Privacy Policy

END-USER LICENSE AGREEMENT FOR APPS BY BESHEVGAMES.

IMPORTANT: PLEASE READ THE TERMS AND CONDITIONS OF THIS LICENSE AGREEMENT CAREFULLY BEFORE CONTINUING WITH PROGRAMS USAGE:

BeshevGames End-User License Agreement (“EULA”) is a legal agreement between you (either an individual or a single entity) and BeshevGames. For the BeshevGames software product(s) identified above which may include associated software components, media, printed materials, and “online” or electronic documentation (“SOFTWARE PRODUCT”). By installing, copying, or otherwise using the SOFTWARE PRODUCT, you agree to be bound by the terms of this EULA. This license agreement represents the entire agreement concerning the program between you and BeshevGames, (referred to as “licenser”), and it supersedes any prior proposal, representation, or understanding between the parties. If you do not agree to the terms of this EULA, do not install or use the SOFTWARE PRODUCT.

The SOFTWARE PRODUCT is protected by copyright laws and international copyright treaties, as well as other intellectual property laws and treaties. The SOFTWARE PRODUCT is licensed, not sold.

1. GRANT OF LICENSE.

The SOFTWARE PRODUCT is licensed as follows:

(a) Installation and Use.

BeshevGames grants you the right to install and use copies of the SOFTWARE PRODUCT on your device.

(b) Backup Copies.

You may also make copies of the SOFTWARE PRODUCT as may be necessary for backup and archival purposes.

2. DESCRIPTION OF OTHER RIGHTS AND LIMITATIONS.

(a) Maintenance of Copyright Notices.

You must not remove or alter any copyright notices on any and all copies of the SOFTWARE PRODUCT.

(b) Distribution.

You may not distribute registered copies of the SOFTWARE PRODUCT to third parties. Evaluation versions available for download from BeshevGames’s websites may be freely distributed.

(c) Prohibition on Reverse Engineering, Decompilation, and Disassembly.

You may not reverse engineer, decompile, or disassemble the SOFTWARE PRODUCT, except and only to the extent that such activity is expressly permitted by applicable law notwithstanding this limitation.

(d) Rental.

You may not rent, lease, or lend the SOFTWARE PRODUCT.

(e) Support Services.

BeshevGames may provide you with support services related to the SOFTWARE PRODUCT (“Support Services”). Any supplemental software code provided to you as part of the Support Services shall be considered part of the SOFTWARE PRODUCT and subject to the terms and conditions of this EULA.

(f) Compliance with Applicable Laws.

You must comply with all applicable laws regarding use of the SOFTWARE PRODUCT.

3. TERMINATION

Without prejudice to any other rights, BeshevGames may terminate this EULA if you fail to comply with the terms and conditions of this EULA. In such event, you must destroy all copies of the SOFTWARE PRODUCT in your possession.

4. COPYRIGHT

All title, including but not limited to copyrights, in and to the SOFTWARE PRODUCT and any copies thereof are owned by BeshevGames or its suppliers. All title and intellectual property rights in and to the content which may be accessed through use of the SOFTWARE PRODUCT is the property of the respective content owner and may be protected by applicable copyright or other intellectual property laws and treaties. This EULA grants you no rights to use such content. All rights not expressly granted are reserved by BeshevGames.

5. NO WARRANTIES

BeshevGames expressly disclaims any warranty for the SOFTWARE PRODUCT. The SOFTWARE PRODUCT is provided ‘As Is’ without any express or implied warranty of any kind, including but not limited to any warranties of merchantability, noninfringement, or fitness of a particular purpose.

BeshevGames does not warrant or assume responsibility for the accuracy or completeness of any information, text, graphics, links or other items contained within the SOFTWARE PRODUCT.

BeshevGames makes no warranties respecting any harm that may be caused by the transmission of a computer virus, worm, time bomb, logic bomb, or other such computer program. BeshevGames further expressly disclaims any warranty or representation to Authorized Users or to any third party.

6. APP PERMISSIONS

Camera – the apps use the Camera on the device for the functionality of the flashlight feature(if such is present). On “MagnifyIT” the camera is the main part of the app.

Microphone – used for noise measurement by the following apps: Sound Meter & Noise in Decibel.

