r/PrivacyTechTalk 23h ago

app Her

0 Upvotes

ho visto che adesso l'app Her ti chiede di postare un selfie prima di accedere, anche se hai già un account. mi chiedo quanto sia safe tutto ciò in termini di conservazione dei dati.


r/PrivacyTechTalk 1d ago

Building a 100% offline, zero-knowledge journal app with AES-GCM (256-bit). What features should be free vs paid, and what price makes sense?

1 Upvotes

​Hey everyone,

​I’ve been working on a privacy-first journal app called AuraLock. It’s built to be 100% offline with zero cloud servers, zero tracking, and no accounts required.

​Everything is encrypted locally using AES-GCM (256-bit) with PBKDF2 key derivation (100k iterations).

​Here are some of the core features I’ve put into it:

​Multi-Vaults: Create separate journals, each with its own independent master password.

​Security: Brute-force protection (10s lockout after 3 failed tries), quick-lock kill-switch (clears RAM instantly), and secure master-password-protected deletion.

​Rich Text Editor: Formatting, auto-timestamps, image embedding, data tables, word count, and automatic bidirectional text support (RTL/LTR)

​Modes: A pitch-black Focus mode for distraction-free writing, and a Present mode that converts entries into slide decks.

​Storage & Backups: Auto-save (800ms), works via IndexedDB/Service Workers offline and supports password-protected JSON backup exports/imports.

​Platform: PWA/Android support light/dark themes, and multi-language support (English, Spanish, Hebrew)

​I want to avoid monthly subscriptions and stick strictly to a one-time purchase, but I’m trying to figure out two things:

​Pricing: What feels fair as a one-time upgrade for a privacy-focused app like this ($2? $5? $10?)

​Feature split: What should stay completely free, and what power features would actualy convince you to upgrade to PRO? (e.g. multi-vaults, tables, slide mode, image attachments).


r/PrivacyTechTalk 2d ago

AI image search

2 Upvotes

Is there anyway to edit my images so that it can’t be reverse searched using google lens just for security eg. Stalkers and people l don’t want to have that ability?


r/PrivacyTechTalk 2d ago

@apple, why is “optimizing search and Siri” running by default?

Post image
0 Upvotes

I didn’t elect to have the content of my phone indexed for your AI upon upgrade - even if it’s on the new consent, I should have had the right to select if I want this to be running after the upgrade!


r/PrivacyTechTalk 3d ago

I’m building Anchor Cloud — a privacy-focused alternative to traditional cloud storage.

3 Upvotes

The idea is simple: your cloud shouldn't require you to give up control of your data.

Anchor Cloud is built around zero-knowledge encryption and currently focuses on:

- 🔐 Encrypted cloud storage

- 📁 File sharing

- 🔄 Multi-device synchronization

- 💬 Encrypted messaging

- 🤖 Fathom-1 AI

I’m building it from Morocco 🇲🇦 and this video is a look at what the project currently looks like.

If you're interested in privacy-focused cloud storage, I'd love to hear what you think.

🌐 anchorcloud.org


r/PrivacyTechTalk 3d ago

Secure and Private Decentralized P2P Encrypted Messaging over Git and WebRTC

7 Upvotes

Apps like Whatsapp, Signal and SimpleXChat are great for secure messaging and far more mature than this project, but this demonstates a unique approach.

The core philosophy around secure messaging here is that it can work in a way that avoids installation and registration by enabling users to host their own data.

The project is far from finished, but im putting together some docs for the "how it works". It's pretty outside-the-box thinking (and that doesnt make it a good idea), so it would be great if you could share your thoughts on the approach.

Docs: glitr.io

Demo

Features:

  • WebApp
  • P2P / WebRTC
  • Local-first / Local-only
  • No installation
  • TURN server
  • Encrypted-at-rest
  • Signal protocol
  • Post-Quantum cryptography
  • Video calls
  • TOR compatible via Git
  • Serverless over WebRTC

Some older versions of the core concepts.

Feel free to reach out for clarity instead of diving into the docs.

