Privacy Policy
Effective August 31, 2026
Kryptis is designed around a local-first encrypted vault. Ordinary vault content stays on your device, but limited information is processed off the device when you use temporary email, request a public-media import, contact us, load these web pages, or connect to essential operational and security services.
1. Scope and controller
Tuvo Labs Limited Co (“Tuvo Labs,” “we,” “us,” or “our”) is responsible for the personal information described in this Privacy Policy. This Policy applies to the Kryptis mobile application, the legal pages at kryptis.app, support communications, and the related features and services we operate (collectively, “Kryptis”).
This Policy explains what information stays on your device, what limited information is processed off the device, why it is used, how long it is retained, and the choices available to you. It does not govern a website, public media source, personal storage account, operating-system feature, app marketplace, or other service that operates under its own privacy practices.
Our Supplemental Terms of Use govern your use of Kryptis. If a translated version of this Policy differs from the English version, the English version controls to the extent permitted by law.
2. Plain-language summary
- Local-first vault. Ordinary vault photos, videos, selected contact copies, protected identity or card fields, vault metadata, credentials, and intruder reports are stored on the device and are not collected by Tuvo Labs unless you separately choose an off-device feature that requires particular content.
- Limited operations. A random persistent installation identifier and basic app, notification, timing, and country-level information are processed to operate and protect Kryptis.
- Temporary email. A device token, alias, sender, subject, body, one-time code, and timestamps may be processed for up to 24 hours so the app can display short-lived messages.
- Public-media import. A URL, source host, pseudonymous authorization, network and subject hashes, eligible media, a client public encryption key, and an encrypted output artifact are processed for a user-requested import under the short retention periods below.
- No advertising profile. We do not sell personal information, use it for cross-context behavioral advertising, or track activity across other companies’ apps and websites.
- No recovery access. Tuvo Labs cannot retrieve a forgotten vault PIN or recovery secret, reconstruct local encryption keys, or unlock your local vault.
3. Information that stays on the device
The following information is handled locally in ordinary use and is not collected by Tuvo Labs:
| Information | Local handling |
|---|---|
| Vault content | Protected copies of photos, videos, identity or card details, and related vault metadata remain in the local encrypted vault unless you separately invoke an off-device feature described below. |
| Selected contacts | Contact copies you choose for the vault are stored and used locally. |
| Vault credentials and keys | Your vault PIN, recovery secret, decoy configuration, and local encryption material remain on the device. We cannot use them to unlock the vault. |
| Biometric information | Face or fingerprint templates are handled by the operating system. Kryptis receives only a local success, failure, or cancellation result and does not receive the biometric template. |
| Intruder reports | If enabled, an intruder image and related report are stored locally under your control. We do not remotely monitor camera output. |
| Local transfer | When the feature operates as designed, content you choose is exchanged between participating devices on a local connection without collection by Tuvo Labs. |
| Personal encrypted backup | If you choose backup, encrypted data is sent to a personal storage account you select and control. Tuvo Labs does not collect that backup, although the storage operator processes it independently under its own terms. |
Your device and operating system may create their own backups, diagnostics, or records outside our control. Deleting something inside Kryptis may not delete an independent device or personal-storage backup. Review the settings for the services you use.
4. Information processed off the device
We process the following limited categories when needed for an operation or when you choose the related feature:
| Context | Information processed |
|---|---|
| Essential app operations and security | A random persistent installation or device identifier; app version and build; service interface version; notification permission status; first-seen and last-seen timestamps; request status; and country inferred from a network request. We also necessarily handle network connection information to receive a request. This is limited operational state, not an advertising profile or a general product-event history. |
| Temporary email | A random device token, generated alias, message sender, subject, body, extracted one-time code when available, delivery and expiry timestamps, and security or error state needed to receive and display a short-lived message. |
| Public-media import | The public HTTPS address you submit and its source host; a pseudonymous subject and authorization grant; one-way network and subject hashes used for quota and abuse controls; request, status, timestamp, and error metadata; eligible public media during processing; your client public encryption key; and the encrypted output artifact waiting for pickup. The network address is handled to communicate with the service and may be transformed into a limited abuse-prevention hash. |
| Support or rights requests | If you contact us, we receive your email address, name if provided, message, attachments, and related correspondence. Please do not send a vault PIN, recovery secret, encryption key, full payment-card number, government identifier, or unneeded vault content. |
| Legal website and network security | When you load kryptis.app, ordinary request information may include a network address, user agent, requested route, timestamp, response status, and security or error details. The current legal pages do not intentionally set application cookies and use no advertising pixels or behavioral analytics. |
We do not ask you to create a conventional Kryptis account. The identifiers above can still link limited records to the same installation or request flow, so we treat them as personal information where applicable law does.
