RotarySafe
Privacy Policy
v1.1 · July 2026
RotarySafe does not collect, transmit, or share any personal data. All information the app uses remains on your device. This policy explains exactly what the app stores locally and why.
RotarySafe is developed and maintained by a single independent developer. Questions about this policy can be directed to:
Email: wearabledesign@gmail.com
App: RotarySafe — TOTP vault for Android and Wear OS
We collect no personal data. RotarySafe does not transmit any information to any server, analytics platform, or third-party service.
The following table describes everything the app stores on your device:
What
Purpose
Where
TOTP account secrets and labels
Generate one-time codes without any server call
Encrypted on-device storage
Combination hash (not the combination)
Verify the rotary combination at unlock time
Encrypted on-device storage
Pairing keys (phone ↔ watch)
Encrypt Bluetooth communication between your own devices
Encrypted on-device storage (both devices)
Encrypted backup file
Allow you to restore your vault if you change devices
A location you choose — we never receive it
RotarySafe does not collect, process, or have access to any of the following:
Your name, email address, or any account identifier
Location data
Device identifiers, advertising IDs, or analytics
Crash reports or diagnostic logs transmitted off-device
Usage statistics or behavioural data
Biometric data (fingerprint/face unlock is handled entirely by Android — we never receive the result)
RotarySafe does not have internet permission and makes no network requests to any server.
The app uses Android's Wear OS Data Layer (Bluetooth) solely to communicate between your own phone and your own watch. This communication is encrypted end-to-end using AES-256-GCM with a session key that is derived on your devices and never leaves them. No data passes through any external server or intermediary.
5. Authentication
Viewing a TOTP code, exporting or importing a backup, and re-pairing to a new watch all require you to prove it's you — either by entering your rotary combination on the
paired watch, or, if the watch is unavailable, through your device's built-in biometric or screen-lock prompt. As noted in Section 3, RotarySafe never receives the result of that
check; Android handles it entirely and only reports pass or fail to the app.
RotarySafe offers an optional encrypted backup feature. The backup file is:
Encrypted locally on your device with a passphrase you provide
Saved to a destination you choose (local storage, cloud drive, etc.)
Never transmitted to or accessible by the developer
We have no ability to recover a backup file or its passphrase on your behalf.
RotarySafe does not integrate with any third-party SDK, analytics library, advertising network, or crash-reporting service.
RotarySafe is not directed at children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect any data from children.
Because we collect no personal data, there is nothing for us to access, correct, export, or delete on your behalf. All data the app stores exists on your device under your control. You can remove it at any time by uninstalling the app or clearing its data in Android settings.
Your rotary combination is set by you and known only to you. RotarySafe does not store the combination in recoverable form and has no mechanism to retrieve it if forgotten. You are solely responsible for retaining access to your combination and your backup passphrase.
The developer provides this application on an as-is basis and accepts no liability for loss of access to accounts stored in the vault resulting from a forgotten combination, lost backup, or device failure.
If this policy changes materially, the updated version will be published at the same location as this document. The effective date at the top of the document will be updated accordingly.
For any questions or concerns about this privacy policy, please contact:
Email: wearabledesign@gmail.com
Effective date: July 2026