๐Ÿ”’ Zero-knowledge ยท Encrypted on-device

Privacy Policy

Vault โ€” a private, offline vault for your photos, documents and credentials.

Effective: 1 July 2026
Developer: Akash Shrestha
Vault is built so we never see your data. Your files, passwords and encryption keys stay on your device, protected by a key derived from your PIN that never leaves the phone. We operate no servers that can read your content, and we do not have โ€” and cannot create โ€” a way to recover or access what is inside your vault.

01 Our approach

Privacy by architecture, not by promise

Vault is a zero-knowledge, offline application. Everything you store is encrypted on your device using AES-256 before it is written to storage. The encryption key is derived on-device from your PIN and is never transmitted to us or any third party. Because of this design, we are technically unable to view, decrypt, recover, or hand over your vault contents.

This policy explains what limited information the app handles, what stays exclusively on your device, and the few third parties involved when you choose to make a purchase.

02 Information we do not collect

What never leaves your device

โœ“Your photos, videos, documents and files
โœ“Your passwords, passkeys, cards, notes and 2FA secrets
โœ“Your PIN, recovery phrase and encryption keys
โœ“Break-in photos and location captures
โœ“Text recognized by on-device OCR and your search history
โœ“Your access log and vault activity

We do not operate accounts, we do not require an email or phone number to use the app, and we do not sell or share any personal data. There is no advertising and no third-party tracking.

03 What stays on your device

Local, encrypted storage

All vault content is stored inside an encrypted database (SQLCipher), with files encrypted before they are written. This includes imported media and documents, credentials, albums, decoy-vault data, OCR text used for search, break-in evidence, and your on-device access log. This data is accessible only after successful unlock and is never sent to us.

04 Optional encrypted backup

Opt-in, end-to-end encrypted

Backup is off by default. If you choose to enable encrypted backup or cross-device sync, your data is encrypted on your device before it is uploaded, and remains readable only with your recovery phrase. The backup destination stores only an encrypted archive; neither we nor the storage provider can decrypt it. If you never enable backup, nothing is ever uploaded.

There is no password reset and no recovery back door. If you lose your device and your recovery phrase, your data cannot be recovered by anyone, including us. This is intentional.

05 Device permissions

Why the app asks for access

Vault requests certain iOS permissions only to provide specific features. Access is used locally and is not transmitted to us.

06 Purchases & subscriptions

Vault Pro

Vault Pro is offered as a subscription or one-time purchase processed by Apple through the App Store. Apple handles your payment; we never receive your card details. To manage entitlements across your devices we use RevenueCat, a subscription-management service that processes a pseudonymous app user identifier and non-personal purchase/receipt information. This data is used only to verify and restore purchases and is never linked to your vault contents.

Confirm before publishing: keep this section only if RevenueCat is in your build. If you use a different processor or none, edit accordingly. Apple's own handling of purchases is governed by Apple's privacy policy.

07 Analytics & diagnostics

No behavioral tracking

Vault does not include advertising SDKs or third-party behavioral analytics, and does not build a profile of you. We do not track your activity across apps or websites.

Confirm: if you have added crash reporting (e.g. Firebase Crashlytics or Sentry), disclose it here โ€” state that crash logs may include device model and OS version, contain no vault contents, and are used only to diagnose stability issues. If you ship with none, keep the statement above as written.

08 Password health & breach checks

Checked privately

Password-health scoring and breach detection run on your device. Your passwords are never uploaded in any form. Breach matching is performed so that a password is never exposed, and results are shown only to you.

Confirm: if breach checking sends a partial, anonymized hash prefix to an external service (k-anonymity, e.g. Have I Been Pwned), disclose that here: only a short SHA-1 hash prefix is sent, the full password never leaves the device, and the service cannot determine your password. Remove this note if the check uses a fully bundled offline dataset.

09 Data retention & deletion

You are in control

Because your data lives on your device, you control its lifetime. You may permanently destroy the entire vault at any time using Emergency Wipe or Shake-to-Wipe, which performs a cryptographic erase โ€” the master key is overwritten and discarded, rendering all encrypted data permanently unreadable. Uninstalling the app also removes its local data.

10 Security

How your data is protected

No system is perfectly secure, and you are responsible for safeguarding your PIN and recovery phrase. We encourage keeping your recovery phrase stored safely offline.

11 Children's privacy

Not directed to children

Vault is intended for general audiences and is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. Since the app collects no personal data on our servers, no such information is gathered regardless of age.

12 Third-party services

Limited processors

The only third parties involved in normal use are Apple (app distribution and payment processing) and, where applicable, our subscription processor for purchase verification. If you enable encrypted backup, the storage provider you select holds only an encrypted, unreadable archive. These parties never receive your decrypted vault contents.

13 Changes to this policy

Updates

We may update this Privacy Policy to reflect changes to the app or legal requirements. When we do, we will revise the "Effective" date above and, for material changes, provide notice within the app. Continued use after an update constitutes acceptance of the revised policy.

14 Contact us

Questions about your privacy

If you have any questions about this Privacy Policy or how the app handles data, contact us at: