Privacy Policy for StealthLock

Effective Date: July 20, 2026

Key Summary: StealthLock is an offline privacy protection application. All security data, encrypted vault files, intruder selfies, and PINs are stored 100% locally on your device. We do not collect, transmit, upload, sell, or share any personal data to external servers or third parties.

1. Introduction

This Privacy Policy governs your use of the mobile application StealthLock ("App"), developed by CluelessTech ("we", "us", or "our").

StealthLock is a security and privacy application designed to protect sensitive Android applications via PIN/biometric locks, securely encrypt local files and notes within a protected vault, offer a stealth calculator disguise, and capture intruder selfies when unauthorized unlock attempts occur.

We are deeply committed to protecting your privacy. This policy explains how information is handled within the App in strict compliance with Google Play User Data policies.

2. Information We Collect and Storage Practices

StealthLock operates under an offline-first, local-storage architectural principle. The App does not collect or transmit data to external servers.

A. Personal Information

We do not collect personal identifiers such as your real name, email address, phone number, physical address, or account credentials.

B. Security Credentials & Authentication Data

When you set up a PIN or Decoy PIN, it is hashed locally using PBKDF2 (Password-Based Key Derivation Function 2) with a 16-byte cryptographically secure random salt and 10,000 iterations. Your actual plain-text PIN is never stored or transmitted anywhere.

C. Vault Media & Documents

Files, images, videos, audio recordings, and notes imported into the StealthLock Vault are encrypted locally using AES-256-GCM (Authenticated Encryption) using keys stored in the Android hardware KeyStore system (via FlutterSecureStorage). Decrypted file data resides strictly on device memory during active viewing and is never backed up to cloud servers.

D. Intruder Selfie Camera Data

If the Intruder Alert feature is enabled, the App uses your device's front camera to capture a photograph when an incorrect PIN is entered. Captured photographs are stored strictly in your device's local application storage and can only be viewed by you inside the App. They are never uploaded or shared.

E. Device Application List

The App queries your device's installed package list solely to present an interactive list of applications for you to select which apps you wish to lock. This package list is processed entirely in memory and is never transmitted off your device.

F. Biometric Data

If you enable Biometric Unlock, authentication is performed via the official Android OS System Biometric API (AndroidX Biometric Library). StealthLock never accesses, reads, collects, or stores your biometric fingerprint or face templates.

3. How We Use Information

All information processed by StealthLock is used exclusively on your device to provide core functionality:

4. Data Sharing and Third-Party Services

We do not share, sell, rent, trade, or transfer any user data to third parties.

5. Data Storage, Security, and Retention

We prioritize state-of-the-art security measures to protect your sensitive data:

6. Android Permissions Explanation

To provide security features, StealthLock requests specific Android system permissions. Below is a complete list and justification for each required permission:

Permission Name Purpose / Usage Justification
SYSTEM_ALERT_WINDOW Required to display the secure unlock overlay screen on top of locked applications.
PACKAGE_USAGE_STATS Required to detect in real-time when a user launches a locked application.
QUERY_ALL_PACKAGES Required to list installed apps on your device so you can select which apps to protect.
FOREGROUND_SERVICE & FOREGROUND_SERVICE_SPECIAL_USE Required to maintain a persistent background service that monitors app launches continuously.
CAMERA & FOREGROUND_SERVICE_CAMERA Required to capture intruder selfies using the front camera when an incorrect PIN is entered.
USE_BIOMETRIC / USE_FINGERPRINT Required to allow unlocking locked apps using your device's native fingerprint/face hardware.
RECEIVE_BOOT_COMPLETED Required to automatically resume AppLock protection when your device reboots.
WAKE_LOCK Required to keep background monitoring operational during low-power device states.
POST_NOTIFICATIONS Required on Android 13+ to display the persistent protection status notification.
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS Required to prompt users to exclude AppLock from aggressive OS memory killers.
BIND_DEVICE_ADMIN Optional permission used exclusively for the Uninstall Shield feature to prevent unauthorized app removal.

7. User Rights and Data Control

Because your data is stored exclusively on your device, you have complete and direct control over your information:

8. Children's Privacy

StealthLock does not address or target anyone under the age of 13. We do not knowingly collect personal information from children. If you are a parent or guardian and become aware that your child has provided personal information, please contact us; however, as StealthLock does not transmit data externally, no children's data is stored or transmitted by our servers.

9. Third-Party Services and Libraries

StealthLock relies on trusted, standard open-source libraries that execute locally within your application binary:

None of these libraries transmit telemetry or user data outside the app sandbox.

10. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. Any changes will be reflected by updating the "Effective Date" at the top of this Privacy Policy. You are advised to review this policy periodically for any updates. Changes are effective immediately upon being posted.

11. Contact Information

If you have any questions, concerns, or inquiries regarding this Privacy Policy or the security practices of StealthLock, please contact us at:

Developer / Company Name: CluelessTech
Support Contact Email: cluelesstech05@gmail.com
Package Name: com.cluelesstech05.stealthlock