Legal
Privacy Policy
Last updated: [DATE]
The short version
Zero-Trust Vault encrypts your data on your own device. We never receive your encryption keys, passphrases, passkey secrets or unencrypted content, so we cannot read, sell or hand over what's inside your vaults. You can use the app without an account, in which case we receive nothing at all.
Who we are
[LEGAL NAME], [ADDRESS] ("we"). Contact: [CONTACT EMAIL].
What stays on your device
- Your secrets and files before encryption, your shards, passphrases and passkey-derived keys.
- Vaults saved to "This device" (browser storage) and your settings.
What we store if you create an account
- Account: your email address, and either a password hash or the sign-in provider you chose (Google, Apple, GitHub or Microsoft). Those providers share your name and email with us; we never see your password for them.
- Cloud vaults: encrypted vault files you choose to upload. Their headers include a vault id, creation time, an optional label you typed, and which unlock methods exist. Contents, file names and file types are encrypted.
- Plan: your plan status and Dodo Payments customer/subscription identifiers. Card details are handled by Dodo Payments and never reach us.
- Legacy (if you use it): your trustees' names and email addresses, your check-in schedule and history, the message you write to them (readable by us so we can deliver it), the ids of vaults to share, and at most one shard you choose to escrow. One shard cannot open a vault.
Waitlist (optional)
If you join the waitlist on our website, we store your email address, the country your request came from (taken from your connection, without keeping your IP address) and which part of the page you used. We use it only to write to you when Pro and Legacy open. We do not sell it or share it. Ask us to delete your address at any time at [CONTACT EMAIL] and we will. The list is kept in our database, which is not readable from the browser.
Google Drive (optional)
If you connect Google Drive, your browser saves encrypted vault files directly to a "Zero-Trust Vault" folder in your own Drive. We use Google's narrowest permission, which only covers files this app creates. The access token stays in your browser for the session and is never sent to our servers. We do not receive or store these files.
Why we use it
- To provide cloud storage, check-in reminders and Legacy delivery you asked for (performance of a contract).
- To process payments and keep records required by law (legal obligation).
- We do not use your data for advertising or profiling, and we do not sell it.
Who processes it for us
- Supabase (database, authentication, encrypted file storage), region [REGION].
- Google, Apple, GitHub or Microsoft, only if you choose to sign in with them.
- Vercel (website hosting and server functions).
- Dodo Payments (payments and tax, as merchant of record).
- Resend (sending reminder and Legacy emails).
Your trustees
If you add trustees, you confirm you may share their contact details with us for this purpose. We contact them only when your plan is released.
Retention
Cloud vaults and Legacy plans are kept until you delete them or your account. Deleting your account removes them. Payment records are kept as long as tax law requires.
Your rights
Depending on where you live, you may access, correct, export or delete your data, and object to or restrict processing. Most of this you can do in the app; for the rest email [CONTACT EMAIL]. You may also complain to your data protection authority.
Security
Encryption happens on your device with AES-256-GCM. Access to stored data is enforced per account by row-level security. The site uses a strict Content Security Policy, loads no third-party scripts and sets no tracking cookies.
Changes
We'll post updates here and, for material changes, email account holders.