Privacy policy
Effective October 10, 2026
Secrets2Go is built so that this policy can stay short: the app has nothing to disclose because it collects nothing.
What the app does with your data
- All network traffic goes directly from your device to the Infisical server you configure (Infisical Cloud or your own self-hosted instance), over HTTPS. There are no other endpoints.
- Connection credentials (client secrets, tokens, passwords) are stored only in the iOS Keychain on your device, with device-only accessibility classes. They are never synchronized, exported, or transmitted anywhere except to your configured server for authentication.
- Connection metadata (names, server URLs) is stored in the app's local container on your device.
- Secrets you view are held in memory only and are cleared when the app locks.
What we collect
Nothing. The developer operates no servers for this app and receives no data from it. The app contains no analytics, no crash reporting, no advertising, and no third-party SDKs. Its App Store privacy label is “Data Not Collected,” and that label is accurate.
What your Infisical server sees
When you use the app, your Infisical server sees the API requests the app makes on your behalf — the same requests the official web dashboard or CLI would make. That server's handling of your data is governed by its operator (you, your employer, or Infisical Inc. for Infisical Cloud), not by this policy.
Purchases
Secrets2Go is a paid app sold through the Apple App Store. Payment is processed entirely by Apple; we do not receive your name, payment details, or any purchaser information beyond Apple's aggregate, anonymized sales reporting.
Children
The app is a developer tool, collects no data from anyone, and is rated 4+ under Apple's rating system.
Changes
If a future version ever changes any of the above — for example, by adding optional crash reporting — this policy and the App Store privacy label will be updated first, and the change will be called out in the release notes.
Contact
Questions about this policy: see the support page.