Privacy Policy
What CrypKey stores on your device, the limited information we receive when you licence the app, and what we do with it.
In short
Your vault never reaches us. Passwords, notes and attachments are written to your own device and are never uploaded or synced.
The app is licensed per device, so when you request or activate a licence we do receive your name, email, phone and device details — and the app checks with our server that the licence is still valid. That is the only data that leaves your phone.
This website sets no cookies and runs no analytics. The demo stays in your browser.
01Who we are
CrypKey is a credential vault for Android and iOS, published by Zap Solutionz (“we”, “us”). This policy covers the CrypKey mobile application, this website at crypkey.in, and the interactive demo hosted on it.
For any privacy question, or to exercise the rights described in section 10, contact us at support@zapwms.com.
02Your vault stays on your device
Everything you save into CrypKey — categories, items, sections, fields, passwords, notes, images and file attachments — is written to storage on your own device. It is never uploaded to us, never synced to a server, and we have no technical means of reading it.
- Vault contents are stored in the app's private storage area on the device.
- Your app PIN is held in the operating system's secure credential store (Keychain on iOS, Keystore on Android).
- Preferences such as bookmarks, chosen colours and the backup-reminder setting are stored locally alongside the vault.
- Backups you create are written as a JSON file into the app's document folder. If you then export or share that file, it goes wherever you send it — from that point it is outside the app and outside our control.
03Information we receive when you licence the app
CrypKey is licensed per device, and that is the one part of the app that communicates with our servers. When you request, activate or use a licence, the following is sent to our licensing service:
- When you request a licence: your full name, email address and phone number, together with a device identifier, device name and device model.
- When you activate a licence: the licence key and the device identifier.
- While you use the app: the licence key and device identifier are sent when the app starts and has an internet connection, so we can confirm the licence is still valid. No vault data is included in this check.
- If you ask us to restore a revoked licence: the reason you give, the revoked licence key and the same device details.
We use this information solely to issue, validate, support and — where necessary — revoke licences, and to contact you about your licence. The lawful basis is the performance of our agreement with you. We do not use it for advertising and we do not sell it.
04Connectivity check
Before validating a licence, the app checks whether the device is online by making a single lightweight request to google.com. No CrypKey data is included in that request, but as with any web request your IP address is visible to the receiving service. If the device is offline the app skips validation and continues to work normally.
05Device permissions the app asks for
Each permission is requested only at the point it is needed, and only for that purpose:
- Biometrics / device credentials — to unlock the vault. Authentication is performed by your operating system; your fingerprint or face data is never shared with, or accessible to, the app.
- Photo library and camera — only when you choose an image for a category, item or image field. Images you pick are stored in the vault on your device.
- Files and documents — only when you attach a document or import a backup file.
- Notifications — to show the optional weekly backup reminder. These are scheduled and delivered entirely on your device; no push service is involved and we send you nothing.
06This website and the browser demo
The website is a static marketing site. It sets no cookies, runs no analytics and includes no advertising or tracking scripts. Fonts are served from our own domain rather than a third-party font service.
The interactive demo runs entirely inside your browser. Its sample vault, and any changes you make to it, are held in your browser's local storage on your own computer and are never transmitted to us. You can clear it at any time with the Reset Demo control in the demo's Settings screen, or by clearing site data in your browser.
Our hosting provider keeps standard server logs (including IP address, timestamp, requested URL and user agent) for security and reliability. These are retained for a short period and are not used to profile visitors.
08How long we keep it
Licence records — your name, email, phone and device details — are kept for as long as the licence is active, and for 24 months afterwards so that we can handle support queries, reissue licences and meet accounting obligations. After that they are deleted or anonymised.
We hold nothing to delete in respect of your vault, because we never receive it. Removing the app from your device removes the vault with it.
09Security — and its limits
The vault is protected by an app PIN and, where your device supports it, biometric unlock. Your PIN is stored in the platform secure store rather than ordinary app storage. After three consecutive failed unlock attempts, the app deletes the working copy of your vault as a defence against someone guessing their way in.
We are also clear about what these measures do not do. The vault relies on your device's own protections; if your device is unlocked, compromised, rooted or jailbroken, those protections can be bypassed. Backup files are unencrypted by design. Neither we nor anyone else can recover your vault if you lose the device without a backup — there is no copy anywhere else.
10Your rights
In relation to the licensing information we hold about you, you may ask us to give you a copy of it, correct it if it is wrong, delete it, or restrict how we use it. Where we rely on your consent, you may withdraw that consent at any time.
Write to support@zapwms.com and we will respond within 7-30 days. Note that deleting your licence record will deactivate the licence on your device. If you are not satisfied with our response, you may complain to your local data protection authority.
11Children
CrypKey is not directed at children and we do not knowingly collect information from anyone under the age of 10. If you believe a child has provided us with licensing information, contact us and we will delete it.
12Changes to this policy
If we change how we handle information we will update this page and revise the “last updated” date at the top. Where a change materially affects you, we will make reasonable efforts to tell you directly using the email address on your licence record.
13Contact us
Questions about this policy, or about how CrypKey handles data, should go to support@zapwms.com. We aim to reply to every enquiry.