Privacy by design

Your private data stays under your control.

This policy explains exactly how iPrivate Data handles information when you use the iPhone and iPad app. The short version: we never sell or use your vault content for analytics or advertising. Product analytics are off by default and only run if you enable them in Settings. App versions with advertising may show ads in the free tier.

EffectiveAugust 11, 2026
Applies toiPrivate Data for iOS
DeveloperNileshKumar Rathod / NilApps

01

Overview

iPrivate Data is a private vault, password manager, private-contact store, identity wallet, browser, backup tool, and storage-cleanup utility. Most processing happens on your device. We do not operate an account system or a developer-controlled server that receives your vault content.

No sale of dataYour personal information and vault content are never sold.
Vault content excludedPasswords, contacts, files, filenames, URLs, searches, and browser history are not sent to analytics or ad services.
Limited product analyticsOptional and off by default. If you enable Product Analytics in Settings, we measure a small set of aggregated feature, paywall, and purchase events.
Advertising transparencyWhen ads are enabled, they appear only in the free tier; Premium remains ad-free.
Optional cloud syncCloudKit sync is off until you choose to enable it.

02

What data the app handles

The app may process information that you choose to add or create, including:

  • Photos, videos, audio, notes, documents, filenames, folders, and file metadata.
  • Passwords, website addresses, login records, private contacts, and identity records.
  • Scanned text, document images, camera captures, and optional failed-PIN intruder photos.
  • Bookmarks, private-browser history, downloads, and browser preferences stored on your device.
  • App preferences, subscription state, sync state, reminders, and local operational diagnostics.

This information is used only to provide the features you request. It is stored in the app's private container unless you export it, share it, enable private iCloud Sync, or direct the app to interact with another service.

03

Device permissions

PermissionHow it is used
PhotosImport or export selected media, scan your accessible library for cleanup suggestions, and move items to Recently Deleted only after your confirmation.
ContactsImport only contacts you select into your encrypted private-contact store.
CameraCapture vault media, scan documents, cards or QR codes, and—only when enabled—capture a failed-PIN intruder photo.
MicrophoneRecord audio you choose to save in the vault.
Face ID / Touch IDAuthenticate locally through iOS. The app never receives or stores biometric templates.
NotificationsDeliver optional product updates, protection reminders, and silent CloudKit change notifications. Notification text is designed to be generic and never includes vault content.

You can review or revoke permissions at any time in iOS Settings. Some related features will then stop working.

04

External services and network activity

Apple services

If you enable private iCloud Sync, vault data is stored in your private Apple CloudKit database. Apple also processes App Store purchases, subscription status, push notifications, and any Apple diagnostics you have chosen to share under Apple's own terms and privacy policy.

Google Analytics for Firebase

Product analytics are off by default. If you enable Product Analytics in Settings › Privacy, we use Firebase Analytics to understand which privacy-safe product features provide value and where users encounter Premium limits or purchase screens. We send only a small allowlisted set of events and parameters: feature category, free or Premium tier, coarse usage range, paywall source, product identifier, and purchase result. We do not send vault content, record identifiers, passwords, contacts, filenames, website addresses, searches, or browser history. You can turn analytics off again at any time in Settings.

When analytics are enabled, Firebase may process an app-instance identifier, general device and app information, coarse location derived from a masked IP address, app lifecycle information, subscription or purchase information, and limited interaction and diagnostic data. We do not set a Firebase user ID or use this analytics data for advertising or cross-app tracking.

Firebase Remote Config and Installations

The app uses Firebase Remote Config to retrieve freemium usage limits and related configuration. A refresh may be requested when the app launches, subject to Firebase caching, and newly retrieved limits apply to a later app session. This service operates even when optional Product Analytics is off.

Firebase Remote Config and Firebase Installations may process a Firebase installation identifier, country and language codes, time zone, OS and app versions, bundle ID, Firebase app ID, SDK information, and limited technical diagnostics. This information is used to deliver and maintain app configuration—not for advertising—and does not include vault content, passwords, contacts, filenames, website addresses, searches, or browser history.

Firebase Cloud Messaging

Push messaging is optional and off by default. After you reach the main app, iPrivate Data explains the benefit of notifications and asks for permission only if you choose Allow Notifications. You can also enable or disable Push Notifications in Settings › Privacy. When enabled, the app uses Firebase Cloud Messaging to receive generic product updates and protection-related messages. Disabling Push Notifications turns off Firebase Messaging and requests deletion of the app's FCM registration token.

