A plain-language summary of the data the StateNull-SecoM app handles, matching the Google Play Data safety section. The full detail is in our Privacy Policy. Last updated 17 July 2026.
| Account info | E-mail, optional display name / @handle, one-way password hash — to create and secure your account. Collected. Not shared. Encrypted in transit. Deletable. |
| Purchase / billing | Handled by Paddle (Merchant of Record). We do not receive or store your full card number. Processed by Paddle under its policy. Encrypted in transit. |
| Photos, scans, PDFs, videos, voice notes | Created by you and stored end-to-end encrypted as ciphertext under your keys — for the app’s core capture/seal/verify function. We cannot read it. Not shared. Deletable. |
| Messages & calls | End-to-end encrypted; our servers are a blind relay. We cannot read/hear it. Not shared. Deletable. |
| Location | Optional — collected only while the OS location permission is granted; the capture screen asks for it once and capture works if you decline. When granted, the location is written inside the sealed (encrypted) capture as its “where” — it is never sent to our servers as a separate field. Optional. Stays inside your encrypted capture. Deleted with the capture. |
| Device & app-registration info | Signed-in devices register a device identifier and signing/attestation certificates (they anchor the capture seals), and report basic device state: model, OS + patch level, battery, free storage, root/lock status. On organisation-enrolled devices this additionally includes a visible-app inventory and compliance state, shared with your organisation’s administrator. Collected. Not shared outside your organisation. Deleted with the account. |
| Purchase history | When you subscribe, we keep the subscription state Paddle reports (customer id, e-mail, plan/status/period) to grant your plan — never your card number or payment method. Collected. Paddle is the Merchant of Record. Statutory billing records are retained by Paddle. |
| Connections & handles | If you connect with another user, both accounts store the mutual connection (@handles) so you can find each other. File/job names, sizes and hashes are visible to the server as metadata (the content itself stays ciphertext). Collected. Not shared. Deleted with the account. |
| Support messages | The e-mail address and message you send us, plus the app version and device model shown to you in the form — to answer your request. Collected. Not shared. Deletable. |
| Security / operational logs | Minimal, rotated logs needed to run the service and prevent abuse. Not used for tracking. Rotated ~90 days. |