Last updated: 2026-09-14 · Version 1.1
Secrets Daemon collects no data. None. It has no networking code, no accounts, no analytics, no advertising SDKs, no crash-reporting service and no third-party SDK of any kind. What you scan, type, verify, store or export stays on your device unless you send it somewhere yourself.
You can check the claim without taking our word for it: iOS Settings › Privacy & Security › App Privacy Report lists every domain an app has contacted, and Secrets Daemon never appears there with one. Our App Store privacy label says "Data Not Collected", and the app ships a privacy manifest that declares no collected data types and no tracking.
Luis Masmela Blanco, developer of Secrets Daemon (the "Developer", "we", "us"). For the purposes of the GDPR and the UK GDPR we are the controller of the (nearly non-existent) personal data described below. Our current contact address is published at https://secretsdaemon.pages.dev/support, which is the single place we keep it current.
This policy covers the Secrets Daemon app for iPhone, iPad, Mac and Apple Watch, its share extension, and the separately distributed Secrets Daemon Companion for macOS.
| Data | Where it is processed | Why | Leaves the device? |
|---|---|---|---|
| Camera frames, photos, screenshots, shared images | On device only, by Apple's Vision text recognition | To read the key you point the app at | Never. Images are never stored, not even temporarily. |
| Text you paste or type | On device only | To classify it and build a file | Never, unless you export, share or copy it. |
| Recognised keys ("secrets") | In memory; and in the device Keychain only if you turn the Vault on | To let you check, name, organise and export them | Never by themselves. Only through an action you take: Save to Files, AirDrop or Share, Copy, Send to Mac, Send to Watch. |
| Vault metadata (names you give keys, collections, tags, pin state) | Device Keychain | To organise the Vault | Never. |
| Settings (clipboard timeout, appearance, Vault on or off, expiry policy, lockdown, the free-key counter) | App Group user defaults on the device | To remember your preferences | Never. |
| Face ID or Touch ID | Handled by iOS; the app receives only success or failure | To gate the Vault | The app never sees biometric data. |
| The paired-Mac and paired-Watch identities | Device Keychain, this device only | To seal a hand-off to hardware you own | The public half travels with the file you send; the private half never leaves. |
The Keychain items the Vault writes are marked this device only and non-synchronisable: they are excluded from iCloud Keychain and from a cross-device restore of an encrypted backup. Each stored secret also carries an access-control flag that makes the Keychain itself require Face ID, Touch ID or your passcode before the value can be read.
The clipboard copy is time-limited. The default is 60 seconds (you can choose 30, 60, 120 or 300), and the copy is marked local to this device unless you opt in to Universal Clipboard.
The Mac app and the separately distributed Secrets Daemon Companion (a command-line engine and its menu-bar panel) run locally on your Mac. They store the keys you choose in the macOS Keychain, keep a local audit log at a path you control, and expose keys to software agents only under a policy file you write. They contain no networking code either. If you run third-party agents against them, for example AI coding assistants, those agents' privacy practices are theirs, not ours, and what an agent does with a key you make available to it is outside our control.
We do not process personal data about you, so in ordinary use no legal basis is engaged. If you contact us, we process the contents of your message and your return address on the basis of our legitimate interest in answering you (GDPR Article 6(1)(f)), and we keep it only as long as needed to deal with your question and any follow-up.
We retain nothing, because we receive nothing. Everything the app holds is on your device and is kept for as long as you keep it: a Vault item lives until you delete it, until the expiry you chose passes, or until you delete the app. Correspondence you send us is kept only for as long as it takes to answer it and to keep a record of any dispute.
Because we hold no personal data about you, there is nothing for us to give you access to, correct, port, restrict or delete. Everything the app holds is on your device: delete a key in the Vault, wipe the Vault in Settings, or delete the app to remove all of it.
If you believe we hold personal data about you, for example because you emailed us, you may ask us for access, correction, deletion, restriction, portability, or to object to processing, and we will respond within the period the law requires. We do not discriminate against anyone who exercises a right.
To exercise a right, write to the contact address on our Support page.
The app is not directed to children, and we do not knowingly collect information from anyone, including children. It is rated for general audiences on content grounds, but the Terms of Use require an adult to accept them (Terms, Section 4.3). We do not knowingly process the data of a child under 13, or under the age of digital consent where you live, because we do not process anyone's data.
On-device processing; Keychain storage with device-only accessibility and a biometric access-control flag on every stored secret; a biometric gate on the Vault; a privacy shield that covers secret text in the app switcher; a clipboard that clears itself; export temp files written with complete file protection and deleted when the hand-off finishes or is cancelled, and swept on the next launch; a sealed, authenticated hand-off to a Mac you have paired, which refuses an unpinned sender and a replayed file. There is no networking code to attack. No design can protect a key you export to the wrong place, so please check the destination.
None. Nothing is transferred, because nothing is collected.
We will update the "Last updated" date and the version above. The current text is always in the app under Settings › About › Privacy Policy and at https://secretsdaemon.pages.dev/privacy. Where a change is material we will give notice in the app. Prior versions are available on request.
Luis Masmela Blanco, developer of Secrets Daemon.