Privacy Policy

Cryptolab

com.glyphworks.cryptolab · in force 26 September 2026 · EmberOak Interactive

AbstractCryptolab is a closed lab: no account, no advertising, no analytics, no network. The messages you type, the ones you save with their cipher settings, and your scores are written to your own phone and to nothing else.

01controller

Who runs the lab

The publisher is Bis Eiendom Holding AS, registered at Krokeidevegen 61, 5244 Fana, Norway and trading under the name EmberOak Interactive, with Frode Kregnes answering for it. Norwegian data law applies the GDPR through personopplysningsloven, and it makes that company the controller for anything personal on this page. One address for all of it: [email protected].

02stored

What the app writes to the phone

  • messages you chose to save, together with the cipher and key used for them;
  • your best scores in the challenges;
  • settings: accent theme, Morse flash speed, language.

A saved message is free text: it holds whatever you decided to type, which is exactly why it is written into the app's private storage and never transmitted. No account exists to attach it to and no server of ours could receive it. Where Android's own backup is enabled, that file may travel into the backup Google holds under your account, which is between you and Google.

03keys

Your keys stay with your messages

A keyword typed into the Vigenère field, or a shift chosen on the Caesar wheel, is stored beside the message it belongs to and nowhere else. The app does not index them, does not sync them and cannot recover them for you: lose the phone and both the message and its key go with it.

04permissions

What the app asks for

Not one permission is requested. Camera, microphone, position, contacts, storage: all untouched, and no socket is opened in either direction. Flashing Morse is simply the screen changing colour, which Android grants to any app for free, and the charts, wheels and flag figures are all drawn in code.

05telemetry

What we learn

Nothing whatsoever. No sign-in, no advertising identifier, no analytics library, no crash reporter of ours, no profiling. We cannot see which ciphers are popular, how many messages anyone has saved, or whether the app has ever been opened.

06store

Google Play

One party sits between the app and you: the store. Google Play delivers it under Google's own terms, and where a handset is configured to send usage and diagnostics to Google, our Play Console dashboard may show pooled crash counts. There is no person, phone or message in those counts — only a tally of what failed.

07minors

Notes passed in class

Children are a natural audience and nothing is collected from them, or from anyone else. There is no chat inside the app, no link out and nothing to buy. Anything written into it stays on that one phone.

08warning

These ciphers protect nothing

Every method in Cryptolab was broken long before computers: a Caesar falls in seconds, a Vigenère in minutes, and a page of substitution is a puzzle-magazine exercise. The app is a teaching lab and says so on each cipher's page.

Never put a password, a bank detail, a health note, a photograph caption you would mind being read, or anything else that actually matters through one of these and treat it as protected. For real secrecy use the encryption already built into your phone and your messaging apps — and be suspicious of any product that offers a hand-rolled cipher for real data.

09post

Writing to us

Mail is the single channel through which anything about you reaches us at all: an address, and whatever the message says. It serves to answer you and to repair the app, resting on legitimate interest under Article 6(1)(f), and the thread goes within a year of our final reply unless a law keeps it alive. One request: don't paste in a saved message you would rather we never read.

10rights

Rights, and where to take a complaint

Every GDPR right is available to you here, from access through to portability, even though an email thread is realistically the only file that exists. Put the request to us and the reply comes inside a month. Not satisfied by it? In Norway the supervisory authority is Datatilsynet, datatilsynet.no; readers elsewhere in the EEA can raise it with the authority in their own country.

11wipe

Clearing the bench, and revisions

One action empties the bench: open the app entry in Android settings, go to storage, clear the data. Saved messages leave with their keys, the scores go, the settings reset, and because nothing was ever copied elsewhere there is no way back — removing the app does the same. Revisions to this page are published before the release that makes them necessary, dated in the masthead.

Bis Eiendom Holding AS · EmberOak Interactive · Krokeidevegen 61, 5244 Fana, Norway

[email protected] · © 2026

Du kan gjerne skrive på norsk.