Privacy Policy

Last updated: July 26, 2026 · Applies to the Loktra Android app
Loktra is built on one principle: your evidence is yours. When Loktra catches an intruder, the photo, video, or audio goes straight to your own Google Drive — never to our servers. We keep the absolute minimum needed to make the app work, and nothing more.

01Who we are

Loktra ("we", "us") is an anti-theft app that protects the phone it is installed on. This policy explains what data the app handles, why, and your choices. Questions: densmac06@gmail.com.

02The short version

  • Intruder photos, video and audio never touch our servers. They are stored on your device and uploaded only to your own Google Drive.
  • We use Google Firebase only for sign-in, a device list, and delivering remote commands — never to store your media.
  • Location is used only for anti-theft: while protection is armed, Loktra keeps a recent location fix ready (refreshed periodically in the foreground) so a capture or a remote “locate” can be tagged instantly — even while the phone is locked. It is never continuously tracked, logged as a route, or sent to us; it travels only with your evidence to your Drive (and, for a remote locate you request, to your own private record).
  • Loktra protects your own device only. Its launcher entry is always present — you may disguise its icon and label, but it is never removed — and by default Loktra shows an ongoing notice while active. An optional Stealth mode, off unless you turn it on and confirm an in-app disclosure, removes that ongoing notice so someone holding your locked phone sees no sign it is protected; Android’s own camera and microphone indicators still appear during every capture, in either mode. We do not sell your data or use it for advertising.

03What Loktra collects and why

DataWhyWhere it lives
Intruder media (photo, video, audio)To identify who tried to access your device.In the app's private storage on your device, then your Google Drive.
Location (at capture)To show where an event happened.With the evidence, on your device and Drive.
Google account (email, ID)To sign you in and connect your Drive.Google Sign-In / Firebase Auth.
Device info (model, push token, last-seen)So your devices appear in your list and receive remote commands.Firestore, your account only.
Portal languageSo the web portal opens in the language you chose, on any browser you sign in from — including a borrowed or replacement one during a theft, which is exactly when a cookie would not be there.Firestore, your account only. A single language code such as "fr". Deleted with your account.
Storage limitSo the Drive storage limit you chose follows you to a new or reinstalled phone, and your saved evidence is not deleted when you move devices.Firestore, your account only. A single number in megabytes. Deleted with your account.
Remote commandsTo carry a command you issue between your devices.Firestore, briefly, your account only.
Device status reports (location, battery, network, SIM/carrier, device model and Android version, storage and memory, screen and security settings, and Loktra's own protection state)So that when you ask "where is my phone and what is happening to it", the portal can answer. Sent only when you request a status — never on a schedule and never in the background. Also used before first unlock, so a restarted phone can still report in. See section 06 below.Firestore, your account only, for up to 30 days.
Sign-in restore keySo that when you set up a new phone from your old one, Loktra is already signed in and protecting it straight away, instead of sitting unprotected until you remember to sign in. It is a random key that identifies nothing about you: it holds no name, no email and no device details, and it is single-use — a replacement is issued the moment it is used, and signing out deletes it. When Loktra opens on your new phone it asks you to confirm your screen lock before it will show your evidence or your remote controls.Google Play services on your devices (Block Store), and a one-way hash of it in Firestore, which cannot be turned back into the key. Deleted with your account.
Never collected: IMEI, device serial number, SIM serial (ICCID), IMSI, phone number, or a list of your installed appsLoktra does not read any of these. They are not needed to recover a phone, and most require system-level access Loktra neither has nor requests.

04How your evidence is delivered

Saving the evidence. Loktra asks for the narrowest Drive permission Google offers: one that lets the app create and manage only the files it puts in your Drive — it cannot see the rest of your Drive. Evidence goes to a "Loktra" folder in your account. If you enable email alerts, the app sends you a message containing a link to that file; the media itself is never attached to or stored in the email system.

Sending you the alert. The alert is sent from your own Google account to you, directly from your phone, so it arrives from you rather than from a stranger. It uses Gmail's send-only permission and nothing else: send-only means it cannot read, search, list, or delete any message in your mailbox. The only message Loktra ever composes is the alert about your own device, addressed to you and to any trusted contact you added yourself.

