Visual Locker Privacy Policy

Private by design, explained plainly.

Who operates Visual Locker

Visual Locker is operated by Handlr Ventures Ltd, trading as Handlr AI (“Handlr AI”, “we”, “us” or “our”), registered in England, company number 12786304. Our ICO registration reference is ZB451786.

Privacy and support questions can be sent to app-support@handlr.ai.

Your vault data

Visual Locker stores imported images, videos, thumbnails, names, dates, source details and folder relationships in its private app storage on your device. Vault files and the vault catalogue are encrypted at rest.

The app has no user account, application server, API, CloudKit database or remote media library. Handlr AI cannot view your vault, retrieve its encryption key or recover a forgotten device passcode or vault password. Your media is decrypted in memory only when needed while the vault is unlocked.

Every Visual Locker installation has its own vault and encryption key. Media, folders, filenames, settings and deletions do not sync between an Apple Vision Pro, iPhone or iPad. Restoring Pro changes access only and never transfers vault data.

Standard Unlock uses Apple’s system authentication and permits the device's biometric method or passcode. Private Password supplies the vault password locally to Apple security controls. Handlr AI never receives it and Visual Locker does not store it as readable app data. An optional Face ID, Touch ID or Optic ID shortcut in Private Password mode does not permit device-passcode fallback.

Vault passwords and access changes

A vault password is accepted only on the device to unlock or update the protected encryption-key record. It is not included in product analytics, diagnostics, feedback or support data. Password fields support paste and password managers.

Handlr AI cannot recover, reveal or reset a forgotten vault password. If the biometric shortcut becomes unavailable, the vault password remains the fallback. If neither route is available, you need another copy you can restore or must reset the vault, which deletes its encrypted contents and access records.

Photos access, saving and deletion

You choose which items Visual Locker can import using Apple’s Photos controls. Imported items are copied into the encrypted vault. An original remains in Photos unless you separately choose to remove it, and Photos may then retain it in Recently Deleted under Apple’s controls.

When you choose Save to Photos, the app reconstructs and sends the selected item to Photos. Any temporary file needed for a large item uses device file protection, is excluded from backup and is cleaned up after the operation or on the next launch.

Apple device backup

The encrypted vault is excluded from Apple device backup by default. If you explicitly enable Apple device backup in Settings, Visual Locker makes the encrypted vault and recovery information eligible for Apple’s device backup. Apple controls when and whether that backup completes. Visual Locker cannot inspect or guarantee it.

Standard Unlock recovery uses Apple system authentication. Private Password recovery remains protected by the vault password. Its optional biometric shortcut is device-only and is not restored as a backup fallback.

Enabling this setting does not confirm that a current, complete or recoverable backup exists. An Apple backup or restore may be delayed, unavailable, incomplete or unsuccessful, and reinstalling Visual Locker by itself cannot retrieve an individual app backup. Apple device backup is not Visual Locker sync and does not keep vaults on different devices matched.

Deletion, device loss and recovery

Deleting or reinstalling Visual Locker normally removes its local app container. Resetting the vault deliberately destroys its local encryption key and encrypted content. Erasing, losing, replacing, damaging or having your Apple device serviced may also make device-only content unavailable. Handlr AI has no remote copy or recovery key and cannot restore that content for you.

These events can cause complete and permanent loss of every item stored only in Visual Locker. Keep an independent copy of important images and videos in Photos or another backup location you control, and verify it before removing originals, resetting the vault, deleting the app, erasing, replacing or servicing the device.

Purchases and entitlement checks

Visual Locker uses Apple’s App Store and RevenueCat to offer and restore the permanent Pro upgrade. RevenueCat processes an anonymous app user identifier, purchase and entitlement status, product information and basic app and device context needed to provide that functionality.

Restore Purchases asks Apple and RevenueCat to check for an eligible Pro purchase. A fresh installation may remain on Free until you choose it. Restoration changes the entitlement only. Visual Locker does not turn your Apple Account into an app account or use it to sync vault data.

RevenueCat does not receive vault media, thumbnails, filenames, folder names, search terms or vault identifiers. Visual Locker does not reuse RevenueCat’s identifier for analytics or to identify you across other services.

Essential feature-availability checks on Apple Vision Pro

On Apple Vision Pro, Visual Locker uses PostHog remote configuration to keep incomplete Spatial features unavailable. These essential checks use a pseudonymous installation identifier plus basic request, app version, operating system and device context. They can occur even when Product Analytics is switched off.

These checks do not send product-usage events or vault content. They are technically separate from Product Analytics and do not turn analytics back on.

Product Analytics

Product Analytics is on by default. Visual Locker sends content-free product events to PostHog using pseudonymous installation and session identifiers. These events help us understand app installations, updates and sessions, fixed screen navigation, feature use, imports, item viewing by broad media type, search use without the search term, sorting, filters, folder organisation, exporting, Settings, Support, Pro purchases and coarse performance and reliability outcomes.

