1. Who this policy covers
FactLockCam is a private, local-first archive. Only you hold the keys that decrypt your sealed media. We do not track, profile, or sell your personal information. We cannot read your unencrypted files or recover lost keys. This policy describes the data that does leave your device, which processors receive it, why we keep it, and how you delete it.
Contact for privacy questions and deletion requests: [email protected].
2. What we collect and why
We collect the following for App Functionality. We do not use it for tracking or advertising.
- Email address (linked to your account). Used to send a one-time Magic Number and to identify your account. We do not use email for marketing.
- User ID (linked to your account). A Supabase authentication identifier created when you sign in. Ledger rows and quota records are stored under this identity.
- Photos and videos (not collected by FactLockCam). Capture happens on device.
Original media stays in the app sandbox as encrypted
.sealfiles. We do not upload photos or videos, and there is no cloud media sync. - Other user content (linked to your account). Titles and descriptions you add, signed capture manifests, fingerprints, and Polygon transaction identifiers associated with your account. Media bytes are not included.
- Purchases (linked to your account). If you buy a plan or Incident Pack, the store's purchase identifiers (Apple transaction identifiers, or Google Play order identifiers and purchase tokens) and the product purchased are stored to grant and renew your Archive plan. We never receive your payment-card number.
- Precise location (not collected by FactLockCam). If you grant location
permission, live GPS coordinates appear only on the camera viewfinder. They are not written
into the signed capture record, not uploaded to our servers, and not included in
.flcproofpackages or certificate PDFs.
3. Processors and public records
Email is not kept solely on your device. The following processors receive the minimum data needed to run the product:
- Supabase — authentication, profiles, quota/subscription status, proof-ledger metadata. Sealed media is not stored in Supabase Storage.
- Resend — delivery of the Magic Number email (your address and the one-time code).
- Cloudflare — hosting and delivery of this website, including
/openand/verify. Opening a proof package in the browser processes the file locally; the site does not upload the package. - Polygon / anchor relay — a hash of the signed capture manifest is broadcast through our relay to Polygon. The public transaction does not include your email, filename, or media bytes.
- Apple — if you purchase a plan or Incident Pack, App Store billing and receipt verification use Apple's purchase identifiers. We do not receive your payment-card number.
- Google — if you purchase on Android, Google Play Billing and purchase verification through the Google Play Developer API use Google's order identifiers and purchase tokens. We do not receive your payment-card number.
4. On-device encryption
Hashing, AES-GCM sealing, and capture-record signing run on your device before any upload. Keys
stay in the device Keychain (and Secure Enclave when the device reports that class). Those keys
are never transmitted to or stored on our servers. Capture records disclose the
device_key_class reported by the device; that label describes the signing key
class, not scene authenticity, and is not a hardware-attestation claim.
5. Public ledger
When notarization completes, only a mathematical hash (SHA-256 of the signed capture manifest) is published on Polygon. Your filenames, identity, and file contents are not written on the public ledger. The ledger is a timestamped integrity record of that hash, not a statement of physical truth.
6. Data protection and AI
FactLockCam does not share your data, files, or identity with third-party AI or machine-learning services. File hashing and sealing run on your device.
7. Backups you control
We do not store your encryption keys or backup passwords. We cannot reset those passwords or
decrypt your archive. Sealed media lives on your device as encrypted .seal files.
FactLockCam does not offer cloud media sync and does not keep a copy of your photos or videos.
You manage two backups and we hold neither: a .factlock file (Account & Settings → Backup & Restore → Export archive keys) containing your sovereign decryption keys, and optional per-item .flcproof sealed copies (Export sealed backup from any archive item). Neither is media from our servers. Keys are restored on the locked screen; sealed items are restored in Backup & Restore with the password you set. Losing keys without .factlock means permanent loss of access to encrypted assets still on the device; only .flcproof copies you already saved stay unlockable.
Lock Archive removes keys from the device but leaves local sealed files; import .factlock to unlock sealed files that remain on this device. App uninstall removes local keys and usually local sealed files; after reinstall, sign in, import .factlock, then restore items from any .flcproof copies you saved. Burn Account deletes your identity, ledger and quota records, local archive, and keys—a prior .factlock cannot restore a burned account. See our Terms of Service for the full scenario table.
8. Retention and deletion
Account, ledger, and quota records stay until you delete the account or we
must retain a subset to operate the service (for example, a public Polygon transaction cannot be
reversed). Burn Account (Account & Settings, double confirmation, typed
OBLITERATE) calls our perform_full_burn procedure and wipes the
server identity, ledger and quota rows, local archive, keys, and journal. Shared
.flcproof packages you already delivered are copies you control; we cannot revoke
them. Step-by-step deletion instructions are on
Delete Account. Email
[email protected] if you need
help locating the in-app deletion path.
9. Your choices
- Decline location permission. Capture and sealing still work; the viewfinder omits GPS.
- Stay offline after a seal. Polygon anchoring waits until the device is online; media stays local either way.
- Export or delete your archive from Account & Settings.
10. Children
FactLockCam is not directed at children under 13 and does not knowingly collect personal information from them.
11. Changes
If this policy changes, we will update the date on this page. Material changes that affect how we handle personal information will be reflected here before they apply to the App Store or Google Play builds.