- Everything you save stays encrypted on your phone.
- The app has no internet permission — it cannot send your data anywhere.
- We do not collect, track, profile, or sell any personal data.
- You can erase everything from within the app at any time.
This Privacy Policy explains how MokaPass (the "App"), developed by Moka Software (Mohamad Khalil), handles your information. By installing or using the App, you agree to this policy. If you do not agree, please do not use the App.
1. Information We Collect
We do not collect any personal data. MokaPass has no user accounts, no analytics, no advertising, and no tracking technologies. We do not operate any servers that receive your information. The App is not granted internet access, so it is technically incapable of transmitting your data off your device.
The content you create inside the App — such as login credentials, notes, website labels, and images — is entered by you and stored only on your device. We never see it.
2. How Your Data Is Stored
- All vault data is encrypted and stored locally in the App's private storage on your device.
- Your unlock secret (PIN or password) is never stored in plain text; it is salted and hashed using PBKDF2 before being stored, and the stored value is additionally encrypted.
- Images you add are encrypted at rest in the App's private storage.
- Automatic system backup and device-to-device transfer of the App's data are disabled, so your encrypted vault is not copied to cloud backups.
3. Permissions We Request and Why
The App requests only the permissions needed for features you choose to use. None of them are used to collect or transmit personal data.
Biometric (Fingerprint / Face)
Used only to unlock the App through the Android biometric prompt. Your biometric data is handled entirely by the Android operating system; the App never accesses, receives, or stores it.
Camera
Used only when you choose to capture a photo to store inside your encrypted vault (for example, a photo of a card or document). Images stay on your device.
Photos / Files
Used only when you choose to import an existing image into your vault. The selected image is copied into the App's encrypted private storage.
Bluetooth (Connect, Scan, Advertise)
Used only when you start the optional device-to-device sync, so the App can find the other phone and transfer your vault directly between your devices. No data passes through any server.
Location (Android 11 and older only)
On older Android versions, the operating system requires the location permission in order to scan for nearby Bluetooth devices. The App uses it solely to enable Bluetooth discovery for sync. It does not collect, use, store, or share your geographic location. On Android 12 and newer this permission is not used.
4. Device-to-Device Sync
MokaPass offers an optional feature to sync your vault between your own devices over a direct Bluetooth connection. When you use it:
- The transfer happens directly between your two devices — never through our servers (we have none).
- The transferred data is end-to-end encrypted using a one-time pairing code that you enter on both devices.
- Sync only occurs when you explicitly start it.
5. Data Sharing
We do not share, sell, rent, or disclose your data to anyone, because we never receive it in the first place. The App contains no third-party SDKs, advertising networks, or analytics providers.
6. Data Retention and Deletion
Your data remains on your device until you delete it. You are in full control:
- Delete individual entries at any time within the App.
- Use Settings → Erase all data to permanently and irreversibly delete your entire vault, stored images, and unlock configuration from the device.
- Uninstalling the App removes all of its locally stored data.
Because your data is encrypted locally and never leaves your device, we cannot recover it for you. If you forget your unlock PIN/password, the data cannot be restored.
7. Security
We use industry-standard measures to protect your data on-device, including AES-GCM encryption, PBKDF2 key derivation, and secure-screen protection that prevents your vault from appearing in screenshots and the recent-apps preview. No method of storage is 100% secure, but keeping your data on-device and offline significantly reduces exposure.
8. Children's Privacy
MokaPass is not directed to children under the age of 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect any information from children. As the App collects no data at all, it poses no data-collection risk to any user.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Continued use of the App after changes take effect constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions about this Privacy Policy, please contact us:
- Email: support@mkhalil.net
- Website: mkhalil.net
- Developer: Moka Software (Mohamad Khalil)