PGPKit

privacy

Privacy Policy

Effective October 9, 2026 · covers PGPKit for iPhone and Android, and this website · Can You Grab It LLC

PGPKit collects no personal data. There is no account, no analytics, no advertising and no crash reporting. We have no servers that receive anything from the app.

What stays on your phone

Your keys are stored only on your phone. On iPhone they are in the Keychain, marked “this device only”, and are not synced to iCloud Keychain or included in iCloud or computer backups. On Android they are encrypted with an Android Keystore key that never leaves the phone, and are excluded from Google backups and device-to-device transfers. Uninstalling the app deletes them.

Saved unlocks. If you choose to remember a key’s unlock, the unlocked key is protected by the phone’s biometric lock. On iPhone it is kept in the Keychain behind Face ID or Touch ID, and iOS deletes it if you remove your passcode. On Android it is encrypted by an Android Keystore key that only a fingerprint or face match can release, and it stops working if you remove the screen lock. Either way it is never backed up, and you choose how long it lasts.

Messages and files you encrypt, decrypt, sign or verify are processed entirely on the phone. Files are written to temporary storage inside the app until you save or share them. They are cleared when you come back to the app after a few minutes, and when the app starts. A file that fails to decrypt is deleted at once.

Decrypted text. When you copy decrypted text, iPhone keeps it off your other devices’ clipboards and clears it after two minutes, and Android marks it as sensitive so it is not shown in previews. While a decrypted message is on screen, screenshots are blocked on Android, and the iPhone app switcher shows a blurred image.

What leaves your phone

Only what you choose to send. Encrypted messages, public keys and backups leave the phone only when you copy, share or save them.

Finding a key by email (PGPKit Pro). When you tap Search, the email address you typed is sent to that address’s mail domain (Web Key Directory) and to keys.openpgp.org to look up a public key. Nothing is looked up in the background.

In-app purchases are handled by Apple (App Store) or Google (Google Play). We receive no payment details. The direct-download Android version contacts no store at all.

“Made with PGPKit”. By default, messages and signatures you make carry the one line “Made with PGPKit”, which tells anyone who reads them which app you used. Turn it off in More → Privacy & data. Keys never carry it.

Clipboard and sharing

PGPKit reads the clipboard only when you tap Paste. On iPhone it may first check whether the clipboard holds text, without reading it, to offer a Paste button. Text you share to PGPKit from another app is opened in PGPKit and not kept anywhere else.

This website

pgpkit.com sets no cookies, runs no analytics or tracking scripts, and loads nothing from other companies. It is served by Cloudflare, which processes the technical data any web request carries (such as your IP address) to deliver and protect the site, under Cloudflare’s privacy policy.

Children

PGPKit does not knowingly collect information from anyone, including children.

Changes

If this policy changes, the new version will be posted here with a new effective date.

Contact

Can You Grab It LLC · support@canyougrab.it. See also the Terms of use.