Native Android help center · Native terms and limits
Native Android app
The current Kotlin Android app has no account, Internet or location permission, analytics, advertising, rules download, or in-app billing. Employer and worker details, entered earnings and deductions, calculations, and the saved draft remain on the device. The draft is encrypted with AES-GCM using an Android Keystore key; hardware protection depends on the device. Android backup is disabled. The developer cannot recover the key or draft. The production app protects screenshots and app-switcher previews.
Saving a PDF uses the Android document picker. A selected storage provider may transfer that exported PDF under its own policy. PDFs are readable and are not encrypted by StubSafe. Erasing the local draft does not erase exported copies. The optional support action opens donate.autosecurelogin.com in a separate browser without payroll data. That website and Stripe process connection or payment information under their own policies; support never changes app access.
The English or Spanish language preference is saved separately on the device. It contains no payroll data and is not sent to a translation service. Names, notes and entered values do not change when selecting another language.
Web and PWA summary
The remaining sections describe the web/PWA and legacy web-based clients. They are designed to generate documents on the device. An optional account is available there, but it is not required for pay-stub creation. StubSafe does not use an advertising identifier, analytics service, cloud payroll database, or payroll-data API.
Data processed and encryption
Information entered into the form, uploaded logos, profiles, drafts, batch queues, and optional history are processed locally. Sensitive saved records are encrypted using AES-256-GCM with a key derived from the user’s vault passphrase. The passphrase is not transmitted and cannot be recovered by the developer.
Optional central account
If the user chooses to sign in, StubSafe opens AutoSecureLogin and processes the account identity, email address, session tokens, and normal connection metadata needed for OpenID Connect authentication. Tokens are kept only in the current browser or app session. Payroll entries, employer and worker details, uploaded logos, generated documents, vault passphrases, and encryption keys are not included in account sign-in. Signing in does not unlock, upload, merge, synchronize, recover, or reset an encrypted local vault.
Location
Location is optional. The app requests approximate or precise device location only after the user presses “Use device location.” Coordinates are compared against bundled U.S. state boundaries on the device to suggest a state. Coordinates are not uploaded or retained in a pay statement.
Recommendation updates
If enabled, the app may download a shared signed tax and compliance rules catalog from the configured HTTPS recommendation service. The request contains no payroll entries, identity details, location coordinates, profile identifiers, or generated documents. The catalog includes source titles, publishers, official links, effective dates, publication dates when available, and collection dates. The app verifies its digital signature before use and retains bundled rules for offline operation. The reference service performs no application-level request logging, although hosting and network providers may process transient connection information needed to deliver the response.
Payments
Optional tips may be processed by Apple, Google Play, or Stripe. Those providers receive information necessary to process the payment under their own policies. Payroll data is not included with a tip. Web tips use fixed Stripe-hosted payment links; StubSafe does not treat the return URL as proof that a payment completed, and support never changes access to app features or generated pay stubs.
Private on-device measurements
StubSafe may keep simple counters on the device for successful document generations, support-button intent, referral shares, and export actions. The counters contain no payroll values, names, employer or worker details, document identifiers, file contents, location, account identity, or payment details. They are not transmitted to StubSafe or any analytics service, can be viewed and reset from System status, and do not identify whether a payment was completed.
Feedback and diagnostics
The optional feedback form can create a report containing app version, device/browser capability information, storage totals, and recommendation-catalog metadata. It is designed to exclude payroll records, names, wages, tax identifiers, bank information, coordinates, PDFs, vault contents, and passphrases. Users must review feedback before sharing it.
Exports
PDF, image, CSV, text, ZIP, and encrypted backup files leave the application sandbox when the user saves or shares them. The user controls and is responsible for those copies.
Data deletion
The “Erase local app data” control removes the encrypted vault and app records from local application storage. Operating-system backups or exported files must be managed separately by the user.
Contact
Email contact@autosecurelogin.com without including sensitive payroll data.
Return to app · Support · Feedback · Terms