WALMI

Política de Privacidad de WALMI · WALMI Privacy Policy


🇪🇸 ESPAÑOL

Responsable del tratamiento: EASYPRO PLUS LLC ("WALMI", "nosotros").

Última actualización: 2026-06-30

WALMI es una bóveda de documentos cifrada de extremo a extremo (conocimiento cero). Esta política explica qué datos manejamos, para qué, con quién, por cuánto tiempo y, sobre todo, lo que NO podemos ver.

1. Nuestro principio: conocimiento cero (zero-knowledge)

Tus documentos se cifran en tu propio teléfono antes de salir. La llave para descifrarlos nace de tu contraseña y nunca se envía a nuestros servidores. Por eso ni WALMI, ni nuestros proveedores, ni nadie con acceso a nuestros servidores puede leer el contenido de tus documentos — solo tú.

Lo que SÍ vemos (metadatos): tu correo (cifrado), identificador de cuenta, fechas, token de notificaciones, y registros técnicos de seguridad. Compromiso de transparencia: te decimos honestamente lo poco que tenemos.

⚠️ Importante: si olvidas tu contraseña y tu llave de recuperación, nadie —incluidos nosotros— puede recuperar tus documentos. Es el precio de la privacidad real.

2. Qué datos recolectamos

3. Permisos que pedimos y por qué (cámara, micrófono, ubicación, biometría)

Pedimos cada permiso solo cuando lo usas, y te explicamos para qué:

4. Para qué usamos los datos (y base legal)

Usamos los datos para: prestarte el servicio (guardar/mostrar tus documentos cifrados), autenticarte, enviarte avisos y proteger la seguridad de tu cuenta.

Base legal (GDPR Art. 6 y equivalentes): ejecución del contrato (darte el servicio), interés legítimo (seguridad), consentimiento (permisos y avisos), interés vital (función de emergencia) y cumplimiento legal. No vendemos ni compartimos tus datos para publicidad.

Datos biométricos (Face ID / Touch ID / huella): el desbloqueo biométrico se procesa exclusivamente dentro de tu dispositivo, por el sistema operativo (Secure Enclave de Apple o equivalente de Android). WALMI nunca recibe, recolecta ni almacena tu rostro, tu huella ni ninguna plantilla biométrica — la app solo recibe la señal de "desbloqueo exitoso o fallido".

5. Con quién compartimos (proveedores / subencargados)

No vendemos datos. Usamos proveedores de infraestructura que solo procesan datos por nosotros y están obligados a la misma protección:

Tu número de teléfono móvil nunca se comparte ni se vende a terceros con fines de marketing. Solo se usa para entregar los mensajes SMS transaccionales o de emergencia que tú o el titular de la cuenta solicitaron. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, excluding aggregators and providers of the text-message services.

ProveedorPara quéQué ve
Cloudflare R2Almacenamiento de documentosSolo blobs cifrados
Render + PostgreSQLServidor y base de datosDatos cifrados y mínimos, con aislamiento por usuario
TwilioMensajes SMS (si aplica)Número/мensaje del aviso
ResendCorreos transaccionalesTu correo y el mensaje
Apple APNs / Google FCMNotificaciones pushToken del dispositivo

Lista actualizada disponible bajo pedido en support@easyproplus.com.

6. Transferencias internacionales

Nuestros servidores pueden estar en EE.UU. u otros países. Cuando transferimos datos fuera de tu país, lo hacemos con salvaguardas legales (p. ej. Cláusulas Contractuales Tipo / marcos de adecuación). Como el contenido viaja cifrado de extremo a extremo, su confidencialidad no depende del país.

7. Conservación y eliminación (plazos concretos)

8. Tus derechos

9. Postura ante solicitudes de autoridades

Por nuestro diseño de conocimiento cero, no podemos entregar el contenido de tus documentos porque no podemos leerlos. Ante un requerimiento legal válido solo podríamos entregar los metadatos mínimos que tenemos (p. ej. correo cifrado, fechas). Para nuestra comunidad migrante: tu contenido permanece matemáticamente inaccesible para terceros, incluidos nosotros.

10. Seguridad

Cifrado fuerte en reposo y en tránsito (Argon2id, XChaCha20-Poly1305, TLS), aislamiento por usuario en la base de datos, revocación de sesiones, detección de dispositivos comprometidos (jailbreak/root) y ofuscación. Ningún sistema es 100% infalible, pero el cifrado de extremo a extremo protege tu contenido aun si nuestros servidores fueran vulnerados.

11. Notificación de filtraciones

Si ocurriera una filtración que afecte tus datos, te lo notificaremos sin demora indebida y a las autoridades dentro de 72 horas, y a residentes de California dentro de 30 días, conforme a la ley.

