Thank you for using QuietBox. This Privacy Policy ("Policy") explains how AppskKuber ("AppskKuber", "we", "our", or "us"), an India-based developer, handles information when you use the QuietBox mobile application available on the Google Play Store (package com.appskuber.quietbox) and this legal website at https://quietbox.appskuber.com (collectively, the "Service").
QuietBox is a private vault for photos and videos. It was designed around one idea: your private photos should stay on your phone, encrypted, and in your hands alone. The App therefore has no internet access at all. It cannot upload anything, and we never receive your photos, your videos, your PIN, your Recovery Code, or anything else from inside your vault.
This Policy is written to be readable. Where legal terms are necessary we have used them; where plain English serves better, we have used that.
If you do not agree with this Policy, please do not use the Service. Continued use of the Service after the Effective Date stated above constitutes acceptance of this Policy.
1. Definitions
- App
- The QuietBox Android application, package identifier
com.appskuber.quietbox. - Vault
- The encrypted collection of photos, videos, albums and related records that you create in the App.
- Main Vault / Decoy Vault
- Your Main Vault opens with your PIN. A Decoy Vault is an optional second, separate vault that opens with a different PIN.
- Vault Folder
- The folder on your phone’s shared storage that you choose during setup (for example
Documents/Backup). The encrypted Vault is stored inside it. - PIN
- The six-digit number you choose to open the Vault.
- Recovery Code
- The sixteen-character code shown to you once during setup. With it, and only with it, you can open your Vault after reinstalling the App, on a new phone, or if you forget your PIN.
- Backup File
- An encrypted copy of your Main Vault that the App writes when you ask it to, to a place you choose.
- Personal Data
- Any information relating to an identified or identifiable natural person, as defined under the DPDP Act, the GDPR, and equivalent laws.
- Service
- The App and this legal website, taken together.
2. Scope & Applicable Law
This Policy applies to all users of the Service, worldwide. Depending on where you live, one or more of the following frameworks gives you rights we honour:
- India — the Digital Personal Data Protection Act, 2023 ("DPDP Act"). For the limited data we receive (Sections 12 and 13), AppskKuber acts as a Data Fiduciary and you are a Data Principal.
- European Economic Area — Regulation (EU) 2016/679 ("GDPR"). For the same limited data, AppskKuber acts as the data controller.
- United Kingdom — the UK GDPR and the Data Protection Act 2018.
- California, USA — the California Consumer Privacy Act as amended by the CPRA ("CCPA").
- United States, children — the Children’s Online Privacy Protection Act ("COPPA").
- Google Play — the Google Play Developer Programme Policies, including the User Data and Permissions policies, which we treat as binding on us in addition to the law.
The contents of your Vault are processed only by the App on your own phone. They never reach us, so we do not process them in the sense these laws use. Where the law of your jurisdiction grants you a stronger right than this Policy describes, that stronger right prevails.
3. About AppskKuber and QuietBox
QuietBox is developed and published by AppskKuber, a sole-proprietor software developer based in Madhya Pradesh, India. Full contact details, including our Grievance Officer, are in Section 23.
What the App does, in outline: you choose photos and videos from your phone, or take them with the App’s own camera, and the App encrypts them into your Vault. You can then remove the unencrypted originals from your gallery, organise the Vault into albums, view and play its contents, move items to a bin, or take them back out to your gallery ("unhide"). Optional features include fingerprint unlock, a Decoy Vault, a disguise that makes the App look like a Calculator, Clock or Notes app, an intruder photo, a panic exit, backup reminders and encrypted backups.
4. An Offline App: What We Do Not Collect
The App does not request Android’s INTERNET permission or any other network permission. Without it, Android does not let the App open any network connection. Our release process checks this automatically: a release build that contains a network permission fails and cannot be published.
