Zero Trace
Privacy Policy
Last updated: October 9, 2026
Zero Trace is a private vault. Your files are encrypted on your phone before they go anywhere, and the keys stay with you. The encrypted files are stored in the cloud storage you connect, not with us. NexlyTech runs no server for Zero Trace, so we never receive your files, your password, your recovery phrase, or your keys, and we could not read your vault even if asked to.
Who We Are
Zero Trace is developed by NexlyTech ("we", "us"). This policy explains what data the app handles, where it goes, and the choices you have. It applies to the Zero Trace mobile application published on Google Play under application ID dev.nexlytech.zerotrace.
The Short Version
- There is no Zero Trace account and no Zero Trace server.
- Photos, videos, audio, documents, and journal entries are encrypted on your phone, together with their names and tags, before they are uploaded.
- The encrypted files go directly from your phone to the storage you connect: your Google Drive, and optionally Dropbox or OneDrive. Those providers hold data they cannot read.
- Your password, recovery phrase, and encryption keys are never uploaded to anyone.
- Zero Trace has no advertising, analytics, or crash-reporting SDKs. We do not sell personal data.
- If you lose your phone and your 12-word recovery phrase, no one, including us, can recover your files.
Encryption, Your Password, and Your Recovery Phrase
When you create a vault, Zero Trace generates a 12-word recovery phrase on your phone and derives your encryption key from it. Files are encrypted on the device with AES-256-GCM before upload. File names, types, sizes, dates, tags, thumbnails, and the list of what your vault contains are encrypted too.
Your master password protects a copy of the key that stays on your phone, in the secure storage provided by the operating system. Neither the password, the recovery phrase, nor any key is sent to us or stored in your cloud. The app does not keep your recovery phrase after you have written it down, so it cannot show it to you again.
This design has a cost you should understand: we cannot reset your password or restore your vault. The recovery phrase is the only way into your vault on a new phone. If you copy the phrase with the Copy button, it passes through your phone's clipboard, where other apps or the system may briefly see it.
Your Cloud Storage
Zero Trace stores your encrypted vault in cloud storage that belongs to you. Uploads and downloads go directly between your phone and the provider. NexlyTech is not in the path and receives no copy.
- Google Drive — you sign in with Google and grant the
drive.filepermission, which lets Zero Trace read and write only the files it created itself. It cannot see or change anything else in your Drive. The app receives your Google account ID, name, and email address so it can show which account is connected. - Dropbox (optional) — Zero Trace is limited to its own app folder and reads your account email to label the account.
- OneDrive (optional) — Zero Trace is limited to its own app folder and reads your account email to label the account.
The sign-in tokens these providers issue are kept in your phone's secure storage and are used only to talk to that provider. The list of your connected accounts, including their email addresses, is saved inside your vault in encrypted form so a new phone can tell you which accounts to reconnect.
Your provider can see that encrypted files exist, how many there are, how large they are, and when they were uploaded or downloaded. It cannot see what they contain or what they are called. Each provider handles that data under its own terms and privacy policy.
Google User Data
Zero Trace's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google account details and Drive access are used only to store and retrieve your own encrypted vault, on your device. They are not transferred to us or to anyone else, not used for advertising, and not used to train AI models. No person at NexlyTech can read them, because they never reach us.
What Stays on Your Device
Zero Trace keeps the following on your phone, in the app's private storage:
- Your password-protected key, and, if you turn on biometric unlock, a key held behind it
- Encrypted copies of your vault listing, thumbnails, journal entries, and any files you keep offline
- Your settings, such as theme, language, auto-lock time, and disguise options
- Temporary decrypted copies of a file while you are viewing it. They are deleted when you close the file, and cleared again whenever the vault locks or unlocks.
- Photos, scans, and voice memos you make inside the app, which wait unencrypted in the app's private storage until their upload finishes, and are then deleted. They are held this way because no other copy exists yet.
On Android, Zero Trace blocks screenshots and screen recording of the app and hides it in the recent-apps view.
Journal
Journal entries are encrypted on your phone and stored in your Google Drive like everything else. The editor cannot load anything from the internet. When you import notes from a Notion or Obsidian export, the files are read on your device and nothing is sent to those services.
