On this page
1. Overview
CryptoBox ("the app", "we", "us", or "our") is a privacy-first encrypted vault for storing photos, files, passwords, two-factor codes, identity records, and personal notes. This Privacy Policy describes how the app handles your information.
Our guiding principle is simple: your data belongs to you. CryptoBox is designed so that the data you place in the vault stays on your device, encrypted with a master password that only you know.
2. Information we collect
2.1 Information you provide to the app
When you use CryptoBox, you may choose to add the following types of content into your encrypted vault:
- Photos and videos imported into encrypted albums.
- Files and documents imported into the file vault.
- Login credentials, including usernames, passwords, websites and tags.
- Payment cards, including card numbers, expiry dates and notes.
- Identity records, including names, addresses and identification numbers you choose to enter.
- Two-factor authentication secrets (TOTP) added by QR code or otpauth:// URI.
- Encrypted memos and notes, optionally with reminders.
- Your master password, used to derive the encryption key. The plaintext master password is never stored or transmitted.
All of this content is encrypted on your device before it is written to disk. We do not have a copy and we have no way to read it.
2.2 Information we do not collect
CryptoBox does not require you to create an account, sign up with an email address, or provide any personal identifier in order to use the app. We do not collect:
- Your name, email address, or phone number.
- Your master password (in any form, including hashed).
- The contents of your vault, including filenames, metadata, or thumbnails.
- Your contacts, calendar, location, or microphone data.
- Behavioral or advertising profiles.
2.3 Diagnostic data
If you opt in to share diagnostic information, the app may send anonymous, aggregated crash logs to help us fix bugs. This data does not include the contents of your vault and cannot be tied back to your identity. Diagnostics are off by default.
3. How we use information
Because the app does not collect personal data on our servers, the only "use" of your information happens locally on your device:
- To encrypt, store, search, and display the items you add to the vault.
- To compute on-device features such as your security score, password health, and 2FA codes.
- To deliver local reminders for encrypted memos.
- To support iOS features you explicitly enable, such as Face ID or Touch ID unlock.
Anonymous diagnostic data, if you opt in, is used only to identify and fix crashes or performance issues.
4. Device permissions
CryptoBox requests the following device permissions only when you actively use a related feature:
- Photos / Files: required to import photos, videos, and files into encrypted vaults. Selected items are copied into the encrypted vault and you can choose to remove the originals.
- Camera: used to scan QR codes when adding 2FA accounts. The camera feed is processed in-memory and never recorded.
- Face ID / Touch ID (Local Authentication): used only as an optional shortcut to unlock the vault. Biometric data never leaves the iOS Secure Enclave.
- Notifications: used solely to fire local reminders for encrypted memos.
You may revoke any permission at any time from iOS Settings.
5. Encryption & on-device storage
CryptoBox uses industry-standard cryptography to protect your vault:
- Vault contents are encrypted using AES-256-GCM authenticated encryption.
- Encryption keys are derived from your master password using a memory-hard key derivation function (such as Argon2id) with a unique random salt per vault.
- Per-album passwords add an extra encryption layer to specific albums.
- The plaintext master password is never written to disk and never transmitted over the network.
The encrypted vault is stored within the app's sandboxed container on your device. Without the master password, the vault is mathematically infeasible to decrypt. We cannot recover your password or your data on your behalf.
6. Sharing & disclosure
We do not sell, rent, or trade your personal data. Because the contents of your vault never leave your device, there is nothing for us to share. We may disclose limited account or usage information only when required by law, such as to comply with a valid subpoena, court order, or other legal process.
7. Third-party services
CryptoBox integrates with a small set of optional, privacy-respecting platform services:
- Apple App Store for distribution and updates.
- Apple iCloud, only if you enable iCloud Backup in iOS Settings. In that case, the encrypted vault file may be included in your encrypted iOS device backup. We do not have access to it.
- Apple StoreKit, used only if you choose to make in-app purchases. We never receive your payment card information.
CryptoBox does not embed third-party advertising, analytics, or tracking SDKs.
8. Data retention
You decide how long your vault data lives. You can delete individual items, entire albums, or wipe the whole vault at any time. Uninstalling the app removes all encrypted data from the device. We do not maintain any server-side copy of your vault.
9. Children's privacy
CryptoBox is not directed to children under the age of 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can take appropriate action.
10. Your rights
Depending on where you live, you may have rights under applicable privacy laws (such as GDPR, UK GDPR, or CCPA), including the right to access, correct, delete, or port your personal data, or to object to certain processing. Because CryptoBox stores your data only on your device:
- Access & portability: you can view and export your data directly inside the app.
- Correction: you can edit any record at any time.
- Deletion: you can delete records, albums, or the entire vault from within the app.
- Objection / withdrawal of consent: you can disable optional features such as diagnostic sharing in the settings.
If you have additional questions about exercising your rights, contact us at the address below.
11. Changes to this policy
We may update this Privacy Policy from time to time, for example to reflect new features or to comply with legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page and, when appropriate, notify you in-app. Your continued use of CryptoBox after the changes take effect means you accept the updated policy.
12. Contact us
If you have any questions, requests, or concerns regarding this Privacy Policy or your personal data, please contact us at:
Email: privacy@cryptobox.app
Support: support center
We will do our best to respond within a reasonable timeframe.