PRIVACY POLICY & DATA HANDLING
Overview
MioCC is built to protect your content — not to collect it.
This Privacy Policy explains how personal data is handled in connection with the MioCC application, the ccyph.com website, licensing and activation services, purchases, support, security, privacy and legal communications.
This Policy applies wherever MioCC is lawfully offered.
Where applicable law provides additional or stronger privacy or data-protection rights or obligations, those mandatory requirements remain fully applicable.
Nothing in this Privacy Policy is intended to limit any non-waivable right available under applicable law.
Authoritative Language
English is the authoritative version of this Privacy Policy to the extent permitted by applicable law.
Translations may be provided for convenience. Where mandatory applicable law requires information to be provided in another language or otherwise limits the effect of this clause, that law prevails.
1. Data Controller
Data Controller: Miodrag Šestović
Status: Private individual
Postal address: Plagenti 2, 85330 Dobrota, Kotor, Montenegro
Privacy and Data Protection Contact: mio.ccomm@gmail.com
The Privacy and Data Protection Contact is responsible for receiving privacy-related requests and communications unless a separate local representative or other legally required contact is identified in this Policy.
Users should not send passwords, PINs, private keys, original unprotected files or other unnecessary confidential content when contacting MioCC.
2. Privacy by Design
MioCC is designed around local processing.
Encryption and decryption of text and files take place on the user's device.
MioCC processes only content that the user intentionally provides to the application for encryption, decryption or another requested operation.
A file may be provided from a download location, device storage, another application or another source selected by the user.
MioCC does not have general access to the location from which a file originates.
MioCC does not independently browse, scan, search or inspect other files, folders or content on the user's device.
The normal encryption and decryption workflow does not require original content to be uploaded to the developer.
MioCC does not require the developer to receive:
• original messages or text provided for encryption;
• original files provided for encryption;
• decrypted files or decrypted text;
• passwords or PINs used for local protection;
• cryptographic values used locally;
• private cryptographic keys;
• other content stored on the user's device.
Providing content to MioCC for a requested operation does not by itself transmit that content to the developer.
Protected and decrypted content remains under the user's control unless the user independently chooses to save, export or share it through another application, service or destination.
MioCC cannot access, restore or disclose content that the developer never receives.
3. Content Processed Locally on the Device
Depending on the operation requested by the user, MioCC may locally process:
• text intentionally provided to the application;
• files intentionally provided to the application;
• passwords or PINs used for the requested operation;
• cryptographic values required for the operation;
• temporary working data required to complete the operation;
• encrypted results;
• decrypted results;
• application preferences and settings.
MioCC does not obtain general access to the user's device storage merely because a file is provided to the application.
MioCC does not independently access the folder, application or other source from which a provided file originates.
The application processes only the content intentionally provided by the user for the requested operation.
This locally processed content is not transmitted to the developer merely because MioCC processes it.
The user controls whether resulting content is saved, copied, exported or shared and selects the destination through MioCC, the operating system or another application.
Files saved or exported by the user outside MioCC's private application storage remain subject to the storage location and controls selected by the user and are not necessarily removed if MioCC is uninstalled.
If the user chooses to send or share content through another application or service, that application or service processes the content under its own privacy and security practices.
Password Entry, Generation, Strength Display and Clipboard
For local encryption and decryption, a user may enter a password manually or ask MioCC to generate a cryptographically random 20-character password locally on the device.
The four-segment strength indicator evaluates the password locally and provides advisory feedback. The result is an estimate and is not transmitted to the developer. It does not guarantee resistance to every attack.
SHOW PASSWORD reveals the current password only on the device screen. COPY places the password in the operating-system clipboard. PASTE reads the text currently available through the device clipboard only when the user selects that control and places the exact text in the password field without trimming, normalization, automatic display or automatic processing. If direct clipboard access is unavailable, the user may use the operating-system long-press Paste command. Depending on the device and installed software, clipboard contents may be available to the operating system, keyboard software or other applications. MioCC does not send clipboard contents or the pasted password to the developer merely because COPY or PASTE is used. Users should use these functions in a private environment and clear or replace clipboard contents after use where supported.
