Privacy Policy
Last updated: June 15, 2026
1. Who we are
Vault ("we", "our", "the app") is a privacy-first application that disguises itself as a calculator to keep your messages and files protected. This policy explains what information we collect, how we use and protect it, and the rights you have over that data. By creating an account or using the app, you agree to this policy.
2. Information we collect
We collect only what is necessary to operate the service:
- Account data: your chosen display name, @handle, and an authentication identifier issued by our backend. We never store or transmit your unlock code in plain text.
- Messages: the content and metadata (sender, recipient, timestamp) of messages you send through the app, stored so that you and your recipient can read them.
- Files: any photos, documents, or attachments you upload to your private storage room.
- Device & diagnostic data: minimal technical logs (error reports, crash diagnostics, approximate request times) used to keep the service running and investigate abuse.
- Premium & billing data: if you upgrade, our payment processor handles your card details. We only receive a confirmation that a purchase succeeded — we never see or store your full card number.
We do not collect your contacts list, your location, your microphone or camera input outside features you explicitly trigger, or any advertising identifiers.
3. How we use your information
- To authenticate you and deliver core features (messaging, file storage, decoy mode).
- To enforce tier limits (storage caps, contact caps) and process upgrades.
- To detect, investigate, and prevent fraud, abuse, or security incidents.
- To respond to your support requests.
- To comply with legal obligations when properly required.
We never sell your personal data, and we do not use your messages or files to train AI models or to serve advertising.
4. How we protect your data
- Encryption in transit: all communication with our servers uses TLS (HTTPS).
- Encryption at rest: messages and files are stored on encrypted infrastructure managed by our backend provider.
- Access control: per-user authorization rules ensure your data is only readable by you and, for messages, the recipient you chose.
- Zero-knowledge unlock code: the unlock code that opens the Vault from the calculator is never transmitted or stored on our servers. If you forget it, we cannot recover it.
- Break-In Capture (Premium): if enabled, the front camera captures an image only after repeated failed unlock attempts. These images are stored in your private vault and never sent to us.
5. Where data is stored and for how long
Your data is processed and stored on managed cloud infrastructure inside the European Union and the United States, depending on your region. We retain your data only as long as your account is active or as needed to provide the service. When you delete your account, your messages, files, and identifiers are permanently removed from active systems within 30 days, except where we are legally required to retain certain records (for example, billing records).
6. Sharing with third parties
We share data only with the limited set of providers required to run the app:
- Cloud hosting & database — to store and serve your messages and files.
- Payment processor — to handle Premium subscriptions and one-time purchases.
- Error & diagnostics tooling — to detect and fix crashes.
Each provider is bound by contract to use your data only to deliver their service to us. We do not share your data with advertisers, data brokers, or social networks.
7. Your rights
Depending on where you live (including the EU/UK under GDPR, California under CCPA/CPRA, and similar laws), you have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate information.
- Delete your account and associated data.
- Object to or restrict certain processing.
- Export your data in a portable format.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email us at support@vltbox.store from the address associated with your account, or contact us through the in-app support screen.
8. Children
The Vault is not directed to children under 13 (or under 16 in the EU). We do not knowingly collect data from minors. If you believe a child has provided us with personal information, contact us and we will delete it.
9. Security incidents
If we ever discover a breach that affects your personal data, we will notify you and the appropriate authorities without undue delay, in line with applicable law.
10. Changes to this policy
We may update this policy as the app evolves. When we do, we will update the "Last updated" date above and, for material changes, notify you inside the app.
11. Contact
Questions, requests, or complaints? Email support@vltbox.store.