diskus.ai Open Diskus

Greenbox Safe — Privacy Policy

Effective date: 7 August 2026

This policy covers Greenbox Safe (ai.diskus.greenbox.safe), the offline encrypted vault published by Discus IT Pvt Ltd (“Diskus”, “we”, “us”), on every platform it ships to, together with its browser extension. The extension additionally has its own detailed policy — see the Greenbox Safe Browser Extension Privacy Policy, which is the one referenced from its store listings. Greenbox Safe works differently from the rest of the Diskus suite: it has no account, no sign-in, and no server of ours behind it. It therefore has its own policy rather than being covered by the general Diskus AI Privacy Policy, which describes an account-based service that Greenbox Safe is not. Your use of the app is governed by the Diskus AI Terms of Service.

The short version. Your vault is created, encrypted and stored on your own device. We do not have an account for you, we do not have a copy of your vault, and we could not read it if we did. The app makes a small number of internet connections, all of them listed in section 5, and none of them carries the contents of your vault to us.

1. There is no Greenbox account

Greenbox Safe does not ask you to register, and there is nothing to sign in to. The master password you choose is used on your device to derive the key that encrypts your vault; it is never transmitted, and we never receive it, store it, or hold anything from which it could be recovered. If you forget it, we cannot help you recover your data — that is a direct consequence of not holding it, and we would rather be plain about the cost than imply a safety net that does not exist.

Because there is no account, the parts of the general Diskus policy that describe account information, single sign-on, and account deletion do not apply to Greenbox Safe. Deleting your data here means deleting it from your device and from wherever you chose to back it up — see section 10.

2. What the app stores on your device

Biometric unlock, where you enable it, is handled entirely by your operating system. The app asks the platform whether you authenticated and receives yes or no. Your fingerprint or face data never reaches the app, and never reaches us.

3. Backups and sync go where you send them

Greenbox Safe can copy your encrypted vault file to a destination you choose. The choices are your Google Drive, your iCloud Drive, a server you reach over SCP/SFTP, a server you reach over FTP, a Greenbox DMS installation, or simply another folder on the same machine. There is no Diskus cloud in that list, and there is no default: if you configure nothing, nothing is uploaded anywhere.

The file is encrypted on your device before it is sent, and it is the encrypted file that travels. The operator of the destination — Google, Apple, or whoever runs the server whose address you typed in — holds an encrypted blob they cannot read, subject to their own terms and privacy policy. We are not a party to that transfer: we do not receive it, we are not sent a copy, and we have no way to reach into your Drive or your server. It also means that if you want that copy gone, you delete it there; we cannot do it for you, and we will not pretend otherwise.

4. Google Sign-In and Google Drive

If — and only if — you choose Google Drive as your backup destination, the app asks you to sign in to Google and requests access to Drive. In that case:

5. Every connection the app makes to the internet

This is the complete list for the shipped app, and we would rather enumerate it than summarise it:

Aside from these, the app does not phone home. There is no analytics SDK, no crash-reporting SDK, no advertising SDK and no advertising identifier in Greenbox Safe, and there is no telemetry of any kind reporting how you use it.

6. Camera, photos, microphone and clipboard

7. Messaging: the Chat tab does not work, and nothing is sent

Greenbox Safe shows a Chat tab in its main navigation. In the version published on the stores today, it does not function, and we would rather tell you that here than let you discover it by trying. The messaging code never starts up: the app does not initialise a messaging identity, no server address is built into it, the conversation screen is registered under the wrong route, and the Android release build does not even request microphone permission. The practical effect is that no message, call, file, contact or key can leave your device through that tab — and none does.

Diskus operates no Greenbox messaging server. There is no address for one in the app, we do not run one, and we hold no messaging data for anyone. So there is nothing for us to disclose, share, retain or delete.

The design is bring-your-own-server. If messaging is ever finished, you or someone you trust would run the relay and enter its address into the app. A relay run that way is operated by whoever runs it — not by us. We would have no access to it and, ordinarily, no knowledge that it exists. If you ever connect to a relay somebody else runs, that operator holds your record, not Diskus, and their terms apply to it.

