OpenLocker

OpenLocker privacy notice

Updated September 21, 2026 · Service provider: GenPy Inc.

OpenLocker checks a Mac's lock status and requests locking between devices you explicitly pair. This notice applies to the Mac, iPhone, and iPad apps, and the OpenLocker public relay and download website under Jayan.studio.

Information that stays on your devices

Private keys and connection credentials are stored in the local Keychain and are not synchronized through iCloud. The Mac's name and pairing information stay on the paired devices. The Mac keeps a local command replay-prevention record. OpenLocker does not access your files, capture screenshots, record your screen, remotely unlock your Mac, or execute terminal commands.

To help identify the connected devices, paired apps exchange device names, model identifiers, OS versions, and OpenLocker versions through the encrypted channel. This information is shown only on the paired devices. The relay cannot decrypt it and does not retain these messages. You can compare the pairing key fingerprints on both ends; device names and models are reported by the device and do not establish identity by themselves.

Information processed by the relay

The public relay runs on Cloudflare Workers and Durable Objects. It stores random device identifiers, hashes of connection tokens, pairing expiry times, and connection-role information to support pairing, authentication, and message forwarding. Lock commands and status messages are encrypted between the devices. The relay does not hold the private keys needed to decrypt them, does not store these messages, and does not queue commands for offline devices.

Connections require processing network metadata such as IP addresses, request timing, and traffic volume. Registration limits use a cryptographic hash that changes each day, rather than storing raw IP addresses in the app's rate-limit records. The service does not use advertising, cross-site tracking, or third-party analytics SDKs, and does not sell personal data. Cloudflare processes infrastructure data to deliver and protect the service under its privacy policy. Data may be processed outside your region.

Permissions

Revocation, deletion, and retention

Revoking a pairing on your Mac first removes local trust, then attempts to delete the relay record and close connections. If network deletion fails, the app tells you; local revocation still applies. Removing a device on your phone deletes only that phone's saved credentials.

To limit registration abuse, the service retains registration fingerprint hashes and cumulative allocation counts that do not contain the original pairing credentials. Revoking a pairing does not automatically delete these records. Daily rate-limit summaries are replaced when a registration occurs on a new day. Device registration records remain until revoked so the pairing can continue to work.

Your choices and contact

You can stop using the service, revoke a pairing, or turn off permissions at any time. Advanced users can select another relay on their Mac; that operator's privacy practices will apply. To contact us about privacy or deletion, use the project support page. Do not include pairing links, keys, or other personal information in a public report.