DoubleRubber is an encryption keyboard and message reader. This policy explains exactly what the app does and does not do with your information. It is short because the app is built to collect nothing.
All of the following is stored only on your device and is never transmitted:
| Data | Where | Purpose |
|---|---|---|
| Your encryption keys | The device Keychain (optionally protected by Face ID / Touch ID) | To encrypt and decrypt your messages |
| Key names (e.g. "Bob") | A private App Group container on the device | To let you choose which key to use |
| Fingerprints (hashes) of already-opened messages | A private App Group container on the device | "Burn after reading" — so the same message can't be opened twice |
Your passphrases themselves are never stored — only a key mathematically derived from them (PBKDF2) is kept, and even that cannot be turned back into the passphrase. Encryption uses AES-256-GCM. Plaintext messages are shown only on your screen and are never written into other apps.
iOS asks you to grant Full Access to the DoubleRubber keyboard. DoubleRubber uses Full Access for one reason only: so the keyboard can read your own encryption key from the shared on-device storage (App Group / Keychain) in order to encrypt and decrypt. The keyboard does not record your keystrokes, does not send anything off the device, and has no network capability whatsoever.
The app can scan a QR code (camera) only when you choose to import a shared key during in-person setup. Camera frames are processed on-device, are never stored, and are never transmitted.
The app is not directed at children and collects no data from anyone.
If this policy changes, the updated version will be posted at this URL with a new effective date.
Questions about privacy: techwinsty@gmail.com