Legal
Terms of Service
1. AGREEMENT & ACCEPTANCE
These Terms of Use ("Terms") constitute a legally binding agreement between you ("User," "you," or "your") and Bugra Acemoglu, an individual software developer operating as "Secure Text" ("Developer," "we," "us," or "our"), governing your use of the Secure Text mobile application (the "App"), including its custom keyboard extension, share extension, home/lock screen widgets, and any related services. By downloading, installing, or using the App, you agree to be bound by these Terms and our Privacy Policy. If you do not agree, do not install or use the App. The Developer is an individual developer — not a corporation, regulated telecommunications provider, cloud service, or professional security consultant. The App is consumer software only.
2. ZERO DATA CUSTODY — READ THIS FIRST
Secure Text is designed so that your encrypted content never passes through developer-controlled servers.
- We do not operate message servers, key servers, backup servers, or user account databases.
- We do not receive, store, index, mine, sell, rent, or monetize your plaintext, ciphertext, contacts, private keys, group keys, OTP pads, SecureVault contents, voice recordings, or clipboard data.
- We have no ability to recover, restore, decrypt, or retrieve your data if you lose your device, forget your PIN, trigger a panic/duress wipe, delete the App, or fail to back up your keys.
- YOU ARE SOLELY RESPONSIBLE for all data you create, encrypt, decrypt, export, copy, or share using the App. THE DEVELOPER BEARS NO LIABILITY FOR ANY LOSS, LEAK, CORRUPTION, OR UNAUTHORIZED DISCLOSURE OF YOUR DATA — WHETHER CAUSED BY USER ERROR, DEVICE FAILURE, BUGS, THIRD-PARTY APPS, NETWORK INTERCEPTION, COERCION, OR ANY OTHER CAUSE — EXCEPT WHERE MANDATORY LAW REQUIRES OTHERWISE.
3. DESCRIPTION OF SERVICE (NOT A COMMUNICATIONS PROVIDER)
Secure Text is an offline-first, client-only cryptographic toolkit. It encrypts and decrypts text, files, and media locally on your Apple iOS device. You manually carry the resulting ciphertext through third-party courier apps (SMS, email, WhatsApp, Telegram, etc.). We do not route, relay, host, or store messages. We have no control over third-party couriers and assume no responsibility for their transmission, interception, metadata logging, outages, or data practices.
4. LICENSE GRANT & RESTRICTIONS
Subject to your compliance with these Terms, Developer grants you a limited, non-exclusive, non-transferable, revocable license to use the App on Apple-branded devices you own or control, per Apple App Store Usage Rules.
You may not: reverse engineer (except where law prohibits this restriction), circumvent security or subscription checks, modify, distribute, create derivative works, or rent/lease/sell/sublicense the App.
5. ASSUMPTION OF RISK
YOU USE THE APP ENTIRELY AT YOUR OWN RISK. YOU ACKNOWLEDGE THAT:
- You alone evaluate whether the App fits your threat model and legal obligations.
- The Developer does not monitor, review, or control your content.
- Reliance on the App for life-safety, legal compliance, journalism, activism, or high-risk communications is your decision alone.
- Encryption tools reduce risk but cannot eliminate it under all conditions.
6. DEVICE SECURITY, APP LOCK, PANIC WIPE & DURESS PIN
Secure Text does not use developer-hosted accounts. Your identity is generated locally on your device.
App Lock: Optional passcode, Face ID, or Touch ID locks the App shell. Biometric enrollment may be required before identity key creation.
Failed-Attempt / Panic Wipe: If configured, consecutive wrong passcodes trigger a destructive forensic wipe — permanently deleting identity keys, contacts, groups, OTP pads, SecureVault data, App Group payloads, and Keychain items. THIS IS IRREVERSIBLE. Developer bears no liability for resulting data loss.
Duress PIN: If configured, entering the duress PIN triggers a SILENT forensic wipe of all real cryptographic material (same scope as panic wipe), then opens a DECOY SHELL with placeholder identity data designed to appear normal to a coercer. Real data is permanently destroyed and cannot be recovered. This is indistinguishable from a normal unlock to an observer but destroys your actual keys and content. Developer bears no liability for data loss from duress PIN use.
Device Security: You are solely responsible for physical device security. Compromise, jailbreak, malware, or unauthorized passcode access may defeat local protections.