5. How information is used
We use off-device information to:
- provide the specific feature you request, including temporary message delivery, public-media processing, encryption and pickup, and operational connectivity;
- maintain compatibility, diagnose errors, respond to support, and communicate about Kryptis;
- authenticate pseudonymous requests, apply quotas and rate limits, prevent spam or abuse, investigate security incidents, and protect users and systems;
- enforce our Terms, establish or defend legal claims, comply with law, and respond to valid legal process; and
- evaluate aggregate service reliability using limited operational records without creating a cross-service advertising or behavioral profile.
We do not use Kryptis information to make automated decisions that produce legal or similarly significant effects about you. We do not use message or media content to train a general-purpose artificial-intelligence model.
6. When information is disclosed
We disclose information only as reasonably necessary in the following circumstances:
- Service contractors. Companies that supply hosting, networking, security, message handling, storage, diagnostics, or technical operations may process limited information for us under contractual restrictions appropriate to their role. We require them to provide the same or equal protection for user information as this Policy and applicable platform requirements provide. They may not use it for their own advertising.
- At your direction. A public source receives the requests needed to retrieve content you selected. A receiving device or personal storage account receives content you chose to send. Those recipients operate under their own terms.
- Professional advisers. Lawyers, auditors, insurers, and similar advisers may receive information subject to professional duties when reasonably necessary.
- Legal, safety, and integrity. We may preserve or disclose information when we reasonably believe it is necessary to comply with law or valid process, protect rights or safety, investigate fraud or abuse, enforce agreements, or secure Kryptis. We assess requests and may object to requests we believe are invalid or overbroad.
- Business transaction. Information may be reviewed or transferred in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of some or all assets, subject to the protections described in Section 15.
7. What Kryptis does not do
- We do not sell personal information for money or other valuable consideration.
- We do not share personal information for cross-context behavioral advertising or use it for targeted advertising.
- We do not track you across apps or websites owned by other companies.
- We do not serve third-party advertising, use advertising identifiers, embed advertising pixels, or maintain a behavioral analytics profile.
- We do not offer a developer-hosted copy of your ordinary vault or a conventional Kryptis user account at this time.
- We do not receive biometric templates from the operating system or possess the credentials needed to unlock your local vault.
- We do not offer a financial incentive in exchange for personal information.
Because these practices may change if Kryptis adds a materially different feature, we will update this Policy and the applicable App Store disclosures before enabling such collection for users when required.
8. Device permissions and choices
Kryptis requests device access only when a feature needs it. Depending on what you use, this can include photos, camera, contacts, local network, notifications, and operating-system authentication. The permission prompt and your device settings control access. Revoking a permission can stop the related feature from working but does not by itself delete previously stored content.
- Choose what to add. You select the photos, videos, contacts, records, public URLs, and local transfers you initiate.
- Choose off-device features. You can use the local vault without using temporary email or public-media import.
- Control permissions. Review or revoke access in device settings; some local data may also be deleted inside Kryptis.
- Control personal backups. Manage or delete an encrypted backup through the personal storage account you selected.
- Avoid sensitive submissions. Do not send sensitive information to support or submit it to a public-media source unless necessary and lawful.
9. Retention and deletion
We retain information only for the period reasonably needed for the stated purpose, then delete or deidentify it unless a longer period is required to comply with law, investigate abuse, secure Kryptis, or establish or defend a legal claim. Current feature-specific limits are:
| Information | Current retention |
|---|---|
| Temporary aliases and message data | Alias, sender, subject, body, one-time code, token, and related timestamps are transient and retained for no more than 24 hours. |
| Local alias history | The app keeps up to the most recent 30 aliases locally on the device. You can remove local history through the app or by deleting its local data. |
| Submitted public-media URL | The submitted URL is cleared from the service record when the request reaches a completed, failed, expired, or otherwise terminal state. |
| Encrypted public-media artifact | The artifact is available only long enough for pickup or deletion and in all cases for no more than 24 hours. |
| Public-media quota and abuse records | Limited pseudonymous and hashed quota records are retained for 2 days. |
| Terminal public-media metadata | Limited status, timing, and error metadata is retained for 7 days after a request becomes terminal. |
| Operational installation record | The random identifier and limited operational state are retained while reasonably needed to operate, secure, and troubleshoot Kryptis, then deleted or deidentified under our operational schedule unless a legal or security need requires longer. |
| Support and rights correspondence | Retained while needed to answer the request and for reasonable legal, security, and recordkeeping needs, then deleted or deidentified. |
| Essential website and network logs | Retained for the short period reasonably necessary for delivery, reliability, abuse prevention, and security, subject to legal holds or incident investigation. |
Local vault content remains until you delete it, delete the app’s data, or the device removes it. We cannot remotely delete or recover local content. Deleting the app may permanently erase local data. Personal storage and device backups must be managed through the account or settings that created them.
