Third-Party Notices
OpenDrop is proprietary software (© NFDGames LLC, all rights reserved). The following open-source components are incorporated into the product and are used under their respective licenses. Their license texts are reproduced as required by each license; nothing on this page weakens the proprietary license of OpenDrop itself.
On this page
iOS / Android Mobile apps
The OpenDrop mobile apps are built with the Flutter SDK and incorporate the following packages. Resolved versions reflect the lockfile shipped with build 1.0.0+18. Dev-only test/lint tooling is omitted.
Apache License 2.0
apache.org/licenses/LICENSE-2.0
- Flutter SDK and Dart SDK (Google)
- background_downloader 9.5.4
- cryptography 2.9.0
- cryptography_flutter 2.3.4
- google_fonts 8.1.0
- multidict, yarl, frozenlist, aiosignal
- com.android.tools:desugar_jdk_libs 2.1.4
- Firebase Android client libraries (BoM 34.11.0)
- Google Play services (play-services-auth/base/tasks)
- Kotlin standard library / AndroidX (build tooling)
BSD 2-Clause / BSD 3-Clause
The bulk of the Flutter ecosystem ships under BSD 3-Clause. opensource.org/license/bsd-3-clause
- http 1.6.0
- path 1.9.1 / path_provider 2.1.5
- image_picker 1.2.2 (all platform packages)
- receive_sharing_intent 1.8.1
- mobile_scanner 7.2.0
- shared_preferences 2.5.5 (all platform packages)
- google_sign_in 7.2.0 (all platform packages)
- intl 0.20.2
- firebase_auth 6.5.1 / firebase_core 4.9.0
- url_launcher 6.3.2 (all platform packages)
- android_intent_plus 6.0.0
- network_info_plus 8.1.0
- flutter_pdfview 1.4.4
- flutter_blue_plus 2.3.2 (all platform packages)
- device_info_plus 13.1.0
- flutter_local_notifications 21.0.0
- flutter_secure_storage 10.2.0 (all platform packages)
- package_info_plus 10.1.0
- share_plus 13.1.0
- crypto 3.0.7 (Dart)
- collection, async, characters, convert, meta, mime, fixnum, source_span, stack_trace, stream_channel
- CocoaLumberjack 3.9.1 (iOS pod)
- win32 6.2.0, win32_registry 3.0.3 (Windows interop)
MIT License
- cupertino_icons 1.0.9
- dio 5.9.2 / dio_web_adapter 2.1.2
- file_picker 12.0.0-beta.3
- permission_handler 12.0.1 (all platform packages)
- purchases_flutter 10.1.0 / purchases_ui_flutter 10.1.0 (RevenueCat)
- sign_in_with_apple 8.0.0
- gal 2.3.2
- bonsoir 6.1.0 (all platform packages)
- cupertino_native_better 1.4.5
- ble_peripheral 2.4.0
- uuid 4.5.3
- unorm_dart 0.3.2
- SVGKit 3.0.0 (iOS pod)
MIT (with bundled Bouncy Castle notices)
- pointycastle 4.0.0, ships a combined LICENSE notice covering the Legion of the Bouncy Castle (MIT-derived).
Win / Linux / macOS Desktop server
The OpenDrop desktop server is a Python/PySide6 application. The components below are pulled from pyproject.toml and resolved at Nuitka build time. Dev-only tooling (nuitka, pytest, lints) is omitted.
LGPL, Qt for Python (PySide6)
The desktop GUI is built on Qt for Python (PySide6) 6.10.2 (Qt 6.10.2). Upstream offers it under LGPL-3.0-only OR GPL-2.0-only OR GPL-3.0-only; OpenDrop elects the LGPL-3.0 option. The Qt/PySide6 libraries are dynamically linked — they ship as separate, replaceable shared libraries (.dll / .dylib / .so); the desktop app is not statically linked against Qt. The complete LGPLv3 and GPLv3 license texts are bundled with the installed application as LICENSE.LGPLv3.txt and LICENSE.GPLv3.txt.
