Privacy Policy
In short
PairVault is built so that there is almost nothing for us to collect. Your setup codes and accessory data are stored on your device and, if you turn on sync, in your own private iCloud. We cannot see that data and we cannot delete it for you. There are no accounts, no analytics in the app, no tracking, no advertising and no third-party SDKs. The only personal data that ever reaches us is what you choose to put in an email to our support address.
Who we are
PairVault is operated by Letrix Labs, a trading name of Dime Corporation Ltd, a company registered in England and Wales under company number 13175488. Our registered address is 124 City Road, London, EC1V 2NX, United Kingdom. We are registered with the UK Information Commissioner's Office under registration number ZC094825.
Dime Corporation Ltd is the data controller for the limited personal data described in this policy. You can contact us at hello@letrixlabs.com.
What this policy covers
This policy covers the PairVault iOS app and this website, pairvault.letrixlabs.com. It does not cover Apple's services. When your data is held in your own iCloud, or when you buy the app through the App Store, Apple's privacy policy applies to Apple's handling of it.
Data stored on your device
Setup codes and accessory data are stored on your device. They are not transmitted to us, and we hold no copy of them. On-device storage is protected by iOS device encryption.
If you back your device up to iCloud, or to a computer, that backup may includePairVault's data along with the rest of your apps. Backups are handled by Apple or by your own computer, not by us.
iCloud sync
If you turn on iCloud Backup & Sync, your data syncs through your own private CloudKit database — the private area of your personal iCloud account. It is stored under your Apple Account, not ours. We have no access to it, cannot read it, and cannot delete it.
If you have Advanced Data Protection enabled on your Apple Account, that synced data is end-to-end encrypted.
Sync is optional. With it turned off, your data stays on the single device you entered it on.
Apple Home
With your explicit permission, PairVault reads accessory metadata from Apple Home on your device: accessory names, room names, home names, manufacturers, models and battery state. You choose which homes it may import from.
We treat this as the most sensitive data the app touches. Home and room names can reveal something about the layout of where you live and who is in it. That data is read locally, stays on your device, and leaves it only through your own iCloud if you turn sync on. It is never sent to us.
Apple Home never exposes setup codes to third-party apps, by design. That is why each code has to be scanned or typed once by hand.
The camera
Scanning a QR code requires camera permission, which iOS asks you for the first time you use the scanner. Camera frames are processed live on your device to read the code. Nothing is recorded, stored or transmitted, and no image is saved. You can decline camera access and type setup codes in instead.
Face ID, Touch ID and your passcode
PairVault can lock itself behind Face ID, Touch ID or your device passcode. Authentication is performed by iOS. The app receives only a success or failure result. Your fingerprint and face data never leave the Secure Enclave and are never exposed to the app — Apple provides no way for an app to read them.
There is no app-specific PIN, so there is no separate code for us to store, and the app never sees your device passcode. If your device has no passcode set at all, the app deliberately unlocks rather than locking you out of your own codes permanently, and it tells you why.
Purchases
Purchases are handled entirely by Apple. We receive no payment details. Whether this device's Apple Account owns the unlock is verified on your device, using signatures Apple attaches to the transaction. Nothing is sent to us, because we operate no servers.
What Apple tells us
We take no action to collect information about you, but Apple gives every developer some reporting about their own app. For completeness, this is all of it:
- Sales reporting. Aggregate figures — units, revenue, country, device type — with no identification of individual purchasers.
- App analytics. Aggregate usage statistics, covering only those users who have left Share With App Developers switched on in their iOS settings. Individuals cannot be identified from it.
- Crash reports. Under the same setting, Apple may pass on crash logs containing a stack trace and a device model. They do not identify you.
All three come from Apple, are governed by your Apple settings, and can be switched off in iOS under Privacy & Security → Analytics & Improvements.
Network requests and links
The app makes network requests only to Apple's iCloud and the App Store, through Apple's own frameworks. It contains no code that makes any other kind of network request: no update check, no remote configuration, no feed, no telemetry endpoint.
The app contains links you can tap — to this policy, and to Apple's standard licence agreement. Nothing is requested until you tap one.
No accounts, no tracking
There are no accounts and no sign-up. You never give us an identity for data to be attached to.
The app contains no analytics, no tracking, no advertising and no third-party SDKs. Every framework it uses is Apple's own. It does not ask for permission to track you across other companies' apps and websites, because it has no use for it.
If you email us
If you write to our support address, we receive your email address and whatever you put in the message. We use it to answer you and for nothing else. We do not add you to a mailing list.
Our mail is hosted by Fastmail, who process it on our behalf as our email provider. We keep support correspondence only as long as we have a reason to, and delete it after that.
Our lawful basis for handling support email is legitimate interest: you have asked us a question and we need to read it in order to reply.
Please do not email us your setup codes. We never need them, and email is not a good place to keep them.
The contact form
The support section of our website has a contact form. If you use it, you give us your name, your email address and your message. We use them to reply to you and for nothing else. Using the form is entirely optional — emailing us directly does the same job.