You may ask us to delete identifiable off-device information by contacting us. Because Kryptis has no conventional account and we intentionally hold little identifying data, we may be unable to locate a record without enough verifiable information to associate it with your installation or request. Never send a vault credential to prove identity.
10. Security and user responsibility
We use safeguards appropriate to the nature of the information, including a local encrypted-vault design, encrypted transport for network features, access controls, limited retention, pseudonymous identifiers, and encryption of a public-media output to a client-provided public key. We limit contractor access according to operational need and use measures intended to prevent unauthorized use.
Protect your device and credentials, keep your operating system and Kryptis current, verify backups, preserve independent copies of important material, review imported content, and notify us if you reasonably believe a Kryptis-operated service has a security issue. Do not send secrets or sensitive vault contents in an ordinary support email.
11. U.S. state privacy rights
Depending on where you live and subject to exceptions, you may have rights to confirm processing; know, access, correct, or delete personal information; receive a portable copy; obtain information about categories collected, sources, purposes, and recipients; opt out of sale, targeted advertising, or certain profiling; limit particular uses of sensitive information; and appeal a denied request.
Kryptis does not currently sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or profile users for decisions with legal or similarly significant effects. For the same reason, a browser-based opt-out signal such as Global Privacy Control does not change the current legal-site experience. If those practices change, we will provide any required controls before they begin.
To exercise a right, email us with the subject “Privacy Request” and describe the request and the Kryptis feature involved. We may ask for information reasonably necessary to verify your request and protect against fraud. Because we do not maintain conventional user accounts or have access to local vault data, our ability to identify or act on a particular record may be limited. You may use an authorized agent where law permits, subject to proof of authority and identity verification.
We will not discriminate against you for exercising a privacy right. If we deny a request, you may appeal by replying with “Privacy Appeal” and explaining why you believe the decision should be reconsidered. You may also contact the regulator identified in our response where applicable.
12. EEA, UK, and Swiss rights
Where European data-protection law applies, Tuvo Labs is the controller for the processing described here. We rely on: performance of a contract to provide a feature you request; legitimate interests in operating, securing, preventing abuse of, and improving the reliability of Kryptis; consent where a device permission or specific processing requires it; and legal obligations or the establishment, exercise, or defense of legal claims. We balance legitimate interests against your rights and do not rely on them where your interests override ours.
Subject to legal conditions and exceptions, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent without affecting earlier lawful processing; and complain to your local supervisory authority. You may object at any time to direct marketing, although Kryptis does not currently use the information described here for direct marketing.
You are not required by law to provide optional feature content. If information is necessary to perform a feature or protect it from abuse and you do not provide it, that feature may not work. Contact us to exercise a right. We may need proportionate information to verify the request.
13. International processing
Tuvo Labs is based in the United States. Information may be processed in the United States and in other countries where service contractors operate. Those countries may have data-protection rules different from those where you live.
When required for an international transfer, we use an approved legal mechanism and supplementary safeguards appropriate to the information, such as standard contractual protections. You may contact us for more information about the safeguards relevant to your information, subject to confidentiality and security limits.
14. Children
Kryptis is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. Anyone who is at least 13 but has not reached the age of legal majority where they live may use Kryptis only with permission from a parent or legal guardian. If you believe a child under 13 has provided personal information to a Kryptis-operated service, contact us with enough detail to investigate without sending additional sensitive information. We will take appropriate steps to delete it when required.
15. Legal requests and business transfers
We may preserve, access, or disclose information if we reasonably believe doing so is required by valid law or legal process; needed to protect a person from serious harm; necessary to investigate fraud, abuse, or a security incident; or appropriate to protect legal rights. We review requests for facial validity and scope. Where lawful and practicable, we may narrow, challenge, or give notice of a request.
If Tuvo Labs is involved in a proposed or completed financing, merger, acquisition, restructuring, bankruptcy, or asset transfer, relevant information may be reviewed under confidentiality restrictions and transferred as part of the transaction. The recipient must honor this Policy for information already collected unless it gives legally required notice and obtains any required consent before a materially different use.
Our local-first design limits what Tuvo Labs can produce in response to a request. We cannot disclose local vault content, biometric templates, or vault credentials that we do not possess.
16. Changes to this Policy
We may update this Policy to reflect a product, legal, security, or operational change. The revised version will show a new effective date. If a change is material, we will provide additional notice in Kryptis or by another reasonable method before it takes effect when required. If applicable law requires consent for a new use, we will request it rather than relying only on a posted update.
17. Contact
For a privacy question, rights request, or complaint, email hello@tuvolabs.com or write to:
Please identify the Kryptis feature and request involved, but do not include your vault PIN, recovery secret, encryption key, full payment-card number, government identifier, or unnecessary vault content.