Camera, Photos, Microphone, and Scanner
- In-app camera — photos you take in Zero Trace go straight into your vault and never pass through your gallery.
- Gallery import and camera backup — when you choose to import, or turn on camera backup, Zero Trace reads the photos and videos you select or newly add, encrypts them, and uploads them. Camera backup runs only while the app is open and unlocked. If you ask the app to remove originals after import, your phone asks you to confirm first.
- Voice memos — recordings are made by the app and saved to your vault. If you turn on recording with the screen off, Android shows a notification for as long as it runs.
- Document scanner — scanning runs on your device using the scanner supplied by Google Play services. Pages are not uploaded for processing. Google may collect diagnostic information about the scanner component itself under its own policy.
- Sharing — when you share a file out of the vault, a decrypted copy is handed to the app you pick, which then applies its own policy.
Wrong-Password Log and Intruder Photo
Zero Trace records the time of each wrong password attempt. If you turn on the intruder photo option, it also takes a picture with the front camera on a wrong attempt. This log is kept only on your phone in the app's private storage and is never uploaded. It is not encrypted with your vault key, because it is written at a moment when the vault is locked. You can clear it in the app.
Disguise and Decoy Vault
The calculator disguise, its PIN, the alternate app icon, and the decoy vault are set up and checked entirely on your device. The PIN is stored as a salted hash, not as digits. A decoy vault's files are encrypted and stored in your cloud the same way as your main vault.
Purchases
Zero Trace Pro is bought and billed through Google Play. We never see or store your card or bank details. The app asks Google Play on your device whether your account holds an active purchase, and keeps the answer on your phone. We run no server that records who has bought what. Manage or cancel a subscription in the Play Store under Subscriptions.
Network Connections
Zero Trace connects to the internet only for these purposes:
- Google, Dropbox, and Microsoft — signing in and transferring your encrypted files to and from the storage you connected.
- Google Play — loading plan prices and checking purchases.
The app also checks, on your device, which store installed it. That check sends nothing anywhere.
Device Permissions
Zero Trace asks for each permission only when you use the feature that needs it:
- Camera — taking photos into the vault, scanning documents, and the optional intruder photo.
- Microphone — recording voice memos.
- Photos and videos — importing from your gallery and the optional camera backup. Zero Trace does not ask for access to your music or audio files.
- Notifications — shown only while a voice memo records with the screen off.
- Biometrics — optionally unlocking the vault with your fingerprint or face. Biometric data never leaves your device's secure hardware, and Zero Trace never receives it.
- Motion sensor — if you turn on shake to lock, the app reads the accelerometer while the vault is unlocked. Readings are not stored or sent.
No Advertising or Tracking
Zero Trace contains no advertising SDK, analytics SDK, remote crash reporter, or behavioral tracker. We do not sell personal data, share it for advertising, or build advertising profiles.
Retention and Deletion
Because there is no Zero Trace account and we hold none of your data, there is nothing for us to delete on your behalf. Deletion is in your hands:
- Items you delete in the app move to Trash, stay there for 30 days, and are then removed from your cloud storage. You can empty Trash sooner.
- To remove a whole vault, delete the Zero Trace folder from your Google Drive, and the Zero Trace app folder from Dropbox or OneDrive if you connected them. Your provider may keep deleted files in its own bin for a period.
- You can withdraw the app's access at any time in your Google, Dropbox, or Microsoft account settings.
- Uninstalling the app removes everything it kept on your phone, including your keys. Encrypted files remain in your cloud storage until you delete them there.
Your Rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, or to object to or restrict its processing. Since your data stays on your device and in your own cloud storage, you exercise those rights directly, in the app and with your storage provider. You may contact us with privacy questions at the address below, and you may complain to your local data-protection authority.
Children
Zero Trace is not directed to children under 13. We do not knowingly collect personal data from children, and the app sends us no personal data from anyone.
International Data Transfers
We do not transfer your data across borders, because we do not receive it. Google, Dropbox, and Microsoft may store and process your encrypted files in their own data centers under their terms.
Changes to This Policy
If this policy changes, we will update this page and the date above. Material changes to how data is handled will be communicated in the app before they take effect.
Contact
Questions about privacy in Zero Trace? Email hello@nexlytech.dev.