Privacy Policy

I'm Kinko. · 金庫です。

Effective 31 August 2026 · Last updated 31 August 2026

This policy describes how the iOS application I'm Kinko. ("the app") handles your information. The app is made by Paul Quilichini ("I", "me"), an individual developer.

The short version. I do not run a server that stores your passwords. Your vault is encrypted on your iPhone and saved to your own Google Drive as unreadable ciphertext. I have no ability to read it. The app contains no analytics, no tracking, and no advertising, and I do not sell or share your information with anyone.

1. Information stored on your device

The app stores the following in your device's app storage and Keychain:

  • Your vault contents — the titles, usernames, passwords, website addresses, and notes you enter. These are encrypted with AES-GCM using a 256-bit key before being written to storage.
  • Your vault keys — stored in the iOS Keychain. See section 5.
  • A device identity key — a Curve25519 private key generated on the device. It never leaves the device, is never backed up to iCloud, and is not transmitted anywhere.
  • A local index — vault names and sync timestamps, itself encrypted.

This information is not transmitted to me.

2. Information stored in your Google Drive

When you create or edit a vault, the app uploads the encrypted vault file to a folder named "I'm Kinko" in your own Google Drive. The file contains only ciphertext and the cryptographic headers needed to open it on an authorized device. Google stores this file on your behalf under your own Google account and Google's own privacy policy; the contents are not readable by Google, by me, or by anyone without a key held on one of your devices.

The app requests only the drive.file permission. This is Google's narrowest Drive scope: it grants access only to files the app itself created. The app cannot see, read, or modify any other file or folder in your Drive.

3. Information from your Google account

When you connect a Google account, the app receives, through Google Sign-In:

  • your Google account identifier (the OpenID "subject"),
  • your email address,
  • your display name.

These are used to identify which vaults and devices belong to you, and to let another person address a shared vault to you by email address. The app never receives, requests, or stores your Google password.

4. The key directory

To let you share a vault with another person, and to let your own additional devices open your vaults, the app uses a small directory service that I operate. It is a public-key directory, not a vault service. It stores only:

  • your account provider and verified account identifier,
  • your email address and display name,
  • the public key of each device you have registered,
  • creation and last-seen timestamps, and whether a device has been revoked.

The directory never receives and never stores vault files, vault contents, vault keys, recovery kits, your Google or Microsoft password, or OAuth refresh tokens. It is technically incapable of decrypting a vault, because the keys required to do so are never sent to it.

5. iCloud Keychain

Your vault keys are stored in the iOS Keychain and are marked for synchronization through iCloud Keychain. This is what allows you to reinstall the app, or set up a replacement iPhone, and still open vaults already stored in your Drive. iCloud Keychain is operated by Apple and is itself end-to-end encrypted; Apple's handling of it is governed by Apple's privacy policy. Your device identity private key is deliberately excluded from this synchronization and never leaves the device it was created on.

6. Sharing a vault with another person

If you choose to share a vault, the vault key is encrypted individually to the public key of each device belonging to the person you select, and the encrypted file is shared through your cloud storage provider. The recipient's email address is used to look them up in the key directory. Sharing only ever happens because you initiated it.

7. What the app does not do

  • No analytics, telemetry, crash reporting, or usage tracking of any kind.
  • No advertising, and no advertising identifiers.
  • No selling, renting, or trading of your information. Ever.
  • No profiling and no automated decision-making.
  • No access to your contacts, photos, location, or any Drive file the app did not create.

These pages on paulq.jp/imkinko also run no analytics and set no cookies.

8. Google API Services User Data Policy

I'm Kinko.'s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: data obtained through Google Drive is used solely to provide the vault storage and sync features visible to you in the app. It is not transferred to others except as needed to provide those features at your direction, is not used for advertising, and is not read by humans.

9. Retention and deletion

You are in control of every copy:

  • On your device — deleting the app removes the local vault files and its Keychain items on that device.
  • In your Drive — delete the "I'm Kinko" folder from Google Drive, and empty your Drive trash.
  • In iCloud Keychain — remove the saved I'm Kinko. entries in iOS Settings, or turn off iCloud Keychain.
  • Access — revoke the app's access to your Google account at myaccount.google.com/permissions.
  • Directory record — email me at the address below to have your directory record and registered device public keys deleted. I will action this within 30 days.

10. Security

Vault contents are encrypted with AES-GCM. Vault keys shared to a device are wrapped to that device's Curve25519 public key. Where a vault is protected by a password you choose, that password is put through PBKDF2-HMAC-SHA256 rather than being stored. All network traffic uses HTTPS.

No system is perfect, and I cannot guarantee absolute security. Because the design gives me no access to your keys, I also cannot recover your vault for you if you lose every device and every key. Please keep a Recovery Kit.

11. Children

The app is not directed at children under 13, and I do not knowingly collect information from them.

12. Your rights

Because I hold almost nothing about you, most requests resolve quickly. You may ask me what the directory holds about you, ask for it to be corrected, or ask for it to be deleted, by writing to the address below.

13. Changes to this policy

If this policy changes materially, I will update the date at the top of this page and, where the change affects how your data is handled, note it in the app.

14. Contact

Paul Quilichini
paul.quilichini@gmail.com
paulq.jp/imkinko