For completeness, so that nobody has to read our source code to find out: were such a relay configured, it would hold, for each person using it, a hash of a public key, the public halves of their encryption keys, a generated handle of the form GBX-…, the groups they belong to, and any messages still waiting for them — as ciphertext the relay cannot read, held for up to seven days. Files sent through it would be stored as encrypted bytes for up to seven days, with no record of who uploaded them. None of that is derived from your name, email address, phone number or device: the handle and the key hash come from a randomly generated key and nothing else. A relay would also tell the other people connected to it when a given key comes online or goes offline.

We will rewrite this section — and our Google Play Data safety declaration with it — before any release in which messaging actually works.

The “Time-Bomb” share link has been withdrawn

An earlier version offered a self-destructing share link from an item's menu. It did not work. The app encrypted the item on your device and then did not upload it anywhere, so the link copied to your clipboard pointed at a server that does not exist and would not have opened for anyone, including you. We have removed the menu entry rather than leave a feature in place that tells you a link is live when it is not.

Nothing about the item ever left your device, and no such link was ever readable by us or by anyone else. If you copied one of these links and passed it on, the person you sent it to could not open it — but the link text itself contains a decryption key, so treat any you still have lying around in a chat or an email as something to delete rather than keep.

We would like to build this properly. Doing so means running a server that holds your encrypted item until the recipient collects it, which is exactly the kind of thing this app is built not to need — so if the feature returns, we will rewrite this section and our Google Play Data safety declaration before it ships, not after.

8. What we do not do

9. Children

Greenbox Safe is a personal security tool intended for adults and for older teenagers who manage their own credentials. It is not directed to children under 13, and we do not knowingly collect personal information from them. Where India's Digital Personal Data Protection Act, 2023 applies, we do not process the data of users under 18 without verifiable parental consent.

10. Deleting your data

Because we hold nothing, there is no deletion request to send us for this app, and no waiting period. Deletion is something you carry out directly:

If you also hold a Diskus account for another Diskus product, that account is separate from Greenbox Safe and is deleted through diskus.ai/delete-account.html. Deleting it has no effect on your Greenbox vault, and deleting your vault has no effect on it. If you would like help working out what to clear, write to hello@diskus.ai.

11. Your rights

Data-protection law gives you rights of access, correction, erasure, portability and objection. We honour them for all users regardless of location. For Greenbox Safe those rights are largely self-executing, because the data is in your hands and not in ours: your vault is the copy, exporting it is the access request, and the wipe in section 10 is the erasure. Where we genuinely hold nothing, the honest answer to a request is that there is nothing to produce — and we will say so plainly rather than manufacture a process.

You may raise a grievance with us, and escalate to your supervisory authority: the Data Protection Board of India under the DPDP Act, 2023; your national authority under the GDPR (EU/EEA); or the California Attorney General under the CCPA/CPRA. We do not “sell” or “share” personal information as those terms are defined by the CCPA.

12. Security

Your vault is encrypted with AES-256, using a key derived from your master password by a deliberately slow key-derivation function so that guessing is expensive. Credentials for backup destinations live in your device's platform keystore. Connections the app makes to the internet use HTTPS.

The strength of all of this rests on your master password and on the security of your device. A vault file copied off an unlocked, compromised device is only as safe as the password protecting it, and we cannot reset a password we do not hold.

13. Changes to this policy

We may update this policy as the app changes. Material changes will be announced in the app or on this page, and the effective date above will be revised. Where a feature described here as not working is made to work, this policy will be updated before that release ships, not after.

14. Contact and grievance redressal (India)

Questions or requests regarding privacy in Greenbox Safe: hello@diskus.ai.

In accordance with the Information Technology Act, 2000, the IT Rules, 2021, and the DPDP Act, 2023, grievances are handled by our Grievance Officer, reachable at hello@diskus.ai (subject line “Grievance”). Acknowledgement within 24 hours; resolution within 15 days. Discus IT Pvt Ltd is registered and operates in India.