Privacy Policy
This Privacy Policy explains how PicSafe: Secure Photo Vault handles information. PicSafe is an offline-first Android app from Chien Pham: it hides photos and videos in an encrypted vault on your device. There is no PicSafe account, no PicSafe server, and no PicSafe cloud upload.
- App
- PicSafe: Secure Photo Vault
- Package name
- com.picsafe.secure.photo.vault
- Last updated
- July 17, 2026
- Developer
- Chien Pham
Your photos, videos, albums, password-derived key material, and recovery phrase stay on your device unless you choose to export an encrypted backup or contact us through another app.
Summary
- PicSafe does not require an account.
- PicSafe does not run ads, analytics, or user tracking.
- PicSafe does not sell personal information.
- PicSafe does not upload your vault files, albums, password, recovery phrase, or backups.
- Data you choose to store in PicSafe stays on your device and is protected with on-device encryption.
Information Stored Locally On Your Device
Everything below is stored locally on your device and is never sent to a server operated by PicSafe:
- Photos and videos you import, stored encrypted with a 256-bit key. Files are only decrypted in memory while you are viewing them.
- Your encrypted vault key material. Your password (via PBKDF2) or biometrics protect this key; the raw key is never written to disk in plain text.
- Your recovery phrase, albums, pinned items, and app preferences such as theme, start page, auto-lock timeout, and biometric settings.
- Backup metadata and encrypted backup files you create or restore. You decide where exported backup files are saved.
We cannot see, recover, or reset this local vault data. If you lose both your password and your recovery phrase, your encrypted media may not be recoverable.
Permissions
PicSafe requests Android permissions only when they are needed for a feature, and uses them solely on your device.
- Photos, media, files, and Android share intents: to import the images and videos you choose into the vault and to export them when you ask. PicSafe only uses the items you select or share with the app.
- Camera: to scan recovery QR codes. QR frames are processed on-device and are not stored or transmitted by PicSafe.
- Biometric hardware: to let you unlock the vault with your fingerprint or face. Biometric templates are handled by Android; PicSafe does not receive or store your fingerprint or face data.
- Internet: used for Google Play features such as in-app review and for links you choose to open. It is not used to upload vault data.
- Vibration: to provide local haptic feedback.
- Hide-app / dialer launch (optional): if you enable stealth mode, PicSafe can be opened by entering a secret code in the phone dialer. This is processed on-device. PicSafe does not collect call history, contacts, or phone numbers.
- Advertising ID: PicSafe does not show ads and does not use the advertising ID for advertising, analytics, profiling, or tracking.
How Information Is Used
- Encrypt, decrypt, display, organize, import, export, and delete the media you choose.
- Protect the vault with password, optional biometric unlock, automatic lock, and recovery phrase features.
- Create and restore encrypted backups when you request it.
- Remember local preferences such as theme, gallery start page, hidden-app mode, and security settings.
Backups
PicSafe can create an encrypted backup file of your vault. You choose where that file is saved (for example, local storage or a location you pick). The backup remains encrypted and under your control — PicSafe does not upload it anywhere.
Analytics, Ads, And Tracking
PicSafe does not include Firebase Analytics, Google Analytics, AdMob, crash reporting SDKs, or other tracking SDKs. PicSafe does not collect app usage analytics and does not use your data for advertising.
Third-Party Services
The app relies on the services below, which process limited information under their own privacy terms. Review their policies for details:
Because the app is distributed through Google Play, Google may process information such as your device, Play account, install status, update status, and review submission to operate Google Play features. PicSafe may request the Google Play in-app review flow, but your review is handled by Google under Google's terms.
If you choose to send feedback by email, your email address and message are processed by your email provider and received by us only because you chose to send them.
Data Sharing And Selling
We do not sell personal information. PicSafe does not share your vault contents, albums, password, recovery phrase, or backups with anyone. Third-party processing is limited to the user-initiated Google Play and email flows described above.
Data Retention And Deletion
All vault data stays on your device until you delete it or uninstall the app. Uninstalling PicSafe removes the app's encrypted files from its private storage. Any backup files you exported remain wherever you saved them until you delete them yourself.
PicSafe does not create user accounts, so there is no account data for us to delete. To delete local data, delete files inside PicSafe, reset the safe, delete exported backup files from their saved location, or uninstall the app. To request deletion of a support email you sent us, contact us from the same email address.
Security
Media is encrypted with AES-256. Your vault key is wrapped using a key derived from your password or your device biometrics and is never stored in plain text. All decryption happens on-device and only while the app is in use.
Google Play Data Safety Alignment
The Google Play Data safety section for PicSafe should match this policy and the app's actual behavior. PicSafe is designed so that vault contents and app activity are not collected by PicSafe or shared by PicSafe. If future versions add any data collection, sharing, analytics, ads, accounts, or cloud features, this policy and the Play Console Data safety declaration must be updated before or alongside that release.
Children
PicSafe is a general-audience utility and is not directed to children under 13. PicSafe does not knowingly collect personal information from children.
Changes To This Policy
We may update this policy when the app changes. The latest version will always be posted on this page with an updated date.
Contact
Questions about this policy can be sent to quangchiennnn@gmail.com.