App publisher
The Clypt application is published by Afinov SARL, a limited-liability company headquartered in Abidjan, Côte d'Ivoire. The data controller, within the meaning of the GDPR, for any personal data that may be collected is Afinov SARL.
For any question regarding this policy, contact us at dev@afinov.net.
What data we collect
The short answer: none, by default.
Clypt requires no account, uses no server-side user identifier, embeds no advertising SDK and includes no tracker. All your clypts, collections, tags, notes and files saved through Android's Share menu remain on your phone, within the application's private storage space.
On-device local storage
Your data is stored exclusively in Clypt's private sandbox, at the standard location Android allocates to applications.
That space is:
- Private. No other app installed on your phone can read it.
- Local. No copy is sent to a server, unless you explicitly enable the optional backup or sync.
- Ephemeral. Uninstalling Clypt permanently removes all files.
On-device intelligence
Clypt's Intelligence features, search by meaning, automatic links between clypts, OCR (text in images and PDFs), image search and summaries, run entirely on your device.
- No content sent. Your clypts are never transmitted to any artificial-intelligence service, neither to us nor to a third party.
- Models downloaded once. Enabling these features downloads models from a third-party host (Hugging Face). That request transmits none of your data: it only fetches the model file.
- Offline processing. Once the models are downloaded, all processing happens locally, even without a connection.
Outputs produced by these models (summaries, OCR) are provided "as is" and may contain inaccuracies.
Anonymous statistics, opt-in only
If you explicitly choose to enable it in the settings, Clypt can send aggregated, anonymous counters that help us improve the application.
In practice, this represents:
- Total number of clypts created over 7 days.
- Distribution by source type: link, video, image, file.
- A flag indicating that a feature has been used at least once.
- Android version and installed Clypt version.
- An anonymous, non-reversible identifier specific to your device, used only to distinguish installations, never to identify you.
The following are never sent: the content of your clypts, captured URLs, titles, notes, tags, collection names, your advertising ID, or any data that could identify you personally.
You can turn the sending off at any time from the Settings screen.
Google Drive backup, optional
If you turn on the backup, Clypt writes an encrypted copy of your database to the private AppData folder of your Google Drive. This folder is invisible from the regular Drive UI and only Clypt can access it.
The encryption key is derived locally from your PIN. Without the PIN, the backup contents remain unreadable, including by us.
Google Drive authentication uses the most restricted OAuth scopes available, limited to the AppData folder. No access to your other Drive files is requested or granted.
Multi-device sync, optional
If you pair several devices, Clypt can sync your clypts between them. This feature is optional and end-to-end encrypted.
- Pairing by code. Your devices pair via a 6-digit code and then share an account key that we never hold.
- End-to-end encrypted, via your Drive. Sync travels through your own Google Drive (private AppData folder, the same as backup). Afinov hosts no sync server and stores nothing: only your devices hold the key and can decrypt.
- No account. Sync creates no user account: it relies solely on the key shared between your devices.
- Revocable. You can reset sync at any time from the settings, which removes the device from the group.
Because everything travels encrypted through your own Drive and we hold no key, we are technically unable to read its content.
Data security
Clypt applies defense-in-depth to protect what stays on your device:
- Your PIN is encrypted and secured on your device.
- Sensitive data is encrypted before any local storage.
- Google OAuth tokens are stored in the Android Keystore, never in clear text.
- Backup files are encrypted on-device before any upload to Drive.
- Multi-device sync is end-to-end encrypted. Afinov SARL cannot read your synced data.
- No sensitive data is logged or sent to error-reporting services.
Android permissions requested
Here are the permissions Clypt uses and their sole purpose:
| Permission | Purpose |
|---|---|
| Internet | Fetching page previews (title, thumbnail) when you clypt a link. |
| Private storage | Reading and writing your local database in the app's sandbox. |
| Biometrics | Unlocking the app via fingerprint or face recognition as an alternative to the PIN. |
| Gallery / shared files | Receiving images, screenshots and documents sent to Clypt from the Share menu. |
| Google account (OAuth) | Optional backup to Drive's private AppData folder. No reading of other files. |
| Display over other apps | Floating search bubble, optional and explicitly enabled by you. Inactive until you turn it on. |
| Background service | Keeps the floating bubble running and performs automatic backup while the app is in the background. |
| Device startup | Automatically restarts the floating bubble when the phone reboots, only if you enabled it. |
Third parties and recipients
Clypt does not sell, rent, share or transmit any data to a third party for commercial, advertising or statistical purposes.
These technical interactions, triggered only at your request:
- Google (Drive AppData), if you turn on backup or sync. Transmitted content is encrypted on-device and stored in your own Drive.
- Third-party websites whose links you clypt, to fetch their Open Graph preview (title, image). No cookie is stored.
- Hugging Face, host of the Intelligence models, only to download the model file if you enable those features. None of your data is transmitted.
- Google Play Billing, if you subscribe to Clypt Premium. Purchase and renewal are handled by Google; we receive a purchase token, never your payment details.
Your rights
Since no personally identifiable data is stored on our servers, most of your GDPR rights are exercised directly from within the application:
- Rectification. Every clypt, collection, tag or note can be edited at any time.
- Erasure. Delete a clypt from its detail screen, or uninstall the app to wipe everything.
- Objection to statistics. Turn them off via Settings › Privacy.
- Sync. Reset sync from Settings to remove the device from the group. Sync data lives in your own Google Drive and is erased like the backup.
You have rights over your data: access, rectification, erasure and objection. These rights are exercised directly from within the application.
For everyone
Clypt provides no content of its own and exposes no sensitive material. The application is a simple aggregator: it classifies and stores only what you send to it through Android's Share menu.
Clypt can therefore be used by everyone, including minors, to organize their own links, images and notes. Responsibility for saved content lies with the person who stores it and with the source applications it was shared from.
Changes to this policy
This policy may evolve to follow changes in the application or in regulation. The last-updated date is shown at the top of the document. Any substantial change will be announced inside the app before taking effect.
Contact us
A question, a concern, an erasure request? Write to us. We respond within 30 days.
Publisher
Afinov SARL
Limited liability company
Abidjan, Côte d'Ivoire