Privacy Policy

LockWhisper

Last updated: July 19, 2026

1. Scope

This Privacy Policy explains how Nevv Atlantis LLC ("Developer," "we," or "us") handles information in the LockWhisper iOS application. LockWhisper is designed as a local-first privacy tool. We do not operate a Courier messaging server.

Contact: support@newatlantisstudios.com. Security reports: support@newatlantisstudios.com.

2. Information the Developer Collects

The app does not include third-party advertising, cross-app tracking, or analytics SDKs. The Developer does not receive your vault records, passwords, notes, files, media, private keys, browsing history, Courier message content, contacts, or usage logs through the app.

If you contact support, report a security issue, submit an App Store review, or otherwise communicate with us, we receive the information you choose to provide and the routing information required by that channel. We use it to respond, investigate, prevent abuse, and maintain the app. We retain it only as long as reasonably necessary for those purposes, security, dispute resolution, and legal obligations.

Apple independently processes App Store purchases, subscription or entitlement information, downloads, crash information you elect to share with Apple, and related account data under Apple's privacy terms. LockWhisper may read an App Store entitlement on your device but does not receive your payment-card information.

3. Local Data

LockWhisper stores sensitive data locally on your device, including vault data, encryption keys, settings, encrypted Courier history, Courier credentials, browser data when history is enabled, and encrypted transfer or backup state. Local protections may include encryption, Keychain storage, data protection, app authentication, biometric access controlled by iOS, and mode-separated storage.

You control local retention through feature controls, deletion actions, and by deleting the app. Exports, backups, screenshots, downloads, copied data, and files shared to another app leave LockWhisper's protection and are governed by the destination you choose.

4. Courier Servers You Select

Courier is optional. To use it, you select a server operated by you or by an independent third party ("Server Operator"). LockWhisper sends protocol data to that server and, for direct delivery, to a recipient's server.

A Server Operator may process:

  • Your Courier address, opaque account identifier, public certificate, and public-key generation.
  • Access and refresh tokens in hashed or protected server form.
  • End-to-end encrypted message envelopes and encrypted attachments until acknowledgment or expiry.
  • Routing metadata such as recipient account, message identifier, timestamps, size, expiry, and delivery state.
  • Limited IP-address, Tor-circuit, rate-limit, authentication-failure, and security metadata used to prevent abuse and operate the server.
  • Federation metadata required to exchange encrypted envelopes with another server.

Message content and attachments are encrypted for recipients before delivery. Encryption does not hide all metadata. The operator's own privacy policy, retention schedule, location, security practices, and legal obligations govern its processing. Review them before registering. We do not select the operator, receive its database, control its backups, or promise that it will honor its policy.

5. Courier Account Deletion, Blocking, and Reports

The app offers Delete Courier Account from the Courier account menu. It signs and sends a deletion request to your selected Server Operator. After the server accepts the request, LockWhisper deletes the local session credential. The reference server disables the account and queues mailbox items, tokens, and published keys for deletion according to its retention process. An independent operator may have a different lawful backup or retention schedule. Local encrypted message history remains until you separately erase it or delete app data.

Blocking a Courier address is stored in the mode-separated local trust store. Future authenticated messages from that address are acknowledged to the server and discarded without storing decrypted text. The sender is not notified.

Courier reports are created locally. LockWhisper does not automatically receive them. Before sharing, the app explains that a report can disclose Courier addresses, server address, timestamps, message ID, attachment names and sizes, and—only if you choose it—decrypted text. The app then uses the iOS share sheet, so you select the recipient and channel. A Server Operator is responsible for responding to reports about its service. Contact us at support@newatlantisstudios.com for app-level safety or functionality issues.

6. Private Browsing and Tor

Private Browsing uses Apple's WebKit. In Tor Mode, supported network requests are routed through the embedded Arti Tor client. Tor relays, destination websites, certificate authorities, search providers, download destinations, and other network participants process the information needed for their role. Tor separates parts of the route but does not guarantee anonymity.

Private Browsing is not Tor Browser and does not include every Tor Browser anti-fingerprinting defense. Websites may identify or correlate users through logins, browser behavior, content, or device characteristics. In explicitly selected Non-Tor Mode, ordinary websites receive direct network connections. Onion destinations always require Tor.

Search queries are sent to the search provider you select when you use address-bar search. Website privacy policies govern website and search-provider data.

7. Device Transfer, Backup, Import, and Export

Device transfer and sync are initiated by you and are designed to move encrypted data directly between devices. Local-network discovery can expose a transient service advertisement to devices on the same network. Exported backups and migration packages are files under your control. Anyone with the file and required credentials may be able to restore its contents.

8. Retention and Deletion by the Developer

Because the Developer does not receive app vault data, browsing history, or Courier content, we have no developer database containing that data to access, correct, export, or delete. Delete local data with in-app controls or by deleting the app. Delete a Courier account with the in-app server request described above. Direct requests about information you intentionally sent to support to support@newatlantisstudios.com.

9. Legal Bases and Disclosures

Where privacy law requires a legal basis, support information is processed to perform requested support, pursue legitimate interests in security and maintenance, comply with law, or with your consent where required. We do not sell or share personal information for cross-context behavioral advertising.

We may disclose support communications when required by valid law, to protect users or the public, to investigate abuse or security incidents, or in a business transfer subject to applicable safeguards. Courier Server Operators make their own disclosure decisions independently.

10. Children

LockWhisper is not directed to children under 13, or the higher minimum age required in a user's jurisdiction. We do not knowingly collect children's personal information through the app. Server Operators must establish and enforce any age and child-safety rules applicable to their service.

11. Security and Limits

We use technical and organizational safeguards appropriate to the limited information we receive. No device, encryption system, network, Server Operator, or communication channel is perfectly secure. Keep iOS updated, use strong credentials, verify Courier fingerprints out of band, test backups, and share exports and reports only with trusted recipients.

12. Changes

We may update this policy as the app, law, or distribution changes. A material in-app legal update requires acceptance of the new document version. The Last Updated date identifies this version.

13. Contact and Rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of information held by the Developer, or to complain to a data-protection authority. Contact support@newatlantisstudios.com. We may need limited information to verify and answer a request. For data held by a Courier Server Operator, contact that operator directly.