What this policy covers
This privacy policy explains how the mobile application Lock PDF (the “app”) handles information when you use it. The app is published under the package name com.lockpdf.passwordprotect.
How the app works
Lock PDF adds a password to a PDF and encrypts it, so that the file asks for that password every time it is opened. The encryption is performed 100% on your device using a standard on-device PDF engine (AES encryption). Your PDF files are never uploaded to any server and never leave your device.
The short version
- Your PDF files never leave your device. All encryption happens locally on your phone.
- The password you set is used only on your device to encrypt the file. It is never stored by the app and never sent anywhere.
- Because encryption happens only on your device and we never receive your password, a lost password cannot be recovered by us or by anyone.
- We do not collect, store, or transmit the content of your documents.
- The app does not require an account or sign-up.
- The app shows ads through Google AdMob, which uses your device’s advertising identifier.
- The app uses a first-party, self-hosted analytics service for anonymous usage analytics, to help us fix bugs and improve the app. This never includes your files or passwords.
What we do NOT collect
- Your PDF files, their content, or any text or images inside them.
- The passwords you set to lock your files. They are used only on your device, in memory, and are never stored by the app or sent anywhere.
- Your name, email address, phone number, or other personal identifiers (unless you choose to send them to us through the contact form).
- Your precise location.
- Your contacts, calendar, microphone, camera input, or files other than the PDFs you choose to lock.
What stays on your device
Locked PDFs are written to a private app folder so the app’s History screen can list your recent results and let you re-share them. Your recent jobs (file name, original and output file size, and timestamp) are stored locally in an on-device database, capped at 50 entries with the oldest removed automatically. The content of your PDFs and the passwords you set are never uploaded by us.
Permissions the app requests
File access
The app lets you pick PDF files to lock. It reads only the files you explicitly select through the system file picker and never scans your device storage for any other purpose.
Internet access
The app uses the internet only to serve advertisements (Google AdMob), to load Google’s consent form, and to send anonymous usage analytics (to our own first-party analytics service). Your PDF files, their contents, and the passwords you set are never sent over the network.
Advertising via Google AdMob
We monetize the app with Google AdMob. AdMob may collect and process the following on Google’s servers in order to serve and measure ads:
- Your device’s advertising identifier (Google Advertising ID on Android).
- General device information such as device model, OS version, language, and approximate region.
- IP address and ad interaction events.
In the European Economic Area, the UK, and Switzerland, the app presents a Google-certified consent message (Google’s User Messaging Platform) on first launch so you can choose whether ads are personalized. You can reset or remove your advertising identifier at any time in your device settings. Google’s use of advertising data is governed by Google’s own privacy policy: policies.google.com/privacy, and AdMob’s practices are described here: support.google.com/admob/answer/6128543.
Analytics
The app uses a first-party, self-hosted analytics service (running on our own infrastructure on Cloudflare) to understand how the app is used in aggregate and to fix bugs. For these purposes it collects:
- An anonymous, randomly generated app-instance identifier (not tied to your identity or your Google account).
- Interaction events, for example the app being opened, a lock started or finished, or a screen opened, together with counts, file sizes in KB, and short labels.
- General app information such as app version and platform.
This data is anonymous, is not used to serve personalized ads, is not sold, and never includes the content of your PDFs or the passwords you set. It is used only to improve the app.
Data sharing
We do not sell your data. Data is received by Google through the AdMob service (for advertising) described above, and by our own first-party analytics service (self-hosted on Cloudflare), which receives only anonymous usage data. These parties act to provide those services on our behalf, subject to their respective terms and privacy policies.
Children
The app is a general-audience utility and is not directed at children under the age of 13. We do not knowingly collect any personal information from children. If you believe a child has provided information, contact us and we will respond.
Data retention
Locally-stored job history stays on your device only and is capped at 50 entries. You can clear all history at any time from inside the app (History, then the clear icon). Uninstalling the app deletes all on-device data. Data held by Google AdMob is retained according to Google’s policies; anonymous events held by our first-party analytics service are retained only in aggregate for product improvement.
Your rights
Because we do not collect personal data on our own servers, there is nothing on our side for you to access, correct, export, or delete. For data Google may hold about your device’s advertising identifier, you can manage your preferences in your device settings or via Google’s ad settings page: adssettings.google.com.
Changes to this policy
We may update this policy as the app evolves. The current version is indicated by the “Last updated” date below. Material changes will be published at this URL before they take effect in the app.
Contact
Questions about this policy or the app can be sent through our contact form. We’ll reply to the email address you provide on the form.