Privacy Policy for SecureD
| Item | Detail |
|---|---|
| Operator (data controller) | Liviu Patrasco, an individual sole proprietor (“we,” “us,” or “our”) |
| App | SecureD for iPhone and iPad |
| Document | SecureD Privacy Policy |
| Version | 2.2 |
| Effective date | August 5, 2026 |
| Last updated | August 5, 2026 |
| Supersedes | Version 2.1, dated August 3, 2026 |
| Contact | support@liviu.me |
| Address | 17412 159th Ave SE, Renton, WA 98058, United States |
| Public URL | https://secured.liviu.me/privacy/ |
This Privacy Policy explains how SecureD handles information when you use the SecureD mobile application (the “App”). It applies to the App and to support communications you send us. It is incorporated by reference into the SecureD End User License Agreement and Terms of Use (the “Agreement”). If this Policy and the Agreement conflict on a privacy matter, this Policy controls.
The official public copy of this Privacy Policy is published at https://secured.liviu.me/privacy/. A matching copy is also available within SecureD.
1. Summary
- Your vault items are stored on your device, with item payloads encrypted on the device.
- We operate no servers that receive your vault. There is no SecureD account, no SecureD login, and no SecureD cloud.
- We do not sell or share your personal information, and we do not use it for cross-context behavioral advertising or targeted advertising.
- The App contains no advertising, analytics, tracking, or crash-reporting SDKs.
- The App makes no network requests of its own. Information leaves your device only when you take an action (Share, Copy, Export a backup) or when an Apple system feature you use requires it.
- iCloud sync of your vault is not offered in this version.
- The App’s lock screen can add a photo or video to your vault without unlocking it, sealed so that a locked vault cannot be read from. You can turn this off (see Section 4.11).
- If you lose your credentials and have not configured a working recovery method, we cannot decrypt or restore your vault.
- The only personal information we routinely receive is what you choose to put in an email to support.
2. Scope of this Policy
This Policy covers:
- the SecureD iOS App and its share extension;
- information stored on your device by the App; and
- information you send us directly, such as support email.
This Policy does not cover:
- Apple’s processing of your information as the operator of iOS, the App Store, TestFlight, iCloud, and related services, which is governed by Apple’s privacy policy;
- other apps, recipients, messaging services, cloud drives, or printers you choose to send content to; or
- your own device backups, mobile device management, or enterprise configuration.
3. Our privacy model: on-device processing
SecureD is designed so that decisions about your information stay with you rather than with us.
Because vault content is created, encrypted, stored, and processed on your device and is not transmitted to us:
- we generally cannot see, access, decrypt, index, scan, monitor, moderate, or recover your vault content;
- we cannot produce your vault content in response to a subpoena, warrant, or other legal demand, because we do not have it;
- we cannot restore your vault if you lose access to it; and
- for most of what you store in SecureD, we are not acting as a “controller,” “business,” or “processor,” because we never receive that information.
You control what you store, how it is protected, and whether it ever leaves your device.
4. Information stored on your device
Depending on the features you use, the following may be stored on your device by the App. Except as described in Section 5, none of this is transmitted to us.
4.1 Vault content (encrypted payloads)
Notes and rich text, secure entries and field values, photos, video, audio recordings, PDFs, archives, documents and other files, payment card details you choose to save (see Section 4.7), identification documents you import, and related item data.
4.2 Metadata stored outside the encrypted payload
Encrypting item payloads does not make every piece of information on your device unreadable. The following may be stored in a form that can be readable on an unlocked device, in a device backup, or through forensic examination of the device:
- item and folder titles;
- file names, content types, and item kind indicators;
- folder relationships, ordering, and timestamps;
- flags such as “biometric-locked” or “hidden”;
- media duration and similar descriptive attributes;
- short list previews, such as the last four digits of a stored card number or brief identification hints;
- limited records about a capture taken while the App was locked, as described in Section 4.11; and
- app settings and locally stored access-history records.
Please take this into account when titling items. Do not place information you need to keep confidential into item titles.
4.3 Security and account data
Passcode-derived material, cryptographic salts and key material, the authentication mode you selected, per-item biometric lock settings, failed-attempt state, and local account records including administrator or user role. Sensitive key material is stored in the iOS Keychain.
4.4 Local accounts
SecureD supports multiple local accounts on one device. Local accounts exist only on the device. There is no SecureD-hosted directory, tenancy, or identity service. An administrator account on the device can manage, reset, or delete other local accounts on that same device.
