LockBytes
Privacy Policy
Privacy Policy
This Privacy Policy explains how LockBytes handles information when you use the LockBytes desktop application.
LockBytes is designed primarily for local use. The application does not operate a centralized LockBytes database or backend for storing your passwords, encryption keys, encrypted files, or personal files.
Internet connectivity is used only for specific features that require it, such as optional Google Drive recovery and application updates.
1. About LockBytes
LockBytes is a locally operated desktop application developed by Rahul Gupta for protecting files through encryption and removable USB-based vault storage.
LockBytes is designed with a local-first approach. The application does not operate a centralized LockBytes server or database for storing your vault information, passwords, encryption keys, recovery codes, or encrypted files.
Your security credentials and encrypted data are intended to remain under your control.
2. No Central Database or Storage
LockBytes does not use a central database to store user information.
LockBytes does not maintain a server-side account containing your:
- Vault Password
- App Lock Password
- Master Key
- Recovery Code or PRC
- Encryption keys
- Encrypted vault files
- Decrypted personal files
- USB vault contents
LockBytes is designed to operate locally on your computer and registered USB device.
As a result, the developer does not maintain a centralized copy of your vault or security credentials.
3. Information Stored Locally
LockBytes may create and use files locally on your computer and registered USB device that are necessary for the application to operate.
Depending on the features you use, these may include:
- Encrypted vault data
- Cryptographic keys or protected key material
- Cryptographic salts
- Vault metadata
- Application configuration
- Recovery-related information
- Protected authentication information required for recovery services
These files are used by LockBytes to provide its security and recovery functionality.
The developer does not receive these files through a LockBytes backend.
4. Passwords, Keys and Recovery Information
Your security credentials are your responsibility.
This includes, where applicable:
- Vault Password
- App Lock Password
- Master Key
- Recovery Code / PRC
- Other recovery credentials
- Google account credentials
- Encrypted vault files
LockBytes is designed so that these credentials remain under your control.
The developer cannot recover your vault for you if you permanently lose the required password, key, recovery code, or other recovery material.
If you lose or permanently delete the information required to decrypt your vault, LockBytes may have no technical method to restore access to the encrypted data.
There is no hidden developer key or central database from which your vault can be unlocked.
You are therefore responsible for securely maintaining your passwords, recovery codes, keys, Google account access, USB device, and appropriate backups.
5. Google Drive Recovery
Google Drive Recovery is an optional feature.
LockBytes does not require a Google account for normal local vault operation.
If you choose to enable Google Drive Recovery, LockBytes connects to the Google account and Drive service that you authorize.
The purpose of this feature is to provide a recovery mechanism when your registered USB device is:
- Lost
- Damaged
- Unavailable
- Accidentally modified
- Accidentally deleted
Information stored in Google Drive
Recovery data uploaded to Google Drive is intended to be protected through the encryption and security mechanisms used by LockBytes.
LockBytes does not intentionally upload your:
- Vault Password
- App Lock Password
- Decrypted files
- Original unencrypted files
to Google Drive as part of the recovery system.
Google Drive is a third-party service and is subject to Google's own terms, policies, and privacy practices.
6. Google Account Access
When you choose Google Drive Recovery, authentication with Google is performed through Google's authentication system.
LockBytes does not receive or store your Google account password.
You are responsible for protecting your Google account, including its password and any authentication or recovery methods associated with the account.
If you lose access to your Google account, LockBytes cannot recover that Google account for you.
7. Internet Usage
LockBytes is primarily designed to operate locally.
An internet connection may be used for specific features, including:
Google Drive Recovery
When you explicitly choose to connect Google Drive Recovery, network communication is required to authenticate and synchronize recovery data with the Google Drive account you authorize.
Application Updates
LockBytes may use an internet connection to check for or download application updates.
Apart from functionality explicitly requiring network communication, LockBytes is designed to operate locally and does not intentionally send your files, passwords, encryption keys, or vault contents to a LockBytes server.