7. CRYPTOGRAPHIC FEATURES & ALGORITHMS
The App uses local cryptographic operations via Apple CryptoKit and the open-source SwiftKyber library (ML-KEM-768, NIST FIPS 203). Algorithms include, without limitation:
- AES-256-GCM for message and store encryption
- P-256 elliptic-curve ECDH for classical key agreement
- ML-KEM-768 (post-quantum) hybrid encapsulation
- ChaCha20-Poly1305 for OTP pad encryption at rest
- HKDF-SHA256 key derivation
- PBKDF2 for passcode/Vault PIN hashing
- Hybrid message formats: STMSG, STMSG:v2, STMSG:otp3, STGRP:v1, and legacy compatibility formats
- Custom file types: .qsafe, .stvoice, .stmsg, .stenc, .tx.pad, .rx.pad, .stgrp, .stmeta, .stpub, .stcontact
No Absolute Guarantee: No encryption is unbreakable. Developer does not warrant immunity from surveillance, lawful interception, forensic analysis, or future cryptanalytic advances. User Responsibility: Verify recipient identities out-of-band (e.g., in-person QR scan). Wrong keys, wrong contacts, or misconfiguration can expose your data. No Professional Advice: Nothing herein is legal, security, or compliance advice.
8. IDENTITY KEYS, RECOVERY KEY & ROTATION
- P-256 private keys are stored in the Apple Secure Enclave (where hardware permits), protected by biometry.
- Post-quantum private keys are wrapped and stored in Keychain.
- A one-time Recovery Key may be shown during setup. You must save it offline. Developer does not store copies and cannot recover it.
- Identity key rotation is destructive — old keys cannot decrypt prior messages. You bear full responsibility for rotation decisions.
9. ONE-TIME PADS (OTP)
Optional dual-pad design: transmit (.tx.pad) and receive (.rx.pad) files, exchanged locally. Pads use destructive read with replay protection. Pad exhaustion permanently prevents further OTP-encrypted messages until new pads are exchanged. You are entirely responsible for pad generation, exchange, backup, and secure storage. Developer holds no copies.
10. GROUPS & IMPORTED KEYS
Distributed group keys via .stgrp files. Free tier: import/decrypt only. Pro tier: create groups and send encrypted group messages. You are responsible for trusting key sources.
11. SECUREVAULT
SecureVault stores encrypted photos, notes, and voice on-device using AES-256-GCM. Optional separate Vault PIN (PBKDF2-protected). Optional DECOY VAULT slot opens a separate decoy database with its own PIN. Plaintext exists in RAM only while viewing. Developer cannot access or recover Vault contents. Vault ciphertext directories are excluded from iCloud backup, but user-exported decrypted files are ordinary plaintext under your control.
12. METADATA BACKUP & FILE EXPORT
- Directory.stmeta / metadata export: Plain JSON of contact/group names and public keys only — NOT a full backup. Does not restore identity, private keys, pads, or encrypted Vault ciphertext.
- If you export a backup package while SecureVault is unlocked, the package may include DECRYPTED Vault files in a Vault/ folder. These are ordinary plaintext files. You are solely responsible for securing, sharing, or losing them.
- UIFileSharingEnabled allows App documents to be visible via Finder/iTunes file sharing. You control what files exist there.
13. NEARBY PEER-TO-PEER TRANSFER
Optional Pro features exchange data over local Wi-Fi/Bluetooth via Apple MultipeerConnectivity and Bonjour services:
- _st-pad-xfer._tcp — OTP pad transfer
- _st-otp-xfer._tcp — OTP transfer (alternate)
- _st-key-xfer._tcp — public key exchange
- _st-vault-xfer._tcp — encrypted Vault item drop
Payloads are encrypted but discovery beacons, timing, and device presence on your local network may be observable. No developer cloud relay is used. Developer is not responsible for local network interception or misdirected transfers.
14. APP EXTENSIONS
Custom Keyboard (Full Access required): Encrypts/decrypts text inside third-party apps. Reads typed text and system pasteboard locally. Does not transmit keystrokes to Developer servers. Clipboard items written by the keyboard may persist up to 10 minutes and are NOT restricted to localOnly — other apps on your device may read them until expiry. Share Extension (Pro only): Reads images, video, audio, files, and text shared from host apps for local encrypt/decrypt. May save decrypted media to Photos (add-only permission). Widgets: Display contact/group names and avatar thumbnails from local App Group snapshots on Home/Lock Screen. No decryption in widgets. Tapping may open encrypt flows and optionally prefill from clipboard.