4.5 Preferences and optional features
App icon selection, related opening-screen preference, hidden-item state, clipboard auto-clear timing, and any location rules or time rules you configure.
4.6 Access history
A local log of events such as unlock success or failure, biometric failure, showing previously hidden items, exports, backup imports, passcode resets, rule-based unlocks, alternate unlock views, and captures taken from the lock screen. This log is stored on the device, can be cleared by an administrator, and is never transmitted to us. It is a convenience log, not an audit trail.
4.7 Payment cards
If you store a card, the App may keep an encrypted cardholder name, card number, expiry, network, and notes. The security code (CVV or CVC) is not saved unless you turn that setting on, and it is off by default. Scanning never reads a security code — you can only type one in yourself. When the setting is on, the code is kept inside the encrypted item and never in a title or list preview; when you turn it off, codes you already saved are removed. Storing a code alongside the card number is enough for someone to attempt an online purchase, so it is worth leaving off unless you want that convenience. Card scanning is performed on your device. SecureD is not a payment application and does not process transactions.
4.8 Identification documents
If you import an identification document, the App may keep encrypted fields such as name, document number, dates, physical descriptors, address, and issuing jurisdiction. Recognition is performed on your device. SecureD performs no identity verification, document authentication, or government validation, and does not transmit these documents anywhere.
4.9 Passcode recovery data (optional)
If you enable a recovery method:
- Trusted place stores the location configuration you set for recovery on your device.
- Trusted image stores a mathematical feature print derived from a photo you enroll. The enrollment photo itself is discarded, and we never receive either the photo or the feature print.
4.10 Share extension staging
When you share content into SecureD from another app, items may be written briefly to a shared App Group container on your device, in unencrypted form, until the main App is unlocked and completes the import. During that interval the items are protected by the operating system’s protections for that container rather than by vault encryption. Complete pending imports promptly.
4.11 Lock-screen capture staging
If you leave the lock-screen camera (Quick Capture) enabled, anyone who can open SecureD while your vault is locked can take a photo or record a video without unlocking it. Unlike share-extension staging, these captures are never written in unencrypted form. Each capture is sealed on your device with public-key encryption to a key belonging to the most recently used local account, and the private key needed to open it remains protected by your vault credentials. The sealed file is also written with the strongest iOS file protection, which keeps it unreadable while the device itself is locked. A locked vault can be written to in this way, but it cannot be read, listed, or deleted from.
Until the next unlock, the following is stored on your device outside the sealed file: which local account the capture is addressed to, when it was taken, the size of the sealed file, and the encapsulated key material that has to be combined with your vault’s private key before the capture can be opened. The title, file name, and media type travel inside the sealed file.
Sealed captures move into your vault the next time you unlock and are then removed from staging. If your vault key material is replaced before that happens, for example by a recovery reset or by deleting the local account, the captures can no longer be opened and are discarded. Each capture is recorded in access history (Section 4.6) so that you can see that something was added while the vault was locked. Nothing about a capture is transmitted to us, and you can turn the lock-screen camera off at any time in the App’s settings.
5. Information we actually receive
This is the complete list of information that reaches us.
| Source | What we receive | Why | Retention |
|---|---|---|---|
| Support email to support@liviu.me | Your email address, your name if you provide it, the content of your message, attachments you choose to send, and standard email headers | To answer your question, troubleshoot, and keep a record of the request | Up to 24 months after the matter is closed, unless a longer period is required by law |
| App Store / TestFlight (from Apple) | Aggregated, non-identifying App Store metrics, and crash or usage diagnostics only if you enabled sharing with developers in iOS Settings or you are a TestFlight tester | To understand stability and adoption at an aggregate level | As provided and retained by Apple; we retain any exports up to 24 months |
| App Store purchases | Nothing. Apple processes any purchase. We do not receive your payment card, billing address, or Apple Account details | Not applicable | Not applicable |
We do not receive your vault content, metadata, passcode, encryption keys, biometric data, location, access history, or recovery data.
We ask that you not send vault content, passcodes, recovery secrets, government ID images, or payment card numbers in a support email. If you do, we will use that information only to handle your request and will delete it when it is no longer needed for that purpose.
6. Sensitive information
Biometrics. Face ID and Touch ID are performed entirely by Apple’s operating system and secure hardware. SecureD receives only a success or failure result. We do not collect, store, transmit, sell, or otherwise obtain biometric identifiers or biometric information, as those terms are used in the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, Washington’s biometric identifier statute, or comparable laws. The trusted-image recovery feature stores a feature print derived from a scene photo on your device for image matching; it is not used to identify a person, and it never leaves your device.
