Privacy promise
Most document scanners upload to a server by default and ask you to create an account. Klypt doesn't. This page explains what that actually means, and the technical commitments behind it.
The short version
If any one of these changes, we update the privacy policy first and tell you before the change ships.
The technical commitments
Marketing pages say "secure" a lot. Here's the specific work that backs it up.
Klypt's scan database is AES-256 encrypted via SQLCipher. The passphrase is generated once per install and held in the Android Keystore โ hardware-backed on every phone Klypt runs on (Android 8 and newer).
Even your settings (lock state, smart-naming toggle) are wrapped by Android Keystore-backed encrypted SharedPreferences. A rooted phone or "adb pull" no longer yields plaintext anything.
Text recognition uses Google ML Kit's on-device library. The page never goes to a server. Klypt works fully offline.
Klypt explicitly opts out of Android's automatic Google Drive backup. Your scans don't sync to your phone's cloud backup either โ by design.
We log app launches, crashes, and which screens get used โ not what's in your documents. OCR text, folder names, and tag names never appear in any analytics event.
Turn on the lock and Klypt requires your phone's fingerprint or PIN to open. Uses the OS credential โ Klypt never sees your biometric data.
What we do collect
We're not zero-data. A few signals are necessary to keep the app working and the ads loading. Here's the complete list.
If the app crashes, we get a stack trace. No scan content, no folder names, no OCR text. Just the line of code that broke.
Anonymous app launches, screen views, and key actions (scan completed, IAP purchased). Used to know if a release broke a flow. No content.
When the banner ad loads in the free tier, your advertising ID goes to Google. We don't add anything to that. Buy the $1.99 IAP to turn off ads entirely.
If you buy the $1.99 ad-removal IAP, Google handles the transaction. We get a "purchased" flag back โ never your payment details.
What's NOT for Klypt
Klypt is not HIPAA-compliant. There's no "Medical" folder by design, and our copy never invites you to store vaccination cards, insurance cards, or lab results. For health records, use a HIPAA-covered system.
Klypt is built for adults filing household paperwork. We don't market to children, don't opt into Google Play's "Designed for Families" category, and ask your age once at first launch.
Email support@klyptapp.com and a real person reads it.