MioCC does not automatically send a password to another person or device. If the password must be shared, the user chooses and controls a separate communication channel. MioCC does not see or control that external transmission merely because the user copied the password.
MioCC does not provide a developer-operated cloud password vault, cross-device password synchronization, password reset or developer-assisted password recovery.
4. Personal Data We May Receive
Core local use of MioCC for encryption and decryption does not require the user to provide personal data to the developer.
An email address, license identifier and Device ID or installation identifier are required only where the user requests activation or verification of LIGHT or PRO licensed functionality. Without the information technically required for licensing, paid functionality cannot be activated or verified. The FREE edition's core local functions do not require a paid-license record.
Contacting MioCC for support, privacy, legal or security questions is voluntary. The user chooses what information to include, but should not send passwords, PINs, private keys or unnecessary confidential content.
Where the user chooses to purchase a license through Paddle, Paddle may require transaction, billing and contact information under Paddle's own terms and privacy practices. The information necessary to complete that separate purchase is not required merely to use MioCC's core local FREE functions.
Although MioCC's core content-protection functions operate locally, limited personal or technical data may be received where necessary for licensing, purchases, website operation, support or security.
Files, text and other content intentionally provided to MioCC for local encryption or decryption are not transmitted to the developer merely because they are processed by the application.
Depending on the service used, personal data actually received by the developer may include the following.
Contact Information
• email address;
• name, where voluntarily provided or made available through an authorized purchase provider;
• information included in a support, privacy, legal or security request.
Licensing Information
Licensing and activation records may include:
• an internal licensing record identifier;
• license identifier or license key;
• customer email address associated with the license;
• plan or MioCC edition;
• billing classification;
• license status and activation status;
• permitted or registered device count;
• expiration or validity information where applicable;
• transaction identifier;
• device or installation identifier used for licensing;
• device platform and device label;
• activation timestamp and last-seen timestamp;
• activation history; and
• other limited technical metadata reasonably necessary to issue, administer, secure or verify a license.
These licensing records are separate from the contents of files, messages, passwords, PINs and cryptographic secrets processed locally by MioCC.
Purchase Information
Where a purchase is completed through an authorized Merchant of Record, payment provider or app-store service, MioCC may receive limited buyer or transaction information made available by that provider, which may include:
• purchaser name;
• email address;
• billing address or country information;
• product or license purchased;
• purchase history relating to MioCC;
• transaction identifier;
• purchase date;
• refund or dispute status;
• invoice-related information;
• transaction status;
• transaction analytics or other transaction metadata made available to MioCC.
The developer does not receive or store the buyer's complete payment-card details when those details are handled by the Merchant of Record or payment provider.
Communications
If a user contacts MioCC, the developer may receive:
• the sender's email address;
• the contents of the communication;
• attachments voluntarily supplied by the user;
• other information reasonably necessary to investigate and answer the request.
Users should not send unprotected confidential content, passwords, PINs or private keys to support.
Website and Security Information
Website, hosting, licensing or security infrastructure may generate limited technical records necessary for operation, diagnostics, fraud prevention, abuse prevention or security.
Such information may include:
• IP address;
• date and time of a request;
• requested page or service endpoint;
• browser or user-agent information;
• technical errors;
• security-event information.
Such information is not used to inspect the contents that a user encrypts or decrypts with MioCC.
5. How Personal Data Is Obtained
Personal data may be obtained:
- directly from the user, when the user contacts MioCC or provides information necessary for a requested service;
- from the licensing system, when activation or verification is performed;
- from Paddle or another authorized Merchant of Record or payment provider, where transaction information is made available to MioCC;
- from an application-distribution provider, where relevant information is made available through that provider's services;
- automatically from website, hosting, licensing or security infrastructure where limited technical records are generated.
MioCC does not purchase personal-data lists.
MioCC does not obtain the user's protected content from data brokers or advertising providers.
