SecureD · Privacy

Privacy Policy

On-device vault. No SecureD cloud. Clear rules for support email and what leaves your device only when you choose.

Privacy Policy for SecureD

ItemDetail
Operator (data controller)Liviu Patrasco, an individual sole proprietor (“we,” “us,” or “our”)
AppSecureD for iPhone and iPad
DocumentSecureD Privacy Policy
Version2.2
Effective dateAugust 5, 2026
Last updatedAugust 5, 2026
SupersedesVersion 2.1, dated August 3, 2026
Contactsupport@liviu.me
Address17412 159th Ave SE, Renton, WA 98058, United States
Public URLhttps://secured.liviu.me/privacy/

This Privacy Policy explains how SecureD handles information when you use the SecureD mobile application (the “App”). It applies to the App and to support communications you send us. It is incorporated by reference into the SecureD End User License Agreement and Terms of Use (the “Agreement”). If this Policy and the Agreement conflict on a privacy matter, this Policy controls.

The official public copy of this Privacy Policy is published at https://secured.liviu.me/privacy/. A matching copy is also available within SecureD.


1. Summary


2. Scope of this Policy

This Policy covers:

This Policy does not cover:


3. Our privacy model: on-device processing

SecureD is designed so that decisions about your information stay with you rather than with us.

Because vault content is created, encrypted, stored, and processed on your device and is not transmitted to us:

You control what you store, how it is protected, and whether it ever leaves your device.


4. Information stored on your device

Depending on the features you use, the following may be stored on your device by the App. Except as described in Section 5, none of this is transmitted to us.

4.1 Vault content (encrypted payloads)

Notes and rich text, secure entries and field values, photos, video, audio recordings, PDFs, archives, documents and other files, payment card details you choose to save (see Section 4.7), identification documents you import, and related item data.

4.2 Metadata stored outside the encrypted payload

Encrypting item payloads does not make every piece of information on your device unreadable. The following may be stored in a form that can be readable on an unlocked device, in a device backup, or through forensic examination of the device:

Please take this into account when titling items. Do not place information you need to keep confidential into item titles.

4.3 Security and account data

Passcode-derived material, cryptographic salts and key material, the authentication mode you selected, per-item biometric lock settings, failed-attempt state, and local account records including administrator or user role. Sensitive key material is stored in the iOS Keychain.

4.4 Local accounts

SecureD supports multiple local accounts on one device. Local accounts exist only on the device. There is no SecureD-hosted directory, tenancy, or identity service. An administrator account on the device can manage, reset, or delete other local accounts on that same device.

4.5 Preferences and optional features

App icon selection, related opening-screen preference, hidden-item state, clipboard auto-clear timing, and any location rules or time rules you configure.

4.6 Access history

A local log of events such as unlock success or failure, biometric failure, showing previously hidden items, exports, backup imports, passcode resets, rule-based unlocks, alternate unlock views, and captures taken from the lock screen. This log is stored on the device, can be cleared by an administrator, and is never transmitted to us. It is a convenience log, not an audit trail.

4.7 Payment cards

If you store a card, the App may keep an encrypted cardholder name, card number, expiry, network, and notes. The security code (CVV or CVC) is not saved unless you turn that setting on, and it is off by default. Scanning never reads a security code — you can only type one in yourself. When the setting is on, the code is kept inside the encrypted item and never in a title or list preview; when you turn it off, codes you already saved are removed. Storing a code alongside the card number is enough for someone to attempt an online purchase, so it is worth leaving off unless you want that convenience. Card scanning is performed on your device. SecureD is not a payment application and does not process transactions.

4.8 Identification documents

If you import an identification document, the App may keep encrypted fields such as name, document number, dates, physical descriptors, address, and issuing jurisdiction. Recognition is performed on your device. SecureD performs no identity verification, document authentication, or government validation, and does not transmit these documents anywhere.

4.9 Passcode recovery data (optional)

If you enable a recovery method:

4.10 Share extension staging

When you share content into SecureD from another app, items may be written briefly to a shared App Group container on your device, in unencrypted form, until the main App is unlocked and completes the import. During that interval the items are protected by the operating system’s protections for that container rather than by vault encryption. Complete pending imports promptly.

4.11 Lock-screen capture staging

If you leave the lock-screen camera (Quick Capture) enabled, anyone who can open SecureD while your vault is locked can take a photo or record a video without unlocking it. Unlike share-extension staging, these captures are never written in unencrypted form. Each capture is sealed on your device with public-key encryption to a key belonging to the most recently used local account, and the private key needed to open it remains protected by your vault credentials. The sealed file is also written with the strongest iOS file protection, which keeps it unreadable while the device itself is locked. A locked vault can be written to in this way, but it cannot be read, listed, or deleted from.

