DE version is available. Content is displayed in original English for accuracy.
I built an Android file viewer that opens PDF, Word, Excel, PowerPoint, images, video, audio, Markdown and code, and asks for no permissions at all.
I have always been uneasy about opening files people send me. On Android you either install a 400 MB office suite and sign in or use a small free viewer that wants storage access and ends up uploading your file to a server to render it. Also the hassle of having to download different apps for different file formats was really annoying.
Gander holds no permissions, not even INTERNET so the OS itself guarantees the file cannot leave the phone.
PDFs use Pdfium, media uses Media3, and Office formats are rendered by bundled JS libraries in a WebView and so no request goes to any server.
It is a viewer only. Complex PowerPoint decks come out approximately right, spreadsheet charts are not drawn, and old binary .doc and .ppt are unsupported. I'll work on it as issues come up :P
It is 14 MB, MIT licensed and uploaded on Github releases.
Do try it! I would love some feedback especially on files that render badly or need new support.

Discussion (18 Comments)Read Original on HackerNews
I thought granting internet access to apps is not avoidable on Android.
When an app does not request internet, is it really guaranteed that it cannot talk to the outside world? Or is it having other avenues like opening a browser or some other component with a custom url or something?
Update: I just asked Gemini, and it does not look good:
An Android app without the INTERNET permission is not guaranteed to be isolated from the outside world. While it cannot make direct network connections itself, it can use several other mechanisms to transmit data externally:
Intent-Based Communication (The Browser) An app can launch an explicit or implicit Intent to hand data over to another app that does have internet access.
That means the app can open a system browser using a URL containing the data it wants to transmit.
It can also load a Chrome Custom Tab inside its own UI task, passing data through the URL string.
There is also Inter-Process Communication: If two apps from the same developer share a User ID (sharedUserId), they run in the same process and share all permissions, including internet access.
There is also the concept of Content Providers: Content Providers allow apps to share data. An offline app can write data into a shared database or a public Content Provider. A secondary, online-enabled app can then read that database and upload the contents.
Edit: also that LLMs are tuned for "engagement" not for answers like "it's secure enough, move along"?
The full list of bypasses is likely much larger because it doesn't fall in the scope of bug bounties.
I'm assuming that all works even with application sandboxing (1) or am I mis-reading how that is applied to applications.
Man I need to move my movement to GrapheneOS up to be sooner.
(1) https://source.android.com/docs/security/app-sandbox
> Requirements: JDK 17+ and the Android SDK (platform 35).
Bummer. I am stuck with Android 14 for the moment.