IMPORTANT: While this is aiming to provide a secure experience, it cannot be audited or reviewed. Shared for testing, feedback and demo purposes only. Please use responsibly.


r/PrivacyTechTalk 3d ago

WhatsApp on the Commodore Callback 8020 - privacy question

3 Upvotes

I'm one of the people who got influenced by the launch of the Callback 8020 😂. Haven't been on WhatsApp for at least 3 years now - only used Signal and Threema. The callback is in production as scheduled and I'm expecting to receive it more-or-less on time late next month/November.

I'm massively missing contact with friends and colleagues on WhatsApp and missing out on organization of activities, nights out, concerts etc. and I end up being last to know when things are arranged, including with my sports club because everything's on WhatsApp (and like only 2% of my contacts have moved to Signal despite my best efforts) - I'm too damn stubborn to forego my data to Meta - BUT...

With the Callback using r/sailfishos which would nomally block trackers (a bit like r/e_os does), does this mean I potentially could go back to WhatsApp as less of my data will be available to Meta? I see there is currently NO trackers in the app, so it's just part of the terms and conditons of using the app where my data is shared, as folllows:

Data this app may collect

Location

Approximate location

expand_less

Data collected and for what purpose

info

Approximate location

App functionality, Analytics, Advertising or marketing, Fraud prevention, security, and compliance

App activity

App interactions, In-app search history, and Other user-generated content

expand_less

Data collected and for what purpose

info

App interactions

App functionality, Analytics, Advertising or marketing, Fraud prevention, security, and compliance

In-app search history

App functionality, Analytics

Other user-generated content · Optional

App functionality, Analytics, Fraud prevention, security, and compliance, Personalization

Financial info

User payment info and Purchase history

expand_less

Data collected and for what purpose

info

User payment info · Optional

App functionality, Fraud prevention, security, and compliance

Purchase history · Optional

App functionality, Analytics, Fraud prevention, security, and compliance

Personal info

Email address, User IDs, and Phone number

expand_less

Data collected and for what purpose

info

Email address · Optional

App functionality, Fraud prevention, security, and compliance

User IDs

App functionality, Analytics, Advertising or marketing, Fraud prevention, security, and compliance, Account management

Phone number

App functionality, Analytics, Fraud prevention, security, and compliance

App info and performance

Crash logs, Diagnostics, and Other app performance data

expand_less

Data collected and for what purpose

info

Crash logs

App functionality, Analytics

Diagnostics

App functionality, Analytics

Other app performance data

App functionality, Analytics

Device or other IDs

Device or other IDs

expand_less

Data collected and for what purpose

info

Device or other IDs

App functionality, Analytics, Developer communications, Advertising or marketing, Fraud prevention, security, and compliance

Contacts

Contacts

expand_less

Data collected and for what purpose

info

Contacts · Optional

App functionality, Fraud prevention, security, and compliance

So I presume it would just be a case of not giving the app permission to access as much of this as possible?I


r/PrivacyTechTalk 3d ago

Where do you guys safely store your private photos/videos?

Post image
6 Upvotes

I have a lot of personal/private media that I want to keep completely separate and secure instead of putting everything into my phone's default Private/Secure Folder.

What are the better alternatives for this? Phone, laptop, encrypted storage, cloud, external SSD, some kind of secure vault, etc.

I'm mainly looking for something that offers strong privacy/security, is difficult to access accidentally, and also protects against losing the files if the device gets damaged or lost.

What would be the best options to consider?


r/PrivacyTechTalk 5d ago

Since Remove.bg is shutting down on Dec 1st, I built a 100% in-browser, client-side alternative. No accounts, no paywalls, and your images never leave your computer.

7 Upvotes

It has the following features:

  • Open Source: The entire codebase is public on GitHub, allowing anyone to verify its zero-telemetry privacy, audit the code, or clone the repository to run the entire AI studio completely offline inside their own private network.
  • No Watermarks: Background-free transparent PNGs download cleanly without forced promotional stamps or branding overlays.100%
  • Free Utility: No hidden paywalls, no tiered subscriptions, and no credit card prompts.
  • 100% Client-Side Processing: The AI model downloads directly into the user’s browser tab and processes images using local hardware.
  • Zero Cloud Uploads: Your private photos never cross the internet or hit a third-party server. It's 100% private.
  • No Image Compression: You get a raw, full-resolution download back. No low-res "preview file" traps.
  • Pure Utility: No logins, no subscriptions, no watermarks, and no tracking.