Until the next unlock, the following is stored on your device outside the sealed file: which local account the capture is addressed to, when it was taken, the size of the sealed file, and the encapsulated key material that has to be combined with your vault’s private key before the capture can be opened. The title, file name, and media type travel inside the sealed file.

Sealed captures move into your vault the next time you unlock and are then removed from staging. If your vault key material is replaced before that happens, for example by a recovery reset or by deleting the local account, the captures can no longer be opened and are discarded. Each capture is recorded in access history (Section 4.6) so that you can see that something was added while the vault was locked. Nothing about a capture is transmitted to us, and you can turn the lock-screen camera off at any time in the App’s settings.


5. Information we actually receive

This is the complete list of information that reaches us.

SourceWhat we receiveWhyRetention
Support email to support@liviu.meYour email address, your name if you provide it, the content of your message, attachments you choose to send, and standard email headersTo answer your question, troubleshoot, and keep a record of the requestUp to 24 months after the matter is closed, unless a longer period is required by law
App Store / TestFlight (from Apple)Aggregated, non-identifying App Store metrics, and crash or usage diagnostics only if you enabled sharing with developers in iOS Settings or you are a TestFlight testerTo understand stability and adoption at an aggregate levelAs provided and retained by Apple; we retain any exports up to 24 months
App Store purchasesNothing. Apple processes any purchase. We do not receive your payment card, billing address, or Apple Account detailsNot applicableNot applicable

We do not receive your vault content, metadata, passcode, encryption keys, biometric data, location, access history, or recovery data.

We ask that you not send vault content, passcodes, recovery secrets, government ID images, or payment card numbers in a support email. If you do, we will use that information only to handle your request and will delete it when it is no longer needed for that purpose.


6. Sensitive information

Biometrics. Face ID and Touch ID are performed entirely by Apple’s operating system and secure hardware. SecureD receives only a success or failure result. We do not collect, store, transmit, sell, or otherwise obtain biometric identifiers or biometric information, as those terms are used in the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, Washington’s biometric identifier statute, or comparable laws. The trusted-image recovery feature stores a feature print derived from a scene photo on your device for image matching; it is not used to identify a person, and it never leaves your device.

Health information. SecureD is not a health app. We do not collect consumer health data, and we do not receive any information you store, which means we do not collect consumer health data within the meaning of the Washington My Health My Data Act, the Nevada consumer health data law, or similar laws. If you choose to store health-related documents in your vault, that information stays on your device under your control.

Precise geolocation. If you enable location rules or trusted-place recovery, location is evaluated on your device by iOS. We never receive your location. Displaying a map while you configure a place is handled by Apple Maps under Apple’s privacy policy.

Special categories under GDPR. We do not intentionally collect special category data under Article 9 of the GDPR. If you voluntarily include such data in a support email, we process it only to respond, on the basis of your explicit consent implied by sending it, and delete it when no longer needed.


7. Permissions the App may request

PermissionWhy the App asksWhere the data goes
CameraCapture photos and video into the vault, including from the App’s lock screen where you leave that enabled, scan cards and IDs, enroll a trusted imageStays on your device
MicrophoneRecord audio and video into the vaultStays on your device
Face ID / biometricsUnlock the App and items you protect with biometricsHandled by iOS; we receive only success or failure
Location (When In Use)Optional location rules and trusted-place recovery that you configureEvaluated on your device; never sent to us
Photo libraryOnly when you pick specific photos to importOnly the items you select are imported

You can grant, deny, or revoke these permissions at any time in iOS Settings. Features that depend on a permission stop working without it. The App does not request contacts, notifications, tracking permission, or background location.


8. On-device processing and automated features

Text recognition, barcode reading, and image feature prints use Apple’s on-device frameworks. There is no cloud recognition service, and no content is sent to us or to a third party for processing.

Automated recognition is an assistance feature and may produce incomplete or incorrect results. You are responsible for reviewing and correcting recognized values.

We do not carry out automated decision-making, profiling, scoring, or any processing that produces legal or similarly significant effects concerning you.


9. When information leaves your device

Your vault does not upload to us automatically or at all. Information may leave your device when you:

Content shared out of the vault is generally decrypted for that purpose. While content is on the pasteboard, other apps on your device may be able to read it, and iOS may make pasteboard content available across your devices if you enabled that feature. Timed clipboard clearing is a best-effort convenience and cannot retrieve a copy another app has already taken.