8. Data Collection
LockBytes does not intentionally collect or transmit personal information to a LockBytes-operated backend.
The application does not have a LockBytes user account system or central user database.
LockBytes does not intentionally send your:
- Personal files
- Decrypted files
- Vault Password
- App Lock Password
- Master Key
- Recovery Code
- Encryption keys
- USB vault contents
to the developer.
9. File Security and Malware
LockBytes is designed to encrypt and protect files, but it is not an antivirus, endpoint-security, or malware-removal application.
LockBytes cannot guarantee protection against:
- Viruses
- Malware
- Ransomware
- Keyloggers
- Spyware
- Compromised operating systems
- Compromised USB devices
- Other malicious software
If your computer is already compromised, an attacker may potentially access information while it is being entered, unlocked, decrypted, or otherwise accessible to the operating system.
For example, malware may potentially monitor passwords entered on an infected computer.
LockBytes should therefore be used together with appropriate operating-system security, antivirus or endpoint protection, and safe computing practices.
10. No Guarantee of Data Recovery
LockBytes is provided as a security and encryption application, but no guarantee is made that encrypted files will always remain recoverable or accessible.
LockBytes does not guarantee that:
- An encrypted vault will never become corrupted.
- A USB device will never fail.
- A computer will never become infected.
- Recovery will always succeed.
- An encrypted file will always be decryptable.
- Lost passwords or keys can be recovered.
- Lost recovery material can be reconstructed.
- Third-party services such as Google Drive will always remain available.
You should maintain appropriate independent backups of important data.
11. User Responsibility
You are responsible for securely maintaining:
- Your Vault Password
- Your App Lock Password
- Your Master Key
- Your Recovery Code / PRC
- Your registered USB device
- Your Google account
- Your Google account recovery methods
- Your encrypted vault files
- Any independent backups
You should never share your passwords or recovery materials with anyone unless you fully understand the security consequences.
The loss of required security material may result in permanent loss of access to your encrypted data.
12. Third-Party Services
LockBytes may interact with third-party services when you explicitly choose features that require them.
These services may include:
- Google Drive for optional recovery
- Services used to distribute or provide application updates
Third-party services operate independently from LockBytes and may have their own privacy policies, security practices, and terms of service.
LockBytes does not control the privacy practices of third-party services.
13. Data Deletion
Because LockBytes is primarily a local application, data created by LockBytes may exist on your computer, registered USB device, or a third-party service that you have explicitly connected.
You are responsible for managing and deleting locally stored data when appropriate.
If Google Drive Recovery is enabled, recovery data stored in your Google Drive may remain there until it is removed through the appropriate recovery or Google Drive controls.
Deleting local LockBytes files or Google Drive recovery files may affect your ability to recover your vault.
14. Application Updates
LockBytes may periodically check for application updates when an internet connection is available.
Updates may contain:
- Security fixes
- Bug fixes
- Performance improvements
- New features
- Changes to existing functionality
The update mechanism is separate from the storage of your encrypted vault and security credentials.
15. Changes to This Privacy Policy
This Privacy Policy may be updated when LockBytes changes its functionality, security architecture, third-party integrations, or privacy practices.
The Last Updated date at the top of this policy will be changed whenever this policy is revised.
You should periodically review this policy to remain informed about how LockBytes handles information.
16. Developer and Contact
LockBytes is independently developed by:
17. Important Security Notice
LockBytes is a security tool, not a guarantee of security.
No software can guarantee that files will never be lost, corrupted, stolen, accessed by malware, or become permanently inaccessible.
LockBytes is designed to give users greater control over their encrypted files and security credentials, but the security of the overall system also depends on the security of the user's computer, USB device, passwords, recovery materials, Google account, and operating environment.
If you lose the keys, passwords, recovery codes, or other required recovery material, the developer may not be able to recover your encrypted files.
Please keep your recovery information secure and maintain independent backups of important data.