Health information. SecureD is not a health app. We do not collect consumer health data, and we do not receive any information you store, which means we do not collect consumer health data within the meaning of the Washington My Health My Data Act, the Nevada consumer health data law, or similar laws. If you choose to store health-related documents in your vault, that information stays on your device under your control.
Precise geolocation. If you enable location rules or trusted-place recovery, location is evaluated on your device by iOS. We never receive your location. Displaying a map while you configure a place is handled by Apple Maps under Apple’s privacy policy.
Special categories under GDPR. We do not intentionally collect special category data under Article 9 of the GDPR. If you voluntarily include such data in a support email, we process it only to respond, on the basis of your explicit consent implied by sending it, and delete it when no longer needed.
7. Permissions the App may request
| Permission | Why the App asks | Where the data goes |
|---|---|---|
| Camera | Capture photos and video into the vault, including from the App’s lock screen where you leave that enabled, scan cards and IDs, enroll a trusted image | Stays on your device |
| Microphone | Record audio and video into the vault | Stays on your device |
| Face ID / biometrics | Unlock the App and items you protect with biometrics | Handled by iOS; we receive only success or failure |
| Location (When In Use) | Optional location rules and trusted-place recovery that you configure | Evaluated on your device; never sent to us |
| Photo library | Only when you pick specific photos to import | Only the items you select are imported |
You can grant, deny, or revoke these permissions at any time in iOS Settings. Features that depend on a permission stop working without it. The App does not request contacts, notifications, tracking permission, or background location.
8. On-device processing and automated features
Text recognition, barcode reading, and image feature prints use Apple’s on-device frameworks. There is no cloud recognition service, and no content is sent to us or to a third party for processing.
Automated recognition is an assistance feature and may produce incomplete or incorrect results. You are responsible for reviewing and correcting recognized values.
We do not carry out automated decision-making, profiling, scoring, or any processing that produces legal or similarly significant effects concerning you.
9. When information leaves your device
Your vault does not upload to us automatically or at all. Information may leave your device when you:
- use Share to send an item to another app, service, or person;
- Copy content to the system pasteboard, including through Secure Clipboard, so that another app can paste it;
- Export an encrypted backup and save or send that file to Files, iCloud Drive, AirDrop, Mail, Messages, or another destination you choose;
- Print content or open it in another application; or
- use an Apple feature that processes data as part of the operating system, such as Face ID or Apple Maps when you configure a place.
Content shared out of the vault is generally decrypted for that purpose. While content is on the pasteboard, other apps on your device may be able to read it, and iOS may make pasteboard content available across your devices if you enabled that feature. Timed clipboard clearing is a best-effort convenience and cannot retrieve a copy another app has already taken.
Recipients and services you choose have their own privacy practices. We do not control them and are not responsible for what they do with content you send.
Your device or account settings may also cause iOS to create backups, caches, thumbnails, previews, indexes, or synchronized copies. Those mechanisms belong to Apple and your configuration, not to us.
iCloud sync of your vault is not offered in this version. Do not rely on SecureD to synchronize vaults between devices.
10. How we use the information we receive
We use the limited information described in Section 5 only to:
- respond to your support request and communicate with you about it;
- diagnose and fix bugs, and improve stability and functionality;
- detect, investigate, and prevent abuse, fraud, and violations of the Agreement;
- comply with legal obligations and respond to lawful requests; and
- establish, exercise, or defend legal claims.
We do not use your information for advertising, marketing profiling, or training machine learning models.
11. Disclosure of information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising or targeted advertising, as those terms are defined in California and other US state privacy laws. We have not done so in the preceding twelve months.
We may disclose the limited information we receive only:
- to service providers acting on our behalf under confidentiality obligations, currently limited to our email and hosting providers;
- when required by applicable law, legal process, or an enforceable governmental request, as described in Section 12;
- to protect the rights, property, safety, or security of users, the public, or us, including investigating suspected abuse;
- to Apple where necessary to address an App Store or platform matter; or
- in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case we will require the recipient to honor this Policy or provide notice of any material change.
12. Law enforcement and government requests
If we receive a subpoena, court order, warrant, or other legal demand, we can only produce information we actually hold, which is limited to support correspondence and any records described in Section 5.