Recipients and services you choose have their own privacy practices. We do not control them and are not responsible for what they do with content you send.

Your device or account settings may also cause iOS to create backups, caches, thumbnails, previews, indexes, or synchronized copies. Those mechanisms belong to Apple and your configuration, not to us.

iCloud sync of your vault is not offered in this version. Do not rely on SecureD to synchronize vaults between devices.


10. How we use the information we receive

We use the limited information described in Section 5 only to:

We do not use your information for advertising, marketing profiling, or training machine learning models.


11. Disclosure of information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising or targeted advertising, as those terms are defined in California and other US state privacy laws. We have not done so in the preceding twelve months.

We may disclose the limited information we receive only:


12. Law enforcement and government requests

If we receive a subpoena, court order, warrant, or other legal demand, we can only produce information we actually hold, which is limited to support correspondence and any records described in Section 5.

We cannot provide your vault content, passcode, encryption keys, recovery secrets, location history, or access history, because we never receive them and have no technical means to obtain them. We will not build a capability to circumvent SecureD’s protections in order to satisfy a request.

Where we are legally permitted to do so, we will review requests for validity, object to overbroad or improper demands, and notify the affected user before responding.


13. Data retention


14. Security

Item payloads are encrypted on your device using industry-standard cryptographic algorithms and key-derivation functions, together with cryptographic and secure-storage facilities provided by iOS. Key material is stored in the iOS Keychain. Content captured while the App is locked is sealed with public-key encryption to a key that only your unlocked vault can open, as described in Section 4.11.

The protection actually applied depends on choices you make, including your authentication configuration, whether you use a device passcode, whether you enable a configuration that does not require unlock, and where you store exported backups.

No security measure is perfect. We cannot guarantee that information will never be accessed, disclosed, altered, or destroyed. Section 4.2 describes metadata that may be readable without decrypting payloads. You are responsible for your device security, your passcode, your recovery configuration, and your backups.

If a security incident affecting personal information that we hold occurs, we will notify affected individuals and regulators where required by applicable law and without undue delay.


15. Your privacy rights

We honor the requests below to the extent they apply to information we actually hold. Because your vault content never reaches us, we cannot access, correct, export, or delete vault content on your behalf. You can do all of that yourself inside the App.

15.1 Everyone

You can, at any time and without contacting us:

To exercise rights over information we hold, email support@liviu.me.

15.2 European Economic Area, United Kingdom, and Switzerland

Where the GDPR or UK GDPR applies, you have the right to request access to your personal data, rectification, erasure, restriction of processing, portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

Our legal bases for the limited processing we carry out are:

ProcessingLegal basis
Responding to your support requestPerformance of a contract, and our legitimate interest in supporting our software
Diagnosing bugs and improving stabilityLegitimate interests in maintaining and improving the App
Preventing abuse and enforcing the AgreementLegitimate interests in protecting users and our rights
Meeting legal obligations and responding to lawful requestsCompliance with a legal obligation
Establishing, exercising, or defending legal claimsLegitimate interests, and legal claims under Article 9(2)(f) where special category data is involved

You have the right to lodge a complaint with your local supervisory authority. In the United Kingdom this is the Information Commissioner’s Office.

We have not appointed an Article 27 representative because our processing of EU or UK personal data is occasional, does not involve large-scale processing of special category data, and is unlikely to result in a risk to the rights and freedoms of individuals. If that changes, we will appoint a representative and update this Policy.

15.3 California

Under the California Consumer Privacy Act, as amended, the categories of personal information we may collect are limited to the following.

Statutory categoryDo we collect it?SourcePurpose
Identifiers, such as name and email addressYes, only if you email supportYouRespond to your request
Customer records informationYes, only if you include it in a support emailYouRespond to your request
Commercial informationNo. Apple processes any purchaseNot applicableNot applicable
Internet or network activityNo. The App makes no network requests of its ownNot applicableNot applicable
Geolocation dataNo. Location is evaluated on your deviceNot applicableNot applicable
Audio, visual, or similar informationNo, unless you attach it to a support emailYouRespond to your request
Biometric informationNoNot applicableNot applicable
Sensitive personal informationNo, unless you voluntarily include it in a support emailYouRespond to your request
Inferences or profilesNoNot applicableNot applicable

Subject to verification, you have the right to know and access, to delete, and to correct personal information we hold, and the right not to receive discriminatory treatment for exercising your rights. Because we do not sell or share personal information and do not use sensitive personal information for purposes requiring an opt-out, there is no “Do Not Sell or Share My Personal Information” link, and there is nothing to limit under the right to limit use of sensitive personal information. We offer no financial incentives for personal information.

