VaultKey ("we", "our", or "us") is committed to protecting your privacy. This policy describes what data we collect, how we use it, and your rights regarding that data. By using VaultKey you agree to the practices described here.
1. Information We Collect
VaultKey stores credential data (usernames, passwords, URLs, categories) that you explicitly enter. All credential passwords are encrypted on-device with AES-256-GCM before being transmitted to or stored in Firebase Firestore. We collect: • Your Google account email address (when you sign in with Google) — used solely to associate your encrypted vault with your account. • An anonymous authentication token when you sign in without a Google account (guest/anonymous session). • Device-level analytics automatically collected by Firebase (crash reports, app performance metrics). No personally identifiable information is included in these analytics. We do NOT collect: • Your master password — it never leaves your device in any form. • Plaintext passwords or credentials — all password data is encrypted before transmission. • Location data, browsing history, or any data beyond what is listed above.
2. How We Use Your Information
We use the information we collect solely for the following purposes: • To synchronise your encrypted vault across your authorised devices. • To authenticate you securely via Google Sign-In or anonymous authentication. • To diagnose crashes and improve application stability (via Firebase, where enabled). • To respond to support requests sent to our contact email. We do NOT: • Sell, rent, or share your personal data with third parties for commercial purposes. • Access or attempt to decrypt the content of your stored passwords. • Use your data for advertising, profiling, or marketing purposes.
3. Data Storage & Security
All passwords are encrypted on-device with AES-256-GCM using a key derived from your master password via PBKDF2 (with a unique random salt per account). Only ciphertext is ever transmitted to or stored in Firebase Firestore. On Android, your key material is additionally protected by the hardware-backed Android Keystore via Expo SecureStore. The key never leaves the secure hardware enclave in plaintext. Encrypted data is stored in Google Firebase Firestore. Firebase applies its own security measures including AES-256 encryption at rest and TLS 1.3 in transit. You are solely responsible for maintaining the security of your Google account credentials, master password, and device biometrics. We cannot access, recover, or reset your encrypted vault.
4. Data Retention
Your encrypted vault data is retained in Firebase Firestore until you choose to delete it. You may delete individual credential entries at any time from within the app. To request complete account and data deletion, contact us at support@vaultkey.app with subject "Data Deletion Request". We will process your request within 30 days and confirm deletion. Firebase authentication records (email address and UID) are also deleted upon account deletion. Anonymised, aggregated analytics data may be retained for product improvement purposes.
5. Third-Party Services
VaultKey uses the following third-party services, each governed by their own privacy policies: • Google Firebase Authentication — handles user authentication (Google Sign-In and anonymous sessions). Privacy policy: firebase.google.com/support/privacy • Google Firebase Firestore — stores your encrypted vault data. Privacy policy: firebase.google.com/support/privacy • Google Sign-In — used for OAuth authentication. Privacy policy: policies.google.com/privacy We do not use any advertising networks, analytics platforms beyond Firebase, or data brokers.
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data: • Right of access — request a copy of the personal data we hold about you. • Right to rectification — request correction of inaccurate personal data. • Right to erasure — request deletion of your personal data ("right to be forgotten"). • Right to data portability — request your data in a machine-readable format. • Right to object — object to our processing of your personal data. • Right to restrict processing — request that we restrict how we process your data. To exercise any of these rights, contact us at support@vaultkey.app. We will respond within 30 days. If you are located in the European Economic Area (EEA), you also have the right to lodge a complaint with your local data protection authority.
7. Children's Privacy
VaultKey is not directed at or intended for use by children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children under these ages. If you believe we have inadvertently collected personal information from a child under the applicable age, please contact us immediately at support@vaultkey.app and we will take steps to delete that information promptly.
8. Cookies & Tracking
The VaultKey web application uses only essential storage mechanisms: • sessionStorage — used to maintain your vault session within a single browser tab. This data is cleared when you close the tab or sign out. No personal data is stored in cookies. • localStorage — not used by VaultKey for personal data. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Firebase may set functional cookies required for authentication. See our Cookie Policy for full details.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will: • Update the "Last updated" date at the top of this page. • Post a notice within the application. • For significant changes, notify you via the email address associated with your account (if applicable). Your continued use of VaultKey after changes are posted constitutes your acceptance of the updated policy. If you do not agree to the changes, please discontinue use and contact us to request data deletion.
10. Contact Us
For privacy-related questions, requests, or complaints, please contact us: Email: support@vaultkey.app Subject line: "Privacy Enquiry" or "Data Deletion Request" We aim to respond to all privacy enquiries within 30 days.
Privacy enquiry or data deletion?
We'll respond within 30 days.