01 Overview
Docuary: Document Vault ("the App") keeps passports, licences, insurance papers, certificates and other important documents in an encrypted vault on your phone. There is no Docuary account, no Docuary server, and no tracking of any kind. Your documents are encrypted with a key derived from your passphrase, and that key never leaves your device.
In short: the App collects nothing. It creates no account, reads no email address, shows no advertisements, uses no analytics or crash-reporting libraries, and touches no advertising identifier. By default it makes no network requests at all — with one narrow, entirely optional exception described in Section 04, which activates only if you personally choose to turn it on.
The developer cannot read your documents. Not as a promise of good conduct, but because they are never received, and are not decryptable without a passphrase only you hold.
02 What Docuary Stores
Everything the App holds is stored on your own device, inside private app storage that other applications cannot read. This includes:
- Document images you capture with the camera or import from your device
- Titles, categories, notes, and issue or expiry dates you enter
- Text extracted from your documents by on-device text recognition
- The search index built from that text
- App preferences such as theme and auto-lock timeout
All of it is encrypted with AES-256-GCM authenticated encryption. The encryption key is derived from your passphrase using Argon2id, or unwrapped by your device's hardware-backed keystore when you unlock with a PIN or biometrics. The key exists in memory only while the vault is unlocked, and is wiped when it locks.
The App stores no data on developer-owned servers, because there are none.
03 What Leaves Your Device
By default, nothing. Two features can send data off the device, and both require you to act:
- Google Drive backup — off by default, described in Section 04
- Sharing a document — you choose the recipient and the app, every time, described in Section 05
If you never enable backup and never share a document, no data ever leaves your phone.
04 Google Drive Backup
The App optionally backs your vault up so it can be restored on a new phone. This feature is off by default and activates only when you turn it on yourself.
The App uses the Google Drive drive.appdata scope only. This means:
- Your backup is stored in a hidden folder that belongs to Docuary alone, inside your own Google Drive account
- The App cannot see, list, open or modify any other file in your Google Drive — not one photo, video or document
- Documents are encrypted on your device before upload. Google stores ciphertext
- Filenames in that folder are random identifiers such as doc.9f3a…, never your document titles. The folder reveals a count of objects and nothing more
- Your encryption key is stored there only in a form wrapped by your recovery passphrase, so that you can restore on a new device. Without that passphrase the backup is unusable — including to the developer
- The developer operates no server in this process and cannot read the contents of your backup
The App does not request Google Sign-In. It asks for authorization to reach that one folder and nothing else, which means it never receives your name, email address or profile picture.
You may disconnect Drive at any time inside the App, and remove the App's access entirely from your Google Account permissions page. Data held in your Drive is subject to Google's Privacy Policy.
Docuary's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
06 On-Device Text Recognition
Text recognition runs entirely on your device, using a model bundled inside the App. Your documents are never uploaded for processing, and the feature works with no network connection at all.
Passports and identity cards are recognised on-device in the same way, including the machine-readable strip. No image and no extracted text is sent anywhere.
07 Permissions Used
- Camera — to photograph documents, which go straight into the encrypted vault. The App has no video or audio capability
- Notifications — to warn you before a document expires. Reminders never name the document; they say something needs attention, and you open the App to see what
- Biometrics and device credential — to unlock the vault. The App never receives your fingerprint or face data; Android performs the match in secure hardware and reports only success or failure
- Internet and network state — used only by the optional Google Drive backup, and only after you connect it
Docuary does not request broad storage access, microphone, contacts, SMS, call log or location permissions. Importing a file uses Android's system file picker, which grants access to the single file you choose and nothing else.
08 User Control & Deletion
Privacy laws including the GDPR and CCPA give you rights to access, correct, export and delete personal data held by a company. The developer holds none of yours, so there is nothing to disclose, correct or delete on your behalf. You already hold direct control over everything the App stores:
- Use the entire App without ever connecting Google Drive
- Export or share any document at any time
- Delete any individual document from within the App
- Destroy the entire vault from Settings, which erases the encrypted database, every document file and the keyring
- Disconnect Drive within the App, and revoke access from your Google Account permissions page
- Uninstall the App to remove all local data
Destroying the vault deliberately does not delete your Drive backup. Removing the App from one device is not a request to destroy your backup, and treating it as one would make that button far more destructive than it says. The backup is deleted separately, from within the App or from your Google account.
09 Data Retention & System Backup
Local data remains on your device until you delete it or uninstall the App. Backup data remains in your own Google Drive account until you choose to delete it. The developer retains no copies and has no access.
Some Android phones perform their own system-level backup that can sweep up an app's stored data. Docuary switches this off for itself, so that Android's cloud backup cannot copy vault files off the device outside the App's own encryption. Device-to-device transfer is blocked for the same reason.
10 Advertising & Analytics
This application displays no advertisements and contains no advertising SDK. It uses no analytics library and no crash-reporting library, and it does not read the advertising identifier. No user data is used for advertising purposes, because no user data is collected.
11 Security
- AES-256-GCM authenticated encryption for every document, every page and the search index
- Argon2id passphrase strengthening, tuned to current OWASP guidance
- Keys wrapped in the Android Keystore, in StrongBox hardware where the device provides it
- Automatic locking after inactivity, and rate limiting with escalating delays after failed attempts
- Document screens are marked secure, so they are excluded from screenshots and the recent-apps preview
No system is perfect, and no claim is made here that Docuary is unbreakable. What can be stated precisely is what a compromise would require: your device and your passphrase.
If you forget your passphrase, your documents cannot be recovered. There is no reset, no recovery email and no back door. This follows directly from the design, and it is the same property that stops anyone else reading your vault.
12 Children's Privacy
This application is not directed toward children under the age of 13. We do not knowingly collect personal information from children, or from anyone else. The App requires no personal information to function.
13 Changes to This Policy
This Privacy Policy may be updated occasionally to reflect changes in the App or applicable regulations. Users will be informed of significant changes via app update release notes. The effective date at the top of this page will always reflect the most recent revision.
14 Contact
For questions regarding this Privacy Policy, or to report a security issue, please contact:
For security issues specifically, please write before disclosing publicly, so that a fix can ship first.