Privacy Policy — Cove: Secret Photo Vault
Last updated: June 19, 2026
The short version. Cove keeps your photos, videos, and files encrypted on your device. We have no servers that store your content, we never see your secret code, and your private items never leave your iPhone or iPad unless you turn on iCloud Backup. We do not sell, rent, or share your personal data with anyone.
This Privacy Policy explains how Cove ("the app", "we", "us") handles information when you use it. By using Cove you agree to the practices described here. If you do not agree, please do not use the app.
Cove is a private vault disguised as a working calculator. Everything you store — photos, videos, documents, audio, and other files — is encrypted directly on your device using strong AES-GCM encryption (Apple CryptoKit). The encryption key is generated on your device and stored in the iOS Keychain; it never leaves the device and is never transmitted to us.
Your secret code (and any recovery or decoy code) is never stored as text. Only a salted cryptographic hash is kept, so even we cannot recover or reverse it. We have no ability to read, decrypt, or access the contents of your vault.
We do not require an account, registration, login, name, or email to use the app.
We do not have a server that receives, stores, or backs up your vault contents.
We do not collect or transmit your photos, videos, files, secret code, recovery code, or decoy vault.
We do not sell, rent, or trade any personal information.
We do not use advertising networks or ad tracking, and we do not track you across other apps or websites.
The following is created and used locally on your device and is never uploaded to us:
Vaulted content — the photos, videos, and files you add, plus their thumbnails and albums (encrypted at rest).
Codes — your secret code, optional recovery code, and optional decoy/duress code (stored only as salted hashes).
Break-in photos — if you enable the break-in feature, the front camera may capture a photo of someone who enters a wrong code. These images are stored encrypted on your device only and are never uploaded.
Decoy vault — any separate "decoy" vault you create stays entirely on your device.
App settings — your preferences (auto-lock, app-icon disguise, privacy toggles, etc.) are saved locally.
Cove only asks for permissions when needed for a feature you use, and explains why at the moment it asks:
Photos — to let you import photos and videos into your vault, and (only if you turn the option on) to remove the original from your camera roll after it is safely secured. iOS shows its own confirmation before any deletion.
Camera — only if you enable the break-in (intruder) feature, to capture a photo when a wrong code is entered.
Face ID / Touch ID (biometrics) — optional second-factor unlock. Biometric data is handled entirely by Apple's Secure Enclave; Cove never sees or stores your biometric data.
You can change or revoke any of these permissions at any time in the iOS Settings app.
If — and only if — you choose to turn on iCloud Backup, Cove can back up your vault to your own private iCloud account using Apple's CloudKit, inside a private container associated with the app. This backup is stored in your Apple iCloud, not on any server we control.
Before anything is uploaded, the data is re-encrypted with a backup key derived from your code. Because that key is derived from a code only you know, the backup cannot be read by us or by Apple. If you lose your code and your recovery code, the backup cannot be recovered by anyone, including us. Apple's handling of iCloud data is governed by Apple's Privacy Policy. You can turn the backup off, and delete the backup from iCloud, at any time within the app.
Cove offers optional paid subscriptions and a one-time purchase to unlock Pro features. Payments are processed by Apple through the App Store; we never receive or store your payment card details.
To manage subscriptions, restore purchases, and validate entitlements, we use RevenueCat, a subscription-management service. RevenueCat processes a randomly generated, anonymous app-user identifier together with purchase and subscription events (for example, which product was purchased, trial status, and renewal/expiration dates), and limited technical data such as device type, app version, and country. This data is used only to deliver and manage your purchases and is not linked to your vault contents or your identity. See RevenueCat's Privacy Policy for details.
Cove relies on a small number of third parties strictly to provide app functionality:
Apple — App Store distribution, in-app purchases, and (optionally) iCloud storage.
RevenueCat — subscription and purchase management, as described above.
We do not integrate advertising SDKs, social-media trackers, or third-party analytics that profile you.
All vault content is encrypted at rest with AES-GCM.
Encryption keys are stored in the iOS Keychain and are excluded from unencrypted device backups.
Codes are stored only as salted hashes, never as plain text.
Optional protections include automatic locking, screenshot/screen-recording blocking, hiding the app in the multitasking switcher, Face ID / Touch ID as a second factor, a break-in capture log, and a decoy vault.
No method of electronic storage is 100% secure, but Cove is designed so that your most sensitive data stays under your control on your own device.
Because your content lives on your device, you control retention. You can delete individual items, empty the Recently Deleted folder, or delete the app entirely. Deleting the app removes the app's local data and encryption keys from the device. If you enabled iCloud Backup, you should also delete the backup from within the app (or from your iCloud storage) to remove the cloud copy, since data stored in your iCloud account is not automatically deleted when an app is removed. The anonymous purchase records held by Apple and RevenueCat are retained according to their own policies.
Cove is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us.
Depending on where you live (for example under the EU/UK GDPR or the California CCPA/CPRA), you may have rights to access, correct, delete, or restrict the processing of your personal data, and to object to certain processing. Because Cove stores your vault content only on your device and does not collect identifying personal data on our servers, you can exercise most of these rights directly by managing or deleting your data in the app. For the limited purchase data processed by Apple and RevenueCat, you may exercise your rights through those providers, or contact us and we will help facilitate the request. We do not sell or "share" personal information as those terms are defined under applicable law.
Your vault data is processed locally on your device. Where third-party providers (Apple, RevenueCat) process limited purchase data, that data may be processed in countries other than your own, with appropriate safeguards as described in their respective privacy policies.
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, provide additional notice. Continued use of the app after changes take effect constitutes acceptance of the updated policy.
If you have any questions about this Privacy Policy or your data, please contact:
Md. Nasar Uddin Redoy Email: developer.nasar416@gmail.com Support: https://sites.google.com/view/eteamhelp
© 2026 Md. Nasar Uddin Redoy. Cove: Secret Photo Vault. All rights reserved.