SECRET FORT PRIVACY POLICY

Secret Fort Privacy Policy

JaMTec, LLC (“we,” “us,” or “our”) establishes this Privacy Policy for the handling of user information in the Secret Fort application.

1. How Secret Fort manages data

Secret Fort encrypts and manages vault data—including passwords, credit cards, bank accounts, IDs, and secure notes entered by the user—on the user's device. We operate no server that receives or stores vault data, and we do not collect vault data, master passwords, or encryption keys.

2. Access to Google user data

If a user optionally enables Google Drive integration, Secret Fort uses Google OAuth to request permission to access that user's Google Drive. Google Sign-In is used only to authorize Google Drive integration and is not used to create a Secret Fort membership account.

To let multiple devices access the same Secret Fort folder, Secret Fort requests the Google Drive drive scope, which permits read/write access to the user's entire My Drive. The app locates or creates its dedicated folder in Google Drive and reads or writes the file information and contents of encrypted containers and save-history files in that folder for backup, restoration, and synchronization across the user's devices. This permission is not used for purposes unrelated to these user-facing features.

3. Storage of Google user data

Vault data is encrypted on the user's device before it is stored in the user's own Google Drive. It is not transmitted to our servers. Google OAuth credentials retained by the app to maintain its Google Drive connection are also stored on the user's device and are not transmitted to our servers. We do not collect or store those credentials.

4. Purpose of use

Google user data is used solely to provide encrypted-data backup, restoration, and synchronization across devices through the Google Drive selected by the user. It is not used for advertising, behavioral analytics, credit assessment, sale, database creation, or the development, improvement, or training of AI or machine-learning models.

5. Sharing and disclosure

We do not sell, share, transfer, or disclose Google user data to third parties. Secret Fort does not transmit Google Drive data to our servers or to third-party servers, except where disclosure is required by law.

6. Data protection

Vault data is encrypted on the user's device before it is sent to Google Drive. Communications use the encrypted channel provided by the Google Drive API. Encryption and key-management details are available in the External Decryption Specification.

7. Retention, deletion, and revoking access

Encrypted data remains on the user's device or in the user's Google Drive until the user deletes it in Secret Fort or Google Drive. Uninstalling the app does not automatically delete files stored in Google Drive. Users can revoke Secret Fort's access at any time through their Google Account connection settings. Revoking access does not automatically delete files already stored in Google Drive; users should delete those files themselves if desired.

8. Information collected through support inquiries

If a user contacts us through the inquiry form or by email, we collect and use the name, email address, inquiry details, and other information the user submits solely to respond and provide support. See the JaMTec website Privacy Policy for details.

9. Compliance with the Google API Services User Data Policy

Secret Fort's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

10. Changes to this Policy

If we change how Google user data is used or change relevant app functionality, we will update this Policy and notify users where required.

Effective and last updated: July 20, 2026