A promise kept in brass: the shortest privacy policy is a feature list of nothing.
If you read only one line of this charter, let it be this: Hyls has no ability to collect anything about you. The app contains no networking code that sends your data anywhere, no analytics kit, no crash reporter that ships your files, no advertising identifier, no account system, and no server of ours to receive any of it. The hall is a closed room on your phone; the doors open inward.
Everything below explains, feature by feature, what the app touches locally while you use it -- because "we collect nothing" is easy to write and harder to deserve, and you are entitled to see the receipts.
A plain accounting of the things an app might take, and what Hyls actually takes:
| Thing | Hyls takes it? |
|---|---|
| Name, email, phone number | never |
| Account of any kind | never |
| Location, past or present | never |
| Contacts, calendar, health | never |
| Advertising or device identifiers | never |
| Usage analytics or crash logs sent out | never |
| Your photos or recordings | never leave |
| Your secret codes | never leave |
| Anything else about you | there is no anything else |
The column on the right is not a policy aspiration. It is a description of the machine: there is no wire for any of it to travel down.
While you use Hyls, the app handles four kinds of content, all of them yours, all of them kept in the app's private sandbox folder on your device: the ledger file (coffer names, mottos, codes, tuning knobs, snapshot titles and notes), the photographs you pressed into coffers (stored as downscaled copies), the voice whispers you recorded, and nothing else. The operating system walls this folder off from every other app and from any website.
When you press a photograph from your library, the app writes its own copy at a friendly size and then forgets the original ever existed -- your camera roll keeps its untouched original, and Hyls keeps no index of what you did not choose. The picker you see for library photos is the system's own; the app never browses your album, only receives the single picture you point at.
Hyls asks the system for camera access the first moment you tap WITH CAMERA or RESHOOT -- not before, not at launch, not ever again once granted. The camera's output goes one place: straight into the snapshot you are composing, as a photograph file in the app's own folder. No preview is recorded, no frame is kept until you seal it, and nothing is transmitted anywhere at any time.
Say no to the permission and the camera doors simply stay shut; the rest of the hall works exactly as before. You may change your mind later in the system settings, and the app obeys whatever state you leave it in.
The microphone is woken only when you deliberately press a voice whisper on a compose or amend desk, and only long enough to capture the single take you asked for -- up to thirty seconds. The audio is written as a small file beside the snapshot it belongs to. The moment the take is sealed or discarded, the microphone is released; there is no background listening, no voice processing sent anywhere, no transcription by some distant machine. What you whisper stays between you and the coffer.
Decline the permission and whispers are unavailable -- every other door, drawer, and dial in the hall is untouched.
When you press FROM LIBRARY or SWAP PHOTO, the system's own picker slides up over your albums. You browse in the system's interface, and the app receives exactly one thing: the picture you tapped, copied into the coffer. The app never sees the rest of your library, never learns what you looked at and passed over, and never keeps a list of what you chose not to press.
Because the picker is the system's, on newer devices this path works without granting the app any standing access to your library at all -- the strongest privacy the shelf can offer: you share one photo by handing it over, not by handing over the album.
The RELEASE TO LIBRARY door works in the opposite direction: a snapshot photograph you kept inside a coffer is written back out into your system photo library, where it joins your camera roll and becomes fully yours to share with anything. The app asks the system for add-only permission the first time you try it, and only that -- adding, not reading, not browsing, not removing. Say no and the release door rests; nothing else in the hall depends on it.
Coffer names, mottos, snapshot titles, and the kept notes you write are stored as plain text in the local ledger file, on your device, nowhere else. They are never read by anyone but you, never sent for spell-checking to some distant service, never used to train anything. The keyboard you type with is the system's own and follows the system's own rules; the app adds nothing to that.
Each coffer's four-digit code is stored in the local ledger and checked locally, every unlock, on your device. There is no copy in any vault of ours because there is no vault. This is the privacy feature that costs something: if you forget a code, nobody -- including us -- can recover it or open the door for you. The in-app reset rite always demands the old code first, so holding a phone is not the same as holding its secrets. We consider that trade worth making, and we would rather tell you plainly than apologize later.
The observatory counts your keeping -- snapshots, coffers, doors swung open, favored motif, milestone lanterns lit. Every figure is computed from the local ledger the moment the page appears and is never stored for analysis, never compared against other people, never transmitted. The door-open tally is a number your own device keeps for your own amusement, as private as a diary's margin notes.
For the record, these permissions do not exist anywhere in Hyls and never will: location, contacts, calendar, reminders, health, home kit, bluetooth, local network, or any notification permission beyond what the system itself shows for downloads. The app also never reads your other apps, your files outside its sandbox, your clipboard, or your motion sensors. If a future version ever needs a new door to the system, this charter gains a new roll explaining it before the feature ships.
