Home / Security
Not a certification logo — the actual mechanisms, because there's no cloud infrastructure here to certify in the first place.
Little Greenhouse uses two genuinely different encryption systems, on purpose — one for locking the app on your own device, a different one for anything meant to leave it.
Backed by the AndroidKeyStore, using AES/GCM/NoPadding. The key is generated inside the device's secure hardware and never leaves it — it isn't derived from your PIN or fingerprint, and it isn't exportable, even by the app itself. This is specifically why App Lock can't double as a backup password: the key behind it is tied to this one device, permanently.
A password you choose derives a 256-bit AES-GCM key via PBKDF2-SHA256 at 150,000 iterations. A random salt and IV are generated per backup or export, so the same password never produces identical ciphertext twice. Unlike App Lock, this key is portable — it's derived from something you know, not something bound to one device, which is exactly what makes a backup restorable on a different phone, or a Partner View file openable on someone else's.
Formal certifications like ISO 27001 exist to audit an organization's infrastructure — servers, access controls, data-handling processes. Little Greenhouse doesn't have that infrastructure to certify, because tracked data never reaches a server in the first place. The claim here isn't "audited and compliant" — it's that there's nothing centralized to audit.