Privacy Policy for CameraVault
Last Updated: July 26, 2026
Developer: Deineko Sergii
Introduction
CameraVault (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you use our mobile application CameraVault (the “App”).
By using our App, you agree to the collection and use of information in accordance with this policy.
- Encrypted Photos: The App captures photos and can import photos you select from your device. All photos are encrypted before being stored locally in the App’s private storage.
- Photo Metadata: The App stores metadata associated with your photos, including:
- Timestamp
- File size
- Orientation information
- Display names (including original import names and names you set manually)
- Encryption key version identifier used to decrypt/export photos
- Generated gallery thumbnails/previews
- Password: The App requires you to set a default password for encryption/decryption purposes. Your password is never stored in plain form on your device. It is used only to unlock encryption keys for access to encrypted content. If you lose your password, encrypted photos cannot be recovered.
- Optional Biometric Unlock: If you enable biometric unlock, the App may store an encrypted copy of the relevant vault password(s) on your device, wrapped with a key kept in the Android Keystore that requires your fingerprint or face for each use. Biometrics do not replace your default password; they are a convenience option. You can turn biometric unlock off at any time in Settings, which removes those wrapped copies. Please note that biometric unlock can be less resistant than a memorized password alone if someone can compel you to use your fingerprint or face on the device.
Encryption Keys
- Encryption Keys: The App uses industry-standard encryption methods to secure your data. Encryption keys are generated and managed on your device. Your password (or, if enabled, biometric unlock of a locally wrapped password) is required to access private keys for decryption purposes.
- Biometric Wrap Key: When biometric unlock is enabled, an AES key may be created in the Android Keystore (often hardware-backed when the device supports it). That key never leaves the device and is used only to wrap/unwrap the optional password copies described above.
Local Processing Only
- All photo encryption, decryption, and storage operations occur entirely on your device
- We do not transmit, upload, or share your photos, passwords, biometric credentials, or encryption keys with any external servers or third parties
- The App operates completely offline and does not require an internet connection
- Biometric authentication is handled by the Android system on your device; we do not receive your fingerprint or face data
Purpose of Data Collection
- Photo Encryption: To secure your photos using industry-standard encryption
- Photo Storage: To store encrypted photos in the App’s private directory on your device
- Photo Display: To decrypt and display photos when you authenticate with your password or optional biometric unlock
- Photo Management: To allow you to import, view, rename, export, change photo password, and delete encrypted photos (including batch/group actions in gallery such as multi-select export and delete)
- Optional Biometric Convenience: To let you unlock decryption with fingerprint or face when you have enabled that feature
Data Storage and Security
Storage Location
- All encrypted photos and metadata are stored in the App’s private directory on your device
- Optional biometric-wrapped password blobs (if you enable biometric unlock) are stored only in the App’s private storage on your device
- Files are stored using Android’s secure file system with app-specific permissions
- Encrypted photos are not accessible by other apps on your device
Security Measures
- Encryption: Photos are encrypted using industry-standard encryption algorithms before storage
- Key Management: Encryption keys are managed using secure cryptographic methods
- Password Security: Passwords are processed using secure key derivation functions and are not stored in plain form
- Biometric Unlock (optional): Uses Android BiometricPrompt with a Keystore-bound cryptographic key; authentication is required for each unlock when a wrap exists
- Secure Storage: Where available, Keystore keys may use hardware-backed protection
- Memory Security: Decrypted photo data is cleared from memory when not in use (for example when leaving the image viewer)
Data Retention
- Your encrypted photos remain on your device until you choose to delete them
- When you delete a photo through the App, the encrypted file is removed from your device
- Disabling biometric unlock removes biometric wrap keys and wrapped password copies from the App
- Uninstalling the App removes App-private data, including encrypted photos and biometric wrap data
- We do not retain any copies of your photos after deletion
Permissions We Request
Camera Permission
- Purpose: Required to capture photos using your device’s camera
- Usage: The App uses this permission only to take photos when you press the capture button
- Storage: Photos are immediately encrypted and stored locally
Biometric Permission
- Purpose: Optional fingerprint or face unlock for decrypting vault content when you enable biometric unlock
- Usage: Only used after you opt in; the App does not access raw biometric templates—Android performs the authentication
- Note: You can decline and continue using your default password only
Photo Import Access
- Purpose: Lets you choose existing photos to import into CameraVault
- Usage: Import uses the Android system picker and only accesses files you explicitly select
- Note: The App does not scan your whole photo library in the background
Storage Permission (Android 9 and below only)
- Purpose: Required to export decrypted photos to your device’s external storage (Pictures/CameraVault folder)
- Usage: Only requested when you choose to export a photo
- Note: This permission is not required on Android 10 and above due to scoped storage
Data Sharing and Third Parties
No Data Sharing
- We do not share, sell, trade, or transmit your photos, passwords, encryption keys, biometric data, or any other data to third parties
- We do not use analytics services, advertising networks, or tracking technologies
- We do not collect or transmit any personal information to external servers
No Cloud Services
- The App does not sync, backup, or upload your data to any cloud services
- All data remains exclusively on your device
Your Rights
Access and Control
- You have full control over your encrypted photos
- You can import, view, rename, change password, export, or delete your photos at any time through the App, including batch/group operations from gallery selection mode
- You can change your encryption password in the App’s settings
- You can enable or disable biometric unlock in Settings at any time
Data Deletion
- You can delete individual photos or all photos through the App
- Uninstalling the App will remove all encrypted photos and associated data from your device
- Warning: If you lose your password, encrypted photos cannot be recovered. Biometric unlock does not restore access if the password is lost and biometric wraps are unavailable or invalidated
Children’s Privacy
Our App is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last Updated” date.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Data Breach Notification
In the unlikely event of a security breach that affects your data, we will notify you as soon as possible. However, since all data is stored locally on your device and encrypted, the risk of a remote data breach is minimal.
International Users
This Privacy Policy is intended for users worldwide. By using our App, you consent to the collection and use of information as described in this policy.
Compliance
This Privacy Policy is designed to comply with:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- Children’s Online Privacy Protection Act (COPPA)
- Other applicable data protection laws
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Deineko Sergii
Email: deineko.sergii@gmail.com
Disclaimer
While we implement industry-standard security measures to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your privacy to the best of our ability.
Open Source Licenses
This application uses code and resources licensed under the Apache License 2.0, including components from the Android Open Source Project and Material Design icons. For license details, please refer to the “About” section within the App or visit: https://www.apache.org/licenses/LICENSE-2.0
Note: This privacy policy applies only to the CameraVault mobile application. It does not apply to any third-party websites, services, or applications that may be linked from or accessible through our App.