Privacy
HILIA ("Hide Like A Pro") is a tool for hiding data inside images, revealing it again, and adding watermarks. It is built by TYO Lab. This policy explains what HILIA does — and does not — do with your images and data, across the website and the Android, iOS and iPad apps.
Last updated: 8 August 2026.
The short version
- Your images are processed for the operation you asked for, and are not kept. We never store the contents of your images, the data you hide, or your passphrases.
- Steganography in the apps runs entirely on your device. Hiding and revealing on Android, iOS and iPad never sends your image off the device.
- You can use most of HILIA without an account. Signing in is optional, and unlocks features like subscriptions, the leaderboard and saved settings.
- We do not use third-party analytics or crash-reporting. The apps ship no analytics or crash-tracking SDKs.
- The apps show ads to non-members (via Google AdMob); paying members are ad-free. The website shows no ads.
What we process, and where
On your device / in your browser — never sent to us:
- Visible watermarking on the website runs entirely in your browser; the image never leaves your device.
- Hiding and revealing in the apps (Android, iOS, iPad) runs entirely on-device using a native engine. Your carrier images, hidden files and passphrases stay on the device.
Sent to the HILIA service, processed transiently, and not stored:
- Hide, reveal and covert watermarking on the website send the image to the HILIA service for processing and return the result immediately. Images and files are processed in memory and are not stored on our servers.
- When you use an account-based feature (below), only the data that feature needs is sent — never the contents of your images or hidden data.
Accounts and sign-in
Signing in is optional. When you choose to sign in, HILIA uses TYO's own identity service
(id.tyo.com.au) as the broker. Depending on the platform you can sign in with:
- Google (website, Android, iOS, iPad)
- Sign in with Apple (website, iOS, iPad)
- Email and password (with optional two-factor code), where offered
When you sign in with Google or Apple, we receive the basic profile information you consent to share (such as your name and email address) so we can create and recognise your account. Sign-in produces a security token that identifies you to HILIA for the session; on the apps this token is stored on your device.
We use your account only to operate the service — to recognise you, apply your entitlements (membership/credits), power the leaderboard if you opt in, and provide support. We do not sell your personal information.
The leaderboard (opt-in)
HILIA has an optional public leaderboard that ranks users by an "XP" score derived from how many operations they have run.
- It is off by default. You are only ranked if you turn it on, and you must be signed in.
- What is stored: your account identifier, your XP (calculated from counts of operations you ran — not from the contents of your images), and a public display name — a nickname you choose, or otherwise an automatically-assigned codename. Your display name and XP are visible to other users on the board.
- We do not put your images, hidden data, or email on the leaderboard.
- Leaving: turn the leaderboard off in settings to stop being ranked, which removes your entry from the board. You can also ask us to delete your leaderboard data (see Deleting your data).
Payments, memberships and credits
- Website credits ("gas"): top-ups on the website are handled through TYO's checkout, with card payments processed by our payment provider (Square). We do not receive or store your full card details — those are handled by the payment provider.
- App subscriptions: where a membership subscription is offered in an app, the purchase is handled by the platform's app store — Google Play on Android, the Apple App Store on iOS and iPad. After a purchase, the app sends the purchase identifier to our backend to verify it and activate your membership on your account. We do not receive your card details from the app stores.
- Enterprise API keys: if you use HILIA via an API key, we record per-key usage counts for metering and billing. We do not log the contents of your API requests' images or hidden data.
The HILIA apps (Android, iOS & iPad)
The apps do as much as possible on your device. Hiding and revealing images never leaves the device on any platform. Below is what each platform does beyond that.
On every platform
- On-device steganography. Carrier images, the files you hide, and your passphrases are processed locally and are not uploaded.
- App lock (optional). You can lock the app with a passcode and biometric unlock (fingerprint / Face ID). Your passcode is never stored in readable form.
- Optional sign-in and the opt-in leaderboard work as described above.
- No analytics or crash-tracking. The apps do not ship third-party analytics or crash-reporting SDKs.
- Uninstalling the app removes its local data from your device.
Android app (au.com.tyo.steghide)
- Advertising. For users who are not members, the Android app shows occasional full-screen ads via Google AdMob, at the end of some hide/reveal operations. To do this the Google Mobile Ads SDK uses your device's advertising ID and shares data with Google and its advertising partners under Google's own policies. Members do not see ads. You can reset or limit your advertising ID in your Android settings, and Google's ad choices apply.
- Sign-in: Google, opened in a secure in-app browser tab and completed through
id.tyo.com.au. - Subscriptions: purchased and managed through Google Play Billing; the purchase is verified with our backend to activate membership.
- Permissions & storage: the app uses the internet (for sign-in, ads, purchase verification and, if you opt in, the leaderboard). Cover images are chosen through the system photo picker; images you keep in the app's vault are stored in the app's private storage, and your passcode is stored encrypted using the Android Keystore. The app does not use the camera or your location, and its data is excluded from Android's automatic cloud backup.
iOS & iPad app (au.com.tyo.hilia)
- Ads for non-members. Like the Android app, the iOS and iPad app shows occasional ads to users who are not members, via Google AdMob; members are ad-free. The app includes no analytics or crash-reporting SDKs. Ads are served under Google AdMob's settings; on Apple devices, whether ads are personalised also follows your device's App Tracking Transparency choice, which you can change in Settings.
- Sign-in: Google, Sign in with Apple, or email and password (with optional two-factor),
brokered through
id.tyo.com.au. - Permissions: the app requests access to your photo library so you can choose a carrier image, and Face ID if you enable biometric app lock. It does not request camera, location, contacts or microphone access.
- Storage: images you keep in the app's vault are stored in the app's own storage on the device and are excluded from device backups; your app-lock passcode is kept only as a one-way hash in the iOS Keychain (it can be checked, never recovered).
Usage statistics
To understand how HILIA is used and keep it running, we record each operation you run — which feature (for example, watermark or hide), whether it succeeded, the size of the file, and a coarse country derived from your network address. We never store your raw IP address: it is one-way hashed with a rotating secret before storage. We do not store the contents of your files or the hidden data itself. On the website, anonymous visitors are counted using a first-party cookie that holds a random identifier only.
Who we share data with
We share personal data only with the providers needed to run HILIA:
- Google — for Google Sign-In, and AdMob advertising (in the apps, shown to non-members).
- Apple — for Sign in with Apple and App Store purchases (iOS/iPad).
- Square — to process card payments for website credits.
- Google Play — for app subscriptions on Android.
- TYO Lab's own identity and store services (
id.tyo.com.au,store-api.tyo.com.au) — which operate the sign-in, membership and metering on our behalf.
Our services run on Google Cloud infrastructure. We do not sell your personal information.
Deleting your data
- The website tool stores nothing about your images, so there is nothing to delete there.
- Leaderboard: turn it off to remove your entry, or ask us to delete your leaderboard data.
- Account: contact us to delete the account you created and the data held under it.
- Apps: uninstalling removes all local app data (vault, settings, saved sign-in) from your device.
If you have any questions about data held under an account you created, contact TYO Lab and we will remove it.
Children
HILIA is a general-purpose tool and is not directed at children. Please use the app store age ratings as guidance and do not sign in if you are below the minimum age in your country.
Changes to this policy
We may update this policy as HILIA evolves. When we make material changes we will update the "Last updated" date above.
Contact
Questions about privacy? Contact TYO Lab via tyo.com.au/contact.