Privacy Policy

Last updated: 20 September 2026

Applies to: ZapLock for macOS, iPhone, iPad and Android, and this website. ZapLock signs you in with a ZapQR account; the ZapQR password manager and browser extension have their own policy at zapqr.ai/privacy.

1. How ZapLock is built

ZapLock encrypts a folder you choose, in place, and unlocks it after you sign in with ZapQR. It does use an account, because the key that opens a folder is split between your device and our server.

Files are encrypted with AES-256-GCM on your device. The key is split: one half stays in your device's secure hardware, and the other half is released by ZapQR only while your sign-in and your access are both valid. We hold one half and cannot decrypt anything with it.

2. What we collect

  • Your email address and account identifier — to sign you in, to hold your account, and so a folder can be shared with you by address. Required.
  • A device identifier and public key for each device you enrol — generated by the app, not read from your phone or computer. It binds your key shares to the devices you approved. Required.
  • The identifier and label of each protected folder, and the encrypted key share for it — so the right half-key is released to the right device.
  • A security event log — sign-ins, device enrolments, folders shared and access revoked.
# stored on our servers
email address
account identifier
device id + public key, per device
vault id + label, per folder
encrypted key share, per vault
security event log

# never stored
your files
your file names
a whole key

3. What we never collect

Your files. ZapLock encrypts and decrypts on your device: file contents and file names never leave it, and neither does a whole key. We hold one half of a split key and cannot open a folder with it. Your folders stay on your own disks and in your own cloud storage.

ZapLock contains no advertising SDKs, no analytics SDKs, and no third-party trackers. We do not sell or share your information, and we do not use it for advertising or profiling.

4. How we use it

Everything listed in section 2 is used only to make the app work and to manage your account: signing you in, releasing the correct key share to a device you enrolled, letting you share a folder with another ZapQR account and take that access back, and investigating security or abuse.

Everything is encrypted in transit with TLS.

5. Third parties and hosting

  • Apple App Store and Google Play — app distribution. They provide us with aggregate install and crash information under their own policies.
  • Cloudflare — hosting for this website and for the ZapLock account service.

These services have their own privacy policies and none of them has access to your files or to a whole key.

6. Security

  • AES-256-GCM for file contents, encrypted and decrypted on your device.
  • A split key: the device half is held in your device's secure hardware (Secure Enclave on Apple platforms, the hardware-backed Keystore on Android).
  • TLS for everything in transit.
  • Key shares are wrapped to a specific device's public key, so enrolling a new device never hands it existing key material by itself.

No system is perfect, and we do not claim ZapLock is. If you believe you have found a vulnerability, write to security@dasecure.com.

7. Your rights and choices

Depending on where you live, you may have the right to access, correct, export or delete the personal information we hold about you, and to object to or restrict certain processing. To exercise any of these, write to privacy@dasecure.com from the address on your account.

You can remove a device, revoke a share, or delete your account at any time from inside the app.

8. Deleting your data

Deleting your ZapQR account removes everything listed in section 2 except the security event log, which we keep for security and fraud prevention. You can start deletion from inside the app under Danger Zone, or at zapqr.ai/delete-account.

Unlock anything you still want to read before you delete. Once the account is gone, the server half of the key is gone with it, and a locked folder cannot be opened again by anyone — including us.

9. Children

ZapLock is not intended for children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us information, write to us and we will delete it.

10. Changes

We may update this policy from time to time. If we make a material change — for example if ZapLock begins to use a new category of data — we will update the date at the top and notify users through the app or this website before the change takes effect.

11. Contact

Questions about this policy: privacy@dasecure.com

DaSecure Solutions LLC
United States