🔒 Privacy & Data Protection
Privacy Policy for Secure Folder & App Locker
This policy explains what Secure Folder & App Locker accesses, what it stores, and what
leaves your device — which, for everything that matters, is nothing.
disguise choice never leave your phone. There is no account and no sign-in. The app is free and
funded by Google AdMob, and advertising is the only part of the app that involves data leaving
your device — it is handled by Google and is kept entirely separate from your vault.
1. Your vault data stays on your device
Your PIN, your list of secured apps, your disguise choice and every other vault setting are
stored only in your device’s private app storage. They are never uploaded, transmitted or shared.
Cloud backup and device-to-device transfer are switched off for this app, so vault data cannot
leave your phone even through Android’s own backup system. Your PIN is stored using PBKDF2
key-stretching with a random salt — never as readable text.
2. Biometric authentication
Unlocking uses Android’s official BiometricPrompt API. Your fingerprint or face data is
processed entirely by the Android operating system and is never accessed, stored or transmitted by
this app. The app is only told whether authentication succeeded.
3. Advertising (Google AdMob)
This app is free and is funded by advertising supplied by Google AdMob. To serve ads, the Google
Mobile Ads SDK may collect and process device and usage information including your advertising ID,
IP address, device model, operating system version, coarse location derived from your IP address,
and how you interact with the ads shown.
This is standard advertising data. It is collected by Google, not by us, and is governed by
Google’s Privacy Policy
and Google’s advertising terms.
with Google, with advertisers or with anyone else. Advertising data and vault data are entirely
separate, and no security feature is ever placed behind an advert or a payment.
4. Your advertising choices
- If you are in the European Economic Area, the United Kingdom or Switzerland, you are asked
for consent before any personalised advert is served. - You can change that decision at any time using Ad Privacy Settings on the
app’s settings screen. - You can reset or delete your advertising ID at any time in
Android Settings → Privacy → Ads. - Watching one rewarded video removes pop-up adverts for 24 hours and the banner for 1 hour.
5. Identifiers
This is the complete list of device identifiers this app and its SDKs can access. It is kept as
a single table so it stays accurate — if this ever changes, this table changes with it.
| Identifier | Used? | Purpose |
|---|---|---|
| Advertising ID (AAID) | Yes | Used by Google AdMob to serve and measure adverts, as described in section 3. It is resettable and deletable by you at any time in Android settings. |
| Firebase installation ID | Yes | Generated by Google Analytics for Firebase and Firebase Remote Config to distinguish one installation from another for aggregate statistics and feature configuration. It is not linked to your identity and is cleared when you uninstall the app. |
| Android ID (SSAID) | No | Not accessed by this app. |
| IMEI, MEID or serial number | No | Not accessed by this app. |
| MAC address | No | Not accessed by this app. |
| Phone number, email address or account name | No | The app has no account system and never asks for any of these. |
6. Analytics and configuration
The app includes Google Analytics for Firebase. It reports anonymous, aggregated usage and
stability information automatically collected by the SDK — for example app opens and crashes. It is
never used to identify you, and it never records which apps you have secured.
The app also uses Firebase Remote Config to adjust settings such as whether adverts are shown
and whether an update notice appears. Remote Config sends configuration to the app; it does not
send your data anywhere.
Google Play’s In-App Review and In-App Update services are used to offer a rating prompt and to
check whether a newer version is available. These are operated by Google Play.
7. Permissions and why they are needed
| Permission | Why it is needed | What it can see |
|---|---|---|
| Usage access PACKAGE_USAGE_STATS | To detect the moment a secured app is opened, so the lock screen can be shown | App package names only — never content inside them. Evaluated on-device, never transmitted. |
| Display over other apps SYSTEM_ALERT_WINDOW | To draw the lock screen above the app being protected | Nothing. It only draws. |
| Query all packages QUERY_ALL_PACKAGES | To list installed apps so you can choose which to secure | The list of installed apps. It stays on your device and is never uploaded. |
| Device admin Force-lock policy only | Optional. Prevents the app being uninstalled to bypass your lock | Nothing — it is a policy, not data access. It cannot read your messages, photos, files or contacts, and it cannot wipe your phone. You can switch it off at any time in Settings → Security → Device admin apps. |
| Accessibility service BIND_ACCESSIBILITY_SERVICE | Optional. Provides near-instant blocking instead of a fractional delay | Window transition events only. It does not read screen content, and nothing it observes is collected, stored or transmitted. |
| Biometric / fingerprint | To unlock the vault using your existing screen lock | Only whether authentication succeeded. Never the biometric data itself. |
| Notifications POST_NOTIFICATIONS | For the ongoing notice showing that protection is running | Nothing. |
| Foreground service | To keep the locker running reliably in the background | Nothing. |
| Run at startup RECEIVE_BOOT_COMPLETED | To restore protection after the phone restarts | Nothing. |
| Advertising ID AD_ID | Used by Google AdMob as described in section 3 | See the identifiers table above. |
| Internet and network state | Added by the Google advertising and Firebase SDKs to fetch adverts and configuration | No vault data is ever sent over the network. |
The app requests no location, camera, microphone, contacts, SMS, call log,
calendar or file-storage permissions.
8. Data retention and deletion
All vault data stays on your device and is deleted when you uninstall the app. We hold no server
copy, because none is ever created. We do not retain browsing history, app usage history or lock
screen logs.
To delete everything: switch off device admin in Settings → Security → Device admin apps if you
enabled it, then uninstall the app. To delete advertising data held by Google, use
Android Settings → Privacy → Ads, and Google’s own privacy controls.
9. Children’s privacy
This app is not directed at children under 13, and we do not knowingly collect personal
information from children. If you believe a child has used this app and you have concerns, contact
us and we will help.
10. Changes to this policy
If our data practices change — including if any additional identifier is ever used — this page
and the policy shown inside the app will both be updated, and the “last updated” date above will
change. Material changes will be reflected in the app before they take effect.
Contact MetaCyberGuru
Questions about this policy, or a privacy request?
Email info@metacyberguru.com — MetaCyberGuru LTD.
See also the Secure Folder app page.