Location – required by the GPS apps to measure data such as speed and distance.

Phone – automatically generated, not used by any current apps. Policy will be updated if an app uses the phone state.

Network – used for analytics and ads in most apps. No personal user data is collected from us, apart from the one that the user provides.

Prevent device from sleeping – used to keep the screen on if the user enables the option.

7. LIMITATION OF LIABILITY

In no event shall BeshevGames and BeshevGames be liable for any damages (including, without limitation, lost profits, business interruption, or lost information) rising out of ‘Authorized Users’ use of or inability to use the SOFTWARE PRODUCT, even if BeshevGames or BeshevGames has been advised of the possibility of such damages. In no event will BeshevGames or BeshevGames be liable for loss of data or for indirect, special, incidental, consequential (including lost profit), or other damages based in contract, tort or otherwise. BeshevGames and BeshevGames shall have no liability with respect to the content of the SOFTWARE PRODUCT or any part thereof, including but not limited to errors or omissions contained therein, libel, infringements of rights of publicity, privacy, trademark rights, business interruption, personal injury, loss of privacy, moral rights or the disclosure of confidential information.

This Privacy Policy may be updated from time to time for any reason. Your continued use of the Apps and Services following the posting of changes will mean you accept those changes.

8. WE USE ONLY ONE PRIVACY SHIELD CERTIFIED PROVIDER

We use only Google’s services(like Admob, Analytics and Firebase services) in our apps in sites to ensure much higher security and privacy for our user’s data.

9. INFORMATION COLLECTION, SECURITY AND USAGE


Ciphiron Privacy Policy

Effective date: 23 August 2026

This Privacy Policy applies to the Ciphiron Android application (package name com.beshevgames.ciphiron), developed and published by Beshev Games. It does not describe the data practices of other Beshev Games applications, websites, forums, or third-party services.

1. Privacy at a glance

Ciphiron is designed as a local, security-focused password manager and encrypted vault.

  • Ciphiron does not require or create a Ciphiron account.

  • Ciphiron does not provide cloud synchronization and does not upload your vault to a Beshev Games server.

  • Beshev Games cannot view your vault, master password, recovery key, authenticator secrets, or protected files.

  • Ciphiron does not contain advertising, rewarded ads, behavioral advertising, or an in-app Premium purchase system.

  • Ciphiron uses Google Analytics for Firebase to collect limited app-usage and technical information as described in Section 8. Ciphiron is designed not to send vault contents or other secrets to Analytics, and Beshev Games does not use Analytics reports to serve advertisements or for remarketing.

  • Ciphiron does not sell personal data.

  • The app’s core vault, password generation, password-health analysis, authenticator, Secure Files, backup, and Autofill functions operate locally on your device.

  • A network connection is used for the limited Firebase Analytics collection described in Section 8, when you explicitly start the optional compromised-password check described in Section 5, or when an external app or service such as Google Play or your browser performs an action outside Ciphiron.

In this Policy, “collect” means transmitting data from the app off your device. Data that Ciphiron processes only on your device is described separately below even though Beshev Games does not receive it.

2. Information processed and stored on your device

Depending on the features you use, Ciphiron may process and store the following information locally:

  • Login credentials, including account names, usernames, email addresses, passwords, website addresses, notes, custom fields, and password history.

  • Secure notes, identity records, payment-card fields, and other vault information that you choose to enter.

  • Time-based one-time password (TOTP) secrets and related authenticator information.

  • Files and photos that you choose to import into Secure Files, together with metadata such as their names, types, sizes, folders, and creation dates.

  • Ciphiron settings, appearance choices, vault-view preferences, reminder preferences, and backup/recovery status.

  • Optional local security-event history containing event types and timestamps, such as successful or failed unlocks, locking, backup creation, and recovery checks. It does not contain vault values or file contents and can be disabled and cleared in Ciphiron.

  • Information supplied to Ciphiron by Android for Autofill, as explained in Section 4.

  • Local device-security signals that Android makes available, such as whether a secure screen lock, strong biometrics, Android Keystore, secure hardware, and a reported security-patch level are available.