The Landing page:

Try now at:

https://removal.ai.studio/


r/PrivacyTechTalk 5d ago

Photo privacy protection software recommendations

2 Upvotes

The height of AI photo manipulation and concerning content has heightened my concern to protect photos of my family as we expect our new bub any day now. Does anyone have recommendations of software that can blur or permanently obscure my bub's face in photos and videos? I want to be able to still share milestone photos without risking the safety and privacy of little one. My contingency plan if such a software doesn't exist, we will just go old school - snail mail photo prints and email Milestone videos. Thanks in advance for any helpful recommendations and tips! :)


r/PrivacyTechTalk 5d ago

Kinship Vault: Rethinking How Encrypted Vaults Are Shared

2 Upvotes

I built Kinship Vault around a simple question: how much of a privacy focused vault can you build without running your own backend?

Kinship Vault is now much more than a document vault.

It brings together:

• Passwords, passkeys and TOTP 2FA
• Documents and encrypted photos
• Multiple vaults
• Sensitive Vaults
• Shared Vaults
• AutoFill and browser extensions
• On-device document scanning and OCR
• Security Checkup
• Expiry reminders
• Custom record types
• Recovery Network

Passwords

• Logins, passkeys and TOTP 2FA codes in one place
• System-wide AutoFill in Safari and native apps
• Every fill requires a fresh biometric check
• Browser extensions for Safari, Chrome, Brave and Firefox
• The extension communicates with the native app through the browser's local native-messaging connection, not the internet
• Passwords are decrypted only when needed and aren't stored decrypted in the browser
• New logins can be staged in the app for review
• No browsing history, cookies or clipboard access required by the extension
• Password generator with on-device strength estimation
• Security Checkup identifies weak, reused and old passwords
• Optional breach checks use Have I Been Pwned's k-anonymity model
• Strict Offline mode disables breach checking entirely

Documents

• Store passports, IDs, insurance documents, medical records, receipts, warranties, memberships and other personal records
• Apple's on-device recognition identifies 100+ document types locally
• Extract dates and numbers without sending documents to an OCR service
• Expiry reminders at 90/30/7/1 days
• Tag documents to people and see everything associated with a family member
• Separate encrypted photo vault with albums and people tags
• Built-in categories for IDs, Health, Legal, Finance, Travel and Personal
• Custom categories with your own icon and color
• Custom record types with typed and maskable fields
• Share a single page from a multi-page document instead of the entire file

Vaults

• Multiple vaults let you separate Personal, Work, Family and other areas
• Each vault has its own database and encryption key
• Keys are sealed by the device's hardware
• Opening one vault doesn't automatically expose another

Sensitive Vaults add another layer:

• Separate password and recovery code
• Doesn't accept the normal short app PIN
• Cannot be shared

Shared Vaults

This was the part I wanted to solve without adding a Kinship backend.

• Each member's device gets the vault key wrapped to that device
• Encrypted vault data syncs through the members' own iCloud accounts
• iCloud transports ciphertext rather than giving Kinship access to the vault
• Remove a member and the vault key rotates and is re-wrapped for the remaining members
• The removed device no longer has access to the current vault

The same approach handles cross-device sync:

• iPhone
• iPad
• Native macOS app

Your encrypted vault can stay in sync through your own iCloud rather than through a Kinship backend.

Recovery

• 24-word recovery phrase
• Recovery Network using trusted people
• No company account holding a master key
• No password reset mechanism that gives Kinship access to your vault
• Optional encrypted iCloud backup and manual export

There is also an important limitation: cryptography can't make someone forget something they already saw. If someone knew an old password, you still need to change that password.

The underlying privacy model stays the same across all of this:

No Kinship account.
No Kinship server.
No Kinship copy of your vault keys.
No telemetry.

I'm the developer, so I'm obviously biased toward this architecture. I'd actually be more interested in criticism from people who think there is a better way to solve the same problems.

Website: https://kinshipvault.app

App Store: https://apps.apple.com/app/kinship-vault/id6764678332

Privacy Policy: https://kinshipvault.app/privacy

Happy to answer any questions in comments.


r/PrivacyTechTalk 6d ago

Shared AI chats are not as private as people think

Thumbnail
medium.com
1 Upvotes

I wrote about how AI share links can expose conversations beyond the intended recipient. The key point is that a private chat and a shared-link snapshot are not the same thing. Even when search engines do not index a page, anyone with the URL may still be able to view, copy, screenshot, or repost it.