6. Purposes of Processing
Personal data under the developer's control may be processed only where reasonably necessary for purposes including:
• issuing and administering licenses;
• activating and verifying licenses;
• maintaining license status;
• delivering licensed functionality;
• processing or reconciling purchase information;
• handling refunds or disputes where applicable;
• responding to support requests;
• responding to privacy or data-protection requests;
• responding to security reports;
• preventing fraud, license abuse and unauthorized activation;
• protecting users, the website and licensing infrastructure;
• diagnosing technical problems;
• maintaining necessary operational records;
• maintaining records required by applicable law;
• establishing, exercising or defending legal claims;
• complying with valid legal obligations;
• maintaining the security and integrity of MioCC services.
Personal data is not collected for the purpose of reading, analysing or profiling the content a user protects with MioCC.
7. Legal Grounds for Processing
Depending on applicable law and the processing concerned, personal data may be processed on one or more lawful grounds.
Performance of a Contract or Steps Requested Before a Contract
This may include:
• license issuance;
• license activation;
• purchase-related administration;
• delivery of paid functionality;
• support connected with the product or license.
Legitimate Operational and Security Interests
Where permitted by applicable law, limited personal data may be processed for legitimate purposes including:
• preventing fraud and license abuse;
• protecting users and systems;
• maintaining service security;
• diagnosing technical problems;
• responding to disputes;
• maintaining necessary operational records.
Such processing is carried out with regard to data minimization and the privacy rights of affected individuals.
Compliance With Legal Obligations
Personal data may be processed or retained where required by applicable law or another legally binding obligation.
Consent
Where applicable law requires consent for a particular processing activity, consent will be requested before that processing occurs.
Where processing is based on consent, the user may withdraw that consent in accordance with applicable law.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Where applicable law uses different terminology or requires another lawful basis, the corresponding mandatory legal standard applies.
8. Paddle and Purchases
Where a MioCC license or other MioCC product is purchased through Paddle, Paddle operates the purchase service as an authorized reseller and Merchant of Record.
Paddle independently processes payment and billing information necessary to complete and administer the transaction under Paddle's own legal terms and privacy practices.
Paddle may provide MioCC with limited buyer and transaction information necessary for purposes such as:
• product delivery;
• licensing;
• activation;
• transaction administration;
• customer support;
• refunds;
• disputes;
• fraud prevention;
• other legitimate product-related purposes.
MioCC does not receive the buyer's complete payment-card details from Paddle.
For Shared Personal Data exchanged for product fulfilment, licensing and transaction administration, Paddle and MioCC act as independent Controllers. Neither party acts as the other party's processor for that Shared Personal Data.
Shared Personal Data made available to MioCC may include the buyer's name and address, email address, purchasing history relating to MioCC, and transaction analytics available through Paddle's dashboard or integration. Paddle may independently process additional payment, billing, tax, fraud-prevention and transaction information under Paddle's own legal terms and privacy practices.
Privacy requests concerning information controlled solely by Paddle should be submitted directly through Paddle's privacy-request service at https://preferences.paddle.com/privacy or by email to privacy@paddle.com.
9. Application Stores and Other Independent Services
Application stores, operating-system providers and other independent services may process personal data in connection with their own services, including:
• application downloads;
• store accounts;
• device compatibility;
• payments where applicable;
• security;
• store operations;
• technical services.
Those activities are governed by the relevant provider's own privacy terms and legal obligations.
The Android application currently distributed through Google Play is the FREE, consumption-only edition. Google Play does not currently process purchases of MioCC LIGHT or PRO licenses. Applicable paid licenses are sold separately through Paddle, acting as an authorized reseller and Merchant of Record.
MioCC does not treat access to an application-store account or operating-system service as permission to access the user's private files or protected content.
10. No Sale of Personal Data
MioCC does not sell personal data.
MioCC does not rent personal data to third parties.
MioCC does not disclose personal data to data brokers.
MioCC does not use protected user content for targeted or behavioural advertising.
MioCC does not disclose personal data under the developer's control for cross-context behavioural advertising.
Where applicable law provides rights to opt out of the sale, sharing or use of personal data for targeted advertising, MioCC's current practices do not involve such activities.
11. No Behavioural Profiling or Significant Automated Decisions
MioCC does not use personal data under the developer's control to create behavioural advertising profiles.