Sensitive vault records are encrypted in app-private storage. Non-sensitive preferences and status information are also stored locally. Ciphiron is designed not to include this user-created content in Firebase Analytics events. Only the limited app-usage and technical information described in Section 8 is transmitted for analytics.

Generated passwords, passphrases, PINs, and tokens are not saved unless you choose to save or copy them.

3. Vault encryption and authentication

Ciphiron protects sensitive vault data with authenticated encryption. The current design uses a random 256-bit vault key, AES-256-GCM authenticated encryption, and PBKDF2-HMAC-SHA-256 master-password key derivation. Individual vault items and the vault summary index are protected as encrypted records. Secure Files are encrypted individually with keys derived from the active vault key.

Your master password is not sent to Beshev Games and is not stored as readable plaintext. Beshev Games has no developer master key, recovery override, hidden synchronization copy, or backdoor capable of opening a vault.

When strong biometric unlock is enabled, Android performs biometric authentication and a non-exportable Android Keystore key protects an additional encrypted wrapping of the vault key. Ciphiron does not receive or store your fingerprint, face image, biometric template, or other raw biometric data. Android reports only the authentication result and authorizes the cryptographic operation.

Ciphiron also uses automatic locking, screen-capture protection, and supported overlay protection. These safeguards reduce risk but cannot guarantee protection against every compromised device, malicious app, operating-system flaw, hardware attack, or action taken while the vault is unlocked.

4. Android Autofill

Android Autofill is optional. It operates only after you select Ciphiron as an Autofill service in Android system settings.

When Android invokes Ciphiron for an Autofill request, Android may provide an on-device representation of the active form. This can include the requesting app’s package identifier, a website domain supplied by the app or browser, form structure, Autofill hints, field labels, and values already present in relevant fields. Ciphiron processes this information on your device to identify suitable vault entries and prepare Autofill suggestions.

Ciphiron does not send Autofill form information, browsing information, or matching results to Beshev Games. If the vault is locked, Ciphiron requires authentication before making protected credentials available. A credential is supplied to the requesting app or website only when you select the relevant Autofill suggestion. Where Ciphiron offers to save or update a credential from an Autofill form, it does so only after your approval and stores the credential in the encrypted local vault.

Autofill necessarily transfers the credential you select to the app or website whose form you are filling. That recipient’s handling of the credential is governed by its own privacy and security practices. Ciphiron does not continuously monitor your screen; it responds to Autofill requests delivered by the Android Autofill framework.

5. Optional compromised-password check

Ciphiron’s normal password-health analysis runs locally. Ciphiron also offers a separate, optional check against Have I Been Pwned’s Pwned Passwords service. This online check never runs automatically and starts only when you press the check button.

For this check, Ciphiron:

  1. hashes each relevant password locally using SHA-1 because the external corpus is indexed by SHA-1;

  2. sends only the first five hexadecimal characters of that hash—a 20-bit prefix—over HTTPS to the Pwned Passwords range API;

  3. requests padded responses;

  4. compares returned hash suffixes locally; and

  5. discards the returned data and in-memory match results when the password-health screen is closed.

Ciphiron does not send the complete password, complete password hash, username, email address, account name, website, vault item identifier, or encryption key to this service. As with any Internet connection, the service and its infrastructure necessarily receive standard connection information such as the requesting IP address and Ciphiron’s request user-agent. Have I Been Pwned processes that connection under its own privacy policy:

https://haveibeenpwned.com/Privacy

The Pwned Passwords feature is optional; all other password-health checks remain available without using it.

6. Permissions and Android system features

Ciphiron may use the following permissions or system capabilities:

  • Biometrics: used through Android’s trusted biometric and Keystore flows for optional strong-biometric vault unlock. Ciphiron does not receive raw biometric data.

  • Camera: requested only when you choose to scan a TOTP QR code. Camera frames are analyzed locally and are not saved or transmitted by Ciphiron.

  • Notifications: requested only if you enable local backup or recovery reminders. Notifications do not contain passwords, TOTP codes, secure-note text, account names, file names, or other vault contents.

  • Run after device startup: used to restore the schedule for optional local reminders after a reboot. It does not unlock the vault or transmit data.

  • Internet: used for the limited Firebase Analytics collection described in Section 8 and for the explicitly initiated compromised-password check described in Section 5. Ciphiron does not use Internet access for ads, crash reporting, cloud synchronization, or vault backup.