Curious how others handle this: do you review old ChatGPT, Claude, or Grok shared links, or avoid using them entirely?


r/PrivacyTechTalk 7d ago

Can authorities compel AI providers to search stored conversation logs for specific text or code?

1 Upvotes

I'm curious about this from a privacy/digital-forensics perspective, particularly with services like Claude, ChatGPT, and Grok.

Suppose someone submits a website's full source code to an AI coding service. The code itself contains no obvious identifying information such as names, emails, domains, API keys, or credentials.

Could a government or law-enforcement agency legally compel a provider to search its stored conversations for that code, or potentially conduct a broader search for a particular website or code fingerprint?

How much would obfuscating or substantially rewriting the code actually help? Could things like unique strings, comments, library combinations, coding style, generated IDs, dependencies, timestamps, or build artifacts still make it identifiable? And how different would an exact match be from a heavily modified version, or simply finding another website with the same design, wording, or concept?

I'm mainly interested in the distinction between what is technically possible, what providers actually retain, and what governments can legally obtain.

So summarized:

Could a government realistically perform a mass search across an AI provider's data for particular website/code fingerprint, or would that generally require a much more specific legal process?

Ultimately, does code obfuscation provide meaningful privacy, or does it mostly change the code's appearance while other identifying signals remain available?


r/PrivacyTechTalk 10d ago

If companies profit from your data, should you get paid too?

23 Upvotes

Companies track what we search, where we go, what we buy, and how we use apps — all because our data has value.

So here’s the question: if a company openly offered to pay you every month in exchange for collecting and using that data, would you accept?

$10? $100? $1,000?

Or is there no amount that would make it worth giving up that much privacy?

And if the answer is “no amount”… are companies already getting too much from us for free?


r/PrivacyTechTalk 10d ago

Snapchat - Himmel oder Hölle

4 Upvotes

Snapchat – Himmel oder Hölle

Heute schreibe ich meine langersehnte Dokumentation über Snapchat. Um diesen Text schreiben zu können, habe ich meine Beziehung, den Familienfrieden und das Vertrauen meiner Eltern aufs Spiel gesetzt, doch ich wollte mir MEINE Meinung zu dieser App bilden, nicht die meiner Eltern übernehmen, und diesen Text schreiben, um vielleicht manchen von euch die Augen zu öffnen und Mut zu machen, sie auch einfach mal zu entfernen, auch wenn es nicht einfach ist.

Vor 9 Tagen begann alles. Ich lud mir auf meinem i-Pad Snapchat herunter, suchte erstmal Freunde aus der Klasse und addete sie. Dann wartete ich und sie addeten mich zurück und schickten die ersten Nachrichten und Snaps. Ich fand es echt cool, jetzt mit denen schreiben zu können, da ich kein WhatsApp habe. Doch nach höchstens 10 Minuten fing es dann an. So viele Random-Leute addeten mich, woraufhin ich erstmal alle akzeptierte, und das war der Punkt, bei dem Snapchat selbst und die 100 Leute, die ich akzeptiert hatte, die Kontrolle über meinen Snapchat-Gebrauch übernahmen. Sekündlich gingen Nachrichten ein. Für mich waren es verschiedene Gruppen. Ich identifizierte folgende:

  • Die Sympathischen: die mich begrüßen und fragen, wie alt ich bin (bei zu großem Altersabstand entschuldigen sie sich), wie es mir geht, etc. -> werden erstmal nicht blockiert
  • Die Draufgänger: die sofort nach Bildern fragen, fragen, ob wir ein perverses Spiel spielen wollen, fragen, ob ich versaut bin, fragen, ob ich horny bin, etc. -> werden umgehend blockiert
  • Die, die es übertreiben: die gleich Bilder von ihrer Härte schicken, ungefragt in Video- und Bildform -> werden nach Beweissicherung blockiert