MioCC does not make decisions producing legal or similarly significant effects about users solely through automated processing.
License verification, fraud-prevention mechanisms and technical security checks may involve automated technical processing.
Such processing is used to administer and protect the product and licensing system rather than to create behavioural profiles of users.
Where applicable law provides additional rights concerning automated decision-making or profiling, those mandatory rights remain available.
12. Artificial Intelligence and Protected Content
Original text, files and other content processed locally by MioCC are not provided by the developer to artificial-intelligence systems for training.
MioCC does not upload protected content to the developer for AI analysis as part of its normal encryption or decryption workflow.
Personal data under the developer's control is not used by MioCC to create advertising profiles through artificial-intelligence or machine-learning systems.
13. Data Sharing and Service Providers
Limited personal data may be disclosed where reasonably necessary to:
• Merchant-of-Record or payment providers;
• hosting and infrastructure providers;
• email and communication providers;
• application-distribution providers;
• security or technical service providers;
• professional advisers where reasonably necessary;
• competent authorities where disclosure is legally required.
Service providers are expected to handle personal data for legitimate purposes connected with the services they provide and subject to applicable contractual and legal requirements.
Hosting Infrastructure
MioCC backend and licensing records are hosted on cloud server infrastructure located in Germany and provided by Hetzner Online GmbH.
Hetzner acts as a data processor under a Data Processing Agreement concluded in accordance with Article 28 GDPR. Under the applicable agreement, where an EU server location is selected, customer data is processed only within the European Union, and technical and customer support services are provided from within the European Union.
Hetzner does not receive the original text or files processed locally by MioCC merely because a user encrypts or decrypts content.
Operational Email Infrastructure
Brevo is used as an email-delivery provider for automated operational and security alerts sent from MioCC server monitoring to the Data Controller.
These alerts are configured for infrastructure administration and are not used for advertising or marketing to MioCC users. They are not intended to contain users' original files or text, passwords, PINs, private cryptographic keys, complete license keys, complete licensing records or database contents.
Brevo may process the sender and recipient addresses, delivery metadata and the limited technical content of an operational alert as necessary to deliver and secure the message under its applicable terms and data-processing arrangements.
Google/Gmail is used to receive and reply to ordinary support and privacy requests sent to mio.ccomm@gmail.com. When a user sends such an email, Google and the sender's email provider may process the addresses, routing metadata, message content and any attachment voluntarily included by the user under their respective terms and privacy practices.
Personal data is not shared with advertisers for behavioural advertising.
14. Government and Legal Requests
Personal data under the developer's control may be disclosed where required by applicable law, a valid court order or another legally binding request from a competent authority.
Where legally permitted, requests may be assessed for validity, scope and proportionality.
MioCC cannot disclose original encrypted or decrypted user content that the developer does not possess.
Nothing in this Privacy Policy should be interpreted as suggesting that the developer has access to data that MioCC's architecture does not collect or transmit.
15. International Processing and Transfers
MioCC is controlled from Montenegro.
Some providers used for payments, application distribution, hosting, infrastructure, email, security or other supporting services may process limited personal data in countries other than the country in which the user is located.
Where applicable law requires safeguards for an international transfer of personal data, appropriate lawful mechanisms will be used.
Depending on the applicable legal regime, such mechanisms may include:
• processing in a jurisdiction recognized as providing an adequate level of protection;
• contractual data-protection safeguards;
• standard contractual clauses or equivalent mechanisms;
• transfers necessary for performance of a contract;
• another lawful transfer mechanism permitted by applicable law.
The existence of international processing does not change MioCC's local-processing architecture for the text and files a user provides for encryption or decryption.
16. Data Retention
Personal data under the developer's control is retained only for as long as reasonably necessary for the purpose for which it was processed, subject to applicable legal requirements. The periods below are standard maximum periods, not a requirement to retain every record for the full period.
A shorter period may be applied where the data is no longer needed. A period may be extended only where reasonably necessary for an active legal claim, regulatory matter, fraud investigation, security incident, chargeback, transaction dispute or another lawful obligation. When the reason for extended retention ends, the ordinary deletion or anonymization process resumes.
