Vault · Privacy Policy

Vault collects nothing.

EFFECTIVE 8 SEPTEMBER 2026 · VERSION 1.0

There is no account, no server and no analytics. Vault makes no network requests of its own, so there is no channel through which your data could reach us — or anyone else.

This policy describes how the Vault iOS and Android app handles your information. In Apple’s App Privacy terms, Vault is declared as Data Not Collected.

What Vault stores, and where

Everything you save stays in Vault’s private storage area on your device:

None of this is transmitted anywhere. It is readable only by Vault, on that one device.

What Vault does not do

Network access

Vault issues no network requests. The single exception is entirely under your control: if you tap Open on an entry that has a URL saved, Vault hands that address to your device’s browser. From that moment you are on that website, and its own privacy policy applies — not this one.

Biometrics

Unlocking uses Face ID, Touch ID or your device passcode. That check is performed entirely by the operating system; Vault receives only a yes or no. Your fingerprint and face data are never available to Vault, and are never stored or transmitted by it.

The clipboard

Copying a password places it on your device’s system clipboard so you can paste it elsewhere. Vault clears it again after a delay you control (45 seconds by default), and clears it immediately whenever the vault locks. It only clears the clipboard if the contents are still what Vault put there, so it will never wipe something you copied yourself in the meantime.

Worth knowing: the system clipboard is not private to Vault. While a password sits on it, other apps you open can read it, and if you use Apple’s Universal Clipboard or a similar feature, your device may relay it to your other devices. These are operating system behaviours outside any app’s control, which is why the auto-clear delay exists and why it is kept short.

Backups you export

Vault can export an encrypted backup file. It is encrypted with a passphrase you choose, using PBKDF2-SHA256 (210,000 iterations) to derive a key and AES-256-GCM to seal the contents. Your device’s own vault key is never included, so the file is useless without the passphrase.

That passphrase is never stored, never transmitted, and cannot be recovered by anyone, including us. If you lose it, the backup cannot be opened.

Once exported, the file is yours to place wherever you choose. If you save it to iCloud Drive, email it, or move it to another service, that service’s privacy policy governs the file from then on. It stays encrypted, but where it travels is your decision.

Deleting your data

Delete the app. The encrypted vault file and the key in the keychain are removed with it. There is no server-side copy to request the deletion of, because there is no server. Any backup files you exported are yours to delete separately.

Children

Vault is not directed at children, and it collects no personal information from anyone regardless of age.

Changes to this policy

If this policy changes, the revised version will be posted at this address with a new effective date. Because the app collects nothing, any change is likely to be a clarification rather than a change in practice.

Contact

Questions about this policy or about Vault: dangngochai@gmail.com