Privacy Policy — Calculator Vault
Publishable text (research pass 2026-08-31). Not yet live. M15 must host this at [POLICY URL] before the first upload, link it in Play Console → App content → Privacy policy, and link it in-app (Settings → Privacy). If the linked page 404s, geofences, or requires login, that is a User Data policy violation: expect update rejection or listing removal until fixed. Verify every ad-network link below still resolves on the day of publication.
In-app twin: renders this same policy offline at Settings → About → Privacy policy. Same facts, same order — if one changes, the other changes in the same commit.
Effective date: 31 August 2026 App: Calculator Vault — Hide Photos (com.neonix.calculatorvault) Publisher and data controller: Neonix Apps Contact: This policy lives at: [POLICY URL]
The short version
Calculator Vault stores your photos, videos, audio, documents and notes encrypted on your own phone. We never see them, we never receive them, and we cannot recover them. There is no account, no sign-up, and no server of ours anywhere in this app.
The only personal data that leaves your device is what advertising in the free version sends to ad networks, and this policy lists all of it. If you buy Premium, the advertising code is never even loaded, and nothing in the "advertising" sections below applies to you.
What the free version's advertising collects
Ads are shown through Appodeal, an ad-mediation service, which passes ad requests to the networks listed below. When an ad is requested, the network serving it receives:
| Data | Why | How to stop it |
|---|---|---|
| Advertising ID (Google advertising ID, and Google's app set ID) | Selecting, limiting and measuring ads; fraud prevention | Buy Premium (ad code never initializes), revoke consent in Settings → Privacy choices, or reset/delete the ID in Android Settings → Privacy → Ads |
| IP address, from which networks estimate your approximate (city-level) region | Ad delivery, coarse regional ad selection, fraud prevention | As above. The app itself requests no location permission and has no precise location |
| Ad interactions (which ads were shown, viewed or tapped) | Measuring and capping ads; billing advertisers | As above |
| Device and diagnostic information (device model, OS version, and the ad SDK's own crash/performance data) | Serving ads that work on your device; keeping the ad SDK working | As above |
That is the whole list. There is no analytics SDK, no attribution SDK and no crash-reporting SDK of ours in the app, and an automated build check fails our release build if one ever appears.
Purchases. Premium is bought through Google Play Billing. Google processes the payment as its own controller under ; we never see your payment details. The app stores only a local yes/no record that Premium is owned.
What the app never collects
- Your photos, videos, audio, documents or notes. They are encrypted on your device and never transmitted anywhere by us.
- Your PIN, password or recovery key. The PIN is not even stored on the device — it is used to mathematically unwrap a key, and a successful unwrap is the only proof it was right.
- Filenames, file counts, album names, or anything else about your vault.
- Contacts, precise location, calendar, call logs, or messages.
- Anything at all, for Premium users.
Your files and the encryption
Files are encrypted on your device with AES-256-GCM (via Google's Tink library), each file with its own key derived from a master key. The master key is wrapped by a key derived from your PIN (using Argon2id), by a key derived from your recovery key, and — if you enable biometric unlock — by a key held in your phone's hardware keystore. Decryption happens in memory only; decrypted files are never written to storage.
We hold no key and operate no escrow. If you lose both your PIN and your recovery key, your files cannot be recovered by anyone, including us. That is not a limitation we can lift on request; it is what makes the encryption real.
The durable-vault folder (Premium) is an encrypted copy of your vault written to a folder you choose on your own device or SD card. Everything in it is ciphertext. It never leaves your device unless you move it, and it is never sent to us. Delete it whenever you like; it is yours.
Advertising consent, and how to change your mind
Where the GDPR, the UK GDPR, the ePrivacy rules or a comparable law applies, the free version asks for your consent through a consent form before any ad code initializes. If you refuse, or your answer is unavailable or indeterminate, ads are requested as non-personalized. You can review or revoke your choice at any time in Settings → Privacy choices; revoking takes effect from the next ad request.
Appodeal and the networks it may mediate for this app, each responsible for its own processing under its own policy:
- Appodeal —
- Google AdMob —
- AppLovin —
- Unity Ads —
- Vungle (Liftoff) —
- Mintegral —
- MyTarget —
- BidMachine —
- Meta Audience Network —
Some of these networks process data outside your country, including in the United States, under their own safeguards (such as EU standard contractual clauses); see their policies for details.
Legal bases (GDPR / UK GDPR)
- Personalized ads: your consent (Article 6(1)(a)). You may withdraw it at any time as described above, without losing any app functionality.
- Non-personalized ads, fraud prevention and keeping the ad SDK working: legitimate interest (Article 6(1)(f)) in funding the free version and preventing ad fraud.
- Knowing whether you own Premium: performance of a contract (Article 6(1)(b)).
Your rights
Everyone: revoke ad consent in Settings → Privacy choices; reset or delete your advertising ID in Android Settings → Privacy → Ads; delete everything the app holds by deleting files in-app or uninstalling the app (and deleting your durable-vault folder, if you made one).
EEA / UK (GDPR, UK GDPR): you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your supervisory authority (in the UK, the ICO). Because we operate no server and keep no records about you, the personal data in scope is what the ad networks hold; write to and we will pass your request to Appodeal, or contact any network directly under its policy above.
California (CCPA/CPRA): the ad requests described above may count as "sharing" (and in some readings "selling") personal information for cross-context behavioral advertising. You can opt out at any time via Settings → Privacy choices — that control is our "Do Not Sell or Share My Personal Information" mechanism — or by buying Premium, which ends all collection. You also have rights to know, to delete, and to non-discrimination; requests to , and we will not treat you differently for exercising them. We have no financial-incentive programs and no way to verify identity beyond your request itself, because we hold no account data.
Data deletion requests: email . For anything on your device, deletion is in your hands as described above; for ad-network data we will forward your request to Appodeal within 7 days.
Children
Calculator Vault is not directed to children and is intended for users 18 and over. We do not knowingly collect personal data from children under 13 (or the higher equivalent age in your jurisdiction). If you believe a child has used the free version and an ad network received their data, contact and we will forward the deletion request.
Retention
We retain nothing, because we receive nothing. Data on your device stays until you delete it or uninstall the app. Ad networks retain what they collect under their own published retention periods (linked above).
Changes to this policy
If this policy changes, we will update the effective date at the top and, for material changes, say so in the app before the change takes effect. Previous versions are available on request from .
Comments
Post a Comment