Locally Processed Content
MioCC does not centrally retain original content merely because it is processed locally on the user's device.
Content saved or exported by the user remains under the user's control and subject to the destination selected by the user.
Application-private temporary data may be removed by the application or operating system as part of normal operation or when the application is removed.
Files intentionally saved or exported outside application-private storage may remain after MioCC is removed and must be managed by the user through the relevant storage location or application.
License Information
The minimum license record needed to issue, operate and verify a valid license may be retained while the license remains valid and for up to 24 months after its final expiration, revocation or termination.
A device or installation identifier needed for an active activation may be retained while that activation remains relevant and for up to 12 months after deactivation, removal or the end of the relevant license relationship.
Individual activation-history events are ordinarily retained for up to 24 months from the event and are then deleted, anonymized or aggregated, unless a longer period is justified by an active security, abuse or legal matter.
Purchase and Transaction Retention
Limited purchase and transaction records received and controlled by MioCC may be retained for up to five years from the transaction or, where a refund, chargeback, fraud investigation or dispute occurs, from the final resolution of that matter if later.
Paddle and other independent providers apply their own retention periods to information under their control.
Support, Privacy and Legal Communications
Ordinary support communications are ordinarily retained for up to 24 months after the matter is closed.
A minimal record of a privacy or data-deletion request and its resolution may be retained for up to three years after final closure to demonstrate that the request was handled. Additional information collected solely to verify identity for such a request is deleted no later than 30 days after verification is completed, unless it is required for an active dispute or another lawful reason.
Records connected with an active legal dispute, confirmed personal-data breach or other formally documented legal matter may be retained for the applicable longer period described in the internal MioCC Data Retention Schedule.
Technical and Security Records
Ordinary website and backend access logs that may identify a user are ordinarily retained for no more than 90 days.
Technical records separated for investigation of suspected abuse, fraud or a security event may be retained for up to 12 months from the event. Documentation of a confirmed security incident or personal-data breach may be retained for up to three years after final closure.
System journal records are configured with a maximum retention of 30 days and a storage limit. Container logs are size-rotated and limited to three files of 10 MB per active container.
Operational health reports are retained for up to 90 days. Detailed daily security and backup audit reports are retained for up to 180 days. These reports are configured not to reproduce user files, passwords, PINs, private keys, complete license keys or complete database records.
Backup Copies
Consistent database backups are retained on a rolling basis for up to 30 days. The hosting provider also maintains up to seven rotating infrastructure-backup slots; when all slots are occupied, creation of a new backup replaces the oldest backup.
Data deleted from an active system may therefore remain temporarily in a protected backup until that backup is overwritten or expires through the applicable rotation. Backups are not used to restore deleted data for an unrelated purpose. If a backup is restored following an incident, documented deletion requests and retention rules are reapplied where necessary.
When personal data is no longer reasonably necessary and no lawful retention ground remains, it will be deleted, anonymized or otherwise rendered non-identifiable where appropriate.
17. Security
MioCC applies technical and organizational measures appropriate to the nature of the personal data under the developer's control.
Measures may include:
• data minimization;
• local processing of protected content;
• encryption in transit for online communications where applicable;
• access restrictions;
• separation of payment processing from local content processing;
• use of established service providers;
• security monitoring;
• limited retention;
• procedures for responding to security incidents.
No digital system can be guaranteed to be completely secure.
Users remain responsible for securing their own devices, passwords, PINs, backups, protected files and access credentials.
18. Personal Data Breaches
If a security incident affecting personal data under the developer's control occurs, the incident will be assessed and reasonable steps will be taken to contain, investigate and remediate it.
Where applicable law requires notification to affected individuals, a privacy regulator or another competent authority, notification will be made within the legally required timeframe.
A suspected security incident involving infrastructure controlled by MioCC may be reported to:
mio.ccomm@gmail.com
Users should not include passwords, PINs, private keys or unnecessary unprotected confidential files in a security report.
