SecondLock Privacy Policy
Last updated: September 5, 2026 Where the App is sold: Japan, Taiwan, South Korea, the United Kingdom, Canada, Australia and New Zealand
The short version
SecondLock ("the App") collects nothing about you.
Most privacy policies explain what a company does with the data it collects. This one exists to explain that there is no collected data to describe, and why.
1. What we don't collect
The App does not collect any of the following:
| Name, email address, phone number | Not collected. There are no accounts to sign up for |
| Location | Not collected |
| Contacts | Not collected |
| Device identifiers, advertising ID | Not collected |
| Usage data, event logs, analytics | Not collected. No analytics software is built into the App |
| Crash reports | Not collected |
| The photos and videos you store | Cannot be collected — see section 2 |
The App contains no third-party SDKs for advertising, analytics, attribution or crash reporting. The App shows no advertising of any kind, including on the free tier. Nothing about you is sent to any other company.
2. The photos and videos you store
- Photos and videos you add are encrypted on your iPhone before they are written anywhere.
- The encryption key is derived from the PIN you choose. We do not hold that key.
- Therefore we cannot read what you store. This is not a policy we could change our minds about; it is how the software is built.
- On a paid plan, the encrypted data is stored in your own iCloud account. We never hold your data.
- The data is still encrypted when it reaches iCloud. We run no servers and never touch the encrypted data or the key.
- So that you can recover on a new device, the information needed to rebuild the key from your PIN (salt, iteration count, and the key wrapped by your PIN) is also stored in iCloud, in encrypted form. Your PIN itself is never stored.
3. We do not sell or share your personal information
We hold no personal information, so there is none to sell, share, or use for targeted advertising. We have never done so and have no mechanism to do so.
Because we collect nothing, requests to know, delete, correct, or opt out have nothing to act on — but you may still contact us at the address in section 10.
4. The App never talks to a server of ours
The App never communicates with a server operated by us.
Network traffic from the App happens in exactly two situations:
- With your own iCloud (through Apple's CloudKit)
- With the App Store (to check your purchase status; handled by Apple)
Both are between you and Apple. We are not in the middle of either.
We run no servers
We currently operate no server of any kind for this App.
In some places, laws about minors require a developer to be able to receive notice that a parent has withdrawn consent. We do not sell the App in the places that require one. The App also collects nothing about you and has no accounts, so there is no consent to withdraw in the first place.
If we ever sell the App where one is required, we will update this policy before that distribution begins. Even then, the only thing that would pass through such an endpoint is Apple-signed information about which app, which kind of notification, and when. No photos or videos would pass through it — not even encrypted ones. No encryption key would pass through it; we don't have one to begin with. Nothing identifying you would pass through it; the App has no accounts.
5. Access to your photo library
- When you add photos or videos, the App does not request access to your photo library. It uses the iOS photo picker, which runs in a separate process, and receives only the items you select. The App cannot see the rest of your library.
- The one exception is the "Delete Originals" feature. If you choose it, the App asks for photo access at that moment, and uses it only to delete the originals you selected. It is never requested at launch or during setup.
6. Notifications
If the App sends you a notification, the notification never contains anything about what you have stored — no counts, no album names, no dates.
7. Disclosure to others
We hold no personal information, so there is nothing to disclose to anyone.
This includes requests from law enforcement. We hold neither information identifying you nor the contents of your vault. There is nothing we could hand over, in any country, under any legal process.
8. Your control over your data
- You can delete stored data at any time from the App's settings.
- Deleted items stay in "Recently Deleted" for 30 days, then are permanently removed from both your iPhone and iCloud.
- "Delete Entire Vault" immediately destroys the data on your iPhone and your PIN.
9. Children
The App is not directed to children under 13, and we do not knowingly collect personal information from anyone — including children — because, as described above, we collect no personal information from any user at all.
10. Contact
https://illustrious-dasik-b7f883.netlify.app/en/support/
Use the page above to reach us. There is no contact form inside the App — putting one there would tie your vault to your message, which we have chosen not to do.
The form on that page is a Google Form. To be exact about it:
- There is no email address field. The only thing stored is what you type into it yourself.
- If you want a reply, put a contact address in the message yourself. It is optional — without one, we have no way to reach you.
- What you submit is stored on Google's servers and read by us. Google's own privacy policy also applies to it.
- The form is not connected to your vault, your encryption key, or the App in any way. Contacting us does not give us the ability to see what you have stored.
11. Changes to this policy
If this policy changes, we will give notice inside the App and on our distribution page. If we ever change what information is collected, we will say so explicitly before the change takes effect.