  • Autofill service: used only after you enable Ciphiron as an Android Autofill service and as described in Section 4.

  • User-selected file access: Android’s system file picker lets you choose files to import, backup files to restore, and destinations for backups or exports. Ciphiron does not request unrestricted access to all files on your device.

  • Clipboard: when you choose Copy, Ciphiron places the selected value on the Android clipboard, marks it as sensitive on supported Android versions, and attempts to clear it after your configured timeout if it has not changed. Android, keyboards, or other apps may be able to access clipboard content according to Android’s rules; avoid copying secrets when you do not need to.

Ciphiron does not request access to your location, microphone, contacts, SMS messages, call history, or phone state.

7. Secure Files, backups, exports, and recovery

Files and photos imported into Secure Files are copied into Ciphiron’s app-private storage and encrypted. The original selected file remains in its original location unless you delete it yourself. Ciphiron may create a temporary authenticated plaintext copy in private storage when displaying or exporting a protected file and attempts to delete that temporary copy after use.

Ciphiron’s encrypted backups are created only when you request them and are written to a destination you select through Android. Backup encryption and recovery depend on user-controlled recovery material. Beshev Games does not receive a backup or recovery key and cannot restore a lost vault for you.

Android automatic cloud backup and automatic device-to-device transfer of Ciphiron’s private application data are disabled. User-created backup files are not managed by Ciphiron after they are written to your selected destination and may remain there after you clear app data or uninstall Ciphiron.

If you deliberately export a Secure File in readable form, copy a secret, open a stored website in a browser, display or share a QR code, or provide data to another app, the selected data leaves Ciphiron’s protected storage at your direction. The destination app, service, or storage provider then controls its copy.

8. Firebase Analytics and information received by Beshev Games

Ciphiron uses Google Analytics for Firebase, an analytics service provided by Google LLC, to understand general app usage, feature adoption, app-version distribution, and device compatibility so that Beshev Games can maintain and improve the app. Firebase Analytics collection can occur automatically while Ciphiron is used.

Depending on the installed Firebase Analytics SDK version, device settings, region, and Analytics configuration, the service may collect and process:

  • a randomly generated app-instance identifier used to distinguish installations for analytics purposes;

  • the Android Advertising ID when it is available and its collection has not been disabled;

  • app lifecycle and interaction information, such as first launch, app opens, sessions, and screen views;

  • app and device information, such as the Ciphiron version, Android version, device brand, model, form factor, language, and screen characteristics; and

  • a masked IP address used by Google Analytics to derive approximate location information such as country, region, and city.

Analytics information is transmitted to Google using encryption in transit. Beshev Games can view Analytics reports and uses them for measurement and product improvement. Ciphiron does not set an Analytics user ID and does not have a Ciphiron account to associate Analytics data with your name, email address, or vault identity.

Ciphiron is designed not to send any of the following to Firebase Analytics: vault contents; passwords; usernames; account names; email addresses entered in vault records; website addresses or Autofill domains; Autofill form contents; secure notes; payment-card fields; identity records; password history; TOTP secrets or codes; protected files or file names; master passwords; recovery keys; encryption keys; clipboard contents; local security-event details; support messages; or other user-entered vault values.

Beshev Games does not use Firebase Analytics for advertising, remarketing, or the sale of personal data. Ciphiron contains no AdMob, rewarded-ad, Firebase Crashlytics, or in-app Google Play Billing integration.

Google Analytics retention controls allow user-level and event-level data to be retained for two or fourteen months. Ciphiron’s Analytics data may be retained for up to fourteen months, while standard aggregated Analytics reports are not governed by that user-and-event retention setting and may remain available for longer. Google may process Analytics data in locations where Google or its service providers operate, subject to Google’s terms and privacy safeguards.

If you voluntarily contact Beshev Games for support or a privacy inquiry, Beshev Games receives the contact details, message, and attachments that you choose to provide. This information is used to respond to the inquiry, maintain necessary support records, prevent abuse, and comply with legal obligations. It is retained only for as long as reasonably necessary for those purposes and is then deleted or anonymized where appropriate. Never send a master password, recovery key, full password, TOTP secret, or unencrypted vault backup to support.

