Privacy Policy

What we process, what we do not, and why privacy is built into the architecture.

Revision of 4 August 2026.

Entrixy is an app and a website for access control: gates, barriers, doors, locks and intercoms. This policy describes what data is processed in the Entrixy Android app and on entrixy.com, and exactly how.

The core principle is privacy by default. Sensitive access data is encrypted on your device, and the server physically cannot read it.

1. Who processes the data

The controller is the developer of the Entrixy project. For questions about data processing and deletion requests write to hello@entrixy.com.

2. Data in the app

Geolocation

If you enable automatic opening by geofence, the app uses the device location, including in the background, to tell when you are approaching an object. The coordinates are processed on the device itself and are never sent to the server in the clear. With no geo condition enabled, background location is not requested at all.

Wi-Fi and Bluetooth

For the Wi-Fi network condition the app checks which network the phone is connected to. For direct opening over Bluetooth it looks for a controller nearby. This data is used on the device and never sent to the server.

Object data

The barrier's phone number, the coordinates, the webhook address and secret, the camera address, the set of Wi-Fi networks — all of it is encrypted on your device with the object key (AES-256-GCM). Only the encrypted package reaches the server. When you share access with a guest, the object key travels inside an encrypted parcel. The server acts as a postman: not even the developers can decrypt the contents.

A guest needs neither the app nor an account: access arrives as a link or a QR code, and the key itself sits inside that link and is never sent to the server.

3. App permissions and what they are for

Permissions are requested as they become necessary. If you do not use the corresponding feature, the permission is not used.

4. Data on the server

The server handles the minimum needed to work: encrypted packages of objects and keys, routing of commands and delivery of push notifications (through Google Firebase Cloud Messaging). Plain phone numbers, coordinates and geofences are not stored on the server — they do not exist there in readable form.

5. Website account

A website account is needed for saving configurations, for the manufacturer area and related features. On registration we store your email address (for signing in, confirmation and password recovery) and your password as an irreversible hash. An account is not required to use the app or guest access.

6. Cookies on the website

On the site's pages — except the sections that carry private data: firmware building, key acceptance, authentication and the account area — we use cookies and web analytics to understand how visitors use the site: visits, referral sources, clicks and interaction with the page. Cookies and analytics are not loaded on pages where secrets or keys may be displayed.

On your first visit a cookie notice is shown. You can turn them off in your browser settings, by blocking cookies or enabling a mode that limits tracking.

7. Sharing with third parties

We do not sell or pass your data on for advertising. The technical processors are a third-party web analytics service (cookies on the site) and Google (push delivery through Firebase Cloud Messaging). Encrypted object data is unreadable to them and to us alike.

8. Storage and deletion

Object data is kept on your device, and in encrypted form on the server, for as long as you use it. A website account and the data tied to it are deleted on request to hello@entrixy.com. Local app data is removed when you uninstall the app.

9. Children

The service is not intended for children under 13 and does not knowingly collect their data.

10. Changes

This policy may be updated. The current version is always available at entrixy.com/privacy; the revision date is shown at the top.

11. Contacts

For any questions about data processing write to hello@entrixy.com.