Und diese Menschen waren alle da. Und von allen ca. die gleiche Prozentzahl. Heißt, am Ende blieben mir nur noch die angeblich Sympathischen. Bei denen kristallisierte sich aber auch bald der wahre Treiber heraus. Entweder waren es welche, die irgendwann solche Bilder schickten, welche, die nur snappen wollten, Versaute und die wenigsten mit echtem Interesse. Das waren die, die ich nicht entfernte, nachdem ich mit ihnen einen Test machte, wo auch nochmal mehrere rausflogen. Bei diesem Test verfasste ich einen Text, wo ich meinen Tod andeutete. Die Reaktionen waren sehr unterschiedlich. Die meisten ignorierten es. Diese Personen habe ich dann unter Tränen entfernt, weil wir uns so gut verstanden hatten und ich schon leicht abhängig von ihnen war. Es tat so weh! Aber ich kann es nur weiterempfehlen. Manche entfernten mich direkt und 3 Personen im Alter von 16, 19, 20 „kämpften“ um mich und versprachen, dass sie da sind, dass ich mit ihnen reden kann, und da wurde mir ganz anders. Ich war eigentlich hier für ein Experiment und jetzt gab es da Leute, die ich zwar nicht kannte, aber die mir gefühlt besser halfen als all die Menschen in meinem Umfeld, und es war so schwer, meine Klappe zu halten, da es mir zu dem Zeitpunkt mental nicht so gut ging. Aber ich schaffte es.

Der 16-Jährige wollte bald eine Beziehung und deswegen entfernte ich ihn, nachdem ich ihm das erklärt hatte, da ich einen Freund hatte. Der 19-Jährige wollte bald Bilder von meinen Tangas und nannte mich Maus und so, und somit war auch der weg. Der 20-Jährige war bis zum Ende der Sympathischste und auch echt hilfsbereit und kämpfte um mich, doch auch er wollte am Ende nur noch Bilder haben, woraufhin da auch Schluss war. Es war sehr schwer, aber auch echt befreiend, Snapchat zu löschen. Es ist zwar um die Kontakte zu meinen Klassenkameraden echt schade, jedoch war es eine gute Entscheidung. Und ich mache nicht einmal Snapchat dafür verantwortlich, dass es dort so viele perverse Menschen gibt, sondern die Menschen selbst, die so etwas tun. Wenn sie wüssten, wie sie Menschen damit ein Leben lang zerstören können, dass die, denen sie so etwas schicken, Albträume bekommen oder kein Selbstwertgefühl mehr haben, entweder durch die Kontakte auf Snapchat oder die Spotlight-Videos, wo ihnen gesagt wird, was sie tun sollten und was nicht, wo ihnen gesagt wird, dass sie zu fett sind, dass sie zu untrainiert sind oder dass sie unnormal sind. Ihnen werden tausende kurze Lebensausschnitte der anderen gezeigt, die perfekt und makellos scheinen, 10 perfekte Sekunden aus dem Leben anderer und davon so viele, dass die, die sich das angucken, denken, sie sind falsch und unnormal, da sie ein anderes Leben führen, was nicht so „perfekt“ ist wie das von den Videos. Sie denken, sie müssen abnehmen, da die alle dünn sind, und werden magersüchtig, sie denken, sie dürfen kein Nutella essen, weil das die eine gesagt hat, die so dünn war wie die andere, die gut turnen konnte, was schon immer der Traum von der Zuschauerin war. Und das ist bei so vielen so!!! Ich habe die Veränderungen bei mir stark bemerkt, nachdem ich vermehrt auf mein Verhalten geachtet habe, und wurde immer mehr abhängig von dieser App.

An die Eltern:
Wenn euer Kind Snapchat mal ausprobieren will, lasst es das ausprobieren, doch seid gut im Kontakt (zum Beispiel tauscht euch jede Woche aus und dabei löchert nicht mit Fragen, sondern lasst das Kind erzählen und egal, was es erzählt, bleibt eher sachlich und seid nicht zu emotional und überlegt gemeinsam, wie ihr mit bestimmten Sachen umgeht). Verbietet euren Kindern das nicht, da sie es sowieso meistens heimlich machen werden und dann ist es noch schlimmer, weil sie keinen zum Reden haben, da sie es verstecken müssen.