As a result, and by design:
- There is no account, no sign-in, and no user identifier of any kind;
- There is no advertising and no advertising identifier;
- There is no analytics, telemetry, or crash-reporting service, and no third-party SDK that sends data anywhere;
- There is no server belonging to us that the App talks to, and no cloud storage of ours in which your data could be kept;
- We never receive your photos, videos, thumbnails, album names, file names, PIN, Recovery Code, keys, intruder photos, notes, settings, or any record of how you use the App.
5. Information Kept Only on Your Phone
To work, the App keeps the following on your phone. None of it is sent to us.
| What | Where | Form |
|---|---|---|
| Photos and videos you add, and their thumbnails | Vault Folder | Encrypted |
| Album names, item dates and sizes, original file names, bin state | Vault Folder | Encrypted |
| Decoy Vault contents | Vault Folder | Encrypted, with the Decoy Vault’s own keys |
| Intruder photos (only if you turn the feature on) | App-private storage | Encrypted (Section 9) |
| The keys that let this phone open the Vault with your PIN or fingerprint | App-private storage and Android Keystore | Encrypted; bound to this phone |
| Your backup-reminder choice and the date of your last backup | App-private storage | Encrypted with your Vault’s keys |
| Settings: auto-lock delay, disguise, app language, panic exit, the time of the next backup reminder, one-time tips already shown | App-private storage | Plain settings, no Vault content |
| Wrong-PIN counter and waiting time | App-private storage | Plain counter |
| Notes you write in the Notes disguise | App-private storage | Stored by the App, separate from the Vault |
| Problem log: the type of each recent error, where in the App it happened, and the program trace — at most the last 200 errors | App-private storage | Plain text; never error messages, file names, folder paths, your PIN or keys |
"App-private storage" is the part of your phone that Android reserves for the App alone. Other apps cannot read it, and Android deletes it when you uninstall the App. The Vault Folder, by contrast, is a normal folder that you chose, so that your Vault survives a reinstall or a move to a new phone; its contents are encrypted and its files have random names.
Your PIN and Recovery Code are never stored, in any form from which they could be read back. They are turned into keys each time you use them (see Section 6).
Android’s own cloud backup and phone-to-phone transfer are switched off for everything the App stores, so none of it is copied to Google’s backup service by the system. Your Vault moves to another phone only through a Backup File you make yourself.
6. How Your Vault Is Protected
- Every photo, video, thumbnail and record is encrypted with AES-256-GCM using Google’s open-source Tink library, in streaming mode so that even large videos are never held unencrypted on storage.
- The keys are derived from your PIN with Argon2id, a password-hashing function designed to make guessing slow and costly, and combined with a key kept in Android Keystore on your phone. Your Recovery Code is turned into a key in the same way.
- Photos and videos are decrypted only in the phone’s memory while you look at them. The App never writes an unencrypted copy to storage.
- An original is removed from your gallery only after its encrypted copy has been written, saved to storage, read back and checked.
- While the Vault is open, the App asks Android to keep its screens out of screenshots, screen recordings and the recent-apps view.
- The Vault locks when you leave the App or turn the screen off (immediately by default, or after the delay you choose). Repeated wrong PINs make you wait before you can try again.
We describe what the App cannot protect you from, just as plainly, in the Help page — for example someone watching you type your PIN, a rooted or compromised phone, or copies of your photos that are still in a cloud service.
7. Android Permissions & Why
| Permission | Why the App needs it | When it is asked |
|---|---|---|
| Camera | Taking photos straight into the Vault, and the optional intruder photo | When you open the in-App camera, or turn on intruder photos. Never on the lock screen. |
| Notifications | A neutral progress notification while a long task runs, and optional backup reminders | When you turn on backup reminders. Everything works without it. |
| Foreground service (data sync) | Keeping a task you started — adding files, unhiding, backing up or restoring — running when you leave the App | Granted at install; used only while such a task runs |
| Run at start-up | Setting the backup-reminder alarm again after the phone restarts or the App is updated | Granted at install; does nothing if reminders are off |
| Biometrics / fingerprint | Optional fingerprint unlock | When you turn fingerprint unlock on |
The App does not request internet access, access to all your photos or files (READ_MEDIA_* or “all files access”), contacts, location, microphone, phone, or SMS. Photos and videos are chosen through Android’s own picker, which gives the App access only to the items you select, and the Vault Folder through Android’s own folder picker.