Hyls embeds no third-party code whatsoever -- no analytics kit, no ad kit, no social kit, no crash-reporting courier. The only outside machinery the app touches is the operating system's own: the photo picker and library door provided by the system's Photos frameworks, the camera and microphone provided by the system's audio and video frameworks, and the app store that delivered the app. Those behave the way the platform maker describes, under the platform's own privacy labels; Hyls adds nothing to their view of you and routes nothing through them.
Hyls collects nothing, so there is no collection to age-limit -- a child's coffer is as unknown to us as an adult's. The app is nonetheless designed for grown-up habits: private doors, no in-app purchases, no links outward, no content from strangers. If a household shares a device, the strongbox logic still holds: doors answer to their own codes, and the outermost door is the phone's own lock. That outer door is the parents' to set and keep.
When you choose to back up your device with the system's built-in backup, the operating system may carry the app's sandbox -- the hall, its coffers, its whispers -- into that backup, and may restore it onto a replacement phone. That journey happens entirely under the system's encryption and your account with the platform maker; the smith holds no key to it and receives no copy. If you prefer the hall never to leave the device it lives on, exclude the app from your system backup -- the choice, like everything else here, is yours.
Until you say otherwise. A snapshot stays in its coffer until you burn it; a coffer stays in the hall until you dissolve it; the whole hall stays until you delete the app. There is no hidden retention, no "deleted" content kept for ninety days, no soft-deleted archive with a staff key -- when the app deletes, the file is removed from the device immediately and permanently.
The complete goodbye, in order: burn the snapshots you want gone, dissolve the coffers you want gone, then uninstall the app -- which removes the ledger, the photo folder, and the whisper folder along with everything else the sandbox held. There is no request form to file and no waiting period, because there is nothing on our side to delete. To confirm the hall is empty, reinstall the app: it will greet you as a stranger, with its seeded demo doors and no memory of you whatsoever.
A few plain habits make the strongbox worth more: keep a strong lock on the phone itself, because it is the outer wall of every coffer. Choose codes you will remember in a decade, since no one can rescue a forgotten one. Be deliberate about releasing a snapshot to your library -- past that door it behaves like any camera-roll picture. And if you hand the phone to someone, seal the doors first; the app seals everything automatically when you leave a chamber, if you keep that knob turned on in the tuning atrium.
You do not have to take this charter's word for any of it, and we would not blame you if you did not. Here is how to check the claims with your own hands, no lawyer or auditor required. Open the system settings and find Hyls in the app list: you will see exactly the permission doors this charter names -- camera, microphone, photo library add -- and nothing else has ever been granted because nothing else has ever been requested. Watch the system's own indicators: the orange dot that appears whenever a microphone is truly live will show only while you are mid-whisper, and vanish the instant the take is sealed.
If you keep your device's network activity in view, the verdict is even simpler: the app never asks to use the network at all, so there is no connection to observe. The store listing's privacy labels for this app read as "data not collected," and the machine behind those labels is the same machine described in every roll above.
Every byte this app writes rests on your device, inside the app's private sandbox, on storage that the operating system keeps encrypted under your own lock-screen passcode. There is no data center to name, no region to cross, no transfer to trace -- not because transfers are protected well, but because they never happen. A hall with no doors to the outside cannot have its contents shipped anywhere.
This also means geography is irrelevant to your privacy here: the app behaves the same in every country, on every network, or on none. Airplane mode changes nothing about how the strongbox works, because the strongbox was always flying that way.
For completeness, the full inventory of ways content can leave the hall -- all of them opened by your hand, none by the app's: the RELEASE TO LIBRARY door, which copies one snapshot photograph into your system library where the system's own sharing rules then apply; your own screenshots and screen recordings, which are the operating system's features and land in your library like anything else you capture; and the system backup you may choose to make, described in its own roll above.
There are no share sheets inside the app, no mail or message hooks, no links to websites, no "recommend a friend" mechanics, no export to cloud drives. If you want a memory to travel, you are the one who carries it out, and you will remember doing so -- because every outward door in this building is a deliberate, single-purpose, ask-first kind of door.
This writing describes the app as it is. If the hall ever grows a feature that changes what is written here -- a new permission, a new kind of content -- this charter gains the matching roll and a new date at its foot before the feature ships, and the newest copy is always posted where the old one was. We will not quietly broaden what "nothing leaves the device" means; if it ever stops being true, this page will be the first place we admit it.
Privacy questions, or a skeptical "prove it": write to hyls8x4kq2@outlook.com. A person reads the inbox; there is no ticket system storing your address. Skepticism is welcome -- the honest answer to "how can I verify all this?" is that the app asks the system for only four permissions, all visible in the system settings, and every piece of content it touches is findable in its own sandbox folders. The machine shows its work.