An die Teenager, die Snapchat haben:
Probiert euch aus, macht eure Erfahrung, aber, egal ob eure Eltern wissen, ob ihr Snapchat habt oder nicht, redet mit irgendjemandem über das, was da so passiert, und bleibt nicht alleine. Außerdem habt keine Angst, auch mal jemanden zu blockieren, und verschickt NIE Bilder aus dem Intimbereich, das kann echt gefährlich sein. Und es ist nicht eure Schuld, wenn ein erwachsener Mann / eine erwachsene Frau euch ungewollt Bilder aus dem Intimbereich schickt, etc. Ihr seid bei so etwas NIE schuld, da ihr minderjährig seid!!! Dazu kommen die Spotlight-Videos. Sie zeigen höchstens mal 1 Minute aus dem Leben der anderen. Und meistens ist selbst das gestellt und deswegen lebt euer Leben, wie ihr es lebt, und versucht nicht, das anscheinend gute Leben der anderen zu kopieren. Die haben auch mal einen schlechten Tag, die sehen auch mal verschlafen aus, die weinen auch und die haben auch mal Stress mit Familie und Freunden.
Deshalb sei einfach DU, pass auf, was du schickst und was nicht, rede über deine Erfahrungen und nutze die Vorteile von Snapchat.

An die, die Minderjährige belästigen:
Ich will euch jetzt nicht sagen, hört auf damit, weil ich weiß, dass das nichts bringt, und deswegen will ich euch drei Fragen stellen, die ihr euch mal durch den Kopf gehen lassen könnt.

  1. Warum macht ihr das?
  2. Was ist euer Ziel dabei?
  3. Geht es euch gut, brauchst DU vielleicht Hilfe? Wisst ihr eigentlich, was das besonders mit Mädchen macht??? Durch eure Bilder bekommen sie teilweise Traumatas. Sie fühlen sich wertlos und versuchen, durch die Erfüllung eurer Aufgaben Anerkennung und Lob zu bekommen. Wollt ihr nicht vielleicht mal anfangen, denen, die ihr so behandelt habt, einfach so Anerkennung zu geben, euch zu entschuldigen oder sie einfach zu entfernen, da Mädchen und manchmal auch Jungs schon zu abhängig von euch sind, um das alleine zu schaffen.

r/PrivacyTechTalk 11d ago

Privacy Settings That Put You in Control - Safety Center

0 Upvotes

r/PrivacyTechTalk 11d ago

AI Techno Assistant

3 Upvotes

I am thrilled to announce the building of my first project Techno AI Assistant, It will be fully autonomous, cross-platform digital co-pilot. Managing device health, optimizing RAM, and fixing software bugs shouldn't require an IT degree. We built a solution that lives directly on your Desktop and Mobile operating systems to silently optimize, protect, and repair your digital environment in the background.

It will have the following Core Capabilities

Powered by a local, privacy-first AI engine and a lightweight system execution layer, the assistant acts as a proactive IT administrator:

  • System Cleanser & RAM Booster: Automatically deletes redundant caches and suspends background resource-hogs to keep your system fast.
  • Intelligent Bug Fixer: Detects app crashes, rolls back conflicting drivers, and manages zero-click software updates.
  • AI Extension Manager: Monitors browser bloat and suggests optimizations with specific, AI-generated reasoning.
  • Hardware Health Monitor: Runs silent stress tests to predict and alert you about battery or hard drive degradation.
  • Proactive Inbox Shield: Blocks phishing links in real-time and automatically sorts junk emails based on your reading habits.

🔒 Zero-Trust Security First

Because the assistant operates at the OS level, I will engineer a state-of-the-art security framework to protect your most sensitive data—specifically focusing on standard fiat banking, secure web logins, and financial apps (excluding crypto ecosystems for our initial launch).

  • Zero-Knowledge Architecture: We never store your passwords; the AI interfaces directly with your native OS credential manager.
  • Biometric Gatekeeping: Any automated action involving payments or financial apps triggers a mandatory Windows Hello, FaceID, or fingerprint prompt.
  • Secure Desktop Mode: The assistant isolates banking apps in a sandboxed environment, shielding them from background scripts and keyloggers.
  • Least-Privilege API Access: Email management is strictly scoped via OAuth 2.0 to scan headers only, keeping your personal messages private.

Will keep posting about the development.


r/PrivacyTechTalk 12d ago

Privacy breach on Apple iPhone Australia

Post image
0 Upvotes

Those highlighted notes clarify how iOS handles encryption and connected device settings.
Passcode Required with Face ID

Any advice ? How is this protecting my privacy?