Analytics may include the app version, build, operating system version, device family, platform, language, environment, distribution channel, fixed action and screen names, broad media type, documented count and duration bands and fixed outcome categories. Import events can include whether a request contains photos, videos or both, broad item-count and known-size bands, how much size information was available, broad preparation-time bands, progress availability, the terminal stage and a fixed failure category. They do not include photos, videos, thumbnails, filenames, folder names, entered search text, feedback text, file paths, Photos identifiers, vault identifiers, item identifiers, exact byte counts, exact import durations, file types, codecs, authentication information, screenshots, screen recordings or arbitrary error descriptions.

Automatic user-interface autocapture, person profiles and session replay are disabled. We do not identify you by name or use this information for advertising or tracking across other companies’ apps or websites. At the date of this policy, PostHog’s live projects report an 84-month retention setting with enforcement disabled, so 84 months is not a confirmed maximum. We will not release this default-on change until 12-month enforced retention has been applied and confirmed, or a different supported period has completed legal and privacy review and is stated here.

Crash and Reliability Diagnostics

Crash and Reliability Diagnostics is on by default. Sentry receives scrubbed crash, fully blocking app-hang and handled technical-failure reports, plus release-health information. Reports can include useful technical context such as stack frames, exception type, threads, device family, operating system, app version, build, environment and distribution channel.

The app disables session replay, screenshots, screen recording, view hierarchy, attachments, personal identity, profiling, automatic user-interaction capture and file or network body capture. It permits safe app-lifecycle and content-free technical breadcrumbs. A scrubber removes private paths, filenames, folder names, search terms, feedback text, vault identifiers and other user-entered values before a report is sent. Our intended Sentry retention limit is 90 days, or a shorter period if that is the limit supported by our service plan. The live setting must be confirmed before this default-on diagnostics change is released.

Anonymous product feedback

Send Product Feedback is always available in Settings, whether or not Product Analytics is switched on. Sending the form authorises only that submission. It does not change your Product Analytics or Crash and Reliability Diagnostics settings.

The submission contains the response, survey identifiers, app version and build, environment, distribution channel, operating-system platform and version, the app's effective language and a fresh anonymous submission reference. It does not contain your contact details, exact hardware model or anything from your vault. Product feedback is not a Support request and we cannot reply because we do not know who sent it. Please do not include personal information or vault content.

After a successful submission, the app displays a copyable privacy reference that can be included in a deletion enquiry. Feedback is used to understand and improve the app. It is not used for advertising or tracking.

Your choices

Product Analytics and Crash and Reliability Diagnostics are on by default and are controlled independently. You can switch either one off at any time in Visual Locker under Settings and Privacy. Turning a setting off stops future collection for that category. Analytics events already placed in PostHog's delivery queue follow its normal delivery behaviour. Information already received by PostHog or Sentry remains subject to the provider retention described above and is not automatically erased by switching a service off, resetting the vault or reinstalling the app.

Anonymous product feedback is separate from both choices. Only pressing Send transmits the text entered in that form.

A full vault reset deletes the local vault and rotates the analytics identity without changing either privacy setting. Deleting and reinstalling the app returns analytics and diagnostics to their default-on state, subject to any Apple device backup you chose to enable and Apple’s own retention controls. Neither action erases provider-held records.

Support email

If you email support, we receive your email address and the information you choose to include. This is not collected by the app automatically. Please do not send private vault media, screenshots, filenames, folder names, passcodes, vault passwords or purchase credentials.

We use support correspondence to respond, investigate the issue and maintain necessary business records. We keep it only for as long as needed for those purposes and legal obligations.

Service providers and international processing

Apple and RevenueCat support purchases and entitlement. PostHog provides essential Spatial feature configuration on Apple Vision Pro, Product Analytics and one-off anonymous product-feedback submission. Sentry provides Crash and Reliability Diagnostics. Our email provider processes support messages. These providers may process limited information in countries outside yours under their own safeguards and our service arrangements.

Your privacy rights

Depending on where you live, you may have rights over personal information we hold, including rights to access, correct, delete, restrict or object to certain processing. Most Visual Locker content remains on your device and is not accessible to Handlr AI.

Contact app-support@handlr.ai to make a request. You may also complain to the UK Information Commissioner’s Office or your local supervisory authority.

Website privacy

This page is hosted on the Handlr AI website. Website analytics only loads after the visitor accepts analytics cookies. See the Handlr AI website privacy policy or use the cookie control in the footer.

Contact and company details

Handlr Ventures Ltd, trading as Handlr AI. Registered address: 82 Wandsworth Bridge Road, London, SW6 2TF, United Kingdom. Email: app-support@handlr.ai.