Open-source project
deltazefiro/Amarok-Hider avatar
deltazefiro/Amarok-Hider

Amarok-Hider: fast hiding on Android, and the warning the README puts above the feature list

Hide your private files and apps with a single click.

3,257 stars111 forksJavaApache-2.0

At a glance

What is it?
An Apache-2.0 Android tool that hides files and apps by obfuscating signatures or adjusting permissions instead of encrypting, distributed through GitHub releases, F-Droid and IzzyOnDroid.
Who is it for?
Amarok is fast because it does the minimum: it changes what a file looks like or who can see it, rather than encrypting anything. That trade is stated plainly in a warning block above the feature list, and it is the single fact to carry into any decision about it.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 56 days ago.
What is it written in?
Mainly Java, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 23, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The disclaimer that defines the whole tool

Most privacy tools on Android lead with what they protect you from. Amarok leads with what it is not. A warning block sits directly under the introduction and states that Amarok is not an encryption tool, that it hides data without cryptographically securing it, and that it should not be used for high-value secrets.

That framing explains the design. Where an encrypted vault has to decrypt a file before showing it, Amarok changes something cheap and reversible: it obfuscates the file signature, or adjusts permissions so other apps cannot read the path. The result is instant, at the cost of being security by obscurity rather than security by cryptography.

The README's argument for that choice is performance. Traditional encryption tools are described as secure but slow, with the example of a large movie file or an app unlock taking noticeable time. Amarok's pitch is that concealment with no performance penalty is better suited to hiding a photo or a banking app from someone glancing at your phone.

The disclaimer block is styled as a GitHub alert callout rather than buried in a footnote, which is the correct editorial choice for a project whose name contains the word Hider.

Two mechanisms for files, three for apps

The hiding methods depend on what you have and what your device allows. Files are handled two ways: on a rooted device by adjusting file permissions with chmod, and without root by altering signatures. Apps get more options because hiding an app is a different problem from hiding a file.

Without root, apps are hidden from the launcher using Shizuku, Dhizuku or DSM modes. Shizuku and Dhizuku are the projects that grant root-like permission elevation over ADB without a full root, and the README credits both by name as what makes root-less hiding possible. With root, the app uses Xposed hooks to scrub an app from system menus and third-party detection surfaces, which is a stronger form of hiding than simply removing a launcher icon.

code
* **Root-Free Support**: Hides apps from the launcher (supports Shizuku, Dhizuku, and DSM modes).
* **Root Support**: Leverages Xposed to *thoroughly* scrub apps from system menus and 3rd-party detection.

The commit history for v0.10.1 shows the maintainer thinking about the failure modes of that last line. The release prevents hiding root managers such as KSU and Magisk forks, and prevents hiding privilege escalation managers including Shizuku and Dhizuku. Hiding the tool that grants your privileges is a good way to lock yourself out of your own device.

Panic button, quick settings tile and a Calendar disguise

The convenience features are where an Android hider differs from a file manager with a rename button. Three of them exist for the same underlying reason: speed of reversal when someone else picks up the phone.

code
* **Panic Button**: A discreet floating button to instantly hide everything.
* **Quick Settings Tile**: Toggle visibility directly from your control center without opening the main app.
* **Camouflage Mode**: Disguise Amarok as a Calendar app.

The panic button is the most interesting of the three, because it inverts the usual flow. Normally you open an app to act; here the control floats over whatever is on screen and hides everything with one tap. v0.10.1 made its colour and position user-configurable, and v0.10.0 added a countdown confirmation to the hide icon action so a mis-tap does not lock you out of your own photos.

The quick settings tile is the same idea at the system level, reachable without launching anything. Camouflage mode is the bluntest option: the app presents itself as a Calendar app in the launcher, which only helps against someone scanning icons casually.

The app also protects itself with a password or fingerprint lock, described as secure access rather than as protection for the hidden content. There is a launcher widget as well, and v0.10.0-beta3 added a security check on the widget's toggle action, which is a sensible response to a control that can change visibility state without a fingerprint prompt.

Reading the release notes for the engineering rather than the features

Three releases in the recent history show a project doing ordinary maintenance well. v0.10.0-beta3, published 2025-11-18, moved the target SDK to Android 16, added XHide support for Android 16, added hiding from recents and hiding the Amarok icon from the launcher, and added an automatic update check. v0.10.0 on 2025-11-26 added the Intent API for toggling the hiding state and the countdown confirmation.

Then v0.10.1 on 2026-02-25, which is the one to read closely. Alongside the dark theme and the panic button customisation it fixed file hiding with chmod on a non-primary user, and fixed preference persistence for hide paths and apps. Both are the kind of bug that only appears on a device with a secondary user profile or after a restart, which is exactly the class of bug that survives for months in an app nobody files issues against.

