Privacy-focused by design
The app is designed around local protection first. Cloud access is optional and is used only when you choose to connect Google Drive for encrypted backup and recovery.
Encrypted private vault
Import private photos and videos into app-private storage protected by authenticated encryption and your vault security controls.
App protection
Optionally protect selected Android apps with a lock overlay. The accessibility service is configured only for window-state detection and cannot retrieve window content.
PIN & biometrics
Use a six-digit PIN for vault access and, when enabled and supported by the device, Android biometric authentication for convenient unlocking.
Photo & video privacy
Manage protected media inside the vault and export selected items back to Android media storage when you choose.
Encrypted recovery backup
Create encrypted backup generations for recovery. Backup media remains encrypted before it is uploaded.
Recovery password
Your recovery password protects the cryptographic recovery envelope. EveryLock does not store the recovery password itself.
Google Drive is used only for optional encrypted backup and restore.
When you explicitly connect a Google account, EveryLock requests the narrow Google Drive app data permission (https://www.googleapis.com/auth/drive.appdata). The app uses this permission to create, list, update, download, and delete EveryLock's own backup files in Google Drive's private appDataFolder. It does not request general access to your My Drive files.
The connected Google account email may be stored locally on your device so the app can show which account is connected. Backup content uploaded by EveryLock is encrypted. Google account authorization alone is not the recovery password for your encrypted vault backup.
Security permissions are purpose-limited
EveryLock may use Android biometric authentication, Usage Access, an Accessibility Service, notifications, network access, and boot-completed handling where required for features you enable. The Accessibility Service is configured with canRetrieveWindowContent=false and is used to detect protected app launches and show the lock overlay; it is not designed to read screen text or passwords.