Fialka Secure Vault Privacy Policy
Last Updated: May 30, 2026
This Privacy Policy explains the data processing approach of the Fialka Secure Vault application ("Application") developed by Mobcrown.
Core Principle (Privacy-First): Photo, video, document, audio, and note content added to the vault is not uploaded to our servers. This content is stored in encrypted form on your device. We do not have a central server/database architecture that would allow us to read back your vault content.
1) Data Controller
Data controller: Mobcrown
Contact: info@mobcrown.com
2) Scope of This Policy
- Covers data processing activities within the mobile application.
- Third-party sites opened from within the application (e.g., web pages, store links) are subject to their own privacy policies.
- App Store / Google Play payment processes are carried out within the infrastructure of the respective store providers.
3) What Data Do We Process?
3.1 Vault Content (actual sensitive data)
- Photo, video, document, audio, and note content.
- This data is encrypted within the device and stored locally.
- No automatic upload to server/cloud is performed.
3.2 Local Technical Metadata (only on the device)
- Index information such as file name, file path, type, size, creation date, and folder mapping may be kept in the local database within the device.
- This metadata is necessary for the vault's file listing and foldering functions.
- Vault content files (file bytes) are not kept in the database; they are kept encrypted in the file system.
3.3 Authentication Data (within the device)
- Password hash values, salt, security settings, and some application preferences are stored in the device's secure storage area.
- Biometric authentication results are obtained via the operating system; we do not access biometric raw data.
3.4 Intruder Alert Data
- The photo taken during failed password attempts and the attempt time are stored within the device.
- These records are also not sent to the server.
3.5 Technical Data from Third-Party Services
- Firebase Crashlytics (Google): device model, OS version, app version, stack trace, and application state information for crash and error diagnosis.
- Firebase Analytics / Google Analytics (Google): anonymous product and usage analytics to understand how the app is used and to improve stability and features. This may include: app session events, feature usage events (e.g. vault unlock, import actions, paywall funnel steps), generic event parameters (e.g. file type category, import source, subscription plan identifier), device/OS/app version, approximate location (country/region derived by Google), and user properties such as premium status and disguise mode preference. Vault passwords, note text, file names, and vault file content are never sent.
- Firebase Remote Config (Google): operational configuration values fetched from Google servers (e.g. minimum supported app version, feature flags). No vault content is transmitted.
- Adapty: anonymous device/profile identifiers, product/subscription status, purchase verification data, paywall presentation logs, and limited profile attributes for subscription segmentation (e.g. cumulative usage counters such as paywall views or import counts). Vault content is not included.
3.6 Analytics and Segmentation — Explicit Exclusions
To avoid ambiguity, the following are never collected or transmitted to Mobcrown servers or the third-party services listed above:
- Master password, panic password, recovery phrase, or intruder wrong-password text
- Note titles or note body text
- Vault file names or encrypted file contents
- Intruder alert photos (stored only on your device)
- Private browser browsing history or page content
Important: Vault content (photo/video/document/note content) is not sent to Crashlytics, Firebase Analytics, Remote Config, or Adapty.
4) Permissions and Purposes of Use
4.1 Camera Permission (CAMERA, iOS Camera permission)
- Capturing photos/videos directly into the vault.
- Capturing a photo of the moment of incorrect entry in the intruder feature.
4.2 Photo/Media/Storage Permissions
- Android:
READ_MEDIA_IMAGES, READ_MEDIA_VIDEO,
READ_MEDIA_AUDIO, older storage permissions on legacy Android versions, and the system save dialog for non-media exports (no broad “all files” access).
- iOS: Photo library read/write permissions.
- Purpose: importing from gallery, exporting from vault to device, media selection.
4.5 Biometric Permissions (USE_BIOMETRIC, Face ID / Touch ID)
- Fast and secure unlocking of the vault.
- Biometric data remains directly in the operating system's secure area.
4.6 Microphone Permission (iOS description key / platform requirement)
- May be required by the operating system for audio recording during video capture with the camera.
- A separate audio collection service is not used on the application side.
4.7 Internet/Connection Permissions (INTERNET)
- Subscription and purchase verification (Adapty / store flow).
- Crash report submission (Firebase Crashlytics).
- Anonymous usage analytics (Firebase Analytics).
- Operational configuration and minimum-version checks (Firebase Remote Config).
- In-app web pages and private browser feature.
5) Storage and Retention Periods
- Vault content and most security data are kept on your device.
- Relevant data on the device can be removed through deletion, export, or application uninstall actions.
- Crashlytics, Firebase Analytics, Remote Config, and Adapty records are subject to the retention policies of Google and Adapty respectively. You can review Google's Privacy Policy and Adapty's Privacy Policy for details.
- When you uninstall the application, data in the local application area is deleted according to operating system behavior; however, your device backup settings (e.g., iCloud/Google backups) may also be effective.
6) Who Do We Share Data With?
- Google / Firebase Crashlytics (crash and error analysis).
- Google / Firebase Analytics (anonymous product and usage analytics).
- Google / Firebase Remote Config (operational app configuration).
- Adapty (subscription, paywall, and purchase management).
- Apple App Store / Google Play (payment and subscription processing).
We do not sell your vault content. Anonymous technical analytics data is processed by Google and Adapty as service providers under their respective terms. Where applicable law requires, you may exercise rights regarding such processing through us or directly with the provider.
7) Security Measures
- On-device encryption, password hashing, secure storage, and temporary file cleaning mechanisms are used.
- Preview/decrypted content is kept in the temporary area as much as possible and cleared at the end of the session.
- Zero-risk guarantee cannot be given; however, reasonable technical and organizational measures are implemented.
8) About Private Browser
- Cookie/cache/local storage cleaning processes are applied when the browser session closes.
- Sites you visit may collect data on their own side; this is outside the application's control.
9) Children's Privacy
The application is not designed for individuals under the age of 13. We do not knowingly collect personal data from children.
10) International Data Transfer
Because we use Google (Firebase Crashlytics, Firebase Analytics, Firebase Remote Config) and Adapty, technical data may be processed on servers located outside your country, including in the United States and the European Union, depending on the provider's infrastructure. Processing is carried out under the providers' contractual safeguards and privacy policies.
10.1) Legal Bases (where GDPR / UK GDPR applies)
- Contract / service delivery: subscription verification (Adapty, app stores), essential app operation.
- Legitimate interests: crash diagnostics, fraud prevention, product analytics to improve security and usability — balanced against your privacy rights; vault content is excluded.
- Legal obligation: where required by applicable law.
11) Your Rights
According to applicable legislation (e.g., KVKK/GDPR), you may have rights such as access, correction, deletion, objection to processing, and complaint. You can contact us for requests.
12) Policy Changes
This policy may be updated in line with legal or operational needs. The new version becomes effective on the date it is published on this page.
13) Contact
E-mail: info@mobcrown.com