8. Adding Photos and Removing the Originals
- You choose items in Android’s picker, or share them to QuietBox from another app. The App reads only what you chose.
- After encrypting and checking each item, the App offers to remove the originals from your gallery. On Android 11 and later, Android itself asks you to confirm before anything is deleted; on Android 10, the App asks you. You can always keep the originals.
- Items shared from another app (for example a messaging app or a cloud photo service) remain in that app. The App tells you so, and you can delete them there.
- Cloud copies are outside our reach. If a photo was already backed up to Google Photos or another cloud service, a copy stays there until you delete it in that service and empty its trash.
- "Unhide" writes the chosen items back to your gallery, in a folder called
Restored, where other apps can see them again.
9. Camera and Intruder Photo
9.1 In-App camera
Photos taken with the App’s own camera are held in memory and encrypted straight into the Vault. They are never saved to your gallery or written anywhere unencrypted.
9.2 Intruder photo (optional, off by default)
- If you turn it on, the front camera takes one photo, without a preview, after the 2nd, 5th and 10th wrong PIN in a row on the App’s PIN screen or the Clock disguise’s PIN pad.
- The photo is encrypted immediately with a public key, so that it can be opened only with a private key that is itself encrypted with your Main Vault’s keys. It is stored in app-private storage, up to thirty (30) photos, and shown to you the next time you open your Main Vault. A Decoy Vault cannot see them.
- Android shows its green camera indicator while the photo is taken; no app can hide it.
- Turning the feature off, or deleting the photos, deletes them from your phone. Uninstalling the App deletes them too.
- Intruder photos never leave your phone. Please see the Terms of Use about using this feature lawfully.
10. Fingerprint Unlock
Fingerprint unlock is optional and uses Android’s own fingerprint prompt. The App never receives your fingerprint or any biometric template; Android only tells the App that a fingerprint enrolled on the phone matched, and then releases a key from Android Keystore. That key stops working if a new fingerprint is added to the phone or the screen lock changes, for your safety; you then turn fingerprint unlock on again with your PIN.
11. Backups
- A Backup File is written only when you ask for one, and only of your Main Vault. It contains the Vault’s encrypted files exactly as they are — nothing is decrypted to make it — plus integrity checks, and it opens only with your Recovery Code.
- You choose where it goes: a folder on the phone, an SD card or USB drive, or — through Android’s own “save to” screen — an app such as Google Drive.
- If you save it to a cloud app, that app uploads it, using its own internet access and your account with that service; QuietBox does not sign in to anything and never goes online. Once the file is there, that service’s own privacy policy applies to it. It stays encrypted throughout.
- We never receive a copy of your Backup File.
12. Support Emails & Problem Reports
These are the only ways information from the App can reach us, and both happen only when you act.
12.1 Contact support
"Contact support" (Settings → Help, or the end of the Help screen) opens your own email app with a new message to help@appskuber.com. Below the space where you write, it fills in the App’s version, the Android version, your phone’s make and model, and the App’s language, because these help us answer. You can see them and delete them before sending. Nothing is sent unless you press send in your email app. Nothing from your Vault is ever included.
12.2 Problem report
Settings → Help → Problem report shows you the whole problem log described in Section 5, together with the App version, Android version and phone model. If you choose to send it, it opens your email app addressed to us (or, if you have no email app, Android’s share sheet). You can also clear the log at any time.