We cannot provide your vault content, passcode, encryption keys, recovery secrets, location history, or access history, because we never receive them and have no technical means to obtain them. We will not build a capability to circumvent SecureD’s protections in order to satisfy a request.
Where we are legally permitted to do so, we will review requests for validity, object to overbroad or improper demands, and notify the affected user before responding.
13. Data retention
- Vault data stays on your device until you delete items, delete a local account, or delete the App. We do not control and cannot extend or shorten this.
- Deleting a local account is designed to remove that account’s key material and vault data, and is irreversible.
- Deleting the App removes App data from that device, subject to iOS behavior and any backups you created.
- Exported backups remain wherever you stored them until you delete those files.
- Support correspondence is retained for up to 24 months after the matter is closed, unless a longer period is required to comply with law or to establish or defend legal claims.
- Aggregate App Store metrics are retained by Apple according to Apple’s policies; any exports we keep are retained for up to 24 months.
14. Security
Item payloads are encrypted on your device using industry-standard cryptographic algorithms and key-derivation functions, together with cryptographic and secure-storage facilities provided by iOS. Key material is stored in the iOS Keychain. Content captured while the App is locked is sealed with public-key encryption to a key that only your unlocked vault can open, as described in Section 4.11.
The protection actually applied depends on choices you make, including your authentication configuration, whether you use a device passcode, whether you enable a configuration that does not require unlock, and where you store exported backups.
No security measure is perfect. We cannot guarantee that information will never be accessed, disclosed, altered, or destroyed. Section 4.2 describes metadata that may be readable without decrypting payloads. You are responsible for your device security, your passcode, your recovery configuration, and your backups.
If a security incident affecting personal information that we hold occurs, we will notify affected individuals and regulators where required by applicable law and without undue delay.
15. Your privacy rights
We honor the requests below to the extent they apply to information we actually hold. Because your vault content never reaches us, we cannot access, correct, export, or delete vault content on your behalf. You can do all of that yourself inside the App.
15.1 Everyone
You can, at any time and without contacting us:
- view, edit, hide, or delete items in your vault;
- change authentication, clipboard, app icon, and rule settings;
- clear locally stored access history;
- export or delete backups you created;
- delete a local account, which deletes that account’s vault data on the device; and
- delete the App from your device.
To exercise rights over information we hold, email support@liviu.me.
15.2 European Economic Area, United Kingdom, and Switzerland
Where the GDPR or UK GDPR applies, you have the right to request access to your personal data, rectification, erasure, restriction of processing, portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
Our legal bases for the limited processing we carry out are:
| Processing | Legal basis |
|---|---|
| Responding to your support request | Performance of a contract, and our legitimate interest in supporting our software |
| Diagnosing bugs and improving stability | Legitimate interests in maintaining and improving the App |
| Preventing abuse and enforcing the Agreement | Legitimate interests in protecting users and our rights |
| Meeting legal obligations and responding to lawful requests | Compliance with a legal obligation |
| Establishing, exercising, or defending legal claims | Legitimate interests, and legal claims under Article 9(2)(f) where special category data is involved |
You have the right to lodge a complaint with your local supervisory authority. In the United Kingdom this is the Information Commissioner’s Office.
We have not appointed an Article 27 representative because our processing of EU or UK personal data is occasional, does not involve large-scale processing of special category data, and is unlikely to result in a risk to the rights and freedoms of individuals. If that changes, we will appoint a representative and update this Policy.
15.3 California
Under the California Consumer Privacy Act, as amended, the categories of personal information we may collect are limited to the following.
| Statutory category | Do we collect it? | Source | Purpose |
|---|---|---|---|
| Identifiers, such as name and email address | Yes, only if you email support | You | Respond to your request |
| Customer records information | Yes, only if you include it in a support email | You | Respond to your request |
| Commercial information | No. Apple processes any purchase | Not applicable | Not applicable |
| Internet or network activity | No. The App makes no network requests of its own | Not applicable | Not applicable |
| Geolocation data | No. Location is evaluated on your device | Not applicable | Not applicable |
| Audio, visual, or similar information | No, unless you attach it to a support email | You | Respond to your request |
| Biometric information | No | Not applicable | Not applicable |
| Sensitive personal information | No, unless you voluntarily include it in a support email | You | Respond to your request |
| Inferences or profiles | No | Not applicable | Not applicable |
Subject to verification, you have the right to know and access, to delete, and to correct personal information we hold, and the right not to receive discriminatory treatment for exercising your rights. Because we do not sell or share personal information and do not use sensitive personal information for purposes requiring an opt-out, there is no “Do Not Sell or Share My Personal Information” link, and there is nothing to limit under the right to limit use of sensitive personal information. We offer no financial incentives for personal information.