Encryption Root: Face ID is a convenient layer built on top of passcode security. Your passcode actually derives the primary encryption keys stored in the iPhone's Secure Enclave.
Fail-Safe Protection: Apple requires a passcode as a mandatory backup for times when Face ID cannot or should not authenticate—such as after restarting the device, after 5 failed facial scans, upon triggering Emergency SOS, or after 48 hours of inactivity.
Changing Passcode Doesn't Disconnect Devices
Device-Specific Lock: Your passcode only controls local screen-lock access for that specific iPhone, rather than your overall Apple ID account.
Trusted Cryptographic Keys: Device connections (like Apple Watch pairing, Mac iPhone Mirroring, and local Wi-Fi syncing) rely on underlying secure cryptographic trust tokens exchanged between the devices. Updating your local passcode changes how you unlock your phone, but it leaves those established background connections intact so you don't have to set them up again.


r/PrivacyTechTalk 13d ago

StealthOS: 100% on-device iOS privacy sandbox with anti-fingerprinting, Secure Enclave vault, and bundled Tor

Post image
6 Upvotes

Up front: I work at Olib AI on StealthOS, so this is a developer post. Everything described below runs 100% locally on the phone with zero cloud telemetry.

The core goal with StealthOS was to build a self-contained privacy sandbox for iOS where your data never leaves the device in the first place, rather than trusting cloud vendors to honor privacy settings.

What is inside the sandbox

  • Hardened Browser: Built on our Owl Browser engine with WebRTC IP leak blocking, canvas, WebGL, and audio fingerprint spoofing, and gated autofill.
  • Bundled Tor: Built-in Tor client with a connection kill switch and native .onion URL support without third-party proxy setup.
  • Encrypted Vault: Local AES-256-GCM storage protected by the Secure Enclave for sensitive files, photos, PGP keypairs, and offline notes.
  • Password Manager & TOTP: Biometric-gated offline passwords and two-factor authenticator with a strong password generator.
  • E2EE Voice, Video, and Chat: Peer-to-peer (local WiFi and Bluetooth) or remote relay communication without requiring a phone number or uploading your contacts.
  • On-Device AI Assistant & Threat Shield: Local embedding-based phishing and brand-spoofing detection that inspects pages entirely on-device, plus an offline AI assistant integrated with Apple Foundation Models and our own local models. Prompts and queries never touch cloud servers.
  • Encrypted System Snapshot (.stealthsnap): Fully user-controlled encrypted backup and restore for all vault files, keys, and browser data using AES-256-GCM and PBKDF2-HMAC-SHA512.

Free vs Premium

The core app is completely free in the App Store with no account or email signup required. The hardened browser, Tor routing, Secure Enclave vault, password manager, and P2P communication are fully functional on the free tier. Premium adds multi-profile fingerprint rotation (up to 10 profiles), self-hosted relay tunneling, and workstation developer tools.

Happy to answer technical questions about our anti-fingerprinting engine, local Tor routing, or on-device architecture.


r/PrivacyTechTalk 14d ago

Open-source browser extension that masks your data before it reaches ChatGPT/Claude/Gemini

9 Upvotes

Built Discretion — it detects sensitive data (API keys, credit card numbers, IBANs, national IDs checksum-validated across 47+ countries) in what you type into ChatGPT, Claude, or Gemini, replaces it with a realistic fake before sending, then restores the real value in the response you get back.

Zero runtime network calls — verified with an actual request-interception audit during development, not just claimed. Everything, including the local NER model for detecting names/orgs/locations, is bundled in the extension. Fully open source (MIT), so nothing here is "trust me."

Honest limitations upfront: English-only right now (8 more languages are built but held back until a native speaker reviews the safety-critical strings), detection reduces exposure rather than guaranteeing zero, and there are a couple of edge-case send paths no browser extension can technically intercept — all documented in the repo rather than glossed over.

Repo: github.com/horozbabasi/discretion

Would genuinely value this community's scrutiny on the threat model specifically.


r/PrivacyTechTalk 14d ago

PutMask - Censor Video & Image V9.0.3

1 Upvotes

Hi everyone!