Firebase Cloud Messaging and Firebase Installations may process an FCM registration token, Firebase installation identifier, IP-derived coarse location, app and device information, message-delivery interactions, and limited performance or diagnostic data to register the device, route messages, maintain delivery, and prevent abuse. This information is used for app functionality—not advertising or cross-app tracking. We do not send vault content, filenames, passwords, identity or payment records, contacts, browser activity, searches, record identifiers, or other private values in notification titles, bodies, or custom payloads.

Google AdMob advertising

When advertising is enabled in an app version, the free tier may use Google AdMob to deliver, limit the frequency of, measure, and protect ads against fraud. The Google Mobile Ads SDK and participating ad providers may process an IP address or general location, device and app identifiers, advertising data, ad views and interactions, product interactions, and performance or diagnostic data. Premium is ad-free.

This release requests only non-personalized or limited ads. It does not request App Tracking Transparency permission and does not use the advertising identifier for cross-app tracking. Google and participating ad providers may still use an IP address, general location, and app- or device-bounded identifiers for ad delivery, frequency control, aggregated reporting, security, and fraud prevention. The app provides a consent and privacy-options flow where required. Learn more in Google's Privacy Policy and information about how Google uses information from sites or apps that use its services.

Password breach checks

When you request a breach check or enable breach monitoring, the app uses the Have I Been Pwned Pwned Passwords range service. It sends only the first five characters of a SHA-1 password hash. Your full password and full hash are not sent; matching is completed on your device. As with any network request, the service can receive technical connection information such as your IP address.

Private browser

Websites you visit receive ordinary web requests and may apply their own cookies and privacy practices. Text entered as a search rather than a web address is sent to DuckDuckGo. Clearing the private-browser session removes the app's local browser session data but cannot erase data already received by a website.

User-directed sharing

When you export, share, email, call, message, or open another app or website, the data you select is handled by the recipient and applicable service according to their policies.

05

How information is protected

Vault files are kept in the app's private iOS container and use Apple Data Protection. Password and private-contact records use AES-256-GCM encryption with keys protected by the iOS Keychain. Optional private iCloud Sync stores content in your private CloudKit database and additionally encrypts sensitive record fields and protected assets where implemented.

No system can guarantee absolute security. Keep your device passcode and iPrivate Data PIN secret, keep iOS current, and retain an encrypted backup of important data.

06

Your choices and controls

  • Use the app without enabling iCloud Sync.
  • Keep Product Analytics off, or enable and disable it in Settings › Privacy.
  • Keep Firebase push messaging off, or enable and disable Push Notifications in Settings › Privacy.
  • Grant limited Photos access or import individual items through system pickers.
  • Choose whether to enable reminders, breach monitoring, AutoFill, or intruder capture.
  • Export your content using the app's share and backup features.
  • Delete individual records, empty Recently Deleted, clear the browser session, or delete the private iCloud vault.
  • Cancel or manage subscriptions in your Apple ID subscription settings.
  • Review or change advertising privacy options when the app makes them available.

Because we do not maintain a developer account or profile about you, we generally cannot view, retrieve, correct, or delete content stored only on your device or in your private iCloud database.

07

Retention and deletion

Local information remains until you delete it, use an in-app cleanup action, or uninstall the app. The free tier retains items in the app's Recently Deleted area for up to 30 days. Premium users can select a retention period from 1 to 90 days. You can permanently delete items sooner. Items deleted from Apple Photos are subject to Apple Photos' own Recently Deleted behavior.

Turning off iCloud Sync stops future syncing but does not automatically remove existing CloudKit data. Use Settings → iCloud Sync → Delete iCloud Vault to remove the app's private CloudKit zone. Apple may retain limited copies as required for backup, security, fraud prevention, or legal compliance.

08

Children's privacy

iPrivate Data is a general-purpose utility and is not directed to children under 13. We do not knowingly use children's vault content for analytics or advertising. A parent or guardian who believes a child has contacted us with personal information should email us so we can address the request.

09

Changes to this policy

We may update this policy when the app, law, or service providers change. A revised policy will show a new effective date on this page. Material changes may also be communicated in the app or App Store release notes.

10

Contact

Questions, privacy requests, or support can be sent to:

NileshKumar Rathod / NilAppsniliosdeveloper@gmail.comSubject: iPrivate Data Privacy or Support

Protection details: How Protection Works · Support Center