decysp
privacy policy

decysp does not collect your data.

last updated 15 august 2026

There is no account, no server that holds your information, and no analytics or tracking of any kind. Everything you put into the app is stored on your device.

If you choose to pair two of your own devices, they can sync directly to each other over your local network — device to device, with no server in between and nothing sent over the internet. That is described in full below.

A small number of optional features look something up on the internet when you use them. None of them send your personal information, and each can be switched off. They are listed in full below, because a privacy policy that hides them would not be worth reading.

What decysp stores

Everything you enter — passwords, secure notes, documents, financial records, journal entries, recipes, books, assets, reminders, and career history — is written to a database on your device. It is not uploaded anywhere.

Vault contents are protected by a master password you choose. That password is never transmitted and is not recoverable: nothing exists anywhere that could reset it. Biometric unlock uses the system's Face ID and Touch ID, which never reveal your biometric data to decysp or to anyone else.

Backups are files you create and place where you choose. Once you export a backup, what happens to that file is up to you.

What leaves your device

Four features make requests to the internet. Each is listed with what is sent, who receives it, and whether it is on when you install the app.

Site icons on by default

To show a recognisable logo next to a saved login, decysp requests an icon for that site's address. The request goes to DuckDuckGo's icon service first, then to the site itself, and finally to Google's icon service if the earlier attempts fail. What is sent is the website address — for example example.com — and nothing else. No username, password, note, or balance is included. Turn this off in atelier and every logo falls back to a monogram.

Password breach check off by default

When you run a breach check, decysp calculates a fingerprint of each password and sends only the first five characters of that fingerprint to the Have I Been Pwned service, which returns a list of possible matches. The comparison happens on your device. Your passwords never leave it, and the five characters sent are not enough to identify a password or a person.

Vehicle lookup off by default

If you paste a VIN into an estate record, decysp can send it to the United States National Highway Traffic Safety Administration's public vPIC service, which returns the year, make, model and engine the manufacturer built. It returns nothing about mileage, condition, ownership or any person. One request is made, at the moment you paste.

Recipe import you start it

If you paste a recipe's web address into hearth, decysp fetches that page so it can read the ingredients and steps. The request goes to the site you named and nowhere else.

Syncing between your own devices

decysp can sync directly between two devices you own, over your local network. There is no server in the middle. Nothing is uploaded, relayed, or stored anywhere outside the two devices, and neither device can reach the other over the internet.

Sync is off until you pair

Nothing is advertised, discovered, or transmitted until you deliberately pair two devices, and nothing syncs on its own afterwards — a sync runs when you start one. Unpairing forgets the key and disables it completely.

Pairing

Both devices show the same six-digit number, and you confirm they match. That number is not a password and is not sent anywhere: it is calculated from the key exchange itself, so an attacker sitting between two devices produces a different number on each screen and you would see the mismatch and stop. A failed comparison discards the keys entirely — there is no retry that reuses anything.

After a successful pair, each device remembers the other's identity key. If a device later presents a different key, the connection is refused rather than flagged, and re-pairing has to be started deliberately.

How the transfer is protected

Each connection performs a fresh X25519 key exchange, derives keys with HKDF-SHA256 over a transcript of the whole handshake, and encrypts everything with ChaCha20-Poly1305. Because the per-connection keys are ephemeral, traffic captured today cannot be decrypted later even if a device is compromised. Each device's long-term private key is generated on that device and held in the system keystore — the Keychain on Apple platforms — and never leaves it.

What someone on the same Wi-Fi can see

Being honest about the limits of any local protocol: your devices announce themselves so they can find each other, and that announcement is a broadcast anyone on the network can observe. What they would see is that a device is running decysp, an opaque random identifier, and a port. The identifier is deliberately not your device's name — the usual default would be something like "Sarah's MacBook Pro", and that is not published here. Your device's readable name is only exchanged after the connection is encrypted.

An observer can also see that two devices are exchanging data, and roughly how much. They cannot see what module it came from, how many items there are, what any field is called, or any content.

What syncs, and what does not

Your records sync — including the contents of the password vault. That is the point of the feature, and it is why the transfer is encrypted the way it is.

Your master password does not sync. It is never transmitted, never used in the key exchange, and nothing derived from it travels. Documents and book files sync their details but not their contents: the other device knows a file exists and fetches the actual bytes only when you open it. Settings, the recycle bin, and sync's own records stay on the device that made them.

Sync history

Each device keeps a local record of when it synced, with which device, and how many items changed. It never records the names or contents of those items, and it is never transmitted.

What never leaves your device

  • Passwords, secure notes, and card details
  • Documents and files you import
  • Account balances, transactions, net worth, and credit scores
  • Journal entries and moods
  • Recipes, books, assets, reminders, and career records
  • Your master password

Analytics and tracking

There are none. decysp contains no analytics library, no crash reporting service, no advertising identifier, and no third-party software development kit that observes how you use the app. Nobody, including its developer, can see what you do inside it.

Sharing

Your information is not sold, rented, or shared, because it is never received in the first place. The only exception is the four lookups described above, and those receive a site address, a partial fingerprint, a VIN, or a web address you chose to paste.

Deleting your data

Deleting decysp from your device deletes everything it holds. There is no server-side copy to request, no account to close, and no retention period, because nothing was ever stored elsewhere. Backups you exported yourself are unaffected and remain wherever you put them, as is anything already synced to a device you paired — each device holds its own copy, and deleting the app from one does not reach the other.

Children

decysp is not directed at children and collects no information from anyone, including children.

Changes to this policy

If a future version of decysp changes what leaves your device, this page will be updated before that version ships, and the date at the top will change.

Contact

Questions about this policy or about decysp: decysp@gmail.com