The short version
Krypta is an offline, encrypted file vault. We do not collect, transmit, sell, or share any of your personal data. There are no Krypta servers, no accounts, no analytics, no advertising, and no tracking. Everything you put in Krypta is encrypted and stored on your device.
The only time any of your data leaves your device is if you turn on Google Drive backup, in which case an already-encrypted backup is uploaded to your own Google Drive. We never receive it, and Google cannot read it.
1. Information we do not collect
Krypta does not collect, log, or transmit:
- your files, photos, videos, audio, documents, or notes;
- your PIN, recovery code, or any encryption key;
- your name, email, contacts, location, or device identifiers;
- analytics, usage statistics, crash reports, or advertising identifiers.
Krypta has no backend server and makes no network requests except those required for the optional Google Drive backup you explicitly enable (Section 5).
2. Data stored on your device
Everything you add to Krypta — imported or captured files, secure notes, and app settings — is stored locally on your device and encrypted with XChaCha20-Poly1305. The encryption key is derived from your 6-digit PIN using Argon2id and combined with a per-device secret held in your device’s hardware-backed secure storage (Android Keystore). As a result, your data cannot be decrypted off the device or on another device, and we cannot access it.
This on-device data is fully under your control. You can delete individual items, or wipe the entire vault, at any time (Section 7).
3. Permissions and why Krypta requests them
Krypta requests the minimum permissions needed for the features you use. None of the data accessed through these permissions is sent to us or any third party.
| Permission | Why it’s used | Leaves your device? |
|---|---|---|
| Camera | Capture photos/videos directly into the vault; scan documents; optionally photograph someone who enters a wrong PIN (“intruder photo”). | No |
| Microphone | Only to record sound when you record a video. | No |
| Photos & videos | The in-app gallery, to let you choose which photos/videos to encrypt and (optionally) delete the originals after. | No |
| Network / Internet | Only to upload/download the encrypted backup if you enable Google Drive backup. | Only the encrypted backup, to your own Drive |
Captured media is written to a temporary location, encrypted into the vault, and the temporary plaintext copy is deleted. Captures never appear in your camera roll.
4. Intruder photos
If you enable “Capture intruder photo,” Krypta silently takes a front-camera photo when an incorrect PIN is entered while the app is locked. These photos are encrypted on your device (under the device secret) and shown only to you in the in-app Security log. They are never uploaded and are deleted when you leave the Security log.
5. Google Drive backup (optional)
If you choose to back up to Google Drive, Krypta uses Google Sign-In and the Google Drive API to store an encrypted backup of your vault in your Google account.
- What is uploaded: a single backup file that is already encrypted on your device under your recovery code before it is uploaded. Google — and anyone else — only ever stores ciphertext. Restoring the backup additionally requires your recovery code, which only you have.
- Where it is stored: in the application data folder (appDataFolder) of your Google Drive — a hidden, app-specific folder. It is not visible in your normal Drive view, and Krypta cannot see or access any of your other Drive files.
- Scope requested: https://www.googleapis.com/auth/drive.appdata only.
- What we receive: nothing. There is no Krypta server; the upload goes directly from your device to your Google Drive.
- Your control: you can disable backup at any time and delete the backup file from your Google account.
Google API Services Limited Use disclosure
Krypta’s access to information from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Krypta uses Google user data (the Google Drive appDataFolder and the basic account identity used to sign in) solely to provide and improve the in-app backup and restore feature that you enable. Krypta does not transfer, sell, or use this data for advertising, and does not allow humans to read it, except (a) with your explicit consent, (b) for security purposes, or (c) to comply with applicable law.
6. Information shared with third parties
We do not share your data with any third party. The only third party involved is Google, and only when you enable Drive backup — and even then Google stores only your encrypted backup in your own account, which it cannot read. We have no advertising, analytics, or data-broker integrations.
7. Data retention and deletion
- On your device: retained until you delete it. Delete individual files, folders, or notes from within the app; use Settings → Wipe vault to erase everything, including the device key (irreversible).
- Optional auto-wipe: if you enable it, repeated wrong PIN attempts will permanently erase the vault.
- In Google Drive: your encrypted backup remains in your Google account until you delete it (disable backup in Krypta, and/or remove the file via Google’s account tools).
- Uninstalling the app removes all on-device Krypta data.
8. Security
Your data is encrypted with XChaCha20-Poly1305 (authenticated encryption), with keys derived via Argon2id and bound to your device’s hardware-backed secure storage. The app supports optional screenshot/screen-recording blocking, a decoy PIN, and auto-lock. No security system is perfect, but your data is never sent to us and never stored in a form anyone but you can decrypt.
9. Children’s privacy
Krypta is not directed to children under 13 (or the equivalent minimum age in your jurisdiction) and does not knowingly collect personal information from children. Because Krypta collects no personal information from anyone, no special data-handling for children applies.
10. Your rights
Because Krypta stores your data only on your device (and, optionally, encrypted in your own Google Drive) and we hold none of it, requests to access, correct, port, or delete your data are satisfied entirely through the app itself and your Google account. If you have questions about your rights under laws such as the GDPR or CCPA, contact us at the address below.
11. Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected by an updated “Effective date” above and, where appropriate, an in-app notice.
12. Contact
Questions about this policy or your privacy: chenna.kiran1@gmail.com.