Privacy Policy
Effective Date: September 15, 2026
Applies to LockLens for iOS and LockLens for Android.
Who we are
LockLens is published by Freeville Holdings LLC, doing business as Richfield Labs. “We,” “our,” and “us” below refer to that company.
The short version
LockLens collects nothing. There is no account, no analytics, no advertising, no crash reporting, and no third-party SDKs. Your photos, videos, PIN, and settings never leave your device. We have no servers, so there is nowhere for your data to go and nothing for us to hand over.
What LockLens stores, and where
Everything LockLens keeps is stored only in the app's private storage on your device:
- Photos and videos: Encrypted with AES-256-GCM, using a unique initialization vector per file.
- Thumbnails: Encrypted with the same key.
- The database (filenames, dimensions, dates, album names): Encrypted with SQLCipher.
- Your PIN: Stored in the device keychain or keystore as a PBKDF2-SHA256 hash (200,000 iterations), never in plain text.
- Encryption keys: Held in device secure hardware — the Secure Enclave and Keychain on iOS, the Keystore on Android — and bound to that one device. The vault's key leaves it only inside a Pro backup you create, encrypted under your backup password.
- Break-in photos (Pro): Encrypted, and viewable only inside the app.
- Your settings: Contain no personal information.
Vault files are excluded from iCloud and from encrypted device backups on iOS, and Android's automatic cloud backup is disabled for LockLens. Your encrypted photos do not appear in a cloud backup, and encryption keys are never synced.
One consequence worth understanding: because keys never leave your device on their own, setting up a new phone or restoring a device backup will not bring your vault with it.
Moving a vault: the Pro encrypted backup. Starting with LockLens 1.0 for iPhone and 1.12 for Android, LockLens Pro can export your vault as an encrypted ZIP file, saved wherever you choose, and protected by a password you set. Your photos stay encrypted inside it. The only key in the file is the vault's own key, itself encrypted under your password (PBKDF2-SHA256 with 600,000 iterations, then AES-256-GCM). Anyone with the file and the password can restore it on a phone running LockLens, iPhone or Android. We never receive the file or the password and cannot recover either: if you forget the password, the backup cannot be opened. Backups made by earlier versions, before backups had a password, restore only into the vault that made them.
Metadata stripping
LockLens removes EXIF metadata — including GPS coordinates, device model, and timestamp — from every photo before it is encrypted and written to the vault. This applies to photos captured in the app and to photos imported from your library. There is no intermediate step where an unstripped copy is retained.
What LockLens sends over the network
Nothing. The apps contain no networking code. On Android, LockLens does not request the INTERNET permission, so the operating system blocks network access outright. On iOS there is no equivalent per-app permission, but the shipped binary links no networking framework at all.
The single exception is the platform's in-app purchase system — Apple's StoreKit and Google Play Billing — used only if you choose to buy or restore LockLens Pro. That exchange is handled entirely by Apple or Google, is between you and them, and carries none of your vault contents. We never see your payment details. We receive only a signed confirmation from the platform that a purchase exists.
Device permissions and why they're asked for
LockLens asks only for what a given feature needs, at the moment it needs it. Declining any of these leaves the rest of the app working.
- Camera — To take photos and videos directly into the vault, and, on Pro, to take a break-in photo after repeated failed unlock attempts.
- Photos / media — To import items you select into the vault. On iOS this uses the system picker, so LockLens only ever receives the specific items you choose.
- Photos, add-only (iOS) — Used solely when you export an item from the vault back to your library. It does not grant LockLens read access to your existing photos.
- Face ID / Touch ID / biometrics — To unlock the vault. Biometric data is handled entirely by your device's operating system; LockLens never sees or stores it.
- Notifications — To tell you when a break-in photo has been captured.
LockLens does not request location, contacts, microphone, or health data.
Decoy PIN (Pro)
The decoy PIN feature opens a separate, empty vault when a secondary PIN is entered, so you can hand over a PIN under pressure without exposing your real vault. The decoy PIN has no cryptographic path to your real photos — it cannot decrypt them even in principle.
Break-in photos (Pro)
If you enable Pro, repeated failed unlock attempts cause LockLens to take a photo with the front-facing camera, encrypt it, and store it in your intrusion log alongside a timestamp and a hashed copy of the PIN that was attempted. The raw attempted PIN is never stored.
These photos never leave your device and are visible only to you inside the app. You can delete individual entries or clear the whole log at any time.
On iOS, this capture is not silent. iOS shows its camera indicator whenever the camera is in use, including for a break-in photo. We cannot suppress that, and would not want to — it exists so that no app can photograph someone without a signal.
Screen security
On Android, LockLens sets FLAG_SECURE, which prevents screenshots and hides the app's content from the recent apps overview.
iOS provides no equivalent, and LockLens for iOS cannot block screenshots. It does cover its own contents in the app switcher, so vault thumbnails are not captured in the system's task-switcher snapshot, and the vault re-locks according to your auto-lock setting.
What LockLens does not protect against
LockLens encrypts your vault so that someone who takes your phone, or who images its storage, cannot read your photos. Encryption keys are bound to the device's secure hardware and cannot be extracted from it, so a copied vault cannot be attacked on another machine.
It is not designed to defend a device that has already been compromised. Software running with system-level privileges on your unlocked phone — a jailbreak, a root exploit, or malware with that level of access — can reach data the app itself is able to read. This is a limit shared by every app that has to display your data to you, and we would rather state it than imply otherwise.
Children
LockLens is not directed at children and collects no information from anyone, including children.
Your rights and choices
Because we hold no data about you, there is nothing for us to disclose, correct, export, or delete on your behalf, and no account to close.
- Delete individual items — From inside the vault, at any time.
- Delete everything — Uninstall the app. All encrypted files, the database, and every stored key are removed with it. Nothing is left behind, and nothing is retained by us. We cannot recover your vault if it is lost.
Changes to this policy
If this policy changes, the date at the top will change with it. Because LockLens has no way to contact you, material changes will also be described in the app's release notes.
Contact Us
Questions about this Privacy Policy, or a security vulnerability to report: [email protected].