1. Who this policy covers
FactLockCam is a private, local-first archive. Only you hold the keys that decrypt your sealed media. We do not track, profile, or sell your personal information. We cannot read your unencrypted files or recover lost keys. This policy describes the data that does leave your device, which processors receive it, why we keep it, and how you delete it.
Contact for privacy questions and deletion requests: [email protected].
2. What we collect and why
We collect the following for App Functionality. We do not use it for tracking or advertising.
- Email address (linked to your account). Used to send a one-time Magic Number and to identify your account. We do not use email for marketing.
- User ID (linked to your account). A Supabase authentication identifier created when you sign in. Ledger rows, quota records, and optional cloud ciphertext are stored under this identity.
- Photos and videos (linked to your account when cloud sync runs). Capture
happens on device. The original media is stored locally as encrypted
.sealfiles. After a seal, optional cloud sync may upload the same ciphertext to storage scoped to your User ID. We cannot decrypt that blob. - Other user content (linked when synced). Encrypted archive blobs, titles and descriptions you add, signed capture manifests, fingerprints, and Polygon transaction identifiers associated with your account.
- Precise location (not collected by FactLockCam). If you grant location
permission, live GPS coordinates appear only on the camera viewfinder. They are not written
into the signed capture record, not uploaded to our servers, and not included in
.flcproofpackages or certificate PDFs.
3. Processors and public records
Email is not kept solely on your device. The following processors receive the minimum data needed to run the product:
- Supabase — authentication, profiles, quota/subscription status, proof-ledger
metadata, and optional encrypted objects in the
factlock_vaultbucket. - Resend — delivery of the Magic Number email (your address and the one-time code).
- Cloudflare — hosting and delivery of this website, including
/openand/verify. Opening a proof package in the browser processes the file locally; the site does not upload the package. - Polygon / anchor relay — a hash of the signed capture manifest is broadcast through our relay to Polygon. The public transaction does not include your email, filename, or media bytes.
- Apple — if you purchase a plan or Incident Pack, App Store billing and receipt verification use Apple's purchase identifiers. We do not receive your payment-card number.
4. On-device encryption
Hashing, AES-GCM sealing, and capture-record signing run on your device before any upload. Keys
stay in the device Keychain (and Secure Enclave when the device reports that class). Those keys
are never transmitted to or stored on our servers. Capture records disclose the
device_key_class reported by the device; that label describes the signing key
class, not scene authenticity, and is not a hardware-attestation claim.
5. Public ledger
When notarization completes, only a mathematical hash (SHA-256 of the signed capture manifest) is published on Polygon. Your filenames, identity, and file contents are not written on the public ledger. The ledger is a timestamped integrity record of that hash, not a statement of physical truth.
6. Data protection and AI
FactLockCam does not share your data, files, or identity with third-party AI or machine-learning services. File hashing and sealing run on your device.
7. Backups you control
We do not store your encryption keys or backup passwords. We cannot reset those passwords or
decrypt your archive. Sealed media lives on your device as encrypted .seal files;
optional cloud sync holds ciphertext we cannot read and is not a downloadable photo library.
You manage two backups and we hold neither: a .factlock file (Account & Settings → Backup & Restore → Export archive keys) containing your sovereign decryption keys, and optional per-item .flcproof sealed copies (Export sealed backup from any archive item). Neither is media from our servers. Keys are restored on the locked screen; sealed items are restored in Backup & Restore with the password you set. Losing keys without .factlock means permanent loss of access to encrypted assets on the device and in cloud sync; only .flcproof copies you already saved stay unlockable.
Lock Archive removes keys from the device but leaves local sealed files; import .factlock to unlock. App uninstall removes local keys; after reinstall, sign in and import .factlock to read cloud ciphertext for the same account. Burn Account deletes your identity, cloud data, local archive, and keys—a prior .factlock cannot restore a burned account. See our Terms of Service for the full scenario table.
8. Retention and deletion
Account, ledger, quota, and cloud-ciphertext records stay until you delete the account or we
must retain a subset to operate the service (for example, a public Polygon transaction cannot be
reversed). Burn Account (Account & Settings, double confirmation, typed
OBLITERATE) calls our perform_full_burn procedure and wipes the
server identity, linked cloud objects, local archive, keys, and journal. Shared
.flcproof packages you already delivered are copies you control; we cannot revoke
them. Email [email protected] if you need
help locating the in-app deletion path.
9. Your choices
- Decline location permission. Capture and sealing still work; the viewfinder omits GPS.
- Stay offline after a seal. Cloud sync and Polygon anchoring wait until the device is online.
- Skip cloud sync by not remaining signed in or by burning the account.
- Export or delete your archive from Account & Settings.
10. Children
FactLockCam is not directed at children under 13 and does not knowingly collect personal information from them.
11. Changes
If this policy changes, we will update the date on this page. Material changes that affect how we handle personal information will be reflected here before they apply to the App Store build.