ZorbiLock
Privacy Policy
ZorbiLock ("the App"), published by Navelo Software ("we", "us", "our"), is built on a zero-knowledge security architecture. This policy explains how the App handles information, what we can and cannot see, and the controls you have. It applies to the iOS and Android versions of the App.
Last updated · January 2026
1. Zero-knowledge architecture
Your vault contents — passwords, notes, identities, cards, attachments, and metadata — are encrypted on your device using AES-256-GCM with keys derived from your master passphrase via a strong key-derivation function (e.g., Argon2id/PBKDF2). Your master passphrase and the resulting keys never leave your device, are never transmitted to Navelo Software, and cannot be recovered by us. If you forget your master passphrase, your vault cannot be decrypted by anyone, including us.
2. Information we may process
To operate the App and its optional features, the following limited information may be processed:
- Account email (optional). If you create an account to enable cross-device sync, we store your email solely for authentication and account recovery, never the master passphrase.
- Encrypted ciphertext blobs. If sync is enabled, only end-to-end encrypted blobs are transmitted and stored on our servers (or your private cloud, where applicable). We cannot decrypt them.
- Billing. Subscriptions are processed by Apple App Store or Google Play, with subscription state managed via RevenueCat using anonymous transaction identifiers. We never see your full payment details.
- Diagnostics (optional). Anonymous crash reports and performance metrics, only if you opt in. These never include vault contents.
3. Biometric authentication
Face ID, Touch ID, and platform biometric APIs are processed entirely on-device through Apple’s Secure Enclave or Android’s equivalent secure hardware. No biometric template ever leaves your device or is accessible to us.
4. Information we do NOT collect
We do not collect your name, phone number, location, contacts, advertising identifiers, browsing history, vault content, or any behavioural profile linked to vault usage.
5. Third parties
The App integrates only the following third parties, each strictly for the function described:
- Apple / Google — distribution, payments, and platform crash reporting.
- RevenueCat — subscription state management.
- Cloud storage provider — encrypted blob storage if sync is enabled. Operators of that service can only see ciphertext.
We do not integrate advertising SDKs, behavioural analytics SDKs, or cross-app trackers.
6. Data sharing
We do not sell, rent, or trade any information. We will disclose limited information only where required by valid legal process; however, because of the zero-knowledge design, what we can disclose is technically limited to account email (if you created one), subscription status, and encrypted blobs that we cannot decrypt.
7. Data retention & deletion
You can export your vault, change your master passphrase, or delete your account at any time from within the App. Uninstalling the App wipes all local vault data. Account deletion permanently removes your encrypted blobs from our systems within a reasonable period, subject to standard backup-rotation windows. Because we cannot decrypt your data, account deletion is irreversible.
8. International transfers
Limited account metadata and encrypted blobs may be stored on servers outside your country. Because data is end-to-end encrypted, the transferred data is unintelligible to the operators of those servers.
9. Children
ZorbiLock is not intended for children under 13 (or under 16 in the EEA/UK), and we do not knowingly collect personal data from them.
10. Your rights
Subject to applicable law (including the EU/UK GDPR, India’s DPDP Act, and the CCPA/CPRA), you may have rights to access, correct, delete, or port your personal data. Because most data is held in encrypted form on your device, most rights are satisfied through in-app controls. To exercise any right or raise a concern, write to support@navelosoftware.com.
11. Security
We follow defence-in-depth practices including device-side encryption, hardened transport (TLS), least-privilege access to operational systems, and periodic review. No security model is perfect; choose a strong, unique master passphrase, keep your devices and OS up to date, and enable biometric or PIN screen locks.
12. Changes
We may update this policy from time to time. Material changes will be reflected by a revised date and, where appropriate, in-app notice.
13. Contact
Security or privacy questions? Write to support@navelosoftware.com. See also our company privacy policy.