15. JAILBREAK & DEVICE INTEGRITY
The App performs local jailbreak/tamper detection (including PT_DENY_ATTACH). If compromise indicators are detected, cryptographic operations are refused. Detection is not guaranteed — false negatives and false positives are possible. Developer is not liable for security failures on compromised devices.
16. SUBSCRIPTIONS, BILLING & REFUNDS
Optional auto-renewing subscriptions and/or lifetime purchase (Pro). All payments via Apple IAP. RevenueCat manages entitlement state only. Subscriptions auto-renew unless canceled 24+ hours before period end. Refunds via Apple only — Developer cannot issue refunds.
17. FREE VS. PRO FEATURES
Developer may modify tier features. Currently: Free: Basic 1:1 decryption, group message decryption (with imported .stgrp), limited keyboard decrypt. Pro: Encryption (keyboard + main app), SecureVault, Share Extension (all flows), group create/send, document/media encryption, OTP pad generation/wrap, nearby pad/key/vault transfer, duress PIN, and related advanced features. Feature gates are enforced locally and via RevenueCat entitlement mirroring in the App Group.
18. ACCEPTABLE USE
Use the App lawfully. Prohibited: illegal activity (including terrorism, trafficking, CSAM), illegal surveillance/harassment/stalking, malware distribution, export control violations.
19. THIRD-PARTY SERVICES
Third-party couriers, Apple, RevenueCat, Google Sites (legal pages), and your email provider are independent. Their terms and privacy policies govern their services. Developer is not responsible for their practices, reliability, or data collection.
20. INTELLECTUAL PROPERTY
App code, UI, designs, file formats, and "Secure Text" trademarks belong to Developer. You retain ownership of content you encrypt.
21. DISCLAIMER OF WARRANTIES
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE APP IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND ERROR-FREE OR SECURE OPERATION.
22. LIMITATION OF LIABILITY
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:
- DEVELOPER SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR ANY LOSS OF DATA, PROFITS, USE, GOODWILL, OR REPUTATION.
- DEVELOPER IS NOT LIABLE FOR DATA LOSS FROM: panic/duress wipe, device loss/theft, App deletion, bugs, misconfiguration, wrong recipient keys, third-party messenger interception, clipboard exposure, iCloud/backup issues, nearby transfer errors, Vault/metadata export, jailbreak, or any user action or omission.
- TOTAL AGGREGATE LIABILITY SHALL NOT EXCEED THE GREATER OF (A) AMOUNTS PAID TO DEVELOPER IN THE 12 MONTHS BEFORE THE CLAIM, OR (B) FIFTY US DOLLARS ($50.00).
- FREE-TIER USERS WHO PAID NOTHING: LIABILITY CAPPED AT $50.00 UNLESS MANDATORY LAW REQUIRES MORE.
23. INDEMNIFICATION
To the maximum extent permitted by law, you agree to defend, indemnify, and hold harmless Developer from claims arising from your use of the App, your content, your violation of these Terms, or violation of applicable law or third-party rights.
24. EXPORT COMPLIANCE
You represent you are not in an embargoed country or on prohibited U.S. government lists. You agree to comply with applicable export/re-export laws for cryptographic software. The App implements standard encryption (including AES-256-GCM and ML-KEM-768) via Apple CryptoKit and open-source libraries. The Developer files applicable U.S. export self-classification / exemption documentation with Apple App Store Connect as required (including annual encryption compliance questions). Distribution through Apple's App Store does not transfer encryption technology to you beyond normal end-user use of the App on your device.
25. GOVERNING LAW & MANDATORY RIGHTS
Governed by the laws of the Republic of Türkiye. Disputes subject to Istanbul courts, except where mandatory consumer protection laws in your country of residence require otherwise. Non-waivable statutory consumer rights remain unaffected. Invalid provisions do not affect the rest.
26. CHANGES
Material changes reflected in the "Last updated" date and, where appropriate, in-app notice. Continued use constitutes acceptance.
27. CONTACT
Email: [email protected]
28. APPLE THIRD-PARTY BENEFICIARY
These Terms are between you and Developer only, not Apple. Apple has no maintenance/support obligation beyond applicable refunds. Apple and its subsidiaries are third-party beneficiaries with the right to enforce these Terms against you.