Krypsis Privacy Policy
Effective 6 October 2026 · Version 1.1 · Kriovate Ltd
This is the Privacy Policy for Krypsis, the iOS vault app published by Kriovate Ltd.
It covers the app and this website (getkrypsis.com). Kriovate Ltd’s corporate site has its own, separate website privacy notice covering visitors to that site and correspondence sent to its inboxes.
The short version
- We don’t track what you do in the app. There’s no analytics, no profile, no account.
- Your content is encrypted on your device with a key derived from a PIN only you know.
- We collect no analytics and no crash reports. Krypsis contains no analytics SDK and no crash-reporting SDK — there is nothing to switch off, because there is nothing there.
- The only things that ever leave your device are:
- Your purchase transaction ID, when you buy Lifetime or subscribe to Premium Sync. Apple and our receipts service (RevenueCat) handle this; no name, email, card number, or billing address reaches us.
- Your own vault content, encrypted, to your own iCloud account — and only if you turn on iCloud Sync, which is off by default. It goes to your iCloud, not to us, and neither we nor Apple can read it (Section 4).
That’s it. The rest of this document explains the details, your rights under UK and EU data protection law, and how to contact us.
1. Who we are
Krypsis is published by Kriovate Ltd, a company registered in England & Wales. Kriovate Ltd is the data controller for the limited data described below, wherever this policy is hosted.
- Registered office: 167-169 Great Portland Street, 5th Floor, London W1W 5PF
- Companies House number: 17256908
- ICO registration number: ZC173593
- Privacy contact: privacy@kriovate.com
2. What we collect
2.1 Purchase records — handled by Apple and RevenueCat
When you buy Lifetime or subscribe to Premium Sync:
- Apple processes your payment under their own privacy terms.
- RevenueCat (the receipts service we use, operated by RevenueCat, Inc.) receives a transaction ID and an installation ID so we know your purchase status across your devices.
We never see your card number, billing address, name, or email address. RevenueCat is contractually limited to processing only what’s needed to verify your entitlements.
Retention: RevenueCat retains transaction records for the lifetime of your purchase (so we can validate Lifetime entitlements indefinitely).
2.2 Support emails — only if you write to us
Krypsis has no crash reporting, so the only way a problem reaches us is if you choose to send it. When something fails, the app can open your own mail app with a short technical description pre-filled — you see the entire message and decide whether to send it.
A problem report contains the app version, your iOS version, your device model (e.g. “iPhone”), and a description of the failure, such as which stage of syncing failed and the error your device reported.
It never contains your photos, videos or documents, filenames or album names, your PIN or encryption keys, or your location.
Because it’s an ordinary email, we receive whatever your mail app sends — including your email address. We use it only to reply and to fix the problem, we don’t add it to any mailing list, and we delete support correspondence once the issue is resolved and no longer needed (normally within 12 months).
Nothing is sent automatically or in the background. If you don’t email us, we receive nothing.
2.3 This website
getkrypsis.com has no analytics, no tracking pixels, no cookies, and no third-party scripts. It is static HTML and CSS served from a CDN. We don’t know that you’ve visited.
3. What we do NOT collect
We do not see, log, or transmit any of the following:
- Your photos, videos, or documents
- Filenames, album names, captions, or any other content metadata
- When you unlock your vault, what you import, what you view, what you share, what you delete
- The existence of a decoy vault on your device (the decoy feature is invisible to anyone outside this device by design)
- Your Apple ID, name, email address, phone number, location, contacts, calendar, or any third-party app data
- IP addresses or device fingerprints
The audit trail is the source code. The production Krypsis app contains no os.Logger or os_log calls that record vault activity. Anyone with the binary can verify.
4. Where your data lives
Vault content (your photos, videos, documents, albums, PIN verifier, decoy data) is encrypted with a key derived from your PIN using PBKDF2 and ChaCha20-Poly1305, and stored only on your device. It never leaves the device unless you explicitly:
- Export a
.vaultbakbackup file (the file is itself encrypted with your PIN) - Share an item via iOS’s share sheet (you control the destination)
- Export an item back to the iOS Photos library
- Turn on iCloud Sync (below)
iCloud Sync (optional, off by default)
If — and only if — you turn on iCloud Sync, your vault also syncs between your own devices. Sync is off by default and must be switched on explicitly in Settings.
Where it goes. Into your own iCloud account (Apple’s CloudKit private database), not to Kriovate. We operate no servers and hold no copy of your content. It uses your iCloud storage, not ours.