9. Google Play and other third parties

Google Play distributes the paid Ciphiron app and may independently process purchase, payment, licensing, installation, device, and account information under Google’s own terms and privacy policy. Ciphiron does not receive your complete payment-card details from Google Play.

Google’s privacy policy is available at:

https://policies.google.com/privacy

Google Analytics for Firebase processes the limited app-usage and technical information described in Section 8. Additional Firebase privacy and security information is available at:

https://firebase.google.com/support/privacy/

Have I Been Pwned is contacted only for the optional action described in Section 5. Apps, websites, browsers, keyboards, storage providers, and communication services that you choose to use with Ciphiron are independent services governed by their own policies.

10. Data sharing and sale

Beshev Games does not sell, rent, or trade Ciphiron data.

Ciphiron sends or discloses data outside its protected local storage only in the following limited circumstances:

  • transmitting the app-usage and technical information described in Section 8 to Google Analytics for Firebase;

  • sending a five-character password-hash prefix and standard connection information to Have I Been Pwned after you explicitly start the optional check;

  • supplying a credential you select to the requesting app or website through Android Autofill;

  • writing a backup or export to a destination you select;

  • copying a selected value to the Android clipboard; or

  • opening or sharing information through another app at your request.

Beshev Games may disclose information received through a support inquiry when required by law, necessary to protect legal rights or safety, or needed to operate the support channel. This does not provide Beshev Games with access to your local encrypted vault.

11. Retention and deletion

Local data remains on your device until you delete it, clear Ciphiron’s storage, or uninstall the app, subject to Android and storage-device behavior.

  • You can delete individual vault items and Secure Files from within Ciphiron.

  • You can clear the optional local security-event history, and disabling that feature clears its stored journal.

  • Clearing Ciphiron’s app storage or uninstalling the app removes its app-private data and causes its Android Keystore keys to become unavailable.

  • User-created backups, readable exports, clipboard copies, screenshots taken outside Ciphiron’s controls, and copies held by other apps or services must be deleted separately from their respective locations.

  • Ciphiron cannot guarantee physical overwriting of deleted bytes on flash storage because Android and the storage hardware control low-level deletion and wear-leveling.

Firebase Analytics data is retained as described in Section 8. Clearing Ciphiron’s app storage or uninstalling the app removes the Analytics identifier stored on that installation, but it does not immediately erase Analytics data that was previously transmitted. Because Ciphiron does not set an Analytics user ID or maintain a user account, Beshev Games may not be able to associate an Analytics record with a particular person. Beshev Games can use Google’s available Analytics deletion tools where an applicable record can be identified.

Because Ciphiron has no developer-hosted account or vault server, there is no remote Ciphiron account or server-side vault record for Beshev Games to delete. You may contact Beshev Games to request access to, correction of, or deletion of personal information that you previously supplied in a support inquiry, subject to applicable legal requirements.

12. Security limitations

Ciphiron uses security measures intended to reduce unauthorized access, but no application, device, storage medium, cryptographic implementation, or transmission method can be guaranteed completely secure. You are responsible for protecting your master password and recovery material, maintaining device security, installing trusted software, and keeping independent encrypted backups where appropriate.

Beshev Games cannot reset your master password, recreate a lost recovery key, or decrypt a vault on your behalf.

13. Children’s privacy

Ciphiron is a general security utility and is not directed to children. Beshev Games does not knowingly use Ciphiron to collect personal information from children. Firebase Analytics may process the limited technical and app-usage information described in Section 8 without telling Beshev Games the user’s identity or age. If Beshev Games learns that personal information relating to a child has been collected, or if a child sends personal information through a support channel, a parent or guardian may contact Beshev Games to request its deletion.

14. Changes to this Policy

This Policy may be updated when Ciphiron’s features, data practices, or legal obligations change. The updated version will be posted at a publicly accessible web address with a revised effective date. Material changes will be communicated through an appropriate in-app, store-listing, or website notice where required.

15. Contact

Beshev Games is the developer and publisher responsible for Ciphiron and is based in Bulgaria.

For privacy questions, requests, or complaints, use the Beshev Games contact page:

https://beshevgames.com/contact/