Kryptra

Privacy Policy

Last updated 10 September 2026

Kryptra is built so that there is almost nothing about you for us to collect. This policy describes what the app does, what leaves your device, and who else is involved.

The short version

  • There is no account. Kryptra never asks for your name, email or phone number.
  • Alexarix Limited operates no server that receives your vault content. We could not read your files if we wanted to.
  • Your unlock pattern, your recovery phrase and your encryption keys never leave your device in any form, encrypted or otherwise.
  • We do not sell data, we run no advertising, and we do not track what you do inside the app.

What stays on your device

All of the following is stored only in Kryptra's private container on your device, encrypted with AES-256-GCM:

Your pattern itself is never stored — not as text, not as a hash that could be tested off the device.

What leaves your device, and only if you ask

Encrypted iCloud backup and sync (optional, off by default)

If you turn it on, Kryptra uploads your files to your own iCloud account, in your private CloudKit database. They are uploaded exactly as they sit on disk — already encrypted under keys that never left your device. Apple stores ciphertext and receives no key. Record names are HMACs, and the recovery envelope is a single fixed-size object, so the backup does not reveal how many vaults you keep. Apple's handling of iCloud data is governed by Apple's Privacy Policy.

Purchases

Payment is processed entirely by Apple; we never see your card or your Apple Account. To know whether your subscription is active we use Adapty (Adapty Tech Inc.), which receives a pseudonymous profile identifier generated on your device, the product you bought, purchase and renewal events, and your App Store country. It receives nothing about your vaults. See Adapty's privacy policy.

Crash reports (optional, off by default)

You may switch on crash reporting in Settings. It is disabled unless you enable it. When on, Firebase Crashlytics (Google) receives a crash stack trace, the device model and the OS version. Kryptra attaches no custom data to a report, and the encryption code never reports at all — a crash report can carry memory contents, which in this app is exactly the material that must not travel. See Firebase's privacy information.

Permissions and why

PermissionUsed for
CameraShooting photos and video directly into the vault. Nothing is added to your photo library.
MicrophoneRecording audio while you film inside the vault.
Photo library (read)Letting you choose items to move into the vault. Kryptra never requests write access.
Face ID / Touch IDOptional quick unlock. The biometric check happens on the device; we receive nothing.

What we never receive

Retention and deletion

Because we hold none of your content, there is nothing for us to delete. On the device, Erase everything in Settings destroys every key and file. If you used encrypted backup, removing the copy is done through your iCloud account — Settings → your name → iCloud → Manage Account Storage → Kryptra — or by turning backup off before you erase. Purchase records held by Apple and Adapty follow their own retention rules; write to us and we will submit a deletion request to Adapty on your behalf.

Children

Kryptra is not directed at children under 13 and we do not knowingly collect anything from them.

Changes

If this policy changes materially, the app will say so before the change takes effect. The date at the top always reflects the current version.

Contact

Alexarix Limited — support@alexarix.com