We operate no mail server, and the alert never passes through us. The message goes directly from your device to Google. We do not store it, its contents, its recipients, or any mailbox data — we have nowhere to store them. The alert carries a link to the file in your Drive, never the media itself. Your access token is issued to the app by Google Play Services on your own device, is used only for that request, and is never transmitted to us — the app stores only your email address and the ID of the Loktra folder in your Drive. You can revoke Loktra's access at any time at myaccount.google.com/permissions, or by signing out in the app, which stops Drive and email delivery immediately.

Limited Use. Loktra's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: we do not use Google user data for advertising; we do not sell, rent, or transfer it to third parties; we do not allow humans to read it; and we do not use it to develop, improve, or train generalised artificial-intelligence or machine-learning models. Google user data is used only to provide and maintain the anti-theft features you turned on.

05Permissions we request

PermissionUsed for
CameraCapturing an intruder photo or video.
MicrophoneRecording audio evidence.
LocationTagging where an event happened.
NotificationsThe required "protection active" notice and alerts.
Device adminDetecting failed unlocks; remote lock; uninstall protection. (Remote factory-erase runs only in the optional Device Owner mode; otherwise erase is handled by Google Find My Device.)
Phone stateDetecting a SIM change (a fingerprint only — never your number).
Foreground service (camera, microphone, location)Keeping protection running reliably and tagging evidence while locked.
Display over other appsOptional. Shows your full-screen warning message on the lock screen after a failed unlock, if you switch that message on. On older versions of Android it also let protection restart itself after a reboot; on Android 15 and newer the system no longer permits this, and protection restarts by other means that need no permission. Never used to draw over other apps otherwise.
Background location (optional, "Allow all the time")Answering a Locate you send from your portal while the app is not open — which is the only situation that matters on a phone you no longer have. Loktra asks for this separately, after you have already allowed location, and you can decline it and still use everything else. It is never used to build a location history: a fix is taken when you ask for one, or when evidence is captured.
Ignore battery optimisations (optional)Asking Android to stop suspending Loktra in the background. Without it, some phones freeze the app while idle and a remote command can arrive late or not at all. It grants no access to any of your data.

You can revoke any permission in Android Settings. Some anti-theft features stop working without the permission they depend on.

06Protection before your phone is unlocked

A stolen phone is usually restarted, and after a restart Android keeps almost everything locked until someone enters the PIN, pattern or password once. Most of Loktra cannot run in that state. So Loktra includes a small separate recovery mode that can answer a few commands from your own portal before that first unlock — the window in which a stolen phone is most findable.

What it can do. Report status, get a location fix, sound the alarm, lock the screen, and re-arm or disarm itself. It cannot use the camera or the microphone before the first unlock — Android does not permit it, and Loktra does not attempt it. A capture you request in that window is queued and runs after the phone is unlocked, never before.

DataWhyWhere it goes
Location (a fix taken before unlock)So you can find the phone during the window in which it is most findable.Firestore, your account only.
Device status — a snapshot built only when you ask for one. In full:
  • Power: battery level, charging state, what it is plugged into, battery temperature and health, whether power saving is on.
  • Connectivity: whether it is online and over what (mobile, Wi‑Fi), whether the connection is metered, whether a VPN is active, whether airplane mode is on, whether NFC is on.
  • SIM and carrier: carrier and network operator name, network generation (for example 4G/5G), carrier and network country, roaming state, how many SIM slots are in use, and whether the SIM can make calls or send texts. Not the SIM serial, IMSI or your phone number — see the “never collected” row in section 03.
  • The phone itself: manufacturer, model, Android version and security patch level, the build identifier, screen size and density, free and total storage, memory, and how long since it restarted.
  • Locale: language and time zone.
  • Security posture: whether a screen lock is set, whether biometrics are enrolled, whether storage is encrypted, whether the screen is on, and whether USB debugging, developer options, or installing from unknown sources have been switched on.
  • Loktra's own state: app version, which permissions are granted, whether device admin is still active, whether protection is armed, whether stealth mode is on, whether Drive delivery is working, and how many uploads have failed.
Every field is optional: the report carries whatever the phone could read, and one sent before the first unlock legitimately leaves parts out.
So that when you ask “where is my phone and what is happening to it”, the answer is specific enough to act on — whether it is flat or has been reset, whether it has moved to another network or country, whether your controls still work, and whether someone is interfering with it. The three developer settings are there for that last reason: switching them on is usually preparation to bypass something, so a change in them is often the first sign a phone was taken rather than mislaid. Firestore, your account only.