What you send goes straight into our own help desk, where it becomes a support ticket. We run that help desk ourselves on our own server — it is not a third-party form service, and your message is not stored by anyone else along the way. Our website host, Vercel, passes the submission through as it travels from the form to the help desk.
To stop the form being abused by bots, it is protected by Cloudflare Turnstile. Turnstile runs a check in your browser to judge whether the request is automated, and in doing so Cloudflare processes your IP address and some technical signals about your browser. It is designed not to track people across sites and shows no puzzles. Our lawful basis is legitimate interest: keeping the form usable and our inbox free of automated submissions.
As with email, our lawful basis for handling what you send is legitimate interest — you have asked us something and we need to read it to answer. Please do not put your setup codes in the form.
This website
Every page of this site is a static file. There are no accounts, no cookies and no analytics on it, and the only JavaScript it runs is the small script that submits the contact form and the bot check that protects it. The single exception to being static is the address the form posts to, which exists only to pass your message to our help desk. If you do not use the form, nothing on this site sends any information about you anywhere.
It is hosted by Vercel and its domain is managed through Cloudflare, who may also serve traffic for it in future. Like any web host, they process the technical details of your request — including your IP address — in order to deliver the page and to protect the service from abuse. That processing is theirs, under their own terms; we do not build profiles from it, and we do not receive any record that identifies you.
Deleting your data
Because your data lives on your device and in your own iCloud, deleting it is something only you can do. The order matters, and getting it wrong leaves a copy behind.
To erase everything:
- Remove the iCloud copy first. In PairVault, go to Settings, turn off iCloud Backup & Sync, and choose Remove From iCloud Too. This deletes your codes from iCloud. Choosing Keep Data in iCloud instead leaves the iCloud copy in place on purpose.
- Then delete the app from your device. That removes what is stored locally.
Deleting the app on its own does not remove the iCloud copy. It remains in your private iCloud indefinitely, and reinstalling the app downloads it again — useful if that is what you wanted, a surprise if it is not. The only in-app control that erases it lives inside the app you would be removing.
If you have already deleted the app, you can still remove the iCloud copy from iOS: Settings → your name → iCloud → Manage Account Storage → PairVault.
To delete individual accessories rather than everything, swipe or press and hold a row in the app, or use Select mode to remove several at once. That removes them from the device and from iCloud on every device you sync with.
We cannot carry out any of these steps for you, and we cannot see the data they remove.
Your rights
Under the UK GDPR and the EU GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to how it is processed, and to receive it in a portable form.
In practice, we hold no personal data about you other than any support email you have sent us — so for the app itself there is nothing for us to hand over, correct or erase. Your setup codes and accessory data are in your hands, and the steps for erasing them are set out under Deleting your data. A request to us can only be answered with those instructions, because we have no ability to reach your data. If you have emailed us and want that correspondence deleted, ask and we will delete it.
We do not carry out automated decision-making or profiling.
We aim to respond to any request within one month. If you are not satisfied with our response, you can complain to the UK Information Commissioner's Office at ico.org.uk, or to the supervisory authority in your own country.
Children
PairVault is a general-purpose utility and is not directed at children. We do not knowingly collect personal data from anyone, including children under 13 — or under 16 in parts of the EEA — because the app collects none.
California and other US states
We do not sell or share personal information as those terms are defined by the California Consumer Privacy Act, and we have no personal information about app users to sell or share. We do not use personal information for cross-context behavioural advertising.
Residents of California and of other US states with comprehensive privacy laws have rights to know about, delete, and correct personal information held about them, and not to be discriminated against for exercising those rights. You can exercise them by emailing us at hello@letrixlabs.com. As above, the only personal information we are likely to hold is your own email to us.
Security
The strongest security measure here is structural: we do not hold your data, so there is no database of setup codes for anyone to breach. On your device, data is protected by iOS encryption and, if you turn it on, by Face ID, Touch ID or your passcode. In iCloud it is protected by your Apple Account, and end-to-end encrypted if you use Advanced Data Protection.
Our support mailbox is protected with a strong unique password and two-factor authentication. If a breach ever affects personal data we hold, we will report it to the Information Commissioner's Office where required and tell affected people directly.
International transfers
We operate no servers, so the app transfers nothing internationally. Your iCloud data is stored wherever Apple stores it for your account, under Apple's terms.
Support email may be processed outside the UK by our email provider. Contact form submissions travel through our website host and are checked by Cloudflare's bot-detection service before reaching our own help desk. Where any of that involves a transfer outside the UK, it relies on safeguards approved for that purpose.
Legal requests
If we were legally compelled to hand over your setup codes or accessory data, we could not do it. We have no copy and no means of obtaining one. A request of that kind would have to go to Apple, or to you.
If Dime Corporation Ltd were ever sold or wound up, this policy would continue to apply to any personal data held at the time, and we would tell you before anything changed.
Changes to this policy
If this policy changes, we will update it here and change the date at the top of the page. This page is the current version.
Contact
Questions about this policy, or about anything else, can go to hello@letrixlabs.com.
Dime Corporation Ltd, 124 City Road, London, EC1V 2NX, United Kingdom. Company number 13175488. ICO registration ZC094825.