Privasi
Pemberitahuan privasi
Cara EverCode menangani data pribadi, pengukuran penggunaan, sinkronisasi terenkripsi, dan hak privasi Anda.
Last updated :
This Privacy Policy describes how EverCode (operated by Liftoff, a French company based at 2A Place de la Grande Hermine, 35400 Saint-Malo, France — SIRET 95299202200014) collects, uses, and protects your personal information when you use the EverCode application across iOS, Android, macOS, Windows, Linux, and Chrome extension, and when you visit the website at https://www.getevercode.app.
1. Core Privacy & Zero-Knowledge Principle
EverCode is built on a fundamental zero-knowledge security architecture. We believe your authentication credentials belong to you alone:
- Zero Access: We never have access to your master password, private cryptographic keys, or unencrypted two-factor secret seeds.
- Client-Side Encryption: All vault data is encrypted on your local device using XChaCha20-Poly1305 with keys derived via Argon2id before any optional cloud transmission.
- Data minimization: The application does not need to know which accounts you secure, when you generate OTP codes, or which websites you access.
- No data sales: We do not sell, rent, or trade your personal data.
2. Information We Collect
Information you provide directly: When contacting customer support or requesting account assistance, we collect your email address and the content of your inquiry.
Account and device access (optional Continuity and Family features): If you create or sign in to an EverCode account, we process the email address used for verification and retain it in protected form with an opaque account identifier. Approved devices are represented by opaque device identifiers and public keys so we can authenticate the device and deliver encrypted synchronization. The account password, one-time codes, vault keys, and private keys are not sent to our servers.
Encrypted Synchronization Data (Optional Continuity feature): When you enable multi-device sync, our servers receive exclusively opaque, end-to-end encrypted ciphertext blobs signed with Ed25519. These encrypted payloads may contain the vault records you choose to synchronize, but our servers act strictly as a blind relay and cannot inspect, read, or decrypt them.
Information collected automatically: Limited technical characteristics (operating system and app version) may be processed for updates, compatibility and error diagnostics. Crash reports may contain limited technical data and the identifiers needed to associate them with a device. In the app, these measurements start automatically during initialization.
In-app analytics and diagnostics: EverCode uses Firebase Analytics and Crashlytics for bounded product-interaction measurement and technical crash or diagnostic reporting, together with the app or device identifiers needed by those services. This collection is part of the app's operation and is not controlled by a consent setting. These services do not receive vault contents, two-factor secret seeds, account names, service names, passwords, or free-form text.
Optional Apple Ads attribution: if you enable it in Settings, the iOS app may request a short-lived attribution token from Apple's AdServices framework and send it once to the EverCode API to measure Apple Ads acquisition. The raw token is not retained by the app or API, placed in logs, or combined with vault contents, visited URLs, or passwords. The mobile app exposes only an attribution state (attributed or unknown) and, when available, a cohort date distinct from the device registration day. For server-side measurement, the API may also process acquisition categories such as campaign, ad group, keyword and country, together with a provider-response fingerprint; these categories do not contain vault secrets or vault content. Consent is off by default and revoking it blocks new requests. Apple and the relevant service providers may process the data needed for this service under their own privacy policies.
Optional advertising in the free app: when the required consent is available, EverCode may use Google Mobile Ads and Google User Messaging Platform to display a banner outside vault, recovery, code and payment surfaces. Depending on the effective consent configuration, Google may process an IP address, coarse location, diagnostic and performance data, a device identifier, advertising data and product interactions. EverCode disables the publisher first-party ID, does not request IDFA, and sends no vault secret, vault content, URL or account identifier to these SDKs. Banners are removed when a premium subscription is verified. You can reopen the consent choices from Settings > Advertising privacy.
Payment Information: Subscriptions and licenses purchased via third-party application stores (Apple App Store, Google Play, Microsoft Store) are processed directly by those platforms. Liftoff does not receive or store your credit card or banking details.
Premium subscription reconciliation: the app uses RevenueCat as a technical service provider to reconcile subscription status between the Store and EverCode. RevenueCat receives an opaque customer identifier and the transaction information needed to determine subscription status. It does not receive vault secrets, two-factor codes, passwords, URLs, or free-form content.
3. Website Cookies & Analytics
The public EverCode website (https://www.getevercode.app) uses cookies and browser storage for technical operation and, when the public Firebase configuration is valid, for automatically started Analytics measurement. Explicit EverCode events cover limited categories of navigation, button actions, platform downloads, language changes, accepted support or deletion requests, and categorized errors, using predefined values. Advertising storage and personalization are denied by the site configuration. This description covers EverCode's explicit events; the Analytics service may apply additional automatic mechanisms according to its stream configuration.
Private browser: the in-app browser uses a non-persistent session; when it is closed, cookies and session data created in that session are discarded. This does not make visits anonymous or replace a VPN: visited sites still receive ordinary network requests, including the IP address needed to serve the page.
4. Data Sharing & Service Providers
We do not sell your personal information. We only share data with trusted infrastructure providers (cloud hosting facilities located in Europe and Switzerland, such as Infomaniak and Google Cloud Platform) under strict data processing agreements and confidentiality obligations compliant with the GDPR. For the in-app analytics and diagnostics described above, EverCode uses Firebase Analytics and Crashlytics, services operated by Google, configured only for the limited data described above.
For Premium subscription reconciliation, RevenueCat processes the opaque customer identifier and the transaction information needed for subscription status for EverCode as the developer's technical service provider. This integration does not receive vault contents or the secrets described above.
For optional Apple Ads attribution, Apple's AdServices framework supplies the short-lived token and the EverCode API receives the one-time, consented request. The mobile app receives only an attributed or unknown state and a possible cohort date; server-side processing may also retain campaign, ad group, keyword and country categories together with a provider-response fingerprint. These data are used for acquisition measurement and remain separate from vault secrets and vault content. EverCode does not retain the raw token.
5. Your Rights under GDPR and Global Privacy Laws
Under the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and applicable privacy legislation, you have the right to:
- Access the personal data we hold about you.
- Request correction or deletion of your personal data.
- Export your data in a portable, structured format.
- Object to or restrict the processing of your data.
- Withdraw your consent at any time.
To exercise any of these rights, please contact our Data Protection Officer at [email protected].
6. Legal Bases, Retention & Deletion
We process support requests to respond to you, account data to provide optional synchronization features, and technical measurements from the website and app when their configuration is available. Apple Ads attribution and in-app advertising remain separate features subject to their own choices. We retain each category only for the period needed for its stated purpose, to meet legal obligations, or to establish and defend legal claims. Local vault data resides exclusively on your device and is deleted when you clear your app data or uninstall the app. If you use optional cloud sync, encrypted blobs are retained for the duration of the active synchronization and are purged after a verified account or device deletion request, subject to legally required retention.
7. Security Measures
We implement state-of-the-art security standards including TLS 1.3 encryption in transit, strict Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), and client-side authenticated cryptography (XChaCha20-Poly1305 / Argon2id).
8. International Data Transfers
EverCode is operated from France (European Union). When data is processed across international boundaries, we ensure adequate protections are in place in compliance with European Standard Contractual Clauses (SCC).
9. Automated Decisions and Complaints
EverCode does not use your personal data for automated decisions producing legal or similarly significant effects. You may lodge a complaint with the data protection authority in your country. In France, the supervisory authority is the Commission nationale de l'informatique et des libertés (CNIL).
10. Contact & Data Protection Officer
For any privacy inquiries, data requests, or complaints, please reach out to our privacy team:
Liftoff — EverCode Data Protection2A Place de la Grande Hermine
35400 Saint-Malo
France
Email: [email protected]