Legal

Privacy Policy

Last updated: [DATE]

Template: replace every [BRACKETED] field and have this reviewed by a lawyer for your jurisdiction before launch. Then delete this note.

The short version

Zero-Trust Vault encrypts your data on your own device. We never receive your encryption keys, passphrases, passkey secrets or unencrypted content, so we cannot read, sell or hand over what's inside your vaults. You can use the app without an account, in which case we receive nothing at all.

Who we are

[LEGAL NAME], [ADDRESS] ("we"). Contact: [CONTACT EMAIL].

What stays on your device

What we store if you create an account

Waitlist (optional)

If you join the waitlist on our website, we store your email address, the country your request came from (taken from your connection, without keeping your IP address) and which part of the page you used. We use it only to write to you when Pro and Legacy open. We do not sell it or share it. Ask us to delete your address at any time at [CONTACT EMAIL] and we will. The list is kept in our database, which is not readable from the browser.

Google Drive (optional)

If you connect Google Drive, your browser saves encrypted vault files directly to a "Zero-Trust Vault" folder in your own Drive. We use Google's narrowest permission, which only covers files this app creates. The access token stays in your browser for the session and is never sent to our servers. We do not receive or store these files.

Why we use it

Who processes it for us

Your trustees

If you add trustees, you confirm you may share their contact details with us for this purpose. We contact them only when your plan is released.

Retention

Cloud vaults and Legacy plans are kept until you delete them or your account. Deleting your account removes them. Payment records are kept as long as tax law requires.

Your rights

Depending on where you live, you may access, correct, export or delete your data, and object to or restrict processing. Most of this you can do in the app; for the rest email [CONTACT EMAIL]. You may also complain to your data protection authority.

Security

Encryption happens on your device with AES-256-GCM. Access to stored data is enforced per account by row-level security. The site uses a strict Content Security Policy, loads no third-party scripts and sets no tracking cookies.

Changes

We'll post updates here and, for material changes, email account holders.