What is stored there. Only ciphertext and opaque identifiers. Every photo, video and document is uploaded as the same encrypted file already stored on your device. All descriptive information — filenames, album names, dates, favourites — is encrypted inside the record before it is sent. Album membership is stored under a keyed hash, so even the relationships between items are not visible.
Who can read it. Nobody but you. Apple stores the encrypted data but cannot decrypt it; neither can we. Decryption requires your vault key, which never leaves your devices in usable form.
How a second device gets the key. A copy of your vault key, still locked by your PIN, is placed in iCloud Keychain, which Apple itself protects with end-to-end encryption. On a new device you enter your PIN to unlock it. Your PIN is never transmitted or stored anywhere.
The decoy vault never syncs. Its key is never placed in iCloud Keychain, and its contents are never uploaded, under any circumstances.
Turning it off. Disabling sync stops further syncing and removes the key copy from iCloud Keychain. “Remove iCloud Data” additionally deletes everything Krypsis has stored in your iCloud. If a Premium Sync subscription ends, syncing simply pauses — nothing is deleted, and it resumes if you subscribe again.
International transfers. Synced data is held on Apple’s iCloud infrastructure, which may store it outside the UK/EEA. Because the data is encrypted before it leaves your device and Apple cannot decrypt it, the content itself remains inaccessible wherever it is stored. See Apple’s iCloud privacy documentation for their infrastructure and safeguards.
The only data that leaves the device to us is your purchase record, described in Section 2. Synced vault content goes to your own iCloud account, not to Kriovate.
5. International transfers
RevenueCat processes purchase records in the United States. Transfers to the United States are covered by the EU-US Data Privacy Framework and the UK Extension to the Data Privacy Framework, and by standard contractual clauses.
If you enable iCloud Sync, your encrypted vault content is held on Apple’s iCloud infrastructure under Apple’s terms and safeguards. Because it is encrypted on your device before it is sent, and neither Apple nor Kriovate holds the key, the content remains unreadable wherever it is stored.
6. Your rights under UK GDPR and EU GDPR
You have the right to:
- Erase your data. Delete the Krypsis app from your device — all vault content is gone instantly. If you used iCloud Sync, use “Remove iCloud Data” in Settings first to delete the encrypted copy from your iCloud.
- Access your data. We have effectively nothing to give you — only a purchase record, which you can also see in your Apple account.
- Object to processing. There is no analytics or crash reporting to object to. Purchase records are required to validate what you bought.
- Restrict processing or request portability. Your data never reaches us, so portability is automatic — it’s all on your device, and the backup export gives you a copy.
- Lodge a complaint with the UK ICO at https://ico.org.uk, or with your local supervisory authority if you’re in the EU.
We respond to verified requests within 30 days.
7. Cookies and trackers
Krypsis contains:
- No advertising SDKs
- No analytics SDKs (no Google Analytics, no Firebase, no TelemetryDeck, no Mixpanel)
- No crash-reporting SDKs
- No cross-app tracking, no IDFA usage
- No third-party trackers running in the background
Two Apple frameworks talk to anything outside the device, and only when you ask them to: StoreKit when you make a purchase, and CloudKit when you have turned on iCloud Sync.
This website sets no cookies and loads no third-party scripts (Section 2.3).
8. Children
Krypsis is rated 17+ in the App Store and is not intended for users under 13. We don’t knowingly collect data from anyone under 13. If you believe a child under 13 is using the app, please contact privacy@kriovate.com.
9. Security
- Vault content is encrypted on-device using ChaCha20-Poly1305 with a per-vault random master key. The master key is wrapped (encrypted) with a key derived from your PIN using PBKDF2 (100,000 iterations).
- Your PIN is never stored. A wrapped-key verifier is stored in the iOS Keychain; if your PIN is wrong, the wrapped key won’t unwrap.
- Synced records are encrypted with per-purpose keys derived from your vault key, and are bound to their own identity so a record cannot be replayed in place of another.
- We have no master key, recovery key, or backdoor. If you forget your PIN and have no backup, the data is mathematically unrecoverable. See our Terms of Service for the consequences.
10. Changes to this policy
If we add new processing — for example a new sub-processor, or a feature that sends something new — we’ll update this policy and bump the version number at the top. Existing users will see an in-app notice on next launch.
The current and previous versions of this policy will remain available at the published URL.
11. Contact
| What | Where |
|---|---|
| Privacy questions / GDPR requests | privacy@kriovate.com |
| ICO complaints | https://ico.org.uk |
| Postal | Kriovate Ltd, 167-169 Great Portland Street, 5th Floor, London W1W 5PF |