legal
privacy
lockbox is built around intimacy: your camera roll stays yours unless you choose to share a live nine. this page says what we collect, where it lives, and how to get it deleted.
the short version
- your photo library is read on your iphone so you can curate. we do not upload your full camera roll.
- keeps, captions, and cleanup stats stay on your device by default.
- if you request the beta, we store your email so we can send an invite.
- if you publish a live pack, only the nine you chose (posters, captions, display name) leave your phone.
- we do not sell data. we do not run ads. we do not add third-party trackers to this site.
who we are
lockbox is a product of polarity lab (rhode island, usa). contact: [email protected].
what we collect
on this website
-
beta waitlist. when you submit the form, we store your email, a source tag
(for example
lockbox-landing), and the time you joined. that row lives in our cosmos database on cloudflare. we may ping our internal slack channel when someone joins so we can send invites. - operational logs. cloudflare may retain short-lived request metadata (ip, user-agent, path, status) for security and reliability. we do not use that for advertising.
- fonts. this site loads ibm plex mono from google fonts. that request is subject to google’s privacy policy.
in the ios app
- photo library access. lockbox asks permission to read (and, when needed, write) your photos so you can swipe, caption, keep, and delete. originals stay in the photos app on your device. you confirm every delete.
- on-device preferences. favorites, captions, session stats, cleanup filters, and similar settings are stored locally on your phone (for example in app storage / userdefaults).
- live pack (optional). if you publish or refresh a live nine, we store for that pack: display name, share token, visibility, slot metadata (caption, media type, optional place/time labels), and poster images (compressed stills, not your full camera roll). posters live in cloudflare r2; pack metadata lives in our cosmos database.
- follows (when enabled). if you follow another person’s live nine, we store that follow relationship between accounts so your feed can load their packs.
what we do not collect
- your entire camera roll, or private keeps you never put in the nine.
- advertising identifiers, fingerprinting scripts, or cross-site trackers on this site.
- likes or engagement scores on your nine. lockbox is not a scoreboard.
- payment card data (there is no in-app purchase on the beta landing).
how we use it
- send beta invites and product updates you asked for.
- show your live nine to people who have your link (or who you let follow you).
- keep the product working, secure, and honest about bugs.
- study aggregated patterns (for example how many people join the waitlist), not to read private camera-roll contents.
we do not sell your data. we do not share it with advertisers.
where it lives
the website and live-pack services run on cloudflare (pages, workers, d1, r2). photo cleanup happens on your device. apple’s photos framework never sends your library to us unless you explicitly publish pack posters.
sharing and access
- you. through the app and any live pack link you create or rotate.
- people you invite. anyone with your current share link can see the published nine and public captions. rotate the link to cut off old recipients.
- polarity lab. we do not browse private camera rolls. staff access to waitlist or pack records is limited to invites, support, security, deletion, and legal requests.
- infrastructure. cloudflare processes data as our host under their terms.
export and deletion
- waitlist. email [email protected] from the address you used and ask to be removed. we delete the row.
- on-device data. delete the app to clear local lockbox state on that device. photos you deleted from the library follow apple’s photos recovery rules.
- live pack. email us from the account you used, or use in-app controls when available, to remove the pack and posters. we aim to complete account or pack deletion within 7 days; backups age out within 30 days.
if you are in the eu or uk and want to exercise gdpr / uk-gdpr rights (access, rectification, erasure, portability, restriction, objection), email the same address. we will respond within 30 days.
children
lockbox is not directed at children under 13. if you believe a child submitted an email or published a pack, contact us and we will delete it.
security
traffic uses https. pack media keys are scoped per account. report a vulnerability privately to [email protected].
changes
if this policy changes in a material way, we will update the date on this page and, when practical, note it in the product or beta email. the current version is always at lockbox.polarity-lab.com/privacy.
contact
privacy questions: [email protected].