Privacy Policy

Last updated: July 26, 2026 · Applies to the Loktra Android app
Loktra is built on one principle: your evidence is yours. When Loktra catches an intruder, the photo, video, or audio goes straight to your own Google Drive — never to our servers. We keep the absolute minimum needed to make the app work, and nothing more.

01Who we are

Loktra ("we", "us") is an anti-theft app that protects the phone it is installed on. This policy explains what data the app handles, why, and your choices. Questions: densmac06@gmail.com.

02The short version

  • Intruder photos, video and audio never touch our servers. They are stored on your device and uploaded only to your own Google Drive.
  • We use Google Firebase only for sign-in, a device list, and delivering remote commands — never to store your media.
  • Location is used only for anti-theft: while protection is armed, Loktra keeps a recent location fix ready (refreshed periodically in the foreground) so a capture or a remote “locate” can be tagged instantly — even while the phone is locked. It is never continuously tracked, logged as a route, or sent to us; it travels only with your evidence to your Drive (and, for a remote locate you request, to your own private record).
  • Loktra protects your own device only. It is never hidden and shows a notice while active. We do not sell your data or use it for advertising.

03What Loktra collects and why

DataWhyWhere it lives
Intruder media (photo, video, audio)To identify who tried to access your device.In the app's private storage on your device, then your Google Drive.
Location (at capture)To show where an event happened.With the evidence, on your device and Drive.
Google account (email, ID)To sign you in and connect your Drive.Google Sign-In / Firebase Auth.
Device info (model, push token, last-seen)So your devices appear in your list and receive remote commands.Firestore, your account only.
Remote commandsTo carry a command you issue between your devices.Firestore, briefly, your account only.

04How your evidence is delivered

Loktra requests only the drive.file permission, which lets the app create and manage only the files it puts in your Drive — it cannot see the rest of your Drive. Evidence goes to a "Loktra" folder in your account. If you enable email alerts, we send you a message containing a link to that file; the media itself is never attached to or stored in the email system.

Email alerts and the Gmail API. Loktra has two ways to send that alert, and the version you install uses exactly one of them. Current Play Store builds send it through a mail relay we operate. Builds that request the gmail.send permission instead send the alert from your own Google account to you, so it arrives from you rather than from a stranger, and it does not depend on our servers at all. In that mode Loktra requests gmail.send and nothing else: it is a send-only permission that cannot read, search, list, or delete any message in your mailbox. The only message Loktra ever composes is the alert about your own device, addressed to you and to any trusted contact you added yourself.

In either mode the alert carries a link to the file in your Drive — never the media itself. We do not store the message, its contents, its recipients, or any mailbox data on our servers. In Gmail mode the message is sent directly from your device to Google; it does not pass through our systems. Your access token is issued to the app by Google Play Services on your own device, is used only for that request, and is never transmitted to us — the app stores only your email address and the ID of the Loktra folder in your Drive. You can revoke Loktra's access at any time at myaccount.google.com/permissions, or by signing out in the app, which stops Drive and email delivery immediately.

Limited Use. Loktra's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: we do not use Google user data for advertising; we do not sell, rent, or transfer it to third parties; we do not allow humans to read it; and we do not use it to develop, improve, or train generalised artificial-intelligence or machine-learning models. Google user data is used only to provide and maintain the anti-theft features you turned on.

05Permissions we request

PermissionUsed for
CameraCapturing an intruder photo or video.
MicrophoneRecording audio evidence.
LocationTagging where an event happened.
NotificationsThe required "protection active" notice and alerts.
Device adminDetecting failed unlocks; remote lock; uninstall protection. (Remote factory-erase runs only in the optional Device Owner mode; otherwise erase is handled by Google Find My Device.)
Phone stateDetecting a SIM change (a fingerprint only — never your number).
Foreground service (camera, microphone, location)Keeping protection running reliably and tagging evidence while locked.
Display over other appsLetting protection restart itself after a reboot or app update, and showing an optional full-screen warning to an intruder. Never used to draw over other apps otherwise.

You can revoke any permission in Android Settings. Some anti-theft features stop working without the permission they depend on.

06What we do not do

07Data retention & deletion

Evidence stays on your device up to a storage limit you set (default 500 MB); when full, the oldest items are removed first. Files in your Google Drive remain until you delete them. Signing out removes this device's record from your account (and even if that removal doesn't complete, the app rejects any command from an account it is no longer signed in to). Remote-command records are short-lived (each is cleared roughly a day after your next command, and all of them when you delete your account). To request deletion of any account data we hold, see our Data Deletion page.

08Third-party services

Loktra relies on Google Firebase (Authentication, Firestore, Cloud Messaging) and Google Drive. If you submit the form on our Data Deletion page, it is delivered to us through Web3Forms (a form-to-email relay) — only the email address and details you type there are processed, solely to action your request. Your use of Google services is also governed by Google's Privacy Policy.

Viewing a capture's location. When you open a captured item that has a location, Loktra shows a small map and, where available, a human-readable address. To do this it sends only that item's coordinates to the device's Google geocoding service (to look up the address) and to OpenStreetMap (to fetch the single map tile shown). This happens only when you view such an item, uses the coordinates only to draw that preview, and never includes your media. Tapping the map opens the location in Google Maps. If you prefer not to make these lookups, simply don't open the location view; your evidence and its coordinates remain on your device and in your own Drive regardless.

09Your rights & choices

You can sign out at any time (which stops delivery and device registration), delete evidence in the app or in your Drive, revoke permissions, and uninstall the app. To request deletion of account data, contact densmac06@gmail.com or use the Data Deletion page.

10Children

Loktra is not directed to children under 13 and we do not knowingly collect their data.

11Changes

We will update this policy as the app evolves and revise the date above. Material changes will be surfaced in the app.