The short version. The VaultSec app collects no personal data. Everything you keep in it stays encrypted on your phone; we never receive it and could not read it if we did. This website sets no cookies and stores nothing in your browser; it counts visits anonymously, without cookies. The only personal data we may ever handle is what you choose to send us by email, and the technical data our hosting provider needs to deliver this site.
This policy covers the VaultSec mobile app (iPhone and Android) and the website at vaultsec.app. The operator responsible for both (the “controller”, or “responsable” under Latin American law) is named in the legal notice. Write to [email protected] for anything about your data.
1. The app
What we never collect
VaultSec has no account, no server and no cloud. It makes no network connections of its own. It contains no analytics, advertising, crash-reporting or tracking software, no advertising identifier and no third-party code that collects data. We do not know who uses VaultSec, how, or what they keep in it.
What stays on your phone
Photos, videos, documents, notes, contacts you add for sharing, settings and the access log are stored only on your device, encrypted with keys that only your PIN together with your phone’s security chip can unlock. We have no copy and no key. Deleting the app, or erasing the vault from its settings, destroys them.
Device permissions
The app asks for a permission only when you use the feature that needs it, and you can refuse:
- Camera — for the in-vault camera, and to scan a contact’s code when you add them in person.
- Photos and files — to import the items you choose.
- Face ID / fingerprint (optional) — handled entirely by your phone’s operating system; VaultSec only receives a yes or no, never biometric data.
- Motion — to detect the panic shake, processed on the device and never stored.
Files you choose to move
Encrypted backups (.vltx) and encrypted share packages are files you create and send wherever you choose. They remain encrypted, but the services you use to store or send them (a cloud drive, a messaging app, email) process them under their own terms. When you export an ordinary copy of an item, that copy is no longer protected by VaultSec.
Purchases
The optional one-time Unlimited purchase is processed by Apple (App Store) or Google (Google Play), who act as independent controllers of your payment and account data under their own privacy policies. We receive no payment details. The stores give us aggregated, non-identifying sales and download statistics.
2. This website
- No cookies, no browser storage, no advertising. We use no advertising, social-media or tag-manager scripts, and all fonts and images are served from our own domain.
- Anonymous visit counts. To know which pages are useful, we use Cloudflare Web Analytics. It sets no cookies, stores nothing on your device, does not fingerprint your browser and does not follow you across sites; it reports only aggregate figures (page views, referring sites, countries, page speed). It runs on our legitimate interest in improving the site (GDPR Art. 6(1)(f)); a content blocker can switch it off with no loss of function.
- Hosting. The site is delivered by Cloudflare, Inc. (content delivery and protection against attacks). To deliver each page, Cloudflare necessarily processes technical data — your IP address, browser type, the page requested and the time — and keeps it in security logs for a short period. Cloudflare acts as our processor under a data processing agreement. We do not use this data to identify visitors.
- Links out. The Quick exit button and the helplines on our safety page link to other sites, which have their own privacy policies.
3. When you email us
If you write to us (support, privacy requests, security reports), we use your email address and message only to answer you and keep them for up to 12 months after the conversation ends, unless a longer period is required by law. Do not send us files from your vault; we do not need them.
4. Legal bases
Where the EU/EEA GDPR or a similar law applies, we process personal data only on these bases: delivering and securing the website (our legitimate interest, Art. 6(1)(f) GDPR); answering your messages (your request, Art. 6(1)(b), or our legitimate interest); and meeting legal obligations (Art. 6(1)(c)).
5. International transfers
Cloudflare may process website data outside your country, including in the United States. Such transfers rely on the EU–US Data Privacy Framework, to which Cloudflare is certified, and on the European Commission’s Standard Contractual Clauses.
6. Your rights
Wherever you live, you can ask us what personal data we hold about you (in practice, only emails you sent us), and ask us to correct or delete it. Write to [email protected]. We answer within one month, and never charge for it.
- EU and EEA (GDPR): you also have the rights to restriction, portability and objection, and the right to lodge a complaint with your national data protection authority.
- United States (California CCPA/CPRA and other state privacy laws): you have the rights to know, delete and correct. We do not sell or share personal information, do not use it for targeted advertising, and do not collect sensitive personal information. We honour Global Privacy Control signals, though there is nothing for them to switch off. We will not discriminate against you for exercising your rights.
- Brazil (LGPD): you have the rights in Article 18, including confirmation, access, correction, anonymisation, deletion, portability and information about sharing. Our data protection contact (encarregado) can be reached at [email protected]. You may also complain to the ANPD.
- Mexico (LFPDPPP 2025): you may exercise your ARCO rights (access, rectification, cancellation and opposition) by email; the authority is the Secretaría Anticorrupción y Buen Gobierno.
- Argentina, Colombia, Chile, Peru, Uruguay and other Latin American countries: you have the rights of access, rectification, updating and deletion under your national law (including Argentina’s Law 25,326, Colombia’s Law 1581 of 2012, Chile’s Law 19,628 and, from 1 December 2026, Law 21,719, Peru’s Law 29733 and Uruguay’s Law 18,331), and may complain to your national authority.
7. Children
VaultSec is not directed at children under 13, and we do not knowingly collect personal data from them. Because the app collects no personal data at all, it does not collect children’s data either.
8. Security
The app’s protections are described on our security page. For this website we use HTTPS only, a strict content security policy, and no third-party code other than Cloudflare’s cookieless visit counter.
9. Changes
If we change this policy, we will update the date below and, for significant changes, say so on the website. The app itself will never start collecting data without an update that you would see described here first.
Last updated: