In plain terms: Digicove has no servers, and your sign-in lives inside your own vault rather than with us. What you store lives on your devices and in your own iCloud. The sensitive parts are encrypted on your iPhone before they reach iCloud, with a key we never have. We don't run ads, we don't track you, and we don't sell anything about you — there is nothing for us to sell.
Who we are
This policy covers the Digicove app for iPhone and iPad and this website, digicove.app. Questions go to hello@digicove.app.
What we collect
Nothing from the app. Digicove does not send the contents of your vault, your account details, your usage, crash data or any identifier to us. The app contains no analytics, advertising or tracking code.
The only information we ever receive is what you choose to send us — for example, an email to support. We use it to reply to you and for nothing else.
Where your vault is stored
Your vault is stored on your devices and synced through Apple's iCloud, in the private database that belongs to your Apple Account. It is not stored on any server we operate.
- Field values and attachments — card numbers, ID numbers, codes, notes, scans and photos — are encrypted on your device with AES-256-GCM before they are saved or synced. The key that unlocks them is protected by your vault password, and we never see it.
- Item titles, the short summary shown in the vault list, folder and tag names are not encrypted by Digicove. They are protected by iCloud's own encryption and by your iPhone's data protection. We recommend keeping anything secret in a field rather than in a title.
- On your iPhone, the vault is stored with Apple's strongest file protection, so it is unreadable while your device is locked.
How Apple handles iCloud data is described in Apple's iCloud security overview.
Sharing your vault
When you invite someone, Apple's iCloud sharing makes your vault available to their Apple Account. The invitation and the shared data travel through Apple; we are not involved and cannot see either. Anyone you share with can read what is shared once they unlock the vault with the account you gave them, so share only with people you trust.
Face ID
If you turn on Face ID unlock, the check happens entirely on your device through Apple's Face ID. Digicove never receives your face data.
Purchases
Subscriptions are sold and billed by Apple through the App Store. We do not receive your name, payment details or Apple Account information — only Apple's confirmation that a subscription is active, which the app checks on your device.
This website
digicove.app is a static website hosted by Cloudflare. It sets no cookies and runs no advertising or tracking scripts. Like any web host, Cloudflare processes technical request data such as IP addresses to deliver pages and protect the site from abuse. We use Cloudflare Web Analytics, which counts visits without cookies and without tracking you across sites.
Children
Digicove is not directed at children under 13, and we knowingly collect no information from anyone. Parents may store information about their children in their own vault; that information stays in the parent's iCloud and is never sent to us.
Keeping and deleting your data
Because we hold none of your data, there is nothing for us to delete. You are in control of all of it:
- Delete items inside the app, then empty the Trash to remove them for good.
- Remove Digicove's iCloud data in Settings → [your name] → iCloud → Manage Account Storage → Digicove.
- Delete the app to remove what is stored on that device.
If you email us, you can ask us to delete that correspondence at any time.
Changes to this policy
If this policy changes, we will update this page and the date above. If a change affects how your data is handled in a meaningful way, we will say so in the app before it takes effect.