- PySide6 / shiboken6 6.10.2, LGPL-3.0 (Qt for Python). qt.io/licensing
- Corresponding source (PySide6 6.10.2): code.qt.io/cgit/pyside/pyside-setup.git · pypi.org/project/PySide6/6.10.2
- Corresponding source (Qt 6.10.2): download.qt.io/archive/qt/6.10/6.10.2
Apache License 2.0
- aiohttp + transitives (multidict, yarl, attrs, frozenlist, aiosignal, async-timeout)
- requests + google-auth-oauthlib
- cryptography (dual MIT/Apache; OpenSSL backend, see below)
- typing-extensions / annotated-types
- google-auth, cachetools (Apache)
MIT License
- aiofiles
- httpx (+ anyio, sniffio, h11, httpcore)
- python-dotenv
- python-multipart
- qrcode
- uvicorn (+ click, BSD-3)
- pillow-heif
- pydantic + pydantic-core
- urllib3
- charset-normalizer
- oauthlib / requests-oauthlib
- ifaddr
- rawpy (Python binding only, LibRaw notice below)
- pyobjc-framework-Quartz (macOS only)
BSD 3-Clause
- fastapi
- starlette
- websockets
- zeroconf
- idna
- pyasn1, pyasn1-modules, rsa
HPND (Historical Permission Notice), MIT-equivalent for attribution
- Pillow (the PIL fork)
Mozilla Public License 2.0
- certifi (Mozilla CA root certificate bundle)
OpenSSL Apache 2.0 (since OpenSSL 3.0)
The Python cryptography wheel statically links a build of OpenSSL. OpenSSL is licensed under the Apache License 2.0 as of OpenSSL 3.0. openssl.org/source/license
Bundled native binaries (shipped inside the desktop installer)
The OpenDrop desktop installer ships the following pre-built native binaries alongside the Python application. Each retains its own license; the per-binary ffmpeg-LICENSE.txt (and ffmpeg-thirdparty-LICENSES.txt) file lives next to the binary in the installed application directory.
ffmpeg (LGPL build), used for file conversion
--enable-libvpx --enable-libmp3lame --enable-libopus.
- ffmpeg core, LGPL-2.1-or-later. ffmpeg.org/legal
- libvpx (statically linked), BSD 3-Clause. webmproject.org/license/software
- LAME (libmp3lame, statically linked), LGPL-2.0-or-later. lame.sourceforge.io
- libopus (statically linked), BSD 3-Clause. opus-codec.org/license
LibRaw, used inside the rawpy wheel for RAW conversion
- License: LGPL-2.1 or CDDL-1.0 (dual). LGPL applies for the redistributed build. libraw.org
- Statically linked into the
rawpywheel; source available on request as described above.
Cloudflare Worker Control plane
The Cloudflare Worker that handles device pairing, presence, key exchange, and account lookup has no runtime third-party dependencies. All npm packages in its lockfile are dev-only (Wrangler, Vitest, the Cloudflare Workers test pool). The Worker source runs on Cloudflare's workerd runtime; workerd is licensed Apache-2.0 by Cloudflare and is not redistributed by OpenDrop.
Relay OpenDrop WebSocket relay
ws8.20.0, MIT. github.com/websockets/ws (the only Node.js runtime dependency)- Node.js 20 (Alpine base image), MIT for Node, with bundled musl/BusyBox components under their respective licenses (BSD-style and GPL-2.0). alpinelinux.org/about
- coturn (self-hosted STUN server, run in STUN-only mode on the Oracle relay boxes), 3-clause BSD. github.com/coturn/coturn
- Caddy (TLS-terminating reverse proxy in front of the Oracle relay boxes), Apache-2.0. caddyserver.com
The relay is operated by NFDGames LLC on Fly.io (primary, for Pro) and Oracle Cloud (free tier and Pro failover); it is not redistributed to end users. The Node.js/ws relay runs on both deployments; the Oracle boxes additionally run Caddy (TLS) and coturn (STUN), while the Fly.io Pro relay runs without Caddy or coturn.
Installers & build tooling (not bundled at runtime)
The following tools are used to build the installers but are not included in the shipping product. Listed here for completeness only.
- Inno Setup 6.3+ (Windows installer), Inno Setup License (modified BSD). jrsoftware.org/files/is/license
- AppImageTool (Linux
.AppImagepackager), MIT. - Nuitka (Python standalone bundler), Apache-2.0.
Fonts & web assets used on nfdgames.com
- Sora (body / UI typeface), SIL Open Font License 1.1. fonts.google.com/specimen/Sora
- Space Mono (display / monospace typeface), SIL Open Font License 1.1. fonts.google.com/specimen/Space+Mono
- Both fonts are served from Google Fonts via a
preconnect-optimized<link>tag; they are not self-hosted.
Request a license text or LGPL source archive
For the full verbatim license text of any component listed above (or for the corresponding source code of any LGPL-licensed component), email support@nfdgames.com with the subject line "Third-Party License Request" and the component name. We will respond within 5 business days with a download link or, where the license text is short, the text inline.
The OpenDrop application itself, including every component developed by NFDGames LLC, is proprietary software. See Terms of Service Section 5 (Acceptable Use) for what you may and may not do with OpenDrop.
Last updated: June 28, 2026 · Build 1.0.0+18 (mobile) / 1.0.0 (desktop) ·
Release notes