19. User Privacy Rights
Depending on applicable law and the processing concerned, a user may have rights including:
• confirmation whether personal data is being processed;
• information about processing;
• access to personal data;
• a copy of personal data;
• correction of inaccurate or incomplete personal data;
• deletion or erasure;
• anonymization or blocking where applicable;
• restriction of processing;
• objection to processing;
• withdrawal of consent;
• data portability;
• information about recipients or categories of recipients;
• objection to direct marketing;
• opt-out rights relating to sale, targeted advertising or certain forms of profiling;
• review of certain automated decisions;
• the right to complain to a competent privacy or data-protection authority;
• the right to appeal a refusal of a privacy request where applicable law provides such a right.
The precise rights available depend on applicable law.
Where mandatory local law grants additional or stronger rights, those rights remain fully available.
20. Exercising Privacy Rights
Privacy requests may be sent to:
mio.ccomm@gmail.com
This mailbox is operated through Google/Gmail. Google may process email addressing, routing, message and attachment data as described in the Data Sharing and Service Providers section.
The request should describe the right the user wishes to exercise and provide enough information to reasonably identify the relevant data.
Users should not provide passwords, PINs, private keys or original confidential files to prove identity.
Where reasonably necessary, limited additional information may be requested to verify identity and protect personal data against unauthorized disclosure or deletion.
An authorized representative may submit a request on behalf of another person where permitted by applicable law and subject to reasonable verification of authority.
Requests will be handled within the period required by applicable law.
Where no shorter mandatory period applies, MioCC aims to provide a substantive response within 30 days or to inform the requester where additional time is reasonably necessary.
Privacy rights will be provided without charge where required by applicable law.
Manifestly unfounded, excessive, repetitive or abusive requests may be handled as permitted by applicable law.
21. Data Deletion
A user may request deletion of personal data controlled by the developer by contacting:
mio.ccomm@gmail.com
Detailed deletion instructions are available at:
https://ccyph.com/legal/data-deletion.html
MioCC does not enable users to create a MioCC user account in the Android application. Core local encryption and decryption functions do not require such an account. Therefore, there is normally no MioCC account that must be deleted from within the application, although licensing, contact, support and other personal data under the developer's control may still be subject to a deletion request.
A deletion request may concern information including:
• licensing information;
• contact information;
• support correspondence;
• other personal data under the developer's control.
Some data may need to be retained where continued retention is permitted or required for reasons including:
• performance of an active license or contractual relationship;
• prevention of fraud or license abuse;
• security;
• legal obligations;
• establishment, exercise or defence of legal claims;
• another lawful retention ground.
Where licensing information necessary to verify or administer a license is deleted at the user's request, deletion may affect the ability to verify that license or provide associated licensed functionality.
Deletion of personal data controlled independently by Paddle, an application store or another provider may need to be requested directly from that provider.
22. Complaints
A person who believes that personal data has been handled improperly may contact:
mio.ccomm@gmail.com
The complaint should identify the privacy concern and provide sufficient information for the matter to be investigated.
MioCC will review privacy complaints in good faith and respond within the timeframe required by applicable law.
Where applicable law provides the right to do so, a person may also submit a complaint directly to the competent privacy, data-protection or supervisory authority.
Using MioCC does not waive any mandatory right to complain directly to a competent authority.
23. Local Representatives
Where applicable law requires MioCC, as a controller established outside a particular jurisdiction, to appoint a local representative, the required representative will be appointed before MioCC is intentionally offered in that jurisdiction where such appointment is mandatory.
Details of an applicable representative will be made available to affected users through this Privacy Policy, an accompanying legal notice or another legally permitted method.
Designated Representative in the Republic of Serbia
Nada Šestović
ul. Jelene Šubić 5
31260 Kosjerić
Serbia
Email: sestovic.nada13@gmail.com
The representative may be contacted regarding personal-data processing and the exercise of applicable data-protection rights in connection with MioCC.
24. Privacy Officer and Data Protection Contact
MioCC designates the following person as its general Privacy Officer and Data Protection Contact:
Miodrag Šestović
Plagenti 2, 85330 Dobrota, Kotor, Montenegro
Email: mio.ccomm@gmail.com
This contact receives and coordinates privacy, data-protection and related compliance matters.
