Trust

Security

How TMS Toolbox protects your information — mostly by never collecting it in the first place.

Security model in one line: the safest data is data that never leaves your device. TMS Toolbox processes everything locally and transmits nothing.

On-device by design

Every calculation TMS Toolbox performs happens locally on your device. The app has no backend service, no user accounts, and no cloud storage. Values you enter are held in memory only for as long as needed to compute a result. Because nothing is transmitted, there is no data in transit to intercept and no server-side database to breach.

Data handling

  • No personal data collected. No names, emails, identifiers, or device fingerprints are gathered by the app.
  • No analytics or tracking SDKs. There is no telemetry, crash-reporting, or advertising code embedded in the app.
  • No network calls in normal operation. The app functions fully offline.
  • Local files stay local. Logs you choose to save are written to your device's storage and are governed by your device's own protections (passcode, biometric lock, and disk encryption).

Platform protections

TMS Toolbox is distributed exclusively through the Apple App Store and Google Play. Both platforms code-sign and review submissions, and the app runs inside the operating system's application sandbox, which isolates its files from other apps. On modern iOS and Android devices, on-device storage is encrypted at rest when a passcode is set. We recommend keeping your device OS up to date and protecting it with a passcode or biometric lock.

Permissions

The app requests no sensitive permissions. It does not access your contacts, photos, location, microphone, camera, or health data. The only storage it uses is the standard app documents area, and only when you explicitly save a log.

Website & contact form

This website is served over HTTPS. If you use the contact form, your message is transmitted to our email over an encrypted connection and used solely to respond to you (see the Privacy Policy). We recommend not including protected health information (PHI) or patient identifiers in support messages.

Responsible disclosure

We welcome reports from security researchers. If you believe you have found a vulnerability in the app or this website, please email info@xeebrah.com with details and steps to reproduce. Please give us a reasonable opportunity to investigate and remediate before any public disclosure. We do not offer a paid bounty at this time, but we are grateful for good-faith reports and will acknowledge your contribution on request.

Contact

Security questions or reports: info@xeebrah.com.

Publisher: Xeebrah · South Carolina, USA