Section 01
Who We Are
AppLock Vault ("we", "our", or "us") is a mobile application developed for Android devices. The app provides app locking, private file vault, intruder detection, guest mode, panic mode, and security intelligence features.
By downloading or using AppLock Vault, you agree to the collection and use of information in accordance with this Privacy Policy.
Section 02
Information We Collect
We collect only what is necessary to deliver app functionality. Here is exactly what we collect and why:
With your explicit permission, we read which app is currently in the foreground to show the lock screen when a protected app is opened. This data is processed locally and never transmitted to any server.
Used for two features: (1) Intruder selfie — captures a front-camera photo when someone enters the wrong unlock code. Photos are stored privately in the app's internal storage (inaccessible to other apps) and are never uploaded. (2) AI Face Unlock — processes your face locally using an on-device ML model to verify your identity. No face data leaves your device.
Used for two optional features: (1) Wi-Fi based profile switching — Android requires location permission to read Wi-Fi network names (SSID). We do not record or transmit your location. (2) Panic SOS — if you have enabled the panic feature with trusted contacts, your approximate location is included in the SOS SMS message sent to those contacts. This requires your explicit setup.
We send local notifications for: protection status, intruder alerts, guest session timers, and panic/SOS events. We do not send marketing push notifications.
The Panic / SOS feature can send a silent text message containing a pre-configured emergency message and your location to contacts you have manually added. This is triggered only by you (via the panic button or shake gesture). We never send SMS without your knowledge or consent. This feature requires explicit opt-in.
We use Google Firebase to collect anonymised crash reports and usage analytics. This helps us identify bugs and improve the app. Firebase may collect: device model, OS version, app version, crash stack traces, and anonymous usage events (e.g., screens viewed). Firebase does not receive your vault files, locked app list, PIN, or any biometric data. You can review Google's data practices at policies.google.com/privacy.
AppLock Vault may display ads served by Google AdMob. AdMob may collect device identifiers (Advertising ID), IP address, and usage data to serve personalised or non-personalised ads depending on your consent and region. We do not pass any of your personal vault data or locked app information to AdMob. You can opt out of personalised ads in your Android device settings under Google → Ads → Delete Advertising ID or opt out of personalised ads. For more information, see Google's Advertising Policies.
Section 03
Data We Do NOT Collect
- Your PIN, pattern, or password (stored encrypted on-device only)
- Contents of your private vault (files are encrypted on-device)
- The list of apps you have locked
- Your face data or biometric templates
- Intruder photos (stored locally, never uploaded)
- Your contacts list (SOS contacts are stored locally only)
- Your browsing history or activity in locked apps
Section 04
How We Use Information
- To provide and improve app features (locking, vault, face unlock)
- To detect crashes and fix bugs (Firebase Crashlytics)
- To understand general usage patterns and improve UX (Firebase Analytics)
- To display advertisements and generate app revenue (AdMob)
- To send local security alerts and notifications on your device
We never use your data for profiling, selling to data brokers, or any purpose beyond what is listed above.
Section 05
Permissions Explained
Here is every Android permission AppLock Vault requests and exactly why:
- PACKAGE_USAGE_STATS — detects foreground app to trigger lock screen
- SYSTEM_ALERT_WINDOW — draws the lock screen overlay above other apps
- CAMERA — intruder selfie on wrong code; face unlock enrollment and recognition
- ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION — Wi-Fi SSID reading for profile auto-switch; panic SOS location attachment
- SEND_SMS — panic SOS only, with explicit user setup and consent
- FOREGROUND_SERVICE / FOREGROUND_SERVICE_SPECIAL_USE — keeps the lock service running in the background
- REQUEST_IGNORE_BATTERY_OPTIMIZATIONS — prevents OEM battery killers from stopping the lock service
- POST_NOTIFICATIONS — shows protection status and security alerts
- RECEIVE_BOOT_COMPLETED — auto-starts the lock service after device reboot
- USE_BIOMETRIC — fingerprint and biometric unlock
- USE_FULL_SCREEN_INTENT — shows the lock screen reliably over a protected app
- ACCESS_WIFI_STATE / ACCESS_NETWORK_STATE — reads the current Wi-Fi network name for profile auto-switch; checks connectivity for ads/analytics
- AD_ID — Google Advertising ID, used by AdMob to serve ads (see the AdMob section above)
- VIBRATE — haptic feedback on the lock screen
- INTERNET — required by Firebase and AdMob SDKs
No storage or media permissions. Vault import uses the Android system photo/document picker, which grants access only to the individual files you pick — AppLock Vault never requests READ_MEDIA_* or storage permissions and cannot browse your gallery or files.
Section 06
Data Storage & Security
All sensitive data — including your PIN hash, vault files, intruder photos, and face enrollment data — is stored exclusively on your device. We use AES-256 encryption for vault files and PBKDF2 with salt for PIN/password hashing.
We do not operate servers that store your personal content. If you uninstall AppLock Vault, all locally stored data is deleted by the operating system.
No backup of sensitive data is allowed — we have explicitly disabled Android cloud backup for all app data (android:allowBackup="false").
Section 07
Third-Party Services
The following third-party services are integrated into AppLock Vault. Each has its own Privacy Policy:
Analytics and crash reporting. Firebase Privacy Policy →
Mobile advertising. Google Privacy Policy →
On-device face detection for the AI Face Unlock feature. All inference runs locally; no data is sent to Google's servers during face recognition. ML Kit Terms →
Section 08
Children's Privacy
AppLock Vault is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and you believe your child has provided us with personal information, please contact us so we can take the necessary steps.
Section 09
Your Rights
Depending on your location, you may have the following rights regarding your data:
- Access — request a copy of data we hold about you
- Deletion — request deletion of your data (most data is already only on your device; uninstalling the app deletes it)
- Opt-out of personalised ads — via Android device settings → Google → Ads
- Data portability — your vault files are on your device; you can copy them at any time
To exercise these rights, contact us at the email below.
Section 10
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by updating the "Last updated" date at the top of this page and, where appropriate, through an in-app notification. We encourage you to review this policy periodically.
Continued use of AppLock Vault after changes constitutes your acceptance of the revised policy.
Section 11
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please reach out:
📧 Email: xypherlabs.dev@gmail.com
We aim to respond to all privacy-related inquiries within 7 business days.