The version naming has a wrinkle worth knowing before you install. The beta notes explain that versions without a suffix are the normal builds, while `-foss` suffixed versions exist only for F-Droid distribution, and because the two are signed differently they cannot be upgraded across. So an install from GitHub releases and an install from F-Droid are separate lineages, and switching means reinstalling rather than updating in place.

Three distribution channels and a separate docs site

Amarok is distributed three ways, and the README links all of them from the download section: GitHub releases, an F-Droid listing under the package name `deltazero.amarok.foss`, and an IzzyOnDroid listing marked as a pre-release channel.

The F-Droid and IzzyOnDroid presence matters for an Android privacy tool specifically. A tool whose job is hiding things on your phone has a legitimate reason to be distributed outside the Play Store, and being buildable from F-Droid means the build is reproducible by someone other than the author. The `-foss` package name follows that convention.

Documentation lives apart from the code, at a separate documentation site with per-language URLs, and the README describes it as setup guides for root, Shizuku, Dhizuku and other app hiders. That is the right split, because installation depends so heavily on which of four privilege levels you have chosen.

The repository itself is a conventional Gradle project, with `build.gradle`, `settings.gradle`, `gradle.properties`, `gradlew` and an `app/` module, plus a `fastlane/` directory for release automation. Two files in the tree are unusual enough to mention: `debug.keystore` is committed, which is normal for a debug keystore and harmless, and there are agent configuration directories at `.cursor/`, `.claude/` and `.opencode/` alongside `AGENTS.md` and `CLAUDE.md`. The README even includes a note telling AI assistants to consult `.cursor/rules` for the project structure, which tells you something about how contributors are being onboarded.

Credits, licensing and the limits of what the README says

The credits section is unusually specific about what this project builds on. The app hiding logic is described as following the core reference from aistra0528's Hail project, Shizuku and Dhizuku are credited for enabling root-less permissions, the icon set comes from Flaticon contributors, and JetBrains is credited for IDE support. Reading that list explains the technical shape of the app better than the feature list does.

Licensing is Apache-2.0, which is the permissive end of the spectrum and unusual for an app that hooks other apps. Translations run through Weblate rather than pull requests, and both v0.10.0 and v0.10.1 carry long generated lists of translator credits covering around thirty languages, with a script producing the usernames from Weblate emails.

The disclaimers section says the app is provided as is without warranties, that the user is fully responsible for harm or data loss, and that you should back up important data before using hiding tools. That last line is not boilerplate: signature obfuscation and permission changes are exactly the operations that can make a file unreachable if the app state and the file state disagree.

What the README does not cover is the internals. There is no explanation of how signature obfuscation is implemented, no detail on which Xposed modules it depends on beyond the XHide reference, and no performance measurements. Those would need the source in `app/`, or the documentation site.

Editorial conclusion

Amarok is fast because it does the minimum: it changes what a file looks like or who can see it, rather than encrypting anything. That trade is stated plainly in a warning block above the feature list, and it is the single fact to carry into any decision about it. The project is properly packaged for Android, Apache-2.0 licensed, documented on its own site, and shipping real fixes, with v0.10.1 on 2026-02-25 and the last push on 2026-08-11. Read the release notes for the guardrail against hiding your own root manager, install the plain build unless you are on F-Droid, and treat the password lock as access control on the app rather than as protection for what is hidden.

Frequently asked questions

How do you find apps hidden by Amarok on Android?

The README describes the mechanisms rather than a detection guide, which is the honest position. Without root an app is hidden from the launcher using Shizuku, Dhizuku or DSM modes; with root, Xposed hooks scrub it from system menus and third-party detection. v0.10.1 also added guards so root managers and privilege escalation managers cannot be hidden, and Amarok can hide itself from the launcher and from recents.

Is Amarok an encryption app?

No, and the README puts a warning above the feature list saying exactly that. Amarok conceals files by obfuscating signatures or adjusting permissions and hides apps by disabling them or using Xposed hooks. It states that it hides data without cryptographically securing it and should not be used for high-value secrets.

Do I need root to use Amarok?

For files, no: the non-root path alters signatures, while root uses chmod on file permissions. For apps, root-free hiding works through Shizuku, Dhizuku or DSM modes and only removes the app from the launcher. Root unlocks the stronger Xposed-based hiding from system menus and third-party detection, and the documentation site has separate setup guides per privilege level.

Official sources

  1. deltazefiro/Amarok-Hider on GitHub
  2. License: Apache-2.0
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/deltazefiro-amarok-hider.svg)](https://hysenlabs.com/projects/deltazefiro-amarok-hider)