Privacy Policy

← Docsly

Last updated: 6 August 2026

Docsly ("the App") is a document vault developed by Igor Gasenko and Denys Kotenko, with design by Viktoriia Batriukova ("we", "us", "our"). Your documents are encrypted on your device, the encryption key never leaves it, and we operate no server that could receive them. We do collect anonymous usage and crash data, and this policy explains exactly what that is.

1. Your documents

Everything you store in Docsly stays on your device. The contents of your documents — files, scans, photos, the pages inside a document — are encrypted at rest (AES-256). The key is held in the platform's secure storage: the Android KeyStore or the iOS Keychain, marked device-only. We have no access to it and no way to decrypt your documents.

To be precise about the rest: document names, folder names, tag names and the small preview thumbnails are stored on your device too, but they are protected by the operating system's own file protection rather than by the App's encryption. They are not readable by other apps, and they are excluded from unencrypted device backups — but they are not part of the AES-256 layer above. We would rather state this than let "encrypted" stand for more than it does.

We do not operate a backend. There is no Docsly account, no sign-up, no email address, no profile. The app never uploads your documents anywhere on its own.

2. Cloud backup — only when you ask

You can create an encrypted backup from Settings. When you do:

Backup is never automatic. On Android the app also sets allowBackup="false", so your vault is excluded from the operating system's own automatic cloud backup.

3. What we do collect

Docsly uses Google Firebase for anonymous product analytics, crash reporting, and remote configuration. This is the only data that leaves your device without you initiating it.

ServiceWhat it collectsWhy
Firebase Analytics Anonymous usage events: which screens are opened, that a folder or document was created or deleted, whether a backup succeeded, which settings were toggled. Event details are shape-only — file type, file extension, size in bytes. To understand which features are used and where people get stuck.
Firebase Crashlytics Crash reports and non-fatal error records: stack traces, device model, OS version. To find and fix crashes.
Firebase Remote Config Fetches configuration values from Google. Sends no usage data. To adjust app limits without shipping an update.

Firebase assigns a randomly generated app-instance identifier so events from one installation can be counted together. It is not linked to your identity, and deleting the app resets it. Docsly does not use the advertising identifier (IDFA/AAID) — the ad-identifier component is not built into the app at all.

4. What analytics never contains

This matters more than usual for an app like this one, so it is worth being explicit. Analytics and crash reports never include:

That last point is deliberate. Docsly supports a decoy PIN that opens a separate vault. Events carry no vault identifier and counts are never split between the real and decoy vaults, so the analytics data cannot reveal that a hidden vault exists — including to us.

5. Advertising and tracking

Docsly contains no advertising, no ad networks, and no attribution or marketing SDKs. We do not track you across other apps or websites, and we do not sell or share your data with anyone. Nothing we collect is used for advertising.

6. Permissions

PermissionUsed for
CameraScanning documents. Scanning runs entirely on your device; frames are never uploaded.
Photo libraryImporting images you pick, and saving documents you export. Access is limited to what you select.
Face ID / biometricsUnlocking the vault. Biometric data stays with the operating system — Docsly only receives a yes or no.

Docsly requests no location, contacts, microphone, or health permissions.

7. Third parties

Google is our only data processor, through the Firebase services listed above. Their handling of that data is governed by Firebase's privacy documentation and Google's Privacy Policy.

If you use Google Drive backup on Android, you sign in with your own Google account and the archive is stored under your account. That storage is governed by Google's terms, not ours. Docsly asks for a single Drive permission, drive.file, which grants access only to files the app itself created — it cannot browse or read anything else in your Drive. Signing in also tells the app the address of the account you picked, which is shown on the backup screen so you can see where a backup will go; we neither store it nor send it anywhere.

Docsly's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8. Your data, and deleting it

9. Children

Docsly is not directed at children under 13, and we do not knowingly collect data from them.

10. Changes

If this policy changes we will update the date at the top of this page. Material changes will also be noted in the app's release notes.

11. Contact

Questions about this policy, or a data deletion request: reach us from Settings → Contact Us in the app, or by email at denyskt.hub@icloud.com (iOS) / igor.gasenko@gmail.com (Android).