You may use an authorized agent by providing written permission that we can verify. We may need to confirm your identity, typically by verifying control of the email address that corresponds with us.

15.4 Other United States state privacy laws

If you reside in a state with a comprehensive consumer privacy law, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comparable statutes, you may have rights to confirm and access, correct, delete, obtain a portable copy, and opt out of sale, targeted advertising, and certain profiling. We do not sell personal information, do not engage in targeted advertising, and do not conduct profiling with legal or similarly significant effects.

If we deny your request, you may appeal by replying to our decision or emailing support@liviu.me with the subject line “Privacy Appeal.” We will respond to an appeal within 45 days and will explain how to contact your state Attorney General if you disagree with the outcome.

Some of these laws apply only to businesses above certain thresholds that we may not meet. We honor these requests regardless of whether we are legally required to do so.

15.5 How to make a request and what to expect

Email support@liviu.me and describe your request. We will acknowledge promptly and respond within 45 days, or within one month where the GDPR or UK GDPR applies, and will tell you if we need an extension permitted by law. There is no fee unless a request is manifestly unfounded or excessive.

We may ask for information sufficient to verify that the request comes from you. Because we do not maintain accounts, verification generally relies on the email address associated with your correspondence. If we cannot verify a request, we may be unable to honor it.


16. Children’s privacy

SecureD is not directed to children. You must be at least 13 years old, or at least 16 where local law sets a higher minimum age, to use the App, and minors below the age of majority may use it only with the consent and supervision of a parent or legal guardian, consistent with the Agreement.

We do not knowingly collect personal information from children below the applicable age. Because vault content stays on the device and we operate no accounts, we generally have no ability to identify a user’s age or to access or delete anything stored on a device. If you believe a child has sent us personal information through support channels, email support@liviu.me and we will delete it.


17. International users and transfers

We are located in the United States. If you use the App outside the United States, on-device processing happens on your own device in your own country. Any support communication you send us is received and stored in the United States, which may not provide the same level of data protection as your jurisdiction.

Where a transfer mechanism is required for personal data originating in the EEA, the United Kingdom, or Switzerland, we rely on your explicit consent to the transfer, implied by your decision to contact us, and on the necessity of the transfer for the performance of a contract with you or the establishment, exercise, or defense of legal claims. If our processing expands beyond support correspondence, we will implement Standard Contractual Clauses or another approved mechanism and update this Policy.


18. Tracking, advertising, and opt-out signals

The App contains no advertising SDKs, no analytics SDKs, no crash-reporting SDKs, no tracking pixels, and no cookies. We do not track you across apps or websites, and the App does not request App Tracking Transparency permission because it does not track.

Because we do not sell or share personal information and do not engage in targeted advertising, there is nothing for a browser-based Global Privacy Control or Do Not Track signal to opt out of. We would honor such a signal if that ever changed.


19. Third parties

Apple Inc. provides iOS, the App Store, TestFlight, Face ID and Touch ID, the Keychain, Apple Maps, on-device recognition frameworks, the share sheet, and the pasteboard. Apple’s handling of information is governed by Apple’s privacy policy, not this one.

The App integrates no third-party advertising networks, data brokers, analytics providers, or software development kits that collect personal information. We do not sell information to data brokers, and we are not required to register as a data broker.

If we later add any third-party service that receives personal information, we will update this Policy before it takes effect.


20. Changes to this Policy

We may update this Policy. When we do, we will revise the “Last updated” date and the policy version.

For changes that materially and adversely affect how we handle personal information we receive, we will provide reasonable advance notice through the App, on our website, or by email where we have one, before the change takes effect. Continued use of the App after a change becomes effective means you accept the revised Policy, to the extent permitted by applicable law.

Previous versions are available on request at support@liviu.me.


21. Contact

For privacy questions, requests, or appeals:

If you are dissatisfied with our response, you may contact your local data protection authority or state Attorney General.


SecureD stores your content on your device. We cannot access or recover it. Please maintain your own backups and recovery methods. This document describes our privacy practices and is not legal advice.

Policy Version 2.1 — Effective August 3, 2026. Copyright © 2026 Liviu Patrasco. All rights reserved.