Privacy Policy

Effective: 2026-05-25

DualKey treats your privacy as the first requirement. Code secrets, vault entries and private notes live only in your device's encrypted store and are never uploaded to our servers. This page explains how the app and this website handle your data.

App data

We collect no personal data

Code secrets and vault entries are held in your device's system encrypted store (the iOS Keychain and Android Keystore); note contents are encrypted and kept on the device; service names, usernames and similar details sit in the device's own preferences. None of it is sent, uploaded or synced to our servers. We run no backend, no database and no cloud accounts.

Scope

The app may store the following on your device:

  • The code secrets you create, held in the system's encrypted store
  • Details alongside each account: service name, account identifier (an email address, say), issuer, and the counter value for counter-based accounts
  • The contents of your vault and private notes, stored encrypted, along with your preferences: theme, language, copy behaviour and the biometric switch (Pro)
  • Your purchase state (whether Pro is unlocked), verified by the Apple or Google receipt

All of it stays on your device and never leaves your phone. Unless you run a Pro cloud backup yourself, the data is local only.

Permissions

The app requests permissions only when needed:

Camera
Required

Scanning an otpauth QR code to import an account. Recognition happens on the device and nothing is sent over the network

Biometrics (Face ID / Touch ID)
Optional

The optional app lock in Pro, handled by the system's own biometric mechanism — we never receive your fingerprint or face data

iCloud / Google account (Pro cloud backup)
Optional

Requested when you run a Pro cloud backup, to reach your own iCloud or Google storage. Contents are encrypted before they are written, into a folder only you can see

Network (ads)
Free tier only

Loading one short ad before you add a fifth or later code account on the free tier. Once Pro is unlocked there are no outbound requests at all

External connections

The app is local first. On the free tier there is one outbound connection: loading a short ad before you add a fifth or later code account. Unlocking Pro removes that connection entirely and the app makes no outbound requests at all. Beyond that there are no analytics, tracking or behavioural tools. The one-time Pro purchase is handled by the Apple App Store and Google Play; the app never touches your card details.

Data deletion

You can remove everything at any time: uninstall the app, which clears the contents held in the system's encrypted store, or clear its data and cache in system settings. If you have ever run a cloud backup, delete it separately from the app's folder in iCloud or Google storage.

Website contact form

When you submit the contact form, we receive your name, email, subject, message, IP, and browser info — used only to reply. We do not use it for marketing or share it with third parties.

Website third-party services

This site uses Cloudflare for DNS, CDN, and security; transactional email via Postmark / Resend. These services only handle necessary request data — they don't touch in-app local data.

Your rights

Email buy.weimi@gmail.com anytime to request inquiry record access, correction, or deletion.

Children's privacy

Neither the app nor this site is designed for children under 13; we do not knowingly collect children's data.

Policy changes

Material changes update the effective date on this page. Check back periodically.

Contact

Questions about this policy? Email buy.weimi@gmail.com.