Privacy
This page describes what data is actually processed when you use Loclavis. It describes the application as it is built. It keeps a strict line between the local file processing and the communication that running a website requires.
This version dates from:
File processing: entirely local
Encryption and decryption happen only in your browser, in a web worker on your device. Your files are not uploaded for this. File passwords and encryption keys are not sent to any server and are not stored.
- File contents do not leave your device in order to be processed.
- Passwords are not transmitted, not logged and not stored.
- Encryption keys are created locally and stay in memory on your device.
- File names sit encrypted inside the container, not in the public header.
- Protected files and restored originals are never stored on our side.
- A password never appears in an address bar and never in a link.
Password generator
The generator runs entirely in your browser. It uses the browser's random number generator for cryptographic purposes.
- Passwords are created locally on your device.
- The only source of randomness is the browser's crypto.getRandomValues.
- Generated passwords are not stored and not logged.
- We do not know your passwords, so we cannot recover them either.
What Loclavis stores on your device
Loclavis stores a small number of entries in your browser's local storage. They stay on your device and are not sent to us. The list below is complete.
| Entry | Purpose and content | Deletion |
|---|---|---|
Appearance setting ls:theme | Stores whether you chose the light or the dark appearance. The content is a single word. It is written only when you use the toggle. | Stays until you clear site data in your browser. With no entry, the page follows your system setting. |
Free protect counter ls:usage | Stores the current calendar month and how many protect operations you have run in it. Needed so the free allowance can be shown and kept. No file name, no time of day, no history. | The counter starts again at zero with every new calendar month. It can be removed at any time by clearing site data. |
Plus key ls:plus | Stores your Plus key and the result of the last licence check, so Plus stays active when you move between pages. It contains no payment details. | Removed when you remove Plus in the application or clear site data. |
Successful protect counter ls:protects | A single number. Its only job is to make sure the voluntary support note appears no earlier than the second protected result you have actually downloaded. No history, no timestamp per operation, no file names. Stored only when the voluntary support feature is switched on in this installation. It is currently switched off, so these two entries are not created at the moment. | Can be removed by clearing site data. |
Support note pause ls:donate | Stores a point in time until which the support note stays hidden. Written only when you choose to be asked later. Stored only when the voluntary support feature is switched on in this installation. It is currently switched off, so these two entries are not created at the moment. | Expires by itself after 30 days, or goes with your site data. |
What is never in there
In none of these entries, and in no other browser storage, does Loclavis put files, file contents, file names, passwords, encryption keys or protected containers.
Other kinds of storage
Loclavis uses no cookies, no session storage, no IndexedDB and no cache storage, and registers no service worker. As with any website, your browser keeps the site's own files in its ordinary HTTP cache so the application starts quickly. Only our program and styling files go there, never your files.
Assessment under German telemedia privacy law
Storing information on your device is allowed without consent only where it is strictly necessary to provide a service you expressly requested. We therefore assess each entry on its own rather than declaring them all necessary.
The appearance setting, the allowance counter and the Plus key are written only after you have triggered the matching function yourself, and that function does not work without them. We treat them as necessary for the service you asked for.
For the support note counter and its pause the assessment is not clear cut. They belong to an optional extra rather than to the core purpose of the application. We say so openly here instead of filing them under necessary without checking. As long as the feature is switched off, neither entry is created at all.
Because Loclavis uses no analytics, no advertising, no profiling and no cookies for such purposes, there is no consent banner. A banner without any technology that requires consent would protect nothing.
No analytics, no tracking
Loclavis includes no analytics, tracking, advertising or profiling services. There are no counting pixels and no third party scripts in the application. Every network connection the page makes goes to our own address; the page's security policy does not technically permit any other destination.
Search engines
So the pages can be found in search engines, we may use site management tools, for instance to confirm that this domain belongs to us. Such tools work through the domain or through an invisible entry in the page head. They are not visitor analytics, they set no cookies and they load no script into the page.
Hosting and server access data
The website is hosted by Vercel. When you open a page, your browser connects to that provider's servers. Technical access data arises in the process, which is needed to deliver the page. That is true of any website and cannot be avoided when a page is fetched over the internet.
- the IP address of your connection
- date and time of the request
- the address requested and the status code
- details your browser sends, such as its identifier and preferred language
- technical details about the connection
This processing serves the operation, delivery and security of the website. The legal basis is our legitimate interest in a working and secure service under Article 6(1)(f) of the General Data Protection Regulation.
We do not analyse this access data and do not combine it with anything else. How long the host keeps it on its systems is set by the host. We do not state a specific period here while we cannot evidence one from the actual configuration. The provider's own privacy information covers this.
The site sends the Referrer-Policy header with the value no-referrer. When you move to an external site, your browser therefore does not reveal which Loclavis page you came from.
Payment and licence
Loclavis Plus cannot currently be bought. While that is the case, no payment is processed and no payment data is handled. The section below describes how it will work once Plus is available.
Stripe is intended as the payment provider for buying Loclavis Plus. At checkout you are sent to Stripe. You enter your payment details there; we neither see nor store them. We keep no customer database of our own and create no user accounts.
- At checkout: redirect to Stripe, where you enter your payment details.
- For a licence check, only your Plus key is sent to our check function. It contains an identifier for the subscription at Stripe and nothing else.
- Never transmitted: files, file contents, file names, file passwords, encryption keys or protected containers.
- Managing the subscription and invoices run through Stripe's customer portal.
Voluntary support
Loclavis can show a voluntary note through which you may support the project. That note appears only when a destination has been set up for it. In the current version none is set up, so the note is not shown and no connection to any payment recipient exists.
If the feature is set up later: the note is an ordinary link. Nothing is appended to it, no file name, no file size, no password, no result of an operation and no identifier. Nothing is requested from the provider until you click the link yourself. We will then extend this statement to name the actual provider.
Services we use
- Vercel: Hosting and delivery of the website. https://vercel.com/legal/privacy-policy
- Stripe: Payment processing, subscription management and checking subscription status. Prepared but not yet in use, because Plus cannot be bought yet. https://stripe.com/privacy
How far these statements reach
The statement about local processing refers to the processing of your files. It does not mean that running the website processes no data at all. Fetching the page itself creates technical access data at the host, and the licence check happens online.
Behaviour without a connection
File processing needs no connection once the page has loaded. You can disconnect and still protect and decrypt files. Loclavis is not an installed offline application, though: no service worker is registered, and reloading the page without a connection does not work.
Your rights
Under the General Data Protection Regulation you have the right to access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with a supervisory authority. Please write to the address below. Note that we hold no data at all about the files and passwords processed locally on your device, so we cannot give information about those.
Controller
Tom Silas Helmkec/o Online-Impressum 4746
Europaring 90
53757 Sankt Augustin
Germany
tshfm78@gmail.com
This text describes the technical state of the application after a review of the source code. It has not been reviewed by a lawyer and is not legal advice.