FileGuard is built so your personal data never reaches us in the first place. No analytics, no tracking, no file contents on our servers — your files, contacts and policies stay on your device.
Most privacy policies explain everything a company collects about you. Ours mostly explains what we deliberately don't.
CYOC ("CYOC", "we", "us") makes FileGuard, an app that seals a file so only the right person, in the right moment, can open it. The entire product is designed around data minimisation: we do not build profiles, we do not run analytics, and we do not keep your personal data. Where the law (including the EU General Data Protection Regulation, "GDPR") gives you rights over your data, this policy explains how they apply — and why, in most cases, we simply hold nothing to act on.
This is the plain-language summary. The numbered clauses below are the full policy.
This policy is issued by CYOC, the provider of the FileGuard application and the operator of this website. For the purposes of the GDPR and equivalent data-protection laws, CYOC is the data controller for the limited processing described here.
It covers the FileGuard mobile app, the .ped sealed-document format, our security-alert service (Watchman), and the pages on this website. It does not cover third-party services you may use to send a file (your messaging app, email provider or cloud drive), which have their own policies.
You can reach us at any time at info@cyoc.eu.
Privacy is not a setting we added to FileGuard; it is the reason FileGuard exists. Because we designed the product not to gather personal data, there is very little for this policy to explain about "what we collect" — the honest answer, for the overwhelming majority of information, is nothing.
We do not collect, receive or store:
We do not sell, rent or trade personal data, because we do not hold it.
To do its job, FileGuard processes certain information locally, on your device. This information is not transmitted to us:
Where an organisation runs its own Remote Release Authority to verify opens, that check is handled by that organisation's infrastructure under its own policy — not by CYOC.
There are a few narrow situations where information reaches us, always because you initiated it:
If you write to info@cyoc.eu or ask to join the waitlist, we receive the email address and any message you send. We use it only to reply to you and, for the waitlist, to let you know when FileGuard is available. We do not add you to marketing lists you didn't ask for.
FileGuard does not send crash or diagnostic data automatically. If something goes wrong, you can choose to export a report and send it to us; it travels only because you decided to send it.
Push notifications act as a doorbell only — they wake the app. They do not carry your file, your contacts or the security event itself. Delivery relies on your operating system's push service (Apple or Google), which handles the transport.
If and when FileGuard is offered as a paid app, payments are processed by the app store you use (such as the Apple App Store or Google Play) under their own terms and privacy policies. Those stores handle your payment details. We do not receive or store your card number or bank details, and we hold no transaction data that identifies you personally.
For the limited processing in clause 5, and where the GDPR applies, we rely on:
Because we hold almost nothing, there is almost nothing to retain. Correspondence you send us is kept only as long as needed to handle your request and then deleted. Waitlist details are removed once the waitlist has served its purpose, or sooner if you ask. On-device data lives entirely on your device and is removed when you delete it or uninstall the app.
We do not share personal data with third parties for their own purposes, and we never sell it. The only external parties involved are the infrastructure providers that make the basics work — for example an email provider to receive your message, and the operating-system push services that deliver notifications. Each acts under its own terms, and we share with them only the minimum necessary.
We may disclose information if strictly required by law, but we cannot produce data we do not hold.
Your files, contacts and policies stay on your device and are not transferred by us across borders. For the limited correspondence in clause 5, where any provider processes data outside your region, we use providers that offer appropriate safeguards recognised under applicable law (such as the GDPR's standard contractual clauses).
This website does not use tracking or advertising cookies, and it runs no third-party analytics. We do not build a profile of your visit. Any strictly necessary storage is limited to what is required for the page to function.
Where the GDPR or similar laws apply, you have the right to access, correct, erase, restrict or object to the processing of your personal data, to data portability, and to withdraw consent at any time. To exercise any of these, email info@cyoc.eu.
In practice, because we do not keep personal data, most requests we receive we can answer simply: there is no profile, no file store and no account for us to hand over, correct or delete. Where we do hold something — such as an email you sent us — we will act on your request promptly.
You also have the right to lodge a complaint with your local data-protection supervisory authority if you believe your rights have not been respected.
FileGuard is not directed at children, and we do not knowingly collect personal data from children. As we do not keep personal data in general, this holds for users of every age.
Not collecting data is itself our strongest protection — data we never hold cannot be breached, leaked or subpoenaed from us. On top of that, FileGuard relies on on-device cryptography to protect the files you seal, and keys are generated and stored on your device. No method of storage or transmission is ever perfectly secure, but minimising what exists is how we keep the risk to you as low as it can be.
FileGuard is in active development, and this policy may be updated as the product grows. When we make a material change, we will update the effective date at the top of this page and, where appropriate, note the change here. Continued use of FileGuard after an update means you accept the revised policy.
For any privacy question, request, or to exercise your rights, contact us: