Privacy Policy

Last updated 25 July 2026

The short version: we hold your email address, what you bought, and what you wrote to support. We do not hold your vault, and we cannot read it. There is no analytics SDK, no advertising identifier and no third-party tracker in Vault.

What we collect

  • Email address — to run your account, bill you, re-issue your licence on a new device, answer support, and send security notices.
  • Account / licence identifier and purchase history — to validate your entitlement across reinstalls and devices.
  • Support correspondence, if you write to us — to answer you.
  • Crash and performance diagnostics — only if you opt in. Vault data, entry titles, URLs and domains are stripped before sending, and the reports are not attached to your account identity.

We do not collect your vault contents, your master password or any key derived from it, card numbers, name, postal address, phone number, contacts, photos, location, advertising identifiers, usage analytics, or browsing history.

What your email address does not enable

There is no password recovery. Your master password never leaves your device. It derives the key that encrypts your vault. We do not have it, cannot obtain it, cannot reset it, and cannot decrypt or restore your vault without it — no support request, no proof of identity, no legal process and no payment changes that. It is a property of the mathematics, not a policy we could waive. Keep a record of your master password somewhere physically safe, and keep your own exports.

Your email lets us bill you, re-issue your licence and answer you. It does not let us open your vault, and verifying your identity does not change that — there is nothing on our side to unlock.

What stays on your device

Your master password (used only as input to key derivation, never stored or transmitted), the derived key-encryption key, the random 256-bit vault key, the decrypted contents while unlocked, and a local encrypted copy for offline use. On iOS, biometric key material is held in the Keychain under Secure Enclave protection; on platforms using WebAuthn PRF, the wrapping secret is held by the platform authenticator.

Sync — your Google Drive, not our server

If you enable sync, your encrypted vault is stored in your own Google Drive in the appDataFolder area, using the drive.appdata OAuth scope. That scope grants access only to a private per-application folder; Vault cannot read your other Drive files. The file is ciphertext, the request goes from your device to Google rather than through us, and your Google OAuth tokens are stored encrypted inside the vault itself. You can revoke access at any time from your Google Account permissions page and delete the file yourself. Sync is optional — Vault works fully offline.

The realtime relay

When sync is on, your devices exchange a "revision changed" ping over a Supabase Realtime channel scoped to your user identifier. It carries a revision indicator and nothing else — no vault contents, entry names, URLs, usernames, passwords or key material. The vault bytes themselves move only between your device and your own Drive.

The sharing directory

Only if you use cross-user sharing, Vault publishes a directory record containing your user identifier, your account email and your public key, so that others can encrypt an item to you. Public keys permit encryption to you and cannot decrypt anything. No private keys and no vault data are published. If you never use cross-user sharing, no directory record exists.

Who else receives what

The full list, and what each can and cannot see, is on the subprocessors page. We do not sell, rent or share personal information for advertising or any other commercial purpose, and have not done so in the preceding twelve months.

Retention and deletion

  • Local device copy: until you delete it or uninstall.
  • Encrypted vault in your Drive: until you delete it. We cannot delete it for you, and cannot restore it after you do.
  • Relay pings: transient, not stored as user records.
  • Account record: while your account exists; deleting it removes licence and support history.
  • Billing records: retained where tax and accounting law requires, then deleted. This is the one category we cannot delete on request while that period runs.
  • Diagnostics, if you opted in: deleted on a rolling basis; turning them off stops collection.

Deleting your account does not delete your vault and cannot: the vault lives on your device and in your own Drive, and we hold no key to it.

Your rights

Portability is built in: Vault exports your complete vault to CSV on demand, free on every tier, without asking us. For the account data we hold — email, licence identifier, purchase history, support mail — email founder@dfacto.ai to request access, correction, or erasure and we will act within one month. EEA, UK and Swiss users have the rights of access, rectification, erasure, restriction, objection and portability under the GDPR, and may complain to their supervisory authority; the legal bases are performance of the contract (account, billing, sync), legal obligation (tax records, security notices), your consent (diagnostics), and our legitimate interest in a secure service.

California residents: the categories collected in the last 12 months are identifiers, commercial information, customer-service records, and — only on opt-in — redacted diagnostics. We do not sell or share personal information, and collect no sensitive personal information. Requests go to founder@dfacto.ai; we verify by requiring a reply from the account email. Verification acts on account records only and never grants access to a vault. Residents of other US states with comparable laws have analogous rights through the same channel.

This website

Static files, no cookies, no analytics, no third-party scripts and no web fonts. Our host records standard server logs for security and operations. See our cookie policy.

Children, transfers, breaches

Vault is not directed to children under 13 and we do not knowingly collect their information. Where account data is transferred out of the EEA or UK, the transfer relies on Standard Contractual Clauses with our processors. Because we hold no vault data and no key to it, a compromise of our infrastructure cannot expose your passwords; it could expose the account data above, and we will notify affected users and, where required, the relevant supervisory authority within 72 hours of becoming aware.

Security

AES-256-GCM content encryption; scrypt (N=2¹⁷) key derivation on desktop and CLI and PBKDF2-HMAC-SHA256 at 600,000 iterations in the browser and mobile apps; a wrapped random 256-bit vault key; ECDH P-256 with HKDF-SHA256 for sharing. Details on the security page. No security measure is perfect, and no independent third-party security audit has been performed.

Contact

founder@dfacto.ai · Deepak Marathe (sole proprietor), Mysuru, Karnataka, India