This policy applies to the CipherNest Android app, the share viewer at share.ciphernest.io, and this website.
The short version
CipherNest has no accounts and no servers that store your files. Your files are encrypted on your device and uploaded to the Google Drive or OneDrive account you already own. I cannot read them, and neither can anyone at Google or Microsoft. The app sends me nothing about you. The only data that leaves your device for anyone other than your own cloud provider is a purchase record, if you buy a subscription, and the encrypted bytes of a file you deliberately share by link.
Who I am
CipherNest is built and operated by Usman Shafi, an individual developer in Lahore, Pakistan. Contact: privacy@ciphernest.io.
What the app collects
Nothing. There is no CipherNest account, no email address, no analytics, no advertising identifier, no crash reporting. The app does not contact any server operated by me during normal use.
Where your files go
When you add a file, the app encrypts it on your device with a key derived from your recovery phrase and uploads the encrypted result to a folder in your own Google Drive or OneDrive. File contents, filenames and file types are encrypted before upload; your folder and album structure is kept in the vault’s encrypted index rather than in the cloud’s own folder tree. Your cloud provider can see that encrypted files exist, their sizes, and when they were uploaded. It cannot see what they are. Google’s and Microsoft’s own privacy policies govern what they do with the data they hold.
What the app asks your cloud provider for
The app requests Google’s drive.file scope, which limits it to files it created itself, and the equivalent OneDrive permission. It cannot see the rest of your Drive. The sign-in tokens are stored on your device only.
Your recovery phrase
The twelve words are generated on your device and never transmitted anywhere. I do not have them and cannot recover them for you. If you lose them, your files cannot be decrypted by anyone, including me.
Biometric unlock
If you turn on fingerprint or face unlock, Android performs the check and releases a key held in the device’s secure hardware. The app never receives your fingerprint or face data, and nothing biometric leaves the device.
Purchases
Subscriptions and the one-time Founder’s Edition are sold through Google Play, which processes the payment and holds your billing details under Google’s privacy policy. To check whether a purchase is active, the app sends a purchase token and a pseudonymous identifier derived from your vault key to RevenueCat, a subscription management service that acts as my processor. RevenueCat never receives your files, your name, your email or your recovery phrase. This is the only data about you that reaches a service I control, and it exists only if you buy something. RevenueCat’s privacy policy is at revenuecat.com/privacy.
Google Play also collects crash and performance statistics from installed apps on its own terms, as it does for every app, and shows me aggregates in the developer console. I cannot see who they came from.
Share links
When you share a file by link, the file stays encrypted in your cloud. The decryption key is placed in the part of the link after the #, which browsers never send to any server. The viewer at share.ciphernest.io fetches the encrypted bytes through a small proxy I run on Cloudflare so that your browser can decrypt them. That proxy sees the encrypted bytes and the ordinary metadata of an HTTP request, such as the IP address and browser of the person opening the link. Cloudflare’s request logs for this proxy are retained for at most seven days and are used only to diagnose faults. The proxy never receives a decryption key and cannot read the file.
This website
It sets no cookies. It stores your light or dark theme choice in your browser’s local storage, which never leaves your browser. The contact form sends your message to a small program I run on Cloudflare, which checks that a person rather than a script sent it (Cloudflare Turnstile, which sets no cookies and shows no puzzle to most people) and passes it to my support inbox through Resend, an email delivery service. Nothing you type is stored anywhere along the way; the message exists only in my inbox and your address is used only to reply. If that path fails, or if you prefer, the form opens your own mail app instead. The site is served by Cloudflare, which processes request metadata as described in Cloudflare’s privacy policy. Cloudflare Web Analytics runs on this site: a small script from Cloudflare counts page views and measures load times in aggregate. It sets no cookies, stores nothing in your browser, does not fingerprint you, and reports no identifier that could tie a visit to you; I see totals, not visitors. Any further server-side feature will be added to this section before it goes live.
Your rights
Wherever you live, you can ask me what I hold about you, ask for it to be corrected or deleted, and ask for a copy. In practice there is almost nothing to return, because the app collects nothing; what exists is the purchase record described above and, for a few days, the proxy’s request logs. Write to privacy@ciphernest.io and I will answer within 30 days.
If you are in the European Union, the United Kingdom or another place with a data protection law: the legal basis for processing purchase records is the performance of our contract, and for the proxy’s short-lived logs it is my legitimate interest in keeping the service working. RevenueCat and Cloudflare process that data in the United States under their standard contractual clauses. You also have the right to complain to your local data protection authority.
Deleting your data
Your files are in your own cloud account; delete them there, or from the app, and they are gone. Uninstalling the app removes everything it stored on the device. Purchase records held by Google Play are governed by Google. Write to privacy@ciphernest.io to have the RevenueCat record associated with your purchase deleted, and include the order number from Google Play so I can find it without any other identifier.
Children
CipherNest is not directed at children under 18, and I do not knowingly collect anything from anyone, of any age.
Changes
Changes to this policy are dated at the top of this page and noted in the app’s release notes when they are material.
Contact
privacy@ciphernest.io. For security reports, security@ciphernest.io.