12.3 What we receive
When you email us, we receive your email address, your name if your email app includes it, and whatever the message contains. Your email app and email provider send the message; their own privacy policies apply to that. Please do not send us your PIN, your Recovery Code or private photos: we will never ask for them, and we cannot use them.
13. Buying the App on Google Play
QuietBox is a paid app sold through Google Play. There are no in-app purchases and no subscriptions.
- We never receive or store your payment details. Card, UPI, wallet and billing-address information is handled entirely by Google under the Google Payments privacy terms.
- Google shares with developers the order information its developer terms provide for sales, tax and refunds — for example an order number, the date, the country, the product and the amount. We use it only for accounting, tax and handling refunds.
- The App does not check your purchase over the internet; it has no internet access.
- Refunds are handled by Google. See the Terms of Use, and please take your photos out of the Vault before asking for a refund, because Google Play uninstalls the App as part of a refund.
14. Information We Receive & Legal Bases
| Information | Purpose | Legal basis (GDPR / DPDP) |
|---|---|---|
| Your support email, with any details you left in it | Answering you, fixing the problem you report | Your consent (you chose to write); legitimate interests in supporting the App |
| A problem report you send | Finding and fixing faults in the App | Your consent; legitimate interests in keeping the App working |
| A privacy or grievance request | Handling the request | Legal obligation |
| Google Play order information | Accounting, tax, and handling refunds | Performance of a contract; legal obligation |
We do not use any information for advertising, marketing, profiling, or any automated decision-making that produces legal effects concerning you. We do not send newsletters or promotional email.
16. International Data Transfers
Your Vault never leaves your phone because of the App. AppskKuber is based in India. Support emails you send us are stored by our email provider, which may keep them on servers outside your country of residence; Google Play order information is held by Google. For transfers out of the EEA and the UK, those providers rely on safeguards such as the European Commission’s Standard Contractual Clauses. For transfers out of India we rely on the DPDP Act’s permission to transfer to countries not restricted by the Central Government.
17. Data Retention & Deletion
17.1 On your phone — you are in control
- Items: select them → Delete moves them to the bin, where they are deleted for good after thirty (30) days; Delete for good or Empty bin removes them at once.
- Decoy Vault: Settings → Decoy PIN → Remove decoy deletes it and everything in it.
- Intruder photos: delete them in the intruder-photo list, or turn the feature off.
- Problem log: Settings → Help → Problem report → Clear.
- Everything: uninstalling the App makes Android delete its app-private storage (keys, settings, intruder photos, problem log, disguise notes). The Vault Folder is deliberately kept by Android, so that your Recovery Code can bring your Vault back; to erase the Vault itself, delete that folder with a file manager. Backup Files are separate files that you delete wherever you saved them.
Because we hold no copy of any of this, deletion on your phone is complete and final; there is nothing for us to delete on a server.
17.2 What we hold
| Data | Retention |
|---|---|
| Support correspondence and problem reports you send | Up to 24 months, so we can see the history of an issue; deleted earlier on request |
| Google Play order information | As long as tax and accounting law requires |
18. Security
The App’s safeguards are described in Section 6. In addition, release builds are obfuscated, and every release is checked automatically for network permissions before it can be published (Section 4).
No system is perfectly secure. If you believe you have found a vulnerability, please write to help@appskuber.com with the subject "[QuietBox] Security" before disclosing it publicly; we will acknowledge within 72 hours. If a breach ever affected Personal Data we hold, we would notify you and the competent authorities as the applicable law requires.
19. Your Rights & Choices
19.1 On your phone
Everything in Section 5 is under your direct control: you can view, change, export (unhide), or delete it at any time without asking us. We cannot access, correct, export or delete Vault data for you, because we never have it.
19.2 Rights under the GDPR / UK GDPR (EEA and UK users)
For the information we do receive (Section 14), you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), and withdrawal of consent (Art. 7(3)) at any time without affecting the lawfulness of processing before withdrawal. We take no decisions based solely on automated processing.
