Privacy Policy

Last updated: April 12, 2026

The Short Version: Your passwords never leave your device

VaultX is a fully local app with no servers. Every password and account credential you store is encrypted with AES-256 and kept exclusively on your device. No account required. We do not collect, store, or sell your personal data.

1. Introduction

This Privacy Policy explains what information VaultX ("the app", "we", "us") collects and how it is used. VaultX is a local password manager designed to securely store passwords and sensitive account credentials. We are committed to protecting your privacy and operating with full transparency.

2. Information We Collect

2.1 Information We Do NOT Collect

VaultX does not collect:

2.2 Information Stored Locally on Your Device

The following information is encrypted with AES-256 and stored exclusively on your device. It is never transmitted to external servers:

2.3 Breach Database Check (Have I Been Pwned)

When you use the password health check feature, VaultX queries the Have I Been Pwned (HIBP) service. This process uses k-anonymity:

2.4 RevenueCat (In-App Purchases)

We use RevenueCat to process VaultX Premium purchases. RevenueCat handles:

Payment information and your Apple ID are handled directly by Apple. We have no access to them.

3. How We Use Information

4. Data Storage & Security

4.1 Military-Grade Encryption

All password data is protected with AES-256-GCM encryption. Your master password is never stored — it is processed through PBKDF2 key derivation to produce an encryption key. Neither we nor anyone else can access your vault without the master password.

4.2 No External Servers

VaultX operates no servers of its own. Your stored passwords and account credentials are never transmitted over the internet.

4.3 iCloud Sync (Optional, Premium)

Premium users may optionally enable iCloud sync to access their vault across multiple devices. When enabled:

4.4 Decoy Mode (Optional, Premium)

Decoy Mode creates a separate, isolated fake vault accessible via a second password. In a coercion scenario, you can unlock this vault to show convincing but non-sensitive data. Your real vault remains protected at all times.

Important: Lost master password cannot be recovered

VaultX does not store your master password on any server. If you forget it, your data cannot be recovered by us. We strongly recommend using the SOS Emergency Recovery feature to split your master password into shares and entrust them to people you trust.

5. Third-Party Services

ServicePurposeData Shared
RevenueCatIn-app purchase managementAnonymous user ID, purchase status
Apple App StorePayment processingHandled directly by Apple — not by us
Have I Been PwnedPassword breach checkingFirst 5 chars of SHA-1 hash only (k-anonymity)

We do not use advertising networks, behavioral tracking, or analytics services of any kind.

6. App Permissions

PermissionPurposeRequired
Face ID / Touch IDBiometric vault unlockOptional
iCloudEncrypted cross-device syncOptional — Premium
AutoFill (Credential Provider)AutoFill in apps and browsersOptional

VaultX does not request access to your camera, microphone, location, contacts, or calendar.

7. In-App Purchases

8. Data Retention

Uninstalling VaultX permanently removes all local data from your device. We hold no copy of it and cannot assist with recovery.

9. Children's Privacy

VaultX is not directed at children under the age of 13. The app does not require account creation and does not collect personal information.

10. Your Rights

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the app after any changes constitutes your acceptance of the revised policy.

12. Contact

If you have any questions about this Privacy Policy, please contact us:

Email: prizm_kr@hotmail.com

Privacy at a Glance

Do you require an account?No
Are passwords sent to a server?No — encrypted locally on your device
Are there ads?No
Do you use analytics or tracking?No
Do you sell data?No
Do you share data with third parties?Only for payment and breach checking (RevenueCat, Apple, HIBP)
Can I delete my data?Yes — in-app or by uninstalling