You may use an authorized agent by providing written permission that we can verify. We may need to confirm your identity, typically by verifying control of the email address that corresponds with us.
15.4 Other United States state privacy laws
If you reside in a state with a comprehensive consumer privacy law, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comparable statutes, you may have rights to confirm and access, correct, delete, obtain a portable copy, and opt out of sale, targeted advertising, and certain profiling. We do not sell personal information, do not engage in targeted advertising, and do not conduct profiling with legal or similarly significant effects.
If we deny your request, you may appeal by replying to our decision or emailing support@liviu.me with the subject line “Privacy Appeal.” We will respond to an appeal within 45 days and will explain how to contact your state Attorney General if you disagree with the outcome.
Some of these laws apply only to businesses above certain thresholds that we may not meet. We honor these requests regardless of whether we are legally required to do so.
15.5 How to make a request and what to expect
Email support@liviu.me and describe your request. We will acknowledge promptly and respond within 45 days, or within one month where the GDPR or UK GDPR applies, and will tell you if we need an extension permitted by law. There is no fee unless a request is manifestly unfounded or excessive.
We may ask for information sufficient to verify that the request comes from you. Because we do not maintain accounts, verification generally relies on the email address associated with your correspondence. If we cannot verify a request, we may be unable to honor it.
16. Children’s privacy
SecureD is not directed to children. You must be at least 13 years old, or at least 16 where local law sets a higher minimum age, to use the App, and minors below the age of majority may use it only with the consent and supervision of a parent or legal guardian, consistent with the Agreement.
We do not knowingly collect personal information from children below the applicable age. Because vault content stays on the device and we operate no accounts, we generally have no ability to identify a user’s age or to access or delete anything stored on a device. If you believe a child has sent us personal information through support channels, email support@liviu.me and we will delete it.
17. International users and transfers
We are located in the United States. If you use the App outside the United States, on-device processing happens on your own device in your own country. Any support communication you send us is received and stored in the United States, which may not provide the same level of data protection as your jurisdiction.
Where a transfer mechanism is required for personal data originating in the EEA, the United Kingdom, or Switzerland, we rely on your explicit consent to the transfer, implied by your decision to contact us, and on the necessity of the transfer for the performance of a contract with you or the establishment, exercise, or defense of legal claims. If our processing expands beyond support correspondence, we will implement Standard Contractual Clauses or another approved mechanism and update this Policy.
18. Tracking, advertising, and opt-out signals
The App contains no advertising SDKs, no analytics SDKs, no crash-reporting SDKs, no tracking pixels, and no cookies. We do not track you across apps or websites, and the App does not request App Tracking Transparency permission because it does not track.
Because we do not sell or share personal information and do not engage in targeted advertising, there is nothing for a browser-based Global Privacy Control or Do Not Track signal to opt out of. We would honor such a signal if that ever changed.
19. Third parties
Apple Inc. provides iOS, the App Store, TestFlight, Face ID and Touch ID, the Keychain, Apple Maps, on-device recognition frameworks, the share sheet, and the pasteboard. Apple’s handling of information is governed by Apple’s privacy policy, not this one.
The App integrates no third-party advertising networks, data brokers, analytics providers, or software development kits that collect personal information. We do not sell information to data brokers, and we are not required to register as a data broker.
If we later add any third-party service that receives personal information, we will update this Policy before it takes effect.
20. Changes to this Policy
We may update this Policy. When we do, we will revise the “Last updated” date and the policy version.
For changes that materially and adversely affect how we handle personal information we receive, we will provide reasonable advance notice through the App, on our website, or by email where we have one, before the change takes effect. Continued use of the App after a change becomes effective means you accept the revised Policy, to the extent permitted by applicable law.
Previous versions are available on request at support@liviu.me.
21. Contact
For privacy questions, requests, or appeals:
- Controller: Liviu Patrasco, individual sole proprietor
- Notice address: 17412 159th Ave SE, Renton, WA 98058, United States
- Email: support@liviu.me
If you are dissatisfied with our response, you may contact your local data protection authority or state Attorney General.
SecureD stores your content on your device. We cannot access or recover it. Please maintain your own backups and recovery methods. This document describes our privacy practices and is not legal advice.
Policy Version 2.1 — Effective August 3, 2026. Copyright © 2026 Liviu Patrasco. All rights reserved.