Icono de Shield

Shield

Protect your identity before sharing a document.

Shield Privacy Policy

Last updated: 2026-07-20

This policy explains how Shield, developed by Lester Romero Bernardo (RomeroDev), handles information when you use the application. Apple independently processes App Store purchases, Apple Account data, and iCloud services under its own policies.

1. On-device processing

Document import, camera capture, scanning, image adjustments, OCR, masking, and export run on your device. Shield does not create advertising profiles or track users across apps or websites.

2. Local storage and security

Imported originals, working files, render caches, and bounded local telemetry are encrypted at rest using device-bound keys protected by Keychain and iOS data protection. The Vault uses a separate device-bound key and configured authentication. Device-only keys are not designed to migrate to another device.

3. Optional iCloud index

If a Pro user explicitly enables iCloud sync, Shield stores only a minimized technical project index in that user's private CloudKit database. Document images, PDF content, OCR text, user-entered titles, and Vault state remain local. Apple processes private CloudKit data as the user's iCloud provider.

4. Permissions and Files providers

Camera, Photos, biometrics, Files, Share Sheet, and iCloud access are used only for features the user requests and remain subject to system controls. When a user chooses a third-party storage provider through Apple's Files picker, Shield receives only the selected file and stores no provider OAuth token.

5. Diagnostics and product analytics

Firebase Analytics and Firebase Crashlytics collect a device identifier, product-interaction events, crash reports, performance data, and other technical diagnostic metadata to measure product use and improve stability. RevenueCat processes anonymous purchase history to validate purchases and enable entitlements. This data is not used for advertising or cross-app tracking. Shield does not send document titles, OCR text, filenames, URLs, document IDs, PIN state, or image content to these services.

6. Retention and deletion

Projects remain until the user deletes them or selects Delete all documents. Temporary exports are protected and removed when the export or share flow ends. Removing the app deletes its local container subject to iOS and backup behavior. Private CloudKit records may require separate deletion or iCloud account controls.

7. Choices and rights

Users can revoke optional permissions in iOS Settings, disable iCloud index sync, and delete projects. Because core document content stays on device, the developer normally cannot access, export, correct, or recover it.

Where applicable, you may request access, rectification, deletion, restriction, objection, portability, or withdrawal of consent by writing to the contact below. You may also lodge a complaint with the Spanish Data Protection Agency or the competent authority where you live.

8. Children

Shield is a general document utility and is not directed to children. Do not process a child's sensitive information without lawful authority and appropriate safeguards.

9. Security and limitations

No security system eliminates every risk. Users must protect their device passcode and Apple Account, retain required originals, verify recipients, and review every exported page. Automated recognition can miss sensitive information.

10. Changes and contact

Material changes will be reflected by a new effective date and, when appropriate, an in-app notice.

Data controller: **Lester Romero Bernardo (RomeroDev)**

Address: **Calle Madre Juana María Condesa Lluch 6, Valencia, Spain**

Privacy contact: **romerodev.app+shield@gmail.com**