12. Menores

WALMI requiere una edad mínima de 13 años. No está dirigido a menores de 13 ni recolectamos conscientemente sus datos; si detectamos una cuenta de un menor de 13, la eliminaremos.

13. Cookies

La app no usa cookies publicitarias. Nuestro sitio/portal puede usar cookies estrictamente necesarias para funcionar.

14. Cambios a esta política

Podemos actualizar esta política. Si un cambio reduce significativamente tus derechos, te lo notificaremos. La fecha de "última actualización" arriba indica la versión vigente.

15. Ley aplicable

Esta política se rige por las leyes del Estado de Florida, EE.UU., sin perjuicio de los derechos que te otorgue la ley de tu lugar de residencia.

16. Contacto

EASYPRO PLUS LLC · support@easyproplus.com · www.easyproplus.com

Puedes presentar quejas ante tu autoridad de protección de datos local.


🇺🇸 ENGLISH

Data controller: EASYPRO PLUS LLC ("WALMI", "we").

Last updated: 2026-06-30

WALMI is an end-to-end encrypted (zero-knowledge) document vault. This policy explains what we handle, why, with whom, for how long, and above all what we CANNOT see.

1. Our principle: zero-knowledge

Your documents are encrypted on your own phone before they leave it. The decryption key is derived from your password and is never sent to our servers. So neither WALMI, nor our providers, nor anyone with access to our servers can read your documents' content — only you.

What we DO see (metadata): your email (encrypted), account ID, dates, notification token, and technical security logs. Transparency commitment: we honestly tell you the little we hold.

⚠️ Important: if you forget your password and recovery key, no one — including us — can recover your documents. That is the cost of real privacy.

2. Data we collect

3. Permissions we request and why (camera, microphone, location, biometrics)

We request each permission only when you use it, and explain why:

4. How we use data (and legal basis)

To: provide the service (store/show your encrypted documents), authenticate you, send notices, and protect account security.

Legal basis (GDPR Art. 6 and equivalents): contract performance, legitimate interest (security), consent (permissions/notices), vital interests (emergency feature), and legal compliance. We do not sell or share your data for advertising.

Biometric data (Face ID / Touch ID / fingerprint): biometric unlock is processed exclusively on your device by the operating system (Apple's Secure Enclave or the Android equivalent). WALMI never receives, collects, or stores your face, fingerprint, or any biometric template — the app only receives a "pass/fail" unlock signal.

5. Who we share with (providers / subprocessors)

We don't sell data. We use infrastructure providers that only process data on our behalf under equal protection:

Your mobile phone number is never shared with or sold to third parties for marketing purposes. It is used solely to deliver the transactional or emergency SMS messages that you or the account holder requested. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, excluding aggregators and providers of the text-message services.

ProviderPurposeWhat they see
Cloudflare R2Document storageEncrypted blobs only
Render + PostgreSQLServer & databaseEncrypted, minimal data, per-user isolation
TwilioSMS messages (if used)Notice number/message
ResendTransactional emailYour email and the message
Apple APNs / Google FCMPush notificationsDevice token

Current list available on request at support@easyproplus.com.

6. International transfers

Our servers may be in the U.S. or other countries. When we transfer data outside your country, we use legal safeguards (e.g., Standard Contractual Clauses / adequacy frameworks). Since content travels end-to-end encrypted, its confidentiality does not depend on the country.

7. Retention & deletion (concrete timelines)

8. Your rights

9. Law-enforcement posture

By our zero-knowledge design, we cannot hand over your documents' content because we cannot read it. Under a valid legal request we could only provide the minimal metadata we hold (e.g., encrypted email, dates). For our migrant community: your content remains mathematically inaccessible to third parties, including us.

10. Security

Strong encryption at rest and in transit (Argon2id, XChaCha20-Poly1305, TLS), per-user database isolation, session revocation, compromised-device (jailbreak/root) detection, and obfuscation. No system is 100% infallible, but end-to-end encryption protects your content even if our servers were breached.

11. Breach notification

If a breach affecting your data occurs, we will notify you without undue delay, authorities within 72 hours, and California residents within 30 days, as required by law.

12. Minors

WALMI requires a minimum age of 13. It is not directed to children under 13, and we do not knowingly collect their data; if we discover an account belonging to a child under 13, we will delete it.

13. Cookies

The app uses no advertising cookies. Our website/portal may use strictly necessary cookies to function.

14. Changes to this policy

We may update this policy. If a change significantly reduces your rights, we will notify you. The "last updated" date above indicates the current version.

15. Governing law

This policy is governed by the laws of the State of Florida, USA, without prejudice to rights granted by the law of your place of residence.

16. Contact

EASYPRO PLUS LLC · support@easyproplus.com · www.easyproplus.com

You may lodge a complaint with your local data protection authority.