Zirkon

ScanLocker asks iOS for five permissions, each for one purpose.

iOS asks you before an application may use the camera, the photo library, Face ID, the local network, or Bluetooth. This page states what ScanLocker does with each permission, quotes the prompt you will see, and tells you how to withdraw it.


When the prompts appear

ScanLocker asks for a permission the first time you use the feature that needs it. Opening the app asks for nothing. Nothing about how a permission is used is reported anywhere, and declining a permission leaves everything you have already saved readable.


Camera

The Scan tab uses the camera to photograph a document. The picture is encrypted as it is saved and never leaves the iPhone on its own. The prompt reads:

ScanLocker uses the camera to photograph documents and pictures you want to keep encrypted in the vault.

Without this permission the Scan tab cannot photograph a page. Importing from Photos and reading what you have already saved continue to work.

Photos

ScanLocker asks for the photo library in two separate ways, and iOS shows a separate prompt for each.

Importing pictures you pick

Choosing pictures from your library brings copies into the app. An imported item carries a yellow open lock, because the original already existed outside the app. The prompt reads:

ScanLocker can import photos you pick from Camera Roll. Imported items carry a yellow open lock because they already existed outside this app.

Saving pictures out

A single action in the app saves copies of your pictures into Camera Roll. iOS asks for permission to add to the library at that moment and at no other. The prompt reads:

ScanLocker saves copies of your pictures into Camera Roll only when you tap Download All Photos To Camera Roll. Camera Roll and iCloud can see those copies.

The app records the time of each save on its Security tab. A copy saved this way lives under the rules of Photos and of whatever iCloud settings you have chosen for Photos.

Face ID

You can switch on Face ID in the app's Settings so that opening ScanLocker requires the device owner. The app never sees your face; iOS answers a single question about whether authentication succeeded. The prompt reads:

ScanLocker asks for Face ID to unlock the app when you have switched that protection on in Settings.

If Face ID is unavailable, iOS offers the device passcode in its place. The app stores no passcode of its own for this lock.

Local network

Transferring your contents to a second iPhone running ScanLocker uses the Wi-Fi network both devices are on. The transfer advertises a service named _sl-migrate._tcp on that network so the second iPhone can find the first, and iOS asks for local network permission before that happens. The prompt reads:

ScanLocker uses Wi-Fi on this local network only to copy encrypted app contents to another iPhone you control. This does not go through the internet or AirDrop.

The payload crosses that link sealed under a key the two iPhones agree for that transfer alone.

Bluetooth

The same transfer can use Bluetooth to find the second iPhone and to carry the contents when no shared Wi-Fi network exists. The prompt reads:

ScanLocker can use Bluetooth to copy encrypted app contents to a nearby iPhone. This does not use the internet or AirDrop.

Bluetooth is used for that transfer and for nothing else. The app never scans for devices at any other time.


Withdrawing a permission

Open iPhone Settings, scroll to ScanLocker, and turn off the permission you want to withdraw. The same switches appear under Settings, then Privacy & Security, under each permission's own heading. The feature that needed the permission stops working, and everything you have already saved stays readable.

Permissions the app never asks for

ScanLocker never asks for your location, your contacts, the microphone, your calendar, your Health data, notifications, or permission to track you. It contains no code that would use any of them.

Contact

Write to support@zirkon.services with a question about any of these permissions. The Privacy Policy states what the application does with what it can see.