same hardening.

  • Notes (free text up to 100,000 characters) and checklists (up to 200 entries, "done to the bottom", "clear ticks") – switch a note between the two, lines become entries and back
  • No save button: the app saves as you type (after 1.5 s) and when you leave the note – encrypted, the whole file every time
  • Markdown preview per note (off by default): a small own subset, no third-party renderer, no HTML, links stay plain text; cheat sheet in the editor
  • Categories like folders (rename them, too), favourites, pinned notes at the top, an "Open" chip for checklists with unfinished entries, search across title, text, checklist entries and category
  • Since 1.1: moving from Standard Notes (decrypted backup as ZIP or text file, 2FA entries are never imported), several notes at once to the trash, into a category or as favourites, "Undo" after deleting, "no preview" per note, three font sizes, confirmations as in-app dialogs instead of system dialogs
  • Clipboard auto-clear (30 s by default, can be switched off) and on lock, flagged sensitive on Android. With "Lock in background: immediately" the copied note stays until the chosen time runs out so it can still be pasted into another app (since 1.3).
  • Locking more relaxed than a password manager: by default no lock after inactivity, in the background after 30 minutes – both adjustable up to "never" / "immediately". With "immediately" the Android app also locks while the file picker is open; unlock within five minutes and the import continues with the chosen file (since 1.2).
  • Trash: deleted notes stay restorable for 30 days, up to 200 at a time, showing only title, type and date
  • Encrypted backup (.notes) and merge between devices, also between phone and Linux desktop (e.g. via Syncthing)
  • Aegis hurdle, fingerprint unlock (Android) and quick unlock by PIN (desktop) – optional, taken over from Alien Pass (Aegis without QR)
  • Screenshots and app-switcher preview blocked by default (FLAG_SECURE), can be switched off in Settings – notes are not always secret
  • No Android autofill, not even third-party (since 1.4): the app keeps its WebView out of the autofill framework – a password manager set up as the autofill service never sees the passphrase fields and cannot offer to save them
  • Also for the Linux desktop – a Flatpak without network permission and without file access, with a GPG-signed checksum
  • Two internal security audits (0.1: the surface new compared to Alien Pass plus the file store; 1.1: Standard Notes import, dialog, undo, multi-select) – all findings fixed before release (no independent audit)

App only, deliberately no web version: on Android no internet permission (only the fingerprint sensor), FLAG_SECURE, no cloud backup – hardening at the operating-system level; on the Linux desktop a Flatpak without network. Details on the Alien Notes page.

Android / GrapheneOS · Linux (Flatpak) · open source (MIT) · no account, no server

Signature fingerprint of the Android APK (SHA-256), identical across all versions — the APK from the Zap Store carries it too: F3:68:F9:0B:F8:DF:8C:55:BB:6C:28:6D:32:25:BA:8A:F4:45:22:7B:A6:9B:36:00:DF:BB:F6:A1:44:09:BA:7C apksigner: f368f90bf8df8c55bb6c286d3225ba8af445227ba69b3600dfbbf6a14409ba7c Linux desktop: GPG release key for the checksum (all desktop apps): 100F 9E25 BFAE A807 DBC3 57D7 50C0 D785 83BF CB81 · guide
App icon: BTC Steuertool

BTC Steuertool

Bitcoin tax report for the German tax office – no internet permission, your data stays with you

Your tax data does not end up on someone else's server. CSV exports from BitBox and brokers in, annual report under § 23 EStG out – calculated entirely on your device. No account, no upload, no telemetry. The same open-source calculation core as the CLI tool and the web version.

  • FiFo per wallet (German Federal Ministry of Finance circular of 6 March 2025, para. 62), every exchange account counting as a wallet of its own – on transfers between your own wallets, purchase date and cost travel along (a reading disclosed in the evidence document); one-year holding period counted by calendar date (§§ 187, 188 BGB) and the exemption limit (600 EUR up to 2023, 1,000 EUR from 2024)
  • BitBox, 21bitcoin, Bison, Swissquote, Strike, Pocket, Bisq 1 (German or English interface) plus manual buys and sells; other exchanges via a CoinTracking or Blockpit export (format not yet confirmed against real exports, the report warns) – brokers are detected from the file contents, ZIPs are unpacked; unknown files block the calculation instead of silently missing
  • Since v1.3: every file is checked for its required columns before reading – a renamed column stops the run with file, line and column instead of silently dropping data; a byte-order mark (e.g. after saving in Excel as "CSV UTF-8") is now read correctly
  • Fees paid in bitcoin (network, withdrawal, Bisq trading fee) treated as a disposal of the fee amount, gifts and donations as a reduction of holdings
  • noKYC kept strictly apart: its own FiFo pool and its own internal report, never part of the documents for the tax office
  • Tax report, formal tax evidence, buys and sells as CSV – saved through the save dialog
  • ECB exchange rates and BTC daily closing prices built in – the app downloads nothing after installation
  • Android: no internet permission, screenshots blocked (FLAG_SECURE), no backup of app data
  • Also for the Linux desktop – as a Flatpak without network permission and without file access, with a GPG-signed checksum
  • In-app guide (German/English); internal security audit before the release, all findings fixed (no independent audit)

Also in the browser and as a CLI: the web version fetches its code from the server on every visit, the CLI runs from the repo. Everything on the tax tool page. Reports are in German, they are meant for the German tax office. No tax advice – a calculation aid.

Android / GrapheneOS · Linux (Flatpak) · open source (MIT) · no account, no server

Signing fingerprint of the Android APK (SHA-256), identical for every version — the APK from the Zap Store carries it too: 26:C5:E0:94:A8:B7:65:0C:A6:65:01:4D:0C:3A:8B:A6:82:B1:7C:05:F5:3C:6C:DE:F0:55:D0:7C:E9:84:BF:0B apksigner: 26c5e094a8b7650ca665014d0c3a8ba682b17c05f53c6cdef055d07ce984bf0b Linux desktop: GPG release key for the checksum (all desktop apps): 100F 9E25 BFAE A807 DBC3 57D7 50C0 D785 83BF CB81 · guide

How to install the apps – without Google Play

All apps are distributed as developer-signed releases – not through the Google Play Store. Easiest via the Nostr Zap Store (cryptographically verified installs, updates through your social graph) or via Obtainium directly from our own download address (setup: vault, Alien Pass, Alien Notes, BTC Steuertool, Alien Fitness, Ausgaben-Tracker) – both entirely without a Google account. Learn more: app stores on GrapheneOS and the Nostr Zap Store explained.

Linux desktop: Alien Pass, Sachwert-Tresor, Alien Notes and the BTC Steuertool are also available as a Flatpak — download, verify the GPG-signed checksum, install. Step by step in the Flatpak guide.

Verify authenticity: open the installed app in AppVerifier and compare the value it shows with the signature fingerprint on the app's card – it is identical across all versions. More in the Obtainium guide.

All apps listed here are my own open-source works. They run offline, collect no data and are fully source-available. Use at your own responsibility.

See all apps at the Alien Investor Zap Store profile.