WithinCells · Privacy

Privacy Policy for WithinCells

WithinCells transfers short secrets in encrypted form between paired devices. The Android app works locally and requires no user account, cloud service, or relay.

Read this Privacy Policy in German

1. Scope and summary

This Privacy Policy applies to the Android app WithinCells, package ID com.schukai.withincells. It provides controlled transfer of short sensitive content such as passwords, credentials, or API keys between paired devices.

WithinCells creates no user account and transfers no user data to the operator. The current Android build has no Internet permission. Encryption, QR processing, and preparation for one-time input take place locally on the participating devices.

Effective: 24 August 2026

2. Controller and privacy contact

Ingrid Schukai & Volker Schukai GbR
Eichenstraße 26
82290 Landsberied
Germany

Email: hey@schukai.com

Further provider details are available in the German-language legal notice.

3. Data on the device

Depending on use, WithinCells processes secrets, encrypted WC1 messages, device identities, public and private keys, pairing information, expiry times, random message identifiers, and local replay and retirement records.

These data remain in private app storage or the device's protected key store. Android system backups and Android device transfer are disabled for the app. The operator receives neither secret plaintext nor cryptographic keys.

4. QR code and optional Bluetooth transport

A QR code contains a recipient-bound encrypted WC1 message with technical fields such as protocol version, sender and recipient identifier, message identifier, and expiry time. The decryption key is not contained in the QR code. Camera processing takes place locally in the app; camera images are neither stored nor transferred.

The app also declares Bluetooth permissions for an optional local transport of encrypted WC1 messages. Android Bluetooth transfer is not enabled in the current development state. This policy will be reviewed against the actual implementation before release of that feature. Bluetooth does not replace encryption and is not intended to transfer secret plaintext.

5. Camera, Bluetooth, clipboard, and input method

The camera is used only after Android permission is granted to scan WC1 QR codes. Bluetooth access is needed only for explicitly started local discovery or transfer once that function becomes available.

The preferred one-time input uses a dedicated Android input method and keeps the secret only temporarily in memory. If the clipboard is used instead, WithinCells marks the content as sensitive and attempts to remove it after a short period. This is a best-effort measure: content already read by another app or keyboard cannot be recalled.

6. No accounts, advertising, analytics, or developer cloud

WithinCells contains no advertising, advertising-ID processing, analytics SDK, or crash-reporting SDK. The Android app sends no usage data, diagnostic data, contacts, location data, camera images, or secret content to the operator or to advertising and analytics providers.

If an optional relay, organization, or issuer service is introduced in the future, the affected data flows will be described separately before public release and the Google Play declarations will be updated.

7. Retention, retirement, and deletion

Local app data remain until removed within the app, cleared through Android, or the app is uninstalled. Android provides the complete deletion path under Settings → Apps → WithinCells → Storage & cache → Clear storage.

“Retired” means that a local WC1 message is marked as used and is not offered for output again. Ephemeral secret copies are discarded, and a used message identifier remains stored locally for replay protection. WithinCells cannot guarantee removal of a secret already entered into a destination app, keyboard, clipboard history, or compromised device. Retirement does not automatically revoke a static password in the target system.

8. Rights, security, and requests

Depending on applicable law, rights may include access, correction, deletion, restriction, portability, objection, and the right to complain to a supervisory authority.

Because WithinCells uses no user account and no operator service for app content, the operator generally holds no attributable secret or usage data. Privacy questions can be sent to hey@schukai.com. Send security reports without real secrets, keys, or WC1 payloads to security@schukai.com.

WithinCells is a security utility for adults and is not directed specifically at children.

9. Changes

We update this policy if WithinCells permissions, integrated services, transport paths, retention, or data processing change. The effective date above identifies the current version.