This policy explains how the NUMIDIE COFFRE Android application accesses, uses and protects data.
1. Controller and contact
Publisher: CONCEPT NUMIDIE
Contact: micipsao@numidie.com
2. Local vault operation
NUMIDIE COFFRE lets users store titles, usernames, passwords, website addresses, categories, favorites, dates and notes. This information is entered voluntarily and stored locally on the device in an encrypted database.
Users may create a NUMIDIE account that is separate from the master password. If synchronization is enabled, the vault is encrypted on the phone before being sent. CONCEPT NUMIDIE never receives the master password and cannot decrypt synchronized vault contents.
3. NUMIDIE account and encrypted synchronization
The service processes the email address, account password hash, device name and technical identifier, session and notification tokens, and security events required for authentication and support.
Synchronized credentials, notes and other vault contents are transmitted only in encrypted form. Communications use HTTPS.
4. Biometrics and Android security
When biometric unlocking is enabled, the application uses Android security interfaces. Fingerprints, facial data and biometric templates remain managed by Android and the device manufacturer. NUMIDIE does not access or store them.
5. Autofill
If the user enables NUMIDIE as the Android Autofill service, the application locally analyzes login fields to suggest matching credentials. Confirmation is requested before saving new credentials.
6. Exposed password checks
When a check is requested, the application locally computes the SHA-1 hash of the password and sends only its first five characters to the Have I Been Pwned Pwned Passwords service. The password and full hash are never transmitted. Comparison is performed locally over HTTPS.
7. Clipboard
At the user’s request, a username or password may be copied to the Android clipboard. NUMIDIE attempts to clear copied passwords after 30 seconds. Final behavior depends on Android and other installed applications.
8. Backups
Users may manually export an encrypted backup to a location selected through the Android file picker. This manual backup is separate from NUMIDIE encrypted synchronization.
9. Notifications and support
With permission, the application displays local reminders and service notifications delivered through Firebase Cloud Messaging. NUMIDIE stores a technical notification token. Tickets, messages and ratings voluntarily sent to support are retained to process the request.
10. Premium subscriptions
Premium purchases are processed by Google Play. NUMIDIE receives only the technical information required to verify subscription status and never has access to payment card details.
11. Data protection and sharing
The local vault is protected by SQLCipher with AES-256 encryption. Biometric secrets use Android Keystore. Backups are encrypted separately and network communications use HTTPS.
NUMIDIE does not sell data and uses neither advertising nor behavioral analytics. Relevant technical providers include Google Play for subscriptions, Firebase for notifications and Have I Been Pwned for optional exposed-password checks.
12. Retention and deletion
Local data remains on the device until deleted. Account and synchronization data remains on the server while the service is used. Users can permanently delete their account from the application. This operation deletes the account and associated server data.
The local vault and exported backups cannot be deleted remotely; they must be removed from the device or the storage location selected by the user.
13. Policy changes
This policy may be updated to reflect changes to the service or applicable requirements. The date at the top identifies the latest version.