# Third-Party Licenses - ScreenTinker

> The open-source components ScreenTinker is built on, with their licences and attribution.

Source: https://screentinker.com/legal/third-party

[← Back to ScreenTinker](https://screentinker.com/)

## Third-Party Software Notices

Last updated: March 24, 2026

ScreenTinker uses the following open-source software components. We gratefully acknowledge the contributions of these projects and their maintainers.

### Summary

| Package | License | Use |
| --- | --- | --- |
| Express | MIT | Web server framework |
| Socket.IO | MIT | Real-time WebSocket communication |
| better-sqlite3 | MIT | SQLite database driver |
| Multer | MIT | File upload handling |
| uuid | MIT | Unique ID generation |
| Jimp | MIT | Image processing and thumbnails |
| @jsquash/webp, @jsquash/avif | Apache 2.0 | WebP / AVIF encoding |
| FFmpeg (ffprobe, ffmpeg) | LGPL 2.1 or later | Video duration, dimensions and thumbnails. Bundled as unmodified binaries with the BrightSign player package only; built from unmodified FFmpeg 7.1.1 sources configured `--disable-gpl`, so no GPL component (including libpostproc) is included. |
| cors | MIT | Cross-origin resource sharing |
| bcryptjs | MIT | Password hashing |
| jsonwebtoken | MIT | JWT authentication tokens |
| Helmet | MIT | HTTP security headers |
| google-auth-library | Apache 2.0 | Google OAuth verification |
| OkHttp | Apache 2.0 | Android HTTP client |
| Gson | Apache 2.0 | Android JSON parsing |
| AndroidX Media3 / ExoPlayer | Apache 2.0 | Android video playback |
| AndroidX libraries | Apache 2.0 | Android UI and lifecycle |
| Material Components for Android | Apache 2.0 | Android UI components |
| Socket.IO Java Client | MIT | Android WebSocket client |
| Kotlin Coroutines | Apache 2.0 | Android async operations |
| AndroidX Security Crypto | Apache 2.0 | Encrypted SharedPreferences |
| AndroidX WorkManager | Apache 2.0 | Background task management |

### MIT License

The following packages are licensed under the MIT License:

Express, Socket.IO, better-sqlite3, Multer, uuid, cors, bcryptjs, jsonwebtoken, Helmet, Socket.IO Java Client

MIT License

Copyright (c) respective authors and contributors

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

### GNU Lesser General Public License v2.1

The BrightSign player package bundles two FFmpeg command-line programs, `ffprobe`
and `ffmpeg`, used to read the duration and dimensions of uploaded video and to
generate thumbnails. They are built from unmodified FFmpeg 7.1.1 sources
([ffmpeg.org](https://ffmpeg.org/)) and are licensed under the GNU Lesser General
Public License, version 2.1 or later.

They are configured with `--disable-gpl`, so no GPL-licensed FFmpeg component is
present — including `libpostproc`, which is GPL-only. No FFmpeg source was modified.

**Written offer.** These binaries are statically linked. On request we will supply
the complete corresponding source, the exact `configure` arguments used, and the
object files needed to relink the programs against a modified version of the library, as
section 6 of the LGPL requires. Contact [support@screentinker.com](mailto:support@screentinker.com).
The full licence text is at
[gnu.org/licenses/lgpl-2.1](https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html),
and a copy ships beside the binaries in the player package.

### Apache License 2.0

The following packages are licensed under the Apache License, Version 2.0:

@jsquash/webp, @jsquash/avif, google-auth-library, OkHttp, Gson, AndroidX Media3/ExoPlayer, AndroidX libraries, Material Components for Android, Kotlin Coroutines, AndroidX Security Crypto, AndroidX WorkManager

Apache License
Version 2.0, January 2004
http://www.apache.org/licenses/

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.

### Contact

If you have questions about the licensing of any component used in ScreenTinker, please contact us at support@screentinker.com
