Privacy Policy
1. Who controls the data
CipherTransLocal refers to the software, website, account and licensing services, and their operator. The product is currently presented under LookMateAI. Before paid sales begin, checkout and order documents will identify the supplier information verified through Creem. The CipherTransLocal operator determines the purposes and means of account, licensing, device, first-party analytics, and product-support processing.
When you pay through Creem, Creem (Armitage Labs OÜ, Estonia) acts as Merchant of Record and contractual reseller. It processes payment collection, payment verification, invoices, sales tax/VAT/GST, fraud prevention, refunds, chargeback administration, and related compliance in its own name. Data Creem collects directly is governed by its Privacy Notice and the Buyer Terms shown in checkout.
2. Account and recovery data
Registration processes a normalized username, Argon2id password hash, one-time recovery-code hash, account creation time, failed-login counters, lock state, and server-side sessions. Plaintext passwords and plaintext recovery codes are not stored. The recovery code is shown once after registration and must be saved by you.
Accounts currently do not use an email address or phone number for authentication, and there is no email, SMS, OTP, or magic-link recovery. Customer sessions use Secure, HttpOnly, SameSite=Strict cookies for the account center and entitlement management.
3. Creem payment, tax, and order data
Creem Checkout may directly collect buyer name, email address, billing address, payment details, order details, country or region, IP address, and browser or device data for payment, tax calculation, invoicing, fraud prevention, compliance, and disputes. The current scope is described in the Creem checkout and Privacy Notice.
To bind payment to the correct account and deliver a license, we receive and retain the minimum transaction data needed for fulfilment, such as Creem checkout, order, customer, product, and event identifiers; amount, currency, order state, payment or refund time; and necessary buyer or billing details included in a verified webhook. The owner of an order is determined by the signed-in account and server-bound request_id created before checkout, not by the success-page URL, redirect parameters, or payment email alone.
Creem collects buyer payments, issues invoices in its own name, and handles applicable sales tax, VAT, or GST. CipherTransLocal will not separately collect the same payment, issue a duplicate payment receipt, or process an off-platform refund for a Creem transaction.
4. Licensing, activation-key, and device data
Commercial licensing processes order entitlements, a peppered activation-key hash, an AES-256-GCM encrypted full key, an independent installation_id, device name, platform, app version, device public key and fingerprint, activation and last-seen times, device state, device-token hashes, active-device allowance, and device-removal records.
A full activation key appears only in the authenticated account center or a temporary authorized administrator action. Administrator reveal, rotation, suspension, allowance, and device-removal actions are audited without storing the full key, password, recovery code, session token, or device access token.
5. LAN transfer content and on-device data
Text, photos, video, documents, APKs, archives, and other files you choose to send are not uploaded to CipherTransLocal servers, the licensing server, or Creem. They move between the sending and receiving devices on the currently reachable LAN.
For discovery and transfer, the clients handle device names, local IP addresses, ports, online state, filenames, sizes, types, messages, speed, progress, results, and local transfer history on your devices and network. Received files are saved to app cache, Downloads, Gallery, or a folder you select according to operating-system permissions and settings.
No upload to CipherTransLocal servers does not mean that other software cannot copy a file. A third-party gallery, receiving folder, or clipboard sync service may upload content under its own settings.
6. Android permissions, foreground service, and notifications
The Android app requests network, Wi-Fi state, nearby Wi-Fi device, notification, foreground-service, and system-file-picker permissions to discover LAN devices, read files you explicitly select, show transfer state, and reduce background interruption. File-picker access is not used to scan all storage.
A foreground-service notification is shown when background discovery or transfer availability must remain active. Stopping it, blocking notifications, restricting background execution, or applying aggressive battery limits may reduce discovery or transfer availability.
7. First-party website analytics
The website records normalized page path, visit time, page language, referring host, and device class. The server uses the network address and User-Agent in memory only to derive a peppered visitor hash that changes each day. It does not store raw IP addresses, full referrers, account identity, filenames, activation keys, messages, or transferred content.
Duplicate event IDs, the administrator route, API paths, and recognized bots are excluded. Page events are retained for 400 days. When Do Not Track or Global Privacy Control is enabled, the client sends no page-view event. Analytics requests use credentials: omit and do not carry customer or administrator cookies.
8. Security, support, and audit data
Necessary security logs, rate-limit identifiers, failed sign-ins, account locks, administrator audits, API error categories, and service health data are processed to prevent abuse, diagnose faults, protect accounts and licenses, and assist with refunds or disputes. Security logging is not designed to record transfer bodies or complete secrets.
When you contact support@ciphertrans.com, we process information you choose to provide, such as username, order identifier, device details, problem description, and attachments. This address is the contact route for purchase, delivery, refund, after-sale, and privacy requests. Do not send passwords, recovery codes, full activation keys, card details, or complete payment credentials by email or in a public GitHub issue.
10. Retention and account deletion
Account, entitlement, activation-key, and device records are retained while needed to provide licensing, support device replacement, handle refunds and chargebacks, maintain audits, and prevent abuse. After account deletion, removable sign-in and device data is separated from order records that must remain for legal, tax, accounting, refund, dispute, or legal-claim purposes.
Customer sessions last no more than 30 days by default and administrator sessions no more than 12 hours. Revoked or expired sessions no longer work. Website page events are retained for 400 days. Encrypted backups rotate under an operations schedule, so deleted records may remain in restricted backups until those backups expire.
Creem applies its own retention periods to payments, contracts, and accounting documents. Its November 2025 Privacy Notice describes continued retention for contract administration and Estonian accounting obligations. Consult the latest Creem notice for the current periods.
11. Your choices and data rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and withdraw processing based on consent. Some order, tax, security, and dispute records cannot be removed immediately because of legal duties or the establishment and defence of claims.
You can remove local history and received files on your devices, remove activated devices in the account center, and use DNT/GPC to stop new page analytics. Requests about payment data controlled directly by Creem should be sent through the process in the Creem Privacy Notice.
12. Changes and contact routes
This policy may change when the product, payment flow, infrastructure, or legal requirements change. Material changes will be signalled on the website, account center, or release notes, and the page date will be updated.
Public repository issues may be used for non-sensitive technical matters. Send account, order, payment, refund, privacy-right, and after-sale requests to support@ciphertrans.com. Do not send passwords, recovery codes, full activation keys, card details, or complete payment credentials. Live payment remains disabled until Creem review and payment integration are complete.