Privacy Policy

Effective date: April 19, 2026

This Privacy Policy explains how Graphene Lab ("we", "us", "our") handles information in the following products and related services:

1. Scope

This policy applies to information handled through the apps listed above, related synchronization services, authentication endpoints, and support channels.

Some products can connect to a private cloud, self-hosted server, or cloud operator chosen by you or your organization. When that happens, the operator of that connected cloud may process your files and account data under its own policies. This policy covers our apps and services, not third-party systems we do not control.

2. Information We Collect

2.1 Information you provide directly or authorize through a sign-in flow

Depending on the product you use, we may collect:

2.2 Files, folders, and media you choose to sync, upload, back up, import, export, download

We may process:

File contents are encrypted on your device before transmission. We receive and store only encrypted content and do not have the ability to decrypt your files, access your encryption keys, or read your files in plaintext.

2.3 Security, authentication, and connection data

We may process data needed to authenticate you, connect your device to your cloud, and protect content, such as:

This data is stored exclusively on your device or computer. Encryption keys, passphrase-derived keys, and private keys never leave your device and are never transmitted to or accessible by us. Where supported by your operating system, sensitive security material is stored using encrypted local storage or OS-provided secure storage (such as the system keychain). If you choose to register or sign in using an email address and password, a QR code and PIN gets stored on our servers solely to deliver connection credentials to your account. This does not include your encryption keys or file content.

2.4 Technical, device, and operational data

We may process technical data needed to operate the apps, such as:

All items listed above are processed and stored locally on your device. The only data that may be transmitted externally is crash and diagnostic information, and only in products where such reporting is explicitly enabled.

3. How We Use Information

We use information to:

4. When We Share Information

We may share information:

In all cases, your file contents are never shared with any party. Due to our client-side zero-knowledge encryption architecture, sharing your file contents in readable form is technically impossible — we do not hold your encryption keys and have no ability to decrypt your files.

5. Retention and Deletion

We retain information for as long as needed to operate the relevant product, maintain security, comply with legal obligations, resolve disputes, and enforce agreements. You may also request account and data deletion at any time by contacting us at contact@graphenelab.cloud.

In practice:

6. Security

We design our products with security as a foundational principle, not an afterthought. Key measures include:

7. Your Choices

You have meaningful control over your data and how our products operate:

8. Children's Privacy

The apps are not directed to children under 13, and we do not knowingly collect personal information from children under 13.

9. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted at the policy URL with a revised effective date.

10. Contact

11. Product-Specific Terms

11.1 Graphene Photos (Android)

11.2 Explorer / Cloud Services Mobile App

11.3 Cloud Client Desktop App