Privacy Policy

Last updated: October 4, 2026

LightDrop moves a file from one screen to one camera. There is no network in between, and there is no company in between either. This policy explains, in plain language, what the app does and does not do with your information.

The short version: Files and passwords stay on your devices. QR transfer works offline; Apple and RevenueCat process purchasing data to verify Pro. There is no app login, advertising or cross-app tracking.

1. Who we are

LightDrop (the "app") is developed and published by Yangworks ("we," "us," or "our"). This policy applies to the LightDrop app for iPhone, iPad, and Mac, and to this website. If you have any questions, you can reach us at support@tk999.top.

2. Information we do not collect

The notable thing about LightDrop is what it doesn't do. We want to be explicit:

  • No accounts. There is no sign-up or login. We never ask for your name, email address, or phone number to use the app.
  • No advertising or cross-app tracking. We do not use the Advertising Identifier or track you across apps or websites. Apple and RevenueCat process purchasing data to verify and restore access; transfer content is never uploaded.
  • No file uploads. We operate no server that receives, stores, or processes the files you send. We never see your content.
  • No crash or transfer-usage reports are sent. RevenueCat SDK diagnostics and optional attribution identifier collection are disabled; purchasing data is described below.

The RevenueCat build declares purchase history and an anonymous purchasing identifier for app functionality, with no tracking. The earlier Data Not Collected label does not apply to this build.

3. How a transfer works

The sending device turns your file into a sequence of QR codes and plays them on its screen. The receiving device points its camera at that screen and rebuilds the file from what it sees. That is the entire transport.

  • QR transfers use no network. With valid cached access, transfers work in airplane mode. Loading plans, purchasing, restoring and verifying access require internet.
  • Nothing is routed through us. There is no relay, no queue, and no temporary storage on any server. The file exists on the sending device, in the light between the two devices, and on the receiving device.
  • Nothing is left behind on our side. Because no data ever reaches us, there is no record of your transfer for us to keep, disclose, or lose.

4. Data stored on your device

The following data is stored locally on your device:

  • Files you send and receive. A file you choose to send is read from where you chose it. A file you receive is written where you choose to save it, or to your photo library if you tap Save. The app does not maintain a hidden archive of past transfers.
  • App preferences. Settings such as transfer speed, fragment size, turbo mode, and your language choice are saved locally in the system preferences store. This information stays on your device and is never shared with another app.
  • Purchase state. Pro access is cached on your device. Apple transactions are verified through RevenueCat, which stores purchasing data separately from transfer content.

Uninstalling removes local preferences and caches, but does not cancel subscriptions or erase Apple or RevenueCat purchase records.

5. Device permissions we request

The system asks for your consent before the app can use certain features. We request the minimum needed and use each permission only for its stated purpose:

  • Camera. Used only to decode QR codes while the Scan screen is open. Frames are analysed in memory and discarded immediately. The app never records video, never takes a still photograph, and never writes anything from the camera to disk.
  • Add to Photos. Requested the first time you save a received image to your photo library. It grants only the ability to add. The app cannot read, browse, or delete your existing photos with this permission.
  • Files you pick. When you choose a file to send, the system hands the app that one file. The app has no access to the rest of your storage. On Mac, LightDrop runs inside Apple's App Sandbox, which enforces this.

Notably, LightDrop never asks for Local Network permission — a good sign that it isn't using one.

6. Password encryption

Pro adds an optional password. When you set one, the payload is encrypted on the sending device before the first QR frame is drawn, using AES-GCM from Apple's CryptoKit.

  • The password is used on your device to derive a key. It is never sent to us, never stored on a server, and never embedded in the QR frames.
  • The receiving device asks the person holding it for the same password and decrypts locally. The two devices never exchange the password itself.
  • We cannot recover an encrypted transfer. If the password is lost, the data cannot be decrypted by us or by anyone else — send it again with a password you both know.

7. What a bystander can see

We would rather state the one real limitation plainly than let you discover it: a transfer happens on a screen, in the open. Anyone who can see that screen — a person standing behind you, a security camera, a screen-sharing session — can photograph the same frames your receiver is reading.

If the room isn't private, use a password. With encryption on, recorded frames are useless without the password. Without encryption, treat a transfer the way you would treat holding the document up to the light.

8. Purchases and subscriptions

LightDrop offers a monthly subscription and a one-time "Lifetime" purchase through Apple's In-App Purchase system. Payments are processed by Apple, not by us. We do not receive or store your payment card details.

RevenueCat receives an anonymous app-user identifier, store transactions, product identifiers and subscription state to verify and restore Pro. Requests also disclose an IP address and app/store metadata. Transfer content, passwords and camera frames are never sent. See Apple and RevenueCat.

9. Third-party services

Apple supplies the App Store and payment services. RevenueCat manages purchasing entitlements, with SDK diagnostics and optional attribution identifiers disabled. This static website sets no tracking cookies.

10. Children's privacy

LightDrop does not target children or create advertising profiles. Purchasing data is limited to the verification described above; no transfer content is collected.

11. Your control and choices

You are always in control of your content:

  • Contact us for help with access or deletion requests concerning purchasing data held through RevenueCat. We never hold your transfer content; store records may be retained as required by law.
  • Delete everything. Deleting the app removes its on-device preferences. Files you already saved stay where you saved them, under your control.
  • Revoke permissions. You can change camera and photo permissions at any time in the system Settings app, on any of your devices, without uninstalling.

12. Changes to this policy

If we update this policy, we will revise the "Last updated" date at the top of this page and post the new version here. Material changes will be reflected on this page before they take effect.

13. Contact us

If you have questions about this policy or your privacy, email us at support@tk999.top. You can also read our Terms of Use or visit the Support page.