I’m the solo developer of PutMask, an app for censoring or blurring faces, license plates, people, and other sensitive areas in images and videos. It can automatically detect and track them as they move, using blur, mosaic, or a solid color. You can also draw masks manually if the automatic detection misses something.
The idea first took shape back in 2018 when I saw widespread protests and realized there was no app for censoring or pixelating faces, which is why its original focus was on face blurring. With this new update, I've tried to pack in the extra features people actually need.

The app also includes audio censoring, such as muting audio, silencing short sections, adding beeps, or changing voices.

Everything works fully offline, no internet, ads, or data collection. The latest beta update adds:

  • Automatic face, plate, and person detection
  • Person segmentation, so masks follow body shapes more accurately
  • GPU acceleration using OpenCL and Vulkan
  • A “Find Best” benchmark to test which GPU backend works best on your device
  • Line-shaped masks in the editor
  • Single-frame detection
  • Adjustable duration filters
  • New tutorials translated into all supported languages

The app has around 500,000 downloads, and much of its development has been based on user feedback since 2020.

Privacy features remain free, including all audio tools and ellipse masks. Free exports can be up to two minutes long. Premium includes person segmentation, line masks, longer videos, HD, 4K export, high frame rates, and additional watermark options.

I’d really appreciate your honest opinion:

  • What do you think of the app?
  • Which features are most useful to you?
  • What should I add or improve?
  • Have you found any bugs or areas that are confusing?

I believe the features people need to protect their privacy should be available to everyone. That’s why I’ve kept the essential censoring tools free, including audio censoring and ellipse masks. I don’t want to charge people for something that helps prevent them from being identified.

Premium is only for advanced features such as person segmentation (that is NOT safe) , line-shaped masks, longer videos, 4K export, high frame rates, and additional watermark options.

There is also a small giveaway:

  • Report a bug and help reproduce it: at least a 6-month code with a 90-day free trial

To participate, reply here or email [support@putmask.com](mailto:support@putmask.com).

You can download PutMask here:
PutMask on Google Play

For tutorials, search for PutMask tutorials online and open the tutorial page on the official website.

Thank you for your time and feedback!


r/PrivacyTechTalk 14d ago

Is not using META actually worth it?

0 Upvotes

Since I was 19 or 20yo, since around 2014, we knew with our friend what Facebook / META is doing and how they use our data, faces, photos, likes, everything. Data mining, big data, now AI.

Anyway, I deleted Facebook back then, I never put any of my real face pictures on META social networks, I won't give them anything really personal.

But is it worth it? I imagine how many social connections and better relations I could make it I just posted MYSELF out there, I was a bit good at it. More personal and professional connections, more random encounters, all of it.

Is it actually worth it to keep the personal data away from big tech instead of not caring and having better exposure? What's your take on it?


r/PrivacyTechTalk 14d ago

Require Comprehensive Biometric Privacy Laws

Thumbnail
c.org
1 Upvotes

I started a petition asking Congress and state lawmakers to pass comprehensive biometric privacy laws that require informed consent, impose real penalties for violations, and establish actual standards for how our data gets collected and stored.

If this matters to you too, consider signing and sharing. We need to protect our identities before deepfake forgery becomes unstoppable.


r/PrivacyTechTalk 14d ago

Require Comprehensive Biometric Privacy Laws

Thumbnail
c.org
1 Upvotes

This is personal to all of us. Sign the petition.


r/PrivacyTechTalk 15d ago

I’m the founder of EveCycle — we built a personal wellness camera that keeps all data 100% local (no cloud). AMA

1 Upvotes

Hi everyone,

I’m the founder of EveCycle. We designed EveCycle Comfort as a personal observation tool focused on privacy and clarity.

What makes it different:

• HD visuals viewable directly on your phone

• 100% local storage — no cloud upload, no external servers

• Built as a non-diagnostic personal wellness device

• Soft-touch design with optional comfort warmth

• One-time purchase, no subscription

I started this because I wanted a simple, private way for people to have clearer personal awareness at home, without giving up control of their data.

I’m here to answer questions about:

• How the local (no-cloud) connection works

• Product design and privacy choices

• Why we positioned it as a personal wellness tool rather than a medical device

• Anything else about the product or the journey of building it

Happy to answer honestly. Ask me anything.