Security
For IT, security reviewers and anyone who wants to check before installing. Last updated 2026-09-30.
Who publishes Privvy
Privvy is published by Grimado Global Group LLC. Official downloads come only from privvyapp.ai; the iPhone app comes only from Apple (TestFlight, then the App Store).
Code signing
- macOS: signed with the Developer ID certificate "Developer ID Application: Grimado Global Group LLC (9S26C22UZH)", hardened runtime, notarized by Apple and stapled. Gatekeeper opens it without warnings.
- Windows: the installer is not code-signed yet. Install with the PowerShell line on the home page (it verifies the download against the published SHA-512 before running it), or verify the checksum below yourself. Code signing is planned.
- iPhone: distributed by Apple under team 9S26C22UZH.
Verify the Mac app after installing:
codesign -dv --verbose=2 /Applications/Privvy.app spctl -a -vv -t exec /Applications/Privvy.app
Expect TeamIdentifier=9S26C22UZH and source=Notarized Developer ID.
Checksums (SHA-256) for version 1.0
| File | SHA-256 |
|---|---|
| Loading the current checksums. | |
Check a download: shasum -a 256 Privvy.dmg on macOS, Get-FileHash Privvy-Setup.exe in PowerShell.
Updates
The app checks https://privvyapp.ai/releases/ over TLS and verifies each update against the SHA-512 in the feed before installing. On macOS the update must also carry the same Developer ID signature or the system refuses it. Updates never install while the cover is up.
What runs where
- On your computer, no account needed: the cover, the input guard, the unlock password (stored as a salted scrypt hash), the camera guard and its captures, and the local agent API (bound to 127.0.0.1, one random key per install).
- Privvy Cloud, only with an account (
api.privvyapp.ai, on Cloudflare): email, a salted password hash, device names, push tokens, and your settings encrypted on your computer with AES-256-GCM under a key derived from your account password. The service stores only ciphertext. - Relayed, never stored: screen frames, remote control input and voice between your computer and your phone.
- Stored for 24 hours, then deleted: camera guard captures you chose to send to your phone.
Permissions the app asks for
- macOS Accessibility: to block the physical keyboard and mouse while covered.
- macOS Screen Recording: only if you use the phone's live view.
- Camera: only if you turn on the camera guard. The camera light is on whenever it is used.
- Microphone: only if you let your phone listen. The cover shows a notice for as long as it does.
What Privvy is not
Privvy is a privacy cover against onlookers and casual interference. It is not an operating system lock, not encryption and not endpoint security. Someone with full physical control of a machine (power button, reboot, Ctrl+Alt+Del) can get past it. Use your OS lock and disk encryption for that.
Report a vulnerability
Email security@privvyapp.ai. Please include steps to reproduce. We answer within 3 business days and will credit you if you wish. Machine-readable contact: /.well-known/security.txt.