Last updated: April 12, 2026
VaultX is a fully local app with no servers. Every password and account credential you store is encrypted with AES-256 and kept exclusively on your device. No account required. We do not collect, store, or sell your personal data.
This Privacy Policy explains what information VaultX ("the app", "we", "us") collects and how it is used. VaultX is a local password manager designed to securely store passwords and sensitive account credentials. We are committed to protecting your privacy and operating with full transparency.
VaultX does not collect:
The following information is encrypted with AES-256 and stored exclusively on your device. It is never transmitted to external servers:
When you use the password health check feature, VaultX queries the Have I Been Pwned (HIBP) service. This process uses k-anonymity:
We use RevenueCat to process VaultX Premium purchases. RevenueCat handles:
Payment information and your Apple ID are handled directly by Apple. We have no access to them.
All password data is protected with AES-256-GCM encryption. Your master password is never stored — it is processed through PBKDF2 key derivation to produce an encryption key. Neither we nor anyone else can access your vault without the master password.
VaultX operates no servers of its own. Your stored passwords and account credentials are never transmitted over the internet.
Premium users may optionally enable iCloud sync to access their vault across multiple devices. When enabled:
Decoy Mode creates a separate, isolated fake vault accessible via a second password. In a coercion scenario, you can unlock this vault to show convincing but non-sensitive data. Your real vault remains protected at all times.
VaultX does not store your master password on any server. If you forget it, your data cannot be recovered by us. We strongly recommend using the SOS Emergency Recovery feature to split your master password into shares and entrust them to people you trust.
| Service | Purpose | Data Shared |
|---|---|---|
| RevenueCat | In-app purchase management | Anonymous user ID, purchase status |
| Apple App Store | Payment processing | Handled directly by Apple — not by us |
| Have I Been Pwned | Password breach checking | First 5 chars of SHA-1 hash only (k-anonymity) |
We do not use advertising networks, behavioral tracking, or analytics services of any kind.
| Permission | Purpose | Required |
|---|---|---|
| Face ID / Touch ID | Biometric vault unlock | Optional |
| iCloud | Encrypted cross-device sync | Optional — Premium |
| AutoFill (Credential Provider) | AutoFill in apps and browsers | Optional |
VaultX does not request access to your camera, microphone, location, contacts, or calendar.
Uninstalling VaultX permanently removes all local data from your device. We hold no copy of it and cannot assist with recovery.
VaultX is not directed at children under the age of 13. The app does not require account creation and does not collect personal information.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the app after any changes constitutes your acceptance of the revised policy.
If you have any questions about this Privacy Policy, please contact us:
Email: prizm_kr@hotmail.com
| Do you require an account? | No |
| Are passwords sent to a server? | No — encrypted locally on your device |
| Are there ads? | No |
| Do you use analytics or tracking? | No |
| Do you sell data? | No |
| Do you share data with third parties? | Only for payment and breach checking (RevenueCat, Apple, HIBP) |
| Can I delete my data? | Yes — in-app or by uninstalling |