LEGAL

Privacy Policy

Effective Date: March 9, 2026 · Last Updated: March 9, 2026
✔ TL;DR — CovertX collects zero personal data. Your files are encrypted on your device and never leave it. We have no servers that receive your content. This is a privacy-first, on-device-only application. Full stop.

1. Who We Are

CovertX is developed and maintained by Crypton Studio (contact: support@cryptonstudio.app). CovertX is an Android application providing on-device encrypted file storage with decoy vault and intruder detection capabilities.

2. What Data We Collect

The short answer: none of your personal data.

The detailed breakdown:

CATEGORY COLLECTED? WHERE IT GOES
Files you import (photos, videos, docs) NEVER UPLOADED Encrypted on-device only
Intruder selfie photos NEVER UPLOADED Encrypted in app's private storage
PIN or biometric data NEVER COLLECTED PIN hash stored locally via flutter_secure_storage
Personal identification info NOT COLLECTED N/A — no account required
Device identifiers NOT COLLECTED BY US Google/AdMob may collect (see §5)
Location data NOT COLLECTED N/A
Usage analytics NOT COLLECTED BY US Firebase may collect crash data (see §5)
Payment information NOT COLLECTED BY US Handled by Google Play + RevenueCat

3. How Your Files Are Handled

When you import a file into CovertX:

Your files are never transmitted to any server — not ours, not anyone else's.

4. Intruder Detection & Selfies

CovertX includes an intruder detection feature that:

Intruder photos are:

5. Encryption Specifications

CovertX uses the following encryption architecture:

Without your PIN, the encrypted files are unreadable binary data. Even if someone extracted your device's internal storage, they would find only encrypted noise.

6. Third-Party Services

CovertX integrates the following third-party SDKs. These operate under their own privacy policies:

Google AdMob (Free users only)
The free version displays banner and interstitial ads. AdMob may collect device identifiers and approximate location to serve relevant ads. Pro users see no ads and ad serving is disabled.
Google Privacy Policy →

Firebase Analytics & Crashlytics
Used for anonymised crash reporting and app stability monitoring. Crash reports contain stack traces only — no file content, no PIN, no user data is ever included in crash reports.
Firebase Privacy Policy →

RevenueCat
Handles in-app purchase verification and subscription management. RevenueCat receives anonymised purchase data from Google Play to verify Pro status. No file content or vault data is shared.
RevenueCat Privacy Policy →

Google Play Billing
In-app purchases are processed by Google Play. We do not receive or store any payment information.
Google Play Privacy Policy →

7. Permissions We Request

8. Data Retention

All vault data exists only on your device with no expiration. You control deletion entirely:

We have no ability to delete data on your behalf because we have no access to it.

9. Children's Privacy

CovertX is not directed at children under 13. We do not knowingly collect any data from children. The app requires understanding of encryption concepts and PIN management that is unsuitable for children. If you are a parent and believe a child is using this app, please contact us.

10. Your Rights

Since CovertX holds no personal data on any server, traditional data rights (access, erasure, portability) are exercised directly on your device by managing content within the app or uninstalling it. For third-party data (AdMob, Firebase, RevenueCat), refer to their respective privacy policies and opt-out tools.

11. Changes to This Policy

We may update this privacy policy from time to time. Changes will be reflected with a new effective date on this page. Material changes will be noted in the app's Play Store release notes. Continued use of CovertX after changes constitutes acceptance of the updated policy.

12. Contact

Questions about this privacy policy: