π Privacy & Data Protection
Privacy Policy for Secure Folder & App Locker
This policy explains what Secure Folder & App Locker accesses, what it stores, and what
leaves your device, which, for everything that matters, is nothing.
disguise choice never leave your phone. There is no account and no sign-in. The app is free and
funded by Google AdMob, and advertising is the only part of the app that involves data leaving
your device, it is handled by Google and is kept entirely separate from your vault.
1. Your vault data stays on your device
Your PIN, your list of secured apps, your disguise choice and every other vault setting are
stored only in your device’s private app storage. They are never uploaded, transmitted or shared.
Android’s own cloud backup and device-to-device transfer are switched off for this app, so
nothing is carried off your phone by the operating system. There is one exception, and you
control it: the optional Google Drive backup. If you switch it on, your vault files are
encrypted on this device before they are uploaded, and they go to your own Google Drive
account, never to us, and never to anyone else. Section 8 explains exactly what is stored
and how to delete it. Your PIN is stored using PBKDF2 key-stretching with a random salt,
is never transmitted anywhere, and is never stored as readable text.
2. Biometric authentication
Unlocking uses Android’s official BiometricPrompt API. Your fingerprint or face data is
processed entirely by the Android operating system and is never accessed, stored or transmitted by
this app. The app is only told whether authentication succeeded.
3. Advertising (Google AdMob)
This app is free and is funded by advertising supplied by Google AdMob. To serve ads, the Google
Mobile Ads SDK may collect and process device and usage information including your advertising ID,
IP address, device model, operating system version, coarse location derived from your IP address,
and how you interact with the ads shown.
This is standard advertising data. It is collected by Google, not by us, and is governed by
Google’s Privacy Policy
and Google’s advertising terms.
with Google, with advertisers or with anyone else. Advertising data and vault data are entirely
separate, and no security feature is ever placed behind an advert or a payment.
4. Your advertising choices
- If you are in the European Economic Area, the United Kingdom or Switzerland, you are asked
for consent before any personalised advert is served. - You can change that decision at any time using Ad Privacy Settings on the
app’s settings screen. - You can reset or delete your advertising ID at any time in
Android Settings β Privacy β Ads. - Watching one rewarded video removes pop-up adverts for 24 hours and the banner for 1 hour.
5. Identifiers
This is the complete list of device identifiers this app and its SDKs can access. It is kept as
a single table so it stays accurate, if this ever changes, this table changes with it.
| Identifier | Used? | Purpose |
|---|---|---|
| Advertising ID (AAID) | Yes | Used by Google AdMob to serve and measure adverts, as described in section 3. It is resettable and deletable by you at any time in Android settings. |
| Firebase installation ID | Yes | Generated by Google Analytics for Firebase, Firebase Remote Config and Firebase Performance Monitoring to distinguish one installation from another for aggregate statistics and feature configuration. It is not linked to your identity and is cleared when you uninstall the app. |
| Crashlytics installation UUID | Yes | A random identifier generated by Firebase Crashlytics so that several crash reports from the same installation can be grouped together. It is not derived from any hardware identifier, is not linked to your identity, and is cleared when you uninstall the app. |
| Android ID (SSAID) | No | Not accessed by this app. |
| IMEI, MEID or serial number | No | Not accessed by this app. |
| MAC address | No | Not accessed by this app. |
| Phone number, email address or account name | No | The app has no account system and never asks for any of these. |
6. Analytics, crash reports and configuration
The app includes Google Analytics for Firebase. It reports anonymous, aggregated usage
information automatically collected by the SDK, for example app opens and which screens are
viewed. It is never used to identify you, and it never records which apps you have secured.
From version 1.1.2 the app also includes Firebase Crashlytics. When the app crashes or
stops responding, Crashlytics sends a technical report so the fault can be found and fixed. That
report contains the stack trace of the code that failed, your device model, your Android version,
the app version, how long the app had been running, and the free memory and storage on the device
at that moment. It is tied only to the random installation identifier listed in section 5. A crash
report never contains your PIN, your list of secured apps, your disguise choice, or the contents of
anything in your vault.
Version 1.1.2 additionally includes Firebase Performance Monitoring, which measures timings
such as how long the app takes to start and how long individual screens take to render, so that
slow builds can be identified. It reports durations and device characteristics, not content.
The app also uses Firebase Remote Config to adjust settings such as whether adverts are shown
and whether an update notice appears. Remote Config sends configuration to the app; it does not
send your data anywhere.
To confirm that these requests genuinely come from a real installation of this app rather than
from a script impersonating it, the app uses Firebase App Check with the Google Play
Integrity API. Google Play returns a verdict about whether the app and the device are genuine.
This verdict describes the app and the device; it does not identify you and carries none of your
vault data.
Google Play’s In-App Review and In-App Update services are used to offer a rating prompt and to
check whether a newer version is available. These are operated by Google Play.
7. Permissions and why they are needed
| Permission | Why it is needed | What it can see |
|---|---|---|
| Usage access PACKAGE_USAGE_STATS | To detect the moment a secured app is opened, so the lock screen can be shown | App package names only, never content inside them. Evaluated on-device, never transmitted. |
| Display over other apps SYSTEM_ALERT_WINDOW | To draw the lock screen above the app being protected | Nothing. It only draws. |
| Query all packages QUERY_ALL_PACKAGES | To list installed apps so you can choose which to secure | The list of installed apps. It stays on your device and is never uploaded. |
| Device admin Force-lock policy only | Optional. Prevents the app being uninstalled to bypass your lock | Nothing, it is a policy, not data access. It cannot read your messages, photos, files or contacts, and it cannot wipe your phone. You can switch it off at any time in Settings β Security β Device admin apps. |
| Accessibility service BIND_ACCESSIBILITY_SERVICE | Optional. Provides near-instant blocking instead of a fractional delay | Window transition events only. It does not read screen content, and nothing it observes is collected, stored or transmitted. |
| Biometric / fingerprint | To unlock the vault using your existing screen lock | Only whether authentication succeeded. Never the biometric data itself. |
| Notifications POST_NOTIFICATIONS | For the ongoing notice showing that protection is running | Nothing. |
| Foreground service | To keep the locker running reliably in the background | Nothing. |
| Run at startup RECEIVE_BOOT_COMPLETED | To restore protection after the phone restarts | Nothing. |
| Advertising ID AD_ID | Used by Google AdMob as described in section 3 | See the identifiers table above. |
| Internet and network state | Used by the private browser, the optional Google Drive backup, and the Google advertising and Firebase SDKs | Vault files are encrypted on this device before any upload, so nothing readable leaves your phone. |
| Camera CAMERA | Optional. Intruder capture takes a photo with the front camera after repeated failed unlock attempts | Only that photo. It stays on your device, is never uploaded, and you can delete every one of them in Settings. Off unless you turn it on. |
| Notification access BIND_NOTIFICATION_LISTENER_SERVICE | Optional. Hides the contents of notifications from locked apps | The notifications it replaces. Nothing is stored, logged or transmitted. |
| Storage on older Android WRITE_EXTERNAL_STORAGE, Android 10 and below | To remove the original copy of a photo or video after you move it into the vault | Only the file you chose to hide. Not requested at all on Android 11 and later. |
The app requests no location, microphone, contacts, SMS, call log or
calendar permissions, and it never asks for all-files access. It does not read your gallery ,
you choose each item yourself through Androidβs own photo picker.
8. Data retention and deletion
We hold no server copy of anything, because none is ever created. We do not retain browsing
history, app usage history or lock screen logs.
Files you hid in the vault
Your vault lives in a folder you chose, outside the app. Uninstalling the app does not
delete those files, that is deliberate, so that reinstalling and entering the same
recovery PIN brings everything back. If uninstall protection is enabled, the app offers to move
every hidden file back to your gallery before it is removed.
To delete hidden files permanently, do either of these:
- Open the vault, select the items and choose Delete. This is irreversible ,
there is no copy anywhere else to restore from. - Or delete the vault folder itself with any file manager. Its contents are encrypted, so
without your recovery PIN nobody can read them, including us.
Encrypted backup in your Google Drive
If you switched on Drive backup, an encrypted copy of your vault is kept in your own Google
Drive, inside a private application folder that we cannot browse. Choose
Settings β Backup & Restore β Delete cloud backup in the app to remove every
one of those files from Drive. You can also remove them from Google Drive directly, under
Settings β Manage apps.
Intruder photos
Photos taken after repeated failed unlock attempts never leave your phone. Remove them all with
Delete all in Settings β View captured attempts.
Everything else
Your PIN hash, the list of locked apps and your preferences live only in the app’s private
storage, and are destroyed when you uninstall it. To delete advertising data held by Google,
use Android Settings β Privacy β Ads together with Google’s own privacy controls.
Requesting deletion
There is no account and no server, so we hold nothing to delete on your behalf, every control
above is in your hands. If you want a question answered, or written confirmation that we hold
none of your data, email info@metacyberguru.com
and we will respond.
9. Children’s privacy
This app is not directed at children under 13, and we do not knowingly collect personal
information from children. If you believe a child has used this app and you have concerns, contact
us and we will help.
10. Changes to this policy
If our data practices change, including if any additional identifier is ever used, this page
and the policy shown inside the app will both be updated, and the “last updated” date above will
change. Material changes will be reflected in the app before they take effect.
Contact MetaCyberGuru
Questions about this policy, or a privacy request?
Email info@metacyberguru.com, MetaCyberGuru LTD.
See also the Secure Folder app page.