Stillgarth privacy policy

Last updated

Stillgarth ("the app") is an encrypted vault for your files and a guard that photographs whoever tries to unlock your phone. This policy explains what the app does with your information. In short: everything stays on your phone, your files and Guard's photos are encrypted, and the app cannot send anything anywhere.

Does Stillgarth use the internet?

No. The app has no internet access. Stillgarth does not request Android's internet permission, so it cannot connect to any server, ours or anyone else's. There are no accounts, no ads, no analytics, no crash reporting and no tracking of any kind. We (the developer) never receive any of your data.

What does the app store, and where?

All of it is stored only on your phone, inside the app's private storage:

  • Files you add to the vault: encrypted with AES-256-GCM before they are written. Their names, folders and dates are kept in an encrypted database. Nothing in the vault can be read without your vault password, PIN or fingerprint.
  • Your vault password and PIN: never stored. The app keeps only encrypted copies of the vault's key, which only your password, PIN or fingerprint can open.
  • Fingerprint: handled entirely by Android. The app is only told "yes, it's you"; it never receives your fingerprint data.
  • Guard photos: when Guard is on, it takes a photo with the front camera when someone enters a wrong unlock code and, unless you turn "Photo on unlock" off, each time the phone is unlocked. Once you have a vault, each photo is encrypted for it the moment it is taken and can only be seen inside your unlocked vault; before you set up a vault, photos wait in the app's private storage and are encrypted into the vault once it exists. Guard also keeps a log of when these events happened (time, kind of event, and where its photo is; the last 30 days or 500 events) in the app's private storage. The log itself is not encrypted; no other app can read the app's private storage.
  • Settings: such as how soon the vault locks (private storage, not encrypted).
  • Intruder-activity log: if you turn on "Record what an intruder opens" (and grant Usage access), then when your phone is unlocked right after a wrong code, Guard notes which apps were brought to the front, and for how long, until the screen turns off. It never sees what was typed, sent or deleted inside those apps. This list is written into a report that is encrypted for your vault and can only be read inside it. If someone reaches a vault screen during that time, Stillgarth also saves a picture of its own screen (only Stillgarth's own screen, never other apps), encrypted for your vault. Everything stays on your phone.

Which permissions does the app use, and why?

  • Camera: to take Guard's photos, and to take photos straight into the vault when you ask.
  • Foreground service (camera): Guard runs as a visible service with a permanent notification, so it can take a photo the moment a wrong code is entered.
  • Device administrator (watch login only): the only Android feature that tells an app about wrong unlock codes. It cannot lock, wipe or change your phone. You can turn it off in Android settings, or by turning Guard off.
  • Notifications: Guard's "watching" notification and its alerts.
  • Run at start-up: to remind you to switch Guard back on after a restart.
  • Biometrics: to unlock the vault with your fingerprint, if you turn that on.
  • Usage access (for the intruder-activity log): lets Guard read Android's list of which apps were opened, so it can tell you what an intruder may have reached after breaking in. You grant it by hand in Android settings and can revoke it any time; the feature does nothing until you do. It reveals only which apps and when, never their contents, and the list never leaves your phone.

The app does not access your contacts, location, messages, call log, microphone or your photo gallery. Files only come in through Android's own file picker, which gives the app access to just the files you pick.

When does information leave your phone?

Only when you do it:

  • Sharing or exporting a file: you choose the app or place it goes to.
  • Encrypted backup: if you turn it on, the app saves an encrypted copy of the vault to a place you pick in Android's "save to" screen (for example your Google Drive). The app itself doesn't upload anything; the app you pick (for example Google Drive) does, under its own privacy policy. The backup can only be opened with your vault password (if it is at least 12 characters) or a recovery code shown to you once. We cannot open it.

How do you delete your data?

Everything the app holds is on your phone. "Erase vault" in the vault settings deletes all vault files, keys and unlock methods; uninstalling the app deletes everything it stored on the phone. A backup file you saved elsewhere stays there until you delete it.

Is the app meant for children?

Stillgarth is not directed at children under 13.

What happens if this policy changes?

If this policy changes, the new version will be published at this address with a new date.

How can you contact us?

A contact address will be published here before the app launches.