How it reaches us without you being signed in. Before the first unlock your Google sign-in is unavailable to the app, so these reports cannot be sent the normal way. Instead the phone signs each report with a key held in the phone's own hardware security module and posts it to a single Loktra endpoint, which checks that signature against the public key your phone registered when you armed it. The private key never leaves the phone's secure hardware. This proves the report came from your phone, and the report is written only under your account. Reports that cannot be sent at the time are held on the phone and sent when it next has a connection.

Retention. These recovery reports are kept for up to 30 days and then deleted automatically. They are also deleted when you remove the device from your portal, when the device is removed automatically because the app was uninstalled or the phone was reset, and when you delete your account.

Turning it off. Recovery mode is active only while protection is armed. Disarming protection, or signing out, stops it and clears the information it keeps on the phone.

What "turn protection off" stops, precisely. Disarming stops Loktra watching and recording — no photo, video or audio is captured, by any trigger. Locating the phone and locking its screen keep working from your own portal, because those are how you find a phone you have lost and neither records anything. To stop those as well, sign out on the phone, which removes it from your account.

07What we do not do

08Data retention & deletion

Evidence stays on your device up to a storage limit you set (default 500 MB); when full, the oldest items are removed first. Files in your Google Drive remain until you delete them. Signing out removes this device's record from your account (and even if that removal doesn't complete, the app rejects any command from an account it is no longer signed in to). Remote-command records are kept for up to 29 days and then deleted automatically, and all of them go when you delete your account. That window exists because a stolen phone that is switched off may not come back online for weeks: Android holds an undelivered command for up to 28 days, so the record has to outlive it or your phone would run a command with nothing left to report back to. Pre-unlock recovery reports (section 06) are kept for up to 30 days and then deleted automatically; removing a device from your portal deletes its recovery reports and its command history along with it. To request deletion of any account data we hold, see our Data Deletion page.

The sign-in restore key (section 03) is deleted the moment it is used, when you sign out, and in any case around 13 months after it was issued. Google Play services only copies it to a new device during the setup transfer you start yourself, and only stores it in the cloud when your phone has a screen lock and end-to-end encryption available.

09Third-party services

Loktra relies on Google Firebase (Authentication, Firestore, Cloud Messaging) and Google Drive. If you submit the form on our Data Deletion page, it is delivered to us through Web3Forms (a form-to-email relay) — only the email address and details you type there are processed, solely to action your request. Your use of Google services is also governed by Google's Privacy Policy.

Viewing a capture's location. When you open a captured item that has a location, Loktra shows a small map and, where available, a human-readable address. To do this it sends only that item's coordinates to the device's Google geocoding service (to look up the address) and to OpenStreetMap (to fetch the single map tile shown). This happens only when you view such an item, uses the coordinates only to draw that preview, and never includes your media. Tapping the map opens the location in Google Maps. If you prefer not to make these lookups, simply don't open the location view; your evidence and its coordinates remain on your device and in your own Drive regardless.

Subscriptions and billing. If you subscribe to Loktra Premium, Google Play handles the payment — we never see your card details. So that your subscription works on your phone, our server stores the purchase identifier Google Play issues for it, together with your Loktra account id and whether the subscription is currently active. Google Play notifies us when the subscription renews, pauses, lapses or is cancelled, and we update that record. It is used only to decide whether Premium features are available to you, is never readable by any app or browser, and is deleted when you delete your account.

10Your rights & choices

You can sign out at any time (which stops delivery and device registration), delete evidence in the app or in your Drive, revoke permissions, and uninstall the app. To request deletion of account data, contact densmac06@gmail.com or use the Data Deletion page.

11Children

Loktra is not directed to children under 13 and we do not knowingly collect their data.

12Cookies

Loktra's website sets one cookie, and only if you choose a language: loktra_lang, holding a language code such as fr. It is a first-party preference cookie — it carries no identifier, is never used for analytics or advertising, and is not shared with anyone. Clearing your cookies removes it and the site returns to English.

The site uses no analytics, no advertising and no third-party tracking cookies. The remote portal additionally stores your chosen language on your account (see section 02) so that it follows you to any browser you sign in from.

13Changes

We will update this policy as the app evolves and revise the date above. Material changes will be surfaced in the app.