EveryLock

Privacy Policy

Effective date: September 17, 2026

This policy explains how the EveryLock Android application accesses, uses, stores, and protects information, including Google user data used for the optional encrypted Google Drive backup and restore feature.

1. Overview

EveryLock is a privacy and security application for Android. Its core features include an encrypted local photo and video vault, PIN and optional biometric access, optional locking of selected applications, and optional encrypted recovery backup to the user's Google Drive app data storage.

EveryLock is designed so that core vault content is stored in app-private storage on the device. Connecting a Google account is optional and is used for the Google Drive backup and restore feature.

2. Information EveryLock handles

DataPurposeWhere it is handled
Photos and videos you importProvide the private vault, viewing, backup, restore, and user-requested export features.Encrypted/app-private local storage; encrypted backup copies may be placed in Google Drive appDataFolder if you enable backup.
PIN and cryptographic key materialAuthenticate access and protect encrypted vault data.Security-related local storage and Android Keystore mechanisms. The recovery password itself is not stored.
Connected Google account emailDisplay which Google account is connected to backup.Stored locally in app preferences while the account is connected.
Selected protected apps / package identifiersKnow which apps you chose to protect with App Lock.Local app database/storage.
Backup metadataTrack encrypted backup generations, integrity, and restore state.Locally and, where needed for recovery, inside EveryLock's private Google Drive app data area.

3. Google user data and Google Drive access

EveryLock requests the Google OAuth scope https://www.googleapis.com/auth/drive.appdata only when you choose to connect Google Drive. This scope allows EveryLock to access files that EveryLock itself creates in the hidden Google Drive appDataFolder.

EveryLock uses this access to create/upload encrypted backup objects, list EveryLock backup objects, download them for restore, update EveryLock backup metadata or pointers, and delete EveryLock backup objects when required by the backup feature. EveryLock does not request broad Google Drive scopes for reading your normal My Drive documents, photos, or unrelated files.

Google Sign-In also provides the email address of the Google account you select. EveryLock uses that email locally to identify the connected backup account in the app.

Google user data use

Google user data obtained through Google APIs is used only to provide and maintain the user-requested Google Drive encrypted backup and recovery functionality and to identify the connected Google account inside the app.

Google user data sharing

EveryLock does not sell Google user data. The application code reviewed for this policy does not provide a feature that transfers Google user data to advertising networks, data brokers, or unrelated third parties. Google Drive data is exchanged directly with Google's APIs as necessary to provide the backup and restore feature.

Google user data storage and protection

Vault media backup content is encrypted before upload. Backup manifests and recovery information are cryptographically protected as part of the backup system. EveryLock uses HTTPS when communicating with Google APIs. The connected Google account email may be retained locally on the device while connected.

Google user data retention and deletion

You can disconnect or revoke Google access. EveryLock can delete backup files that it created in its Google Drive appDataFolder as part of its backup management operations. Local application data can also be removed by clearing app data or uninstalling the application, subject to Android behavior. Revoking Google authorization prevents further authorized access unless you grant access again.

Limited Use

EveryLock's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only for user-facing features described in this policy.

4. Local vault security

EveryLock uses authenticated encryption for protected vault content and uses Android Keystore-based key protection as part of its security architecture. A six-digit PIN is used for vault authentication. If you enable biometric unlock, authentication is performed through Android's biometric framework; EveryLock does not receive your fingerprint or biometric template.

A separate recovery password can protect recovery key material used by cloud backup. The recovery password itself is not stored by EveryLock, so users should keep it in a safe place.

5. App Lock, Accessibility Service, and Usage Access

EveryLock includes an optional App Lock feature. When enabled by the user, its Accessibility Service listens for Android window-state changes so it can detect when a user-selected protected app is opened and display a secure lock overlay.

The Accessibility Service is configured with canRetrieveWindowContent=false. It is not intended to read screen text, passwords, messages, form contents, or other window content. Usage Access may also be requested as part of app-protection functionality. Protected-app selections and related lock state are handled locally.

6. Device permissions and system capabilities

Depending on enabled features and Android version, EveryLock may use internet/network access for Google Drive, biometric authentication, notifications, boot-completed events, foreground service capability, Usage Access, and Accessibility Service capability. These permissions are used to provide the corresponding app features.

7. Data sharing and sale

EveryLock does not provide a feature for selling your vault content or Google user data. Data is transmitted to Google only when needed for the optional Google Drive functionality you initiate or enable, and Google processes that data under its own applicable terms and privacy practices.

8. Children's privacy

EveryLock is a general-purpose privacy utility and is not specifically directed to children. Users should use the application in accordance with applicable age and account requirements.

9. Security and limitations

EveryLock uses technical safeguards intended to protect private data, but no software, device, storage system, or transmission method can be guaranteed to be completely secure. Keeping your device, PIN, recovery password, and Google account secure remains important.

10. Changes to this policy

This Privacy Policy may be updated when EveryLock's features or data practices change. The effective date at the top of this page will be updated when material revisions are published.

11. Contact

For privacy questions or support regarding EveryLock, contact: uunayhtet1998774@gmail.com

← Return to EveryLock home page