Where applicable law requires a separately qualified or locally established officer, representative or other privacy contact, the additional requirement will be implemented where mandatory before or when MioCC is intentionally offered in that jurisdiction.
25. Additional Local Privacy Requirements
Mandatory local privacy and data-protection laws remain applicable even where this Privacy Policy uses different terminology or establishes a general standard.
Where applicable law:
• grants additional privacy rights;
• requires shorter response periods;
• requires additional information to be provided;
• requires specific security or transfer safeguards;
• requires a local representative;
• requires notification or registration;
• requires another specific compliance measure;
MioCC will apply the mandatory requirement where it applies to MioCC's processing.
Expansion into a jurisdiction requiring additional mandatory compliance measures will be assessed before MioCC is intentionally offered there.
26. Adult Users Only
MioCC is intended only for users aged 18 years or older.
MioCC is not directed to children or minors.
The developer does not knowingly collect personal data directly from persons under 18.
If the developer becomes aware that personal data from a person under 18 has been provided directly to MioCC or the developer, appropriate steps will be taken to delete or otherwise handle that information as required by applicable law.
Local encryption or decryption performed on a device does not by itself transmit the user's content to the developer.
27. Sensitive Personal Data
MioCC can be used by an adult user to protect files or text that may contain sensitive information.
The fact that MioCC locally processes such content does not mean that the developer receives or has access to it.
Users should not voluntarily send sensitive personal data, passwords, PINs, private keys, unprotected confidential documents or decrypted content to the developer unless genuinely necessary for a specific request.
If sensitive personal data is voluntarily provided through support or another communication channel, it will be handled only as reasonably necessary for the relevant lawful purpose and in accordance with applicable legal requirements.
28. Cookies and Similar Technologies
The MioCC application does not use cookies to access or inspect content that users process locally.
The ccyph.com website or its technical infrastructure may use cookies, local storage or similar technologies where reasonably necessary for website operation, security, preferences or other technical functions.
MioCC does not use protected user content for behavioural advertising.
If non-essential cookies or similar tracking technologies are introduced where applicable law requires notice or consent, an appropriate mechanism will be provided before such technologies are used as required by law.
29. Changes to This Privacy Policy
This Privacy Policy may be updated to reflect:
• changes to MioCC;
• new platforms or functionality;
• changes to service providers;
• changes to data-processing practices;
• security improvements;
• changes in applicable law;
• expansion into additional jurisdictions.
The current version will display its effective or “Last updated” date.
Where applicable law requires additional notice, consent or another procedure for a material change, the legally required procedure will be followed.
30. Relationship With Other MioCC Legal Documents
This Privacy Policy should be read together with the applicable:
• Terms of Use;
• End User License Agreement (EULA);
• Payment, Activation and Refund Policy;
• Data Deletion information;
• other legal notices specifically identified as applying to MioCC.
Official legal information is available at:
• Privacy Policy: https://ccyph.com/legal/privacy.html
• Data Deletion: https://ccyph.com/legal/data-deletion.html
• License terms: https://ccyph.com/legal/license.html
• Refund information: https://ccyph.com/legal/refund.html
If another MioCC document conflicts with a mandatory privacy or data-protection right under applicable law, the mandatory legal requirement prevails with respect to personal-data processing.
31. Contact
Data Controller: Miodrag Šestović
Status: Private individual
Postal address: Plagenti 2, 85330 Dobrota, Kotor, Montenegro
Privacy and Data Protection Contact: mio.ccomm@gmail.com
Representative in the Republic of Serbia
Nada Šestović
ul. Jelene Šubić 5
31260 Kosjerić
Serbia
Email: sestovic.nada13@gmail.com
Users should never send passwords, PINs, private keys, original unprotected files or other unnecessary confidential content in a privacy request.
Privacy starts on your device.
MioCC is designed so that encryption and decryption of user-provided content take place locally, while online processing is limited to functions such as licensing, purchases, website operation, support, security and other activities expressly described in this Privacy Policy.