BINIT
privacy
The whole of it
BINIT collects nothing. There is no BINIT server, no account, no analytics and no third-party code in the app. Nothing about you or your mail is sent to me or to anybody else, because there is nowhere for it to be sent to.
What stays on your phone
When BINIT reads your mailbox it keeps a record of who wrote to you, what each message was called, when it arrived, which folder it was in, and whether it carried an unsubscribe link. It never keeps the message itself.
Alongside that it keeps the decisions you make and what came of them: which senders you blocked, kept or left the mailing list of; what was cleared out and when; any email address you typed into Leak Shield yourself and which known break-ins it matched; the result of a password check; the alerts you've been shown; and your mailbox score over time.
All of that lives in one file inside the app on your iPhone, and it goes when you delete the app.
Your mailbox sign-in is encrypted on the phone with a key held in the iPhone's Secure Enclave, behind Face ID. It is never sent anywhere and no copy of it exists off the device.
Who BINIT talks to
Only ever these, and only when what you asked for needs it:
- Your mail provider — the app connects to your mailbox directly, over an encrypted connection, to read it and to carry out what you've asked for.
- Microsoft — if you use Outlook or Hotmail, signing in happens on Microsoft's own page. Your password is never typed into BINIT.
- An unsubscribe address — when you choose to leave a mailing list, the app contacts the address that sender published for it. Nothing beyond that request is sent.
- The public break-in list — BINIT downloads the catalogue of companies known to have been robbed. It is the same list for everybody and carries nothing about you; the crossing-off against your own mail happens on the phone. Your address is not sent to do this.
- The password-checking service — only if you use Check a password. See below, because it deserves its own explanation.
- Apple — for the purchase, and nothing else.
Buttons like Change password and Delete account simply open that company's own page in your browser. BINIT does not sign in for you, fill anything in, or watch what you do there.
The password check, in full
Everywhere else BINIT tells you never to type a password into it. The Check a password screen is the one exception, and it exists because there is no honest way to answer "has this password already been stolen?" without the password.
What actually leaves the phone
The password is scrambled on your iPhone and only the first five characters of the scramble are sent. Those five match roughly half a million different passwords. The service sends back all of them and cannot tell which one you asked about. The comparison happens back on your phone.
The password itself, the full scramble, your email address and your device are never sent. Nothing about the password is written down afterwards — the app keeps one word, found, weak or clean, and the date.
Checking one particular address
Asking whether a specific address has been in a break-in means sending that address to somebody — there is no clever arrangement that avoids it, the way there is for passwords. So BINIT ships with that switched off, and nothing is sent.
If you put in your own key for the breach service, that lookup turns on, and then the address you typed does go to it. The screen says so at the point you use it. Everything else on this page is unaffected.
Payment
The one-time unlock is bought through Apple. Apple handles the payment; BINIT never sees your card, your name or your Apple Account. All the app receives is Apple's answer to "has this been paid for".
Children
BINIT is not directed at children and collects no information from anybody.
Changes
If this ever changes it will be changed on this page, and the app will change with it. Last change: the password check and the optional address lookup were both written up in full, above.
Asking me about it
Write to theitgroupapps@gmail.com.