Encrypt My Data
Privacy policy
Last updated: 2026-09-12
Your vault stays under your control. This policy distinguishes data used locally by the app from information processed when you visit this website or contact support.
The app has no user account, advertising SDK, analytics SDK or developer-operated sync service. It does not send your vault contents, master password or keys to us. Website requests and support emails are different: they necessarily involve processing some personal information.
1. Who is responsible?
The publisher and controller for the website and support service is Karlsen PcSoft, Norway.
hello@encryptmydata.netUse this address for privacy questions and rights requests. We do not appoint ourselves as the controller of information you choose to keep solely in your own local vault.
2. Information in the app
You choose the website logins, notes, images, fields, folders, tags and drafts stored in your vault. The database and images are encrypted on your iPhone. The app uses your master password to protect the vault key; we do not receive either. The working database is held in memory while the vault is unlocked.
The app has no integrated advertising, analytics, tracking or crash-reporting service and makes no application-controlled network requests. It does not create a remote account or upload vault contents to the publisher. Local search, password generation and password checks take place on the device.
Images may contain embedded metadata, including location information. Importing an image does not necessarily remove it. When sharing images, check the metadata-removal option; removal is enabled by default for sharing.
3. Features that move or temporarily expose information
- Apple device backups. You choose whether the encrypted vault is eligible for your normal iPhone backup. Apple's system handles those backups. Changing this setting does not delete older copies. Restoring requires the master password associated with the backup.
- Backup export. You can save an encrypted backup to a location of your choice. The chosen storage service may process the encrypted file and related metadata under its own terms.
- Sharing. You can share one item as a password-protected encrypted file, or deliberately export it without encryption after confirmation. Recipients, selected apps and services control what happens to the exported copy. The publisher does not receive it unless you separately send it to us.
- Temporary exports. Explicit exports can create temporary decrypted files. The app protects them, excludes them from backup and attempts to remove them when sharing ends or on the next launch. The receiving app may retain its own copy.
- Clipboard. Copying intentionally puts a value on the device clipboard for a limited time so it can be pasted. Automatic vault locking can preserve that short paste window; manual locking clears it. Clipboard items created by the app are marked local-only to prevent Handoff.
- Optional Password AutoFill. If enabled, a separate encrypted snapshot of saved website logins is stored in a shared app container on the same iPhone. It includes the website, username, password and identifying item information. A dedicated biometric-protected key is used, separate from the vault key. The extension requires interaction and confirmation before passing the selected credentials to iOS for the destination you choose. Drafts are excluded. Disable the feature in the app to remove its key and snapshot.
- External links. Opening a saved website, this privacy page, a support email or another external link uses the selected browser or app and its privacy practices.
4. Permissions
Face ID is optional; iOS handles biometric matching and the app does not receive biometric templates. Camera access is requested when you choose to take a photo. The system photo picker gives the app only the pictures you select, without granting access to your whole photo library. Permissions can be changed in iPhone Settings. Your master password works without Face ID.
5. This website and support
| Activity | Information and purpose | Legal basis |
|---|---|---|
| Website delivery and security | IP address, requested page, request time, browser information and technical errors may be processed by the web server to deliver pages, investigate faults and prevent abuse. | Legitimate interests in operating a reliable, secure website; GDPR Article 6(1)(f). |
| Support enquiries | Your email address, message and any details you voluntarily provide are used to answer and resolve your request. Please do not send passwords, vault files or sensitive screenshots. | Article 6(1)(b) where needed to provide requested contractual support; otherwise Article 6(1)(f), our legitimate interest in answering enquiries. |
| Legal obligations or disputes | Relevant correspondence may be retained where required by law or necessary for a specific legal claim. | Article 6(1)(c) for a legal obligation, or Article 6(1)(f) for establishing or defending a claim. |
Providing a support email address and message is voluntary, but we cannot reply without contact details. We do not use support correspondence for mailing lists or targeted advertising. There is no automated decision-making or profiling by this website or support service.
Cookies: this website has no analytics, advertising, embedded third-party widgets, cookies, local storage or tracking pixels in its page code. Language is selected through ordinary page links. Server request logs are separate from browser cookies.
6. Providers and international processing
Website and email hosting: Gigahost AS. The agreed location for these services is Norway. Our hosting provider processes service data under documented instructions and applicable processor terms. Access is limited to what is needed for hosting, delivery, maintenance and security.
Website and email services are agreed to be provided in Norway, within the EEA, so no transfer of this data outside the EEA is intended. Should that change, this policy will be updated and a valid transfer mechanism under Chapter V of the GDPR will be used. Apple handles App Store downloads and payments under its own terms and privacy information.
Apple separately handles App Store downloads, payments, device backup services and any diagnostics you choose to share with Apple. The publisher may receive sales reports and aggregated App Store statistics from Apple. See Apple's privacy information. Services you choose for email, file storage or sharing have their own privacy terms.
7. Retention and deletion
- Vault: local information remains until you delete it. Use the app's delete-vault function and disable AutoFill before uninstalling if you want to remove the app-managed keys and shared snapshot. Uninstalling alone is not a promise that iOS Keychain entries, exported files or backups are erased.
- Server logs: Server access logs are held by the hosting provider only to operate and secure the website, and are not used for profiling or marketing. The exact retention period agreed with the provider is not yet documented here; ask us and we will state the current position.
- Support email: Support email is kept for as long as it is needed to answer you and to document the case, and is deleted when it is no longer needed for that purpose or to meet a legal obligation.
- Hosting and email backups: The hosting provider maintains its own backups of website and email data as part of the service, so deleting a message can take effect in those copies later than in the mailbox. The retention period for provider backups is not yet documented here; ask us and we will state the current position.
Exported or shared copies and Apple-managed backups must be managed separately at their destination. A specific legal preservation requirement may prevent immediate deletion of affected correspondence; we will explain it where permitted. We do not promise forensic overwriting of flash storage or every temporary memory copy.
8. Your rights
For personal information we process, you may request access, correction, deletion, restriction and, where applicable, portability. You may object to processing based on legitimate interests and ask for information about our balancing assessment. If a future activity relies on consent, that consent can be withdrawn. Contact hello@encryptmydata.net; we normally respond within one month. We may request proportionate information to verify your identity.
These rights have legal conditions and exceptions. We cannot export or reset a vault we do not possess. You can manage local vault data in the app. You may complain to Datatilsynet in Norway or your relevant supervisory authority.
9. Children and changes
The app does not ask for age or create profiles, and is not a child-directed online service. The applicable App Store age rating is shown on the store listing. Do not send children's sensitive information to support.
Changes will be published here with a new date. Material changes in processing will be communicated as required before they take effect.