1. Data Controller
The controller responsible for the processing of personal data in connection with the app is Vantaguard, Owner René Marcel Köllgen, Quellenweg 33, 50259 Pulheim, Germany. You can reach us by email at info@vantaguard.de.
This privacy policy applies to the Android app Secure App Lock with the package name de.vantaguard.secureapplock.
2. Purpose of the App
Secure App Lock is an app-lock and security app. It helps protect user-selected apps and certain security-relevant Android settings areas locally on the device.
The app processes protection rules, app selections, groups, schedules, lock and unlock events, settings, and optional security features. Cloud synchronization or backup in a Vantaguard cloud is not part of the app.
3. Locally Processed Data
During use, the following data may be processed or stored locally on the device:
- protected apps, package names, and app names,
- app groups, schedules, protection rules, and security-related settings,
- onboarding status, lock screen designs, and launcher icon selection,
- unlock sessions, unlock events, failed unlock attempts, and cooldowns,
- local security logs as well as risk and diagnostic events,
- premium status and activation status,
- optional intruder selfies including associated metadata,
- local authentication verifiers, hash and salt information, and configuration metadata, where a PIN or password method has been set up.
Storage takes place in local app stores such as SecureStore, AsyncStorage, Android SharedPreferences, and internal app files. Intruder selfies are stored in the internal app storage and are not automatically transmitted to Vantaguard.
4. Purposes of Processing
Processing is carried out in particular for the following purposes:
- Providing app-lock and protection features,
- detecting protected apps and security-relevant settings areas,
- performing local lock and unlock operations,
- documenting local security events and diagnostic information,
- providing optional features such as biometric unlock or intruder selfie,
- activating purchased premium features,
- displaying and managing advertising in the free version.
5. Legal Basis
Insofar as processing is necessary for providing the app and its core features, it is based on Art. 6(1)(b) GDPR, where a usage relationship exists, and additionally on Art. 6(1)(f) GDPR based on the legitimate interest in secure, stable, and functional operation of the app.
For optional features such as camera, biometric unlock, notifications, or advertising-related consents, processing is based on the respective consent, the activated device setting, or another applicable legal basis.
6. Device Permissions and System-Level Access
Secure App Lock uses Android permissions and system-level access depending on activated features. These include in particular:
- Usage Access: to detect which app is being used in the foreground.
- Accessibility Service: for faster detection of certain app and system settings states and for protecting critical settings.
- Display over other apps / Overlay: to display the lock screen over protected apps.
- Notifications: for local alerts and the visible notification of the foreground protection service. Depending on the Android version, this is recommended for complete protection.
- Camera: for intruder selfie, if the feature is activated and permission has been granted.
- Biometrics: for unlocking via Android system functions. Biometric raw data is not stored by Vantaguard.
- Internet: for Google Play Billing, Google AdMob, and necessary Google services.
- Foreground Service and Boot Start: so that the protection service can detect protected app starts and critical settings as reliably as possible and be available again after a restart. The persistent notification is part of Android requirements; manufacturers may still handle background services differently.
- Advertising ID / AD_ID: insofar as this is used by Google AdMob for advertising, measurement, fraud prevention, or similar purposes.
- Query installed apps and package information: so that users can select apps and the protection logic can locally assign package names.
Depending on the Android version and manufacturer, additional battery, autostart, or background execution settings may be required for Secure App Lock to function reliably.
7. Accessibility Services and Protection of Critical Settings
The Accessibility Service is used exclusively for security-related app features. It helps Secure App Lock detect protected apps and certain critical system areas more quickly and support a local protection response. Users must enable it themselves in Android; the app cannot turn it on by itself. The app does not use accessibility services to capture text input in third-party apps and does not store content from third-party apps such as messages, images, passwords, or documents.
Secure App Lock does not automate clicks, gestures, or inputs in third-party apps. For protection decisions, only the technical information required for local detection is processed, for example package name, class name, event type, timestamp, or a security-related page indicator.
8. Security Logs and Diagnostics
The app may store local security events. These include in particular successful or failed unlocks, timestamps, lock reasons, affected package names, risk events, and other security-related status information. This data serves the local security function, traceability, and error analysis on the device.
9. PIN, Password, Security Question, and Biometric Unlock
PINs and passwords are processed locally for unlocking and are not stored as raw values or transmitted to Vantaguard. For verification, the app stores local verifiers based on hash and salt information. Native authentication data for the Android lock screen is additionally stored in an AES-GCM envelope protected by an Android Keystore key.
A security question may be stored locally as a readable question. The associated security answer is not stored as a raw answer, but only as a local recovery verifier. During an in-app reset, local authentication data including verifiers, recovery data, native envelopes, legacy authentication keys, and the Keystore alias are deleted. Biometric raw data is not stored by Secure App Lock; biometric verification is performed through the functions provided by the Android system.
