1. Summary
Wing Secure ("the app") is built offline-first. Your vault, your notes, your passwords, your 2FA secrets and your activity log are stored and processed on your iPhone. We do not operate an account system, we do not host a copy of your vault, and we do not sell personal data to anyone.
Three features can send data over the internet, and only at the moment you use them: the online link check, the password breach check and the email breach check. Each is described in section 5.
2. Who we are
The app and this website are operated by C&F PANGERAS LTD, 54 Pafou, Pissouri, Limassol 4607, Cyprus ("we", "us"). For privacy questions, contact support@wingsecure.tech.
Where the GDPR applies, C&F PANGERAS LTD is the data controller for the limited processing described below. We are established in Cyprus, an EU member state, so no separate EU representative is appointed.
3. What stays on your device
The following is created, encrypted and stored locally on your iPhone. It is not transmitted to us and we have no ability to read it:
- Vault contents — passwords, logins, secure notes, documents, cards and their attachments.
- 2FA (TOTP) secrets and the codes generated from them.
- Your vault code, decoy code and biometric-unlock preference. Codes are never stored in plain text and never leave the device.
- The SMS scam filter's classification rules and the results of filtering. The filter runs entirely offline.
- Photo metadata cleaning. EXIF and GPS data are stripped locally; the original and cleaned photos are not uploaded.
- Link cleaning (tracker-parameter stripping) and local phishing heuristics.
- The activity log, including security events such as failed unlock attempts.
- App settings and theme preference.
Because there is no cloud copy and no recovery mechanism, if you lose your vault code, neither you nor we can recover the contents. This is a deliberate design decision.
iOS Message Filter extension
When you enable Wing Secure as a Message Filter in iOS Settings, Apple's system passes texts from numbers that are not in your contacts to the extension for classification. By Apple's design the extension operates in a restricted environment, and Wing Secure's classifier runs offline. We do not receive, store or transmit the content of your messages.
4. Information you provide
We process the following only when you actively use the relevant feature:
- Email address (breach check) — the address you type is sent to the breach-database provider to look it up. We do not store it on our own servers. It is retained on your device only if you keep the result in your activity log.
- URLs (online link check and redirect tracer) — the address you are checking is sent to the check provider, or requested directly, in order to return a verdict or trace the redirect chain.
- Password hash prefix (password breach check) — see section 5.
- Support messages — if you contact us through the support form or by email, we receive the address and message you send, and keep them for as long as needed to answer you and to keep a record of the correspondence. We keep support correspondence for 24 months and then delete it.
5. Third-party services
Wing Secure uses the following services. Each is contacted only when you use the corresponding feature, and each has its own privacy policy:
- Google Safe Browsing — used by the online link check to match an address against Google's threat database. The address being checked is sent to the service. You can turn online link checking off completely in Settings → Online link check, in which case only local heuristics are used.
- Have I Been Pwned — used by the email breach check. The email address you enter is sent to the service to look up known breaches.
- Pwned Passwords (k-anonymity API) — used by the password breach check. The password is hashed on your device and only the first five characters of that hash are sent. The service cannot reconstruct your password from this, and your password itself never leaves your iPhone.
- Apple — App Store distribution, and (if you enable it) sharing anonymous crash and usage data with developers through your iOS privacy settings. This is controlled by Apple and by your device settings, not by us.
These providers may process the data they receive, including the IP address your request comes from, under their own terms. We do not receive a copy of what you look up. Their policies: Google Privacy Policy and Have I Been Pwned privacy policy (which also covers Pwned Passwords).
6. Website and analytics
This website is a static site. It sets no advertising cookies and does not build a profile of you. The support widget is a front-end demonstration only: nothing you type into it is transmitted or stored anywhere. To reach us, email the address in section 12.
We do not run analytics on this website. There are no tracking scripts, no cookies set by us, and no cross-site tracking.
Our hosting provider may process standard server logs, including IP addresses, for security and to deliver the site.
7. What we never do
- We do not sell or rent personal data.
- We do not share personal data with advertisers or data brokers.
- We do not use your data to train models.
- We do not upload your vault, your notes, your photos or your messages.
- We do not require an account, a phone number or a name to use the app.
8. Data retention
Data stored on your device stays there until you delete it, or until you delete the app. Deleting the app removes its local storage, including the vault. Self-destructing notes are deleted according to the rule you set for them (after first open, or after 24 hours).
Support correspondence is retained as described in section 4. We do not maintain a database of app users.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or port your personal data, to object to processing, and to lodge a complaint with your data protection authority.
Because almost everything the app handles is stored solely on your own device, you can exercise most of these rights directly: view, edit and delete items in the app, clear the activity log, or delete the app. For anything held by us — in practice, support correspondence — email support@wingsecure.tech and we will respond within 30 days.
10. Children
Wing Secure is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has sent us personal data, contact us and we will delete it.
11. Changes to this policy
If we change how the app handles data, we will update this page and the "last updated" date above. Material changes will also be noted in the app's release notes. Continuing to use the app after an update means you accept the revised policy.
12. Contact
Questions, requests or complaints: support@wingsecure.tech, or use the support chat on this site. Postal address: C&F PANGERAS LTD, 54 Pafou, Pissouri, Limassol 4607, Cyprus.