19.3 Rights under the DPDP Act (Indian users)
You have the right to access a summary of your Personal Data and our processing, the right to correction, completion, updating and erasure, the right to nominate another individual to exercise your rights in the event of death or incapacity, and the right of grievance redressal through our Grievance Officer (Section 23) before approaching the Data Protection Board of India.
19.4 Rights under the CCPA / CPRA (California residents)
You have the right to know what Personal Data we collect, use and disclose; the right to delete it; the right to correct it; the right to opt out of sale or sharing (we do neither); the right to limit the use of sensitive personal information (we collect none); and the right not to be discriminated against for exercising any of these rights. You may use an authorised agent, with proof of authorisation.
19.5 How to exercise a right
Email help@appskuber.com with the subject "[QuietBox] Privacy Rights Request", from the address you used to write to us. We respond within 30 days (extendable once, with notice, where the law permits). We do not ask for identity documents. There is no charge unless a request is manifestly unfounded or excessive.
20. Children’s Privacy
QuietBox is not directed to children. You must be at least 13 years old, or the higher minimum age set by the law of your country (16 in parts of the EEA), to use the Service; if you are under 18, use it with the involvement of a parent or guardian. The App collects no Personal Data from anyone, including children, and shows no advertising. If you are a parent or guardian and believe a child under 13 has emailed us, write to help@appskuber.com with the subject "[QuietBox] Child" and we will delete that correspondence promptly.
21. This Website, Cookies & Do Not Track
This legal website sets no cookies, uses no local storage, runs no analytics, and loads no third-party scripts or fonts. Like any website, it is delivered by a hosting provider, which processes your IP address and standard request details in order to serve the page and keep the service secure. The App is not a browser and performs no tracking, so there is no Do Not Track signal for it to honour.
22. Changes to This Policy
We may update this Policy to reflect changes in the Service or the law. When we do, we revise the "Last Updated" date and the version number in the header. Because the App never goes online, it cannot notify you of a change by itself: we describe material changes — for example a new permission or a new way data could leave your phone — in the App’s release notes on Google Play, and such a change applies to you only once you install that version of the App. Superseded versions are available on request.
23. Contact & Grievance Officer
Data Controller / Data Fiduciary
AppskKuber
Rupesh Patel
5/50/1 Chanakyapuri Colony, Padra
Rewa – 486001, Madhya Pradesh, India
Email: help@appskuber.com (please start the subject with [QuietBox])
Legal centre: https://quietbox.appskuber.com
Developer: https://appskuber.com
Grievance Officer (DPDP Act, India)
Name: Rupesh Patel
Designation: Grievance Officer, AppskKuber
Address: 5/50/1 Chanakyapuri Colony, Padra, Rewa – 486001, Madhya Pradesh, India
Email: help@appskuber.com
Subject line: "[QuietBox] Privacy Grievance"
Response time: within thirty (30) days of receipt
If you are not satisfied with our Grievance Officer’s response, you may complain to the Data Protection Board of India once it is constituted and operational under the DPDP Act.
Privacy Rights Requests
For a request under any applicable law (DPDP, GDPR, UK GDPR, CCPA/CPRA, COPPA or other), email:
help@appskuber.com
Subject line: "[QuietBox] Privacy Rights Request"
Supervisory Authority — EEA & UK
EEA and UK users have the right to lodge a complaint with their local supervisory authority. A list of EU authorities is at edpb.europa.eu/about-edpb/about-edpb/members_en. UK users may complain to the Information Commissioner’s Office at ico.org.uk.
California Privacy Rights
California residents may submit verifiable rights requests by emailing help@appskuber.com with the subject "[QuietBox] California Privacy Request", and may designate an authorised agent to act on their behalf.
This Privacy Policy is the entire statement between you and AppskKuber regarding the privacy of your Personal Data in the QuietBox Service, and supersedes any prior privacy notice issued for it.