Privacy Policy
Effective date: July 12, 2026
This Privacy Policy describes how PixNest ("we", "our", or "the App") handles information when you use our Android application. PixNest is an encrypted photo & video vault: it lets you move private photos and videos behind a PIN (with an optional biometric unlock and a decoy vault for plausible deniability), all stored encrypted on your own device.
Core promise: The App is built with zero INTERNET permission. It cannot open a network connection, cannot phone home, and contains no ad SDK, no analytics SDK, no Firebase, and no consent (UMP) SDK. Every byte the App handles — your vault, your PIN, your settings — stays on your device unless you personally choose to export a backup or send us a feedback email. You can independently verify this by inspecting the installed APK's manifest (aapt dump permissions): it will list neither INTERNET nor ACCESS_NETWORK_STATE.
1. Information We Collect
1.1 Information collected automatically
None. The App has no network access, so it cannot transmit device identifiers, advertising IDs, analytics events, or crash reports to us or to anyone else.
1.2 Information stored locally on your device
- Vault contents: photos and videos you choose to import are encrypted (AES-256-CBC, per-file random salt/IV, PBKDF2-derived key) and stored only in the App's private local storage.
- PIN / decoy PIN: only a one-way salted hash of each PIN is stored. The plaintext PIN itself is never written to disk — it is held in memory only for as long as the App process is running.
- Biometric unlock (optional): fingerprint/face data never leaves Android's own secure hardware (the system Keystore); the App never sees or stores it.
- Local Recovery Key (optional, Premium): a 128-bit key generated on-device that wraps your current PIN so you can reset a forgotten PIN. It is shown to you once and never retained by the App in plaintext form.
- Break-in attempt log: timestamps of wrong-PIN attempts are recorded in a local, on-device database, purely so you can review them under Settings — never transmitted anywhere.
- App settings: auto-lock delay, chosen app language, theme, app-disguise selection, and the album watched by Auto-Monitor (Premium) are stored in local app preferences.
- Feedback (optional): if you use Settings → Feedback, the message you write is sent through your own device's email client to our support address. This is the only case in which anything you type leaves your device, and only when you choose to send it.
1.3 Information we do NOT collect
- We do not collect your name, email, phone number, or any contact information.
- We do not require account registration to use the App.
- We do not collect your location.
- We do not run any analytics, crash-reporting, or advertising SDK.
- We do not operate any server that stores or backs up your vault content — there is no cloud copy of your data anywhere.
2. How We Use Information
Every piece of information listed above is used exclusively, on-device, to run the App's own features: unlocking and displaying your vault, protecting it with a PIN/biometric/decoy layer, letting you recover a forgotten PIN, and remembering your preferences. None of it is used for advertising, profiling, or any purpose off your device.
3. Permissions We Request
- READ_MEDIA_IMAGES / READ_MEDIA_VIDEO (and, on older Android versions,
READ_EXTERNAL_STORAGE / WRITE_EXTERNAL_STORAGE): needed so you can pick photos and videos from your device's gallery to move into the encrypted vault, and so the App can permanently delete the original file afterward. This requires direct MediaStore access rather than the system Photo Picker, because deleting an original needs an explicit, OS-mediated delete confirmation the Photo Picker does not support.
- Biometric hardware (declared by the Android
androidx.biometric library): used only for the optional fingerprint/face unlock feature. No biometric data is ever accessible to the App itself.
The App does not request Internet, network state, camera, microphone, contacts, or location permissions.
4. Third-Party Services
The only third-party service integrated in the App is:
- Google Play Billing (processes the one-time "PixNest Premium" purchase): Google Privacy Policy. Billing communicates with the Play Store app on your device through Android's bound-service mechanism, not through a network socket opened by this App, and we never see or store your payment details.
There is no AdMob, no Firebase (Analytics/Crashlytics/Remote Config), and no Google User Messaging Platform (UMP) anywhere in the App.
5. In-App Purchases
The App offers a one-time "PixNest Premium" purchase (product ID pixnest_lifetime) that removes the 50-item free-tier vault cap and unlocks: custom auto-lock delay, App Disguise, Local Recovery Key, Auto-Monitor, Vault Dedup cleanup, and Multi-Vault. It is a single lifetime purchase — not a subscription — processed by Google Play Billing.
6. Data Storage and Security
- Vault photos/videos are encrypted with AES-256-CBC before being written to disk; each file has its own random salt and IV, and the encryption key is derived with PBKDF2 from your PIN.
- Your PIN is never stored in plaintext, on disk or in a backup — only a salted hash, or (if you enable it) an encrypted wrapper used solely by the Local Recovery Key feature.
- The decoy vault stores plain, user-picked filler photos (not run through vault encryption, since they are not real secrets) so that, under duress, the decoy is indistinguishable from a genuine but unremarkable vault.
- Local backup/restore (Settings → Backup) is entirely user-initiated: it writes a zip file to a location you choose via Android's Storage Access Framework. The App never uploads this file anywhere on its own.
7. Data Retention
- Vault items you delete are moved to a Recycle Bin and permanently erased after 30 days, or immediately if you empty the Recycle Bin yourself.
- Break-in attempt logs, settings, and all other local data are retained until you clear the App's data or uninstall it — at which point everything is gone, since no server-side copy exists to also delete.
8. Children's Privacy
The App is not directed at children under the age of 13. We do not knowingly collect personal information from children, and given the App collects no information off-device in the first place, no such data could reach us even inadvertently.
9. Your Rights
Because everything the App stores lives only on your device, you are always in full control:
- Delete any vault item, or empty the Recycle Bin, at any time from within the App.
- Erase all App data instantly by clearing the App's storage or uninstalling it in your device settings.
- Contact us at the email below with any privacy questions.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page, with the "Effective date" above updated accordingly.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Email: sedance.studio.support@gmail.com