Privacy
Last updated: 2026-05-28
Sigillum is a local-first file-encryption tool. Your files, vault keys, and passphrases never leave your device. There is no Sigillum cloud, no telemetry server, and no analytics endpoint that learns anything about your data. This page exists to make that promise concrete.
What stays on your device
- Vault contents — always encrypted.
- Vault metadata (vault names, last-opened timestamps, theme preference, language preference).
- Encryption keys — held in the operating system’s secure keystore (Apple Keychain on macOS / iOS, Android Keystore with Class-3 biometric binding on Android). Never written to disk in cleartext.
- Passphrases — never stored anywhere by Sigillum. You enter them every unlock.
What leaves your device, and where it goes
- Sync backends you configure — encrypted blobs only. We never see your cloud credentials; the cloud’s own app or SDK is talking directly to iCloud Drive, Google Drive, Dropbox, Nextcloud, Proton Drive, or any other provider you chose. Sigillum has no visibility into that transport.
- Tamper attestation (Android, Play Store builds) — Play Integrity API verdicts originate from your device, signed by Google Play, and are checked locally by Sigillum. No network round-trip to EINIX.
- This website — basic aggregated page-view counts are collected via the hosting provider. No cookies. No accounts. No long-term IP storage. The hosting setup may change over time; nothing about it depends on identifying you.
Apple App Store & Google Play data-safety declarations
Sigillum’s store listings declare:
- No data collected.
- No data shared with third parties.
- App functionality requires Internet only for sync backends you opt into.
How long do we keep anything?
There is nothing on our side to keep. We have no servers that touch your vault data. If you delete the app from your device, every byte Sigillum ever processed is gone with it (your encrypted blobs in cloud storage are deleted by you through your cloud provider, on your timetable).
Your rights
Under GDPR / UK GDPR / equivalents you have rights of access, rectification, erasure, restriction, portability, and objection over your personal data. Sigillum holds none of yours, so all of those are automatically satisfied. You can verify by network-inspecting the app while it runs — you’ll see no outbound connections from the Sigillum process itself.
Children
Sigillum is a productivity / security tool with a 13+ rating in app-store listings. It is not designed for children and does not knowingly collect data from children (or anyone else).
Changes to this policy
If we materially change this policy we update the “Last updated” date at the top and announce the change on the upcoming community forum. Continued use of Sigillum after an update means you accept the revised policy.
Contact & questions
Privacy questions, security disclosures, and bug reports go through the in-app “Send feedback” menu and the community forum (coming soon). We don’t publish public email addresses on this site — spam-bot harvesting otherwise turns the inbox into noise the day after launch.
© 2026 EINIX SA · sigillum.einix.org · Manuals · Open source