10. Intruder Selfie
If the intruder selfie feature is activated and camera permission has been granted, Secure App Lock may take a photo after failed unlock attempts. These photos and associated metadata are stored locally in the internal app storage and are not automatically transmitted to Vantaguard. Users can view and delete the photos in the app. The app does not promise a gallery or export function; it does not display ads in the security log or in the intruder area.
11. Local Export and Import
Secure App Lock may provide a local export and import function for the app configuration. A JSON file is created locally on the device or read from a local file selected by the user. There is no upload of this backup file to Vantaguard and no cloud synchronization by Vantaguard.
The export is limited to non-sensitive configuration, for example protected apps, groups, schedules, as well as supported lock screen design and launcher icon selections. Authentication secrets are not included in the local export: PINs, passwords, security answers, verifiers, hashes, salts, AuthConfig, recovery verifiers, security questions, native authentication snapshots and envelopes, and legacy authentication keys. Also excluded are biometric raw data, intruder selfies, security logs, billing data, and advertising or consent data. If users save or share the file via a system dialog, they decide for themselves on the storage location or the receiving app.
During import, Secure App Lock ignores authentication data from old or manipulated backups. Existing authentication on the device remains preserved. After an in-app reset, an import does not restore authentication setup; it must be completed again.
12. In-App Purchases via Google Play Billing
Digital in-app purchases are processed via Google Play Billing. The product pro_lifetime permanently unlocks premium features. Ad-free activation removes ads, but keeps the free limits for apps, groups, and schedules unchanged. Pro also removes ads and lifts these limits.
Payment data, payment methods, and the actual payment processing are handled by Google Play. Secure App Lock only stores locally the purchase, premium, or activation status required for unlocking features. Vantaguard does not store complete payment data in the app.
13. Advertising via Google AdMob
Secure App Lock may display ads via Google AdMob and the Google Mobile Ads SDK in the free version. For ads, Google or Google services may process data such as device information, app usage information, Advertising ID, IP address, approximate location data, diagnostic data, and interaction data, insofar as this is necessary for ad delivery, fraud prevention, measurement, and where applicable, personalization.
Pro users or users with ad-free activation do not see ads, insofar as the app technically provides for this. Free users may see banners on regular app screens. Secure App Lock does not display ads on the lock screen, in authentication or security flows, in the security log, in the intruder area, or in critical protection dialogs.
Vantaguard does not create complete payment or advertising profiles in the app. Processing by Google is governed by Google's privacy policies and settings.
14. Consent Management
In regions where consent is required, Secure App Lock uses consent management, in particular the Google User Messaging Platform. Users can manage consents for personalized advertising, cookies or similar technologies, and processing by Google or advertising partners there.
Without consent, non-personalized or limited ads may be displayed depending on the region, insofar as this is legally permissible. If the app provides a corresponding function, users can reopen their privacy and consent options later in the app.
15. Recipients and Third-Party Providers
Insofar as data leaves the device, recipients may include the following services:
- Google Play and Google Play Billing for in-app purchases,
- Google AdMob and the Google Mobile Ads SDK for advertising,
- Google User Messaging Platform for consent management,
- Google Play Services for necessary Android and Google platform functions.
As described herein, Secure App Lock does not use Vantaguard cloud synchronization and does not integrate Firebase Analytics or Crashlytics.
16. Data Transfer to Third Countries
When using Google services, processing of personal data may also take place outside the European Union or the European Economic Area. Information on processing by Google can be found in Google's privacy policies and product information.
17. Storage Duration and Deletion
Locally stored data generally remains stored on the device as long as it is necessary for using the app or until it is deleted by users. An in-app reset deletes local app configuration and authentication data, but does not automatically remove Android system permissions. Clearing app data in Android system settings or uninstalling the app removes app data according to the respective Android system behavior.
Data that Google processes in connection with purchases, advertising, consents, or platform services is subject to Google's privacy and retention policies.
18. Obligation to Provide Data
Certain data and permissions are technically required for the core features of the app to be used. Without usage access, overlay function, or local processing of selected apps and protection rules, Secure App Lock may not function as intended in whole or in part.
Other features, in particular intruder selfie, biometric unlock, notifications, or advertising-related consents, depend on the respective activation or system setting.
19. Rights of Data Subjects
Data subjects have, subject to the legal requirements, in particular rights to information, rectification, deletion, restriction of processing, data portability, objection, and withdrawal of granted consents. There is also the right to lodge a complaint with a competent data protection supervisory authority.
Since Secure App Lock processes much data locally on the device, users can remove numerous data directly by clearing app data or by uninstalling the app.
20. Changes to This Privacy Policy
This privacy policy may be updated if the app's features, permissions, third-